The UKs #1 Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

SAR Support

Explore our Subject Access Request (SAR) Handling Service and understand how Data Protection People can support your organisation

Contact Us

Data Protection Support

Data Protection People's world-class GDPR Support Desk. If you're navigating the complex landscape of data protection, PCI DSS, and cybersecurity, our support desk is your reliable compass.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us

Data Protection Audit & GDPR Audit Services

A range of high level reviews, detailed audits and mid-range assessments to test compliance with data protection laws and standards

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

PCI DSS

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Rob Wilkinson answering a call

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

What an Outsourced DPO Actually Does

An outsourced DPO is a qualified Data Protection Officer who works for your organisation without being your employee. You get the same role, the same legal duties and the same point of accountability that an in-house DPO would provide, just delivered as a service rather than a salary.

What a DPO actually does

Under UK GDPR, a Data Protection Officer monitors your organisation’s compliance with data protection law, advises staff and leadership on their obligations, acts as the contact point for the Information Commissioner’s Office (ICO) and handles enquiries from the people whose data you hold. The DPO doesn’t do the processing themselves, they oversee it, flag risk and make sure the organisation can demonstrate it’s meeting its obligations if asked.

Who actually needs one

UK GDPR requires a DPO for public authorities, and for any organisation whose core activities involve large-scale, regular and systematic monitoring of individuals, or large-scale processing of special category data (health records, criminal offence data and similar). Plenty of organisations outside those categories choose to appoint one anyway, generally because they handle enough personal data that having a named, accountable expert reduces real risk, not because the law requires it in their case. If you’re not sure which category you fall into, that’s usually the first question worth answering before deciding on the DPO question at all.

Why organisations outsource the role rather than hire for it

A few reasons come up consistently:

Hiring a full-time, qualified DPO is expensive, and for most organisations there isn’t enough day-to-day work to justify a full salary. An outsourced DPO gives you the expertise at a fraction of the cost of a permanent hire.

An internal DPO can end up with a conflict of interest if they also hold another senior role, since the DPO is meant to operate independently and report any issues without being compromised by their own operational responsibilities elsewhere in the business. An external DPO doesn’t have that conflict.

You get access to a wider team, not just one person. When a DPO works alongside colleagues who specialise in different areas, subject access requests, breach response, DPIAs, you’re covered even when one specific issue falls outside their personal specialism.

It’s also faster to start. Recruiting, vetting, and training an internal DPO can take months. An outsourced service is already in place and already qualified.

What to expect from the service day to day

A properly run outsourced DPO service isn’t a once-a-year sign-off. It should include regular contact with your organisation, advice on specific decisions as they come up (a new supplier, a new system, a marketing campaign that touches personal data), oversight of your data protection processes and direct handling of ICO contact if it’s ever needed. You should always know who your DPO is and how to reach them, the same as you would with an internal hire.

Common misconceptions

An outsourced DPO is not the same as general data protection consultancy. Consultancy is project-based advice, an outsourced DPO is an ongoing, named, accountable role with specific legal duties attached to it. It’s also not a way to transfer legal responsibility away from your organisation, the DPO advises and oversees, but your organisation remains the data controller and carries the ultimate accountability for compliance.

Questions organisations usually ask before appointing one

Can one DPO work for several organisations at once? Yes, this is normal practice for an outsourced service, and it’s specifically permitted under UK GDPR provided the DPO can genuinely prioritise and give each organisation proper attention, and provided there’s no conflict of interest between the organisations involved. A reputable outsourced provider manages this deliberately, not as an afterthought.

What happens if someone internally already handles some of this? Common situation, and not a problem. Many organisations already have someone fielding data protection questions informally, often alongside a completely different job. An outsourced DPO doesn’t replace that person’s day-to-day work, it gives the organisation a properly qualified, independent, named point of accountability that the informal arrangement usually can’t provide, while your existing staff member becomes the internal point of contact the DPO works through.

How is cost usually structured? Typically a fixed monthly or annual retainer based on the size of your organisation, how much personal data you process and how much day-to-day contact you need, rather than being billed hour by hour for every query. This makes budgeting considerably more predictable than either an internal hire or ad hoc consultancy.

What happens if the ICO does contact us? This is one of the clearest reasons to have a DPO in place before you need one. Your DPO handles that contact directly, on your behalf, drawing on experience of exactly this kind of engagement, rather than your organisation trying to manage a regulator conversation for the first time with no one who’s done it before.

Is an outsourced DPO right for your organisation

If you’re required to have one under UK GDPR, the question isn’t whether, it’s how. If you’re not required to but handle a meaningful volume of personal data, weigh the cost of an outsourced service against the actual risk of not having anyone clearly accountable for data protection in your organisation. For most small and mid-sized organisations, outsourcing gives you a properly qualified DPO without the overhead of a full-time role.

If you want to know whether your organisation needs a DPO, or you already know you do and want to see how an outsourced service would actually work for you, our Outsourced DPO service covers exactly this.

Could the UK Really Scrap GDPR and Keep EU Adequacy?

Could the UK Really Scrap GDPR and Keep EU Adequacy?

Reform UK wants a New Zealand-style privacy regime. Would that actually reduce the compliance burden for UK businesses?

Written by Mark Farrell and Gbenga Onojobi.

Reform UK has proposed replacing the UK GDPR with what it describes as a “light-touch” privacy law modelled on New Zealand. The pledge forms part of its Contract with Small Business, published on 26 August 2026, and is presented as a way of reducing the regulatory burden for smaller firms and technology businesses.

At this stage, however, there is no detailed Bill setting out what a replacement regime would contain. The proposal therefore raises more questions than answers. In particular, would a New Zealand-style model significantly reduce compliance costs for UK businesses, what would the wider implications be for data protection in the UK, and could the UK make such a change without putting its EU adequacy status at risk?

What Is Actually Being Proposed?

The proposal is not to remove privacy law altogether. New Zealand has a comprehensive privacy regime under the Privacy Act 2020, but it is structured differently from the UK GDPR.

Rather than using the GDPR’s detailed framework of lawful bases and accountability requirements, New Zealand’s legislation is built around Information Privacy Principles governing how personal information is collected, stored, used, disclosed and transferred. Individuals have rights of access and correction, organisations must report serious privacy breaches, and the regime includes regulatory and enforcement powers.

New Zealand has also continued to develop its privacy framework. Since 1 May 2026, Information Privacy Principle 3A has introduced additional transparency requirements where organisations collect personal information indirectly.

Therefore, “light-touch” should not be read as meaning little or no regulation. New Zealand takes a less prescriptive approach in some areas, but organisations still have legal duties and individuals still have enforceable privacy rights.

Could a New Zealand-Style Model Work in the UK?

In principle, yes. GDPR is not the only possible model for regulating personal information. The fact that the UK recognises New Zealand as offering adequate protection shows that the standard is recognised as sufficient overall.

One reason New Zealand has featured so prominently in the proposal is that it already benefits from an EU adequacy decision. In January 2024, the European Commission concluded that New Zealand continued to provide an adequate level of protection for personal data transferred from the EU. However, New Zealand’s adequacy status does not mean that the UK could simply adopt parts of its legislation and automatically retain its own adequacy decision.

The Commission assesses a country’s framework as a whole. This includes individual rights, regulatory oversight and enforcement, international transfers, and the circumstances in which public authorities may access personal data.

The UK’s own adequacy decision was renewed in December 2025, after the Commission considered the reforms introduced by the Data (Use and Access) Act 2025. The current decision runs until December 2031, subject to continued monitoring.

For UK businesses, adequacy has a clear practical benefit. It allows personal data to flow from the EEA to the UK without organisations having to put additional transfer safeguards in place. If adequacy were lost, many businesses would instead need to rely on mechanisms such as Standard Contractual Clauses.

A reform intended to reduce domestic compliance costs could therefore create a different set of costs if UK-EU data transfers became more complicated.

The UK Has Already Been Reforming GDPR

The Data (Use and Access) Act 2025 has already changed significant parts of the UK data protection framework without replacing the UK GDPR. Its reforms include changes to rules around automated decision-making, recognised legitimate interests, international transfers, subject access, and storage and access technologies such as cookies.

This raises a fair policy question: if the aim is to reduce unnecessary compliance burdens, does that require wholesale replacement of the UK GDPR, or can the UK continue making targeted changes within the existing framework?

In our view, the evidence on burden is mixed. The UK Business Data Survey 2026 found that 90% of businesses handling digitised personal data said data protection law had not prevented them from carrying out any of the activities surveyed. Only 1% specifically reported being prevented from introducing a new or significantly improved product, process or business model. At the same time, 19% said their compliance burden had increased, while 76% said it had remained broadly the same.

Reframing Data Protection as Red Tape Overlooks What the Law Is Actually For

The language used to introduce Reform UK’s pledge, including businesses being “suffocated” and “strangled” by regulation, is entirely cost-focused. It says nothing about what the UK GDPR secures for the people it protects. Some of what could be lost is not simply paperwork.

Of the potential losses should the UK mimic New Zealand’s approach, the right to erasure is perhaps the most significant, as New Zealand’s Privacy Act has no direct equivalent. This is an important privacy remedy that allows individuals to compel the removal of inaccurate or unwanted personal data in many circumstances. It is not merely a compliance formality.

The same is true of mandatory DPIAs, which require organisations to assess risk before deploying high-risk processing. Framing these protections purely as a burden for organisations ignores the imbalance of power they exist to address.

Individuals generally cannot negotiate terms with a bank, employer or advertising technology platform. Rights of access, rectification and erasure are among the main tools available to them. A reform proposal that focuses only on costs to businesses, without considering what protections individuals may lose, fails to engage with an important underlying purpose of data protection law.

A Lighter Penalty Regime May Cost More Than It Saves

The gap between the fine structures of the UK GDPR and New Zealand’s regime is significant, ranging from a ceiling of £17.5 million or 4% of global turnover under the UK GDPR to fines of approximately £4,500 in New Zealand, alongside compensation awards capped at NZ$350,000.

Such a significant reduction in monetary sanctions could weaken the deterrent effect provided by larger fines. This may lead some organisations to take a more relaxed approach to data protection, including slower breach responses, reduced investment in security and less appetite for proactive risk assessment.

Organisations may make compliance savings, but there is a risk that the cost would be passed to individuals through lower standards of protection.

The argument that the EU’s adequacy decision for New Zealand means the UK would retain adequacy if it proceeded with Reform UK’s proposal is not without merit. However, adequacy is monitored continually and should not be treated as a foregone conclusion.

If UK law diverged sufficiently to place adequacy at risk, businesses could lose frictionless data flows with the EU and would need to invest in appropriate safeguards and transfer risk assessments for affected transfers. That cost could fall hardest on the small businesses the policy is intended to help.

Weakening the Regime Now Is a Mistimed Bet Against Emerging Technology

Notably absent from the debate so far is consideration of artificial intelligence and its associated risks, which a robust data protection framework can help to address. This is significant because the safeguards a lighter regime might lack are precisely those increasingly needed for AI-era processing.

Mandatory DPIAs require organisations to scrutinise automated decision-making, profiling and biometric systems before they go live. Removing that requirement would reduce oversight at the same time these systems are scaling rapidly.

The right to erasure also raises new and unresolved questions in an AI context, including whether a person can have their data removed not only from a database but also from a trained model. A regime without a standalone right to erasure may be less equipped to address that question.

A significantly reduced penalty ceiling may also be poorly matched to AI-driven harm, which can affect large numbers of people simultaneously in ways that a relatively small fixed fine cannot reflect.

The more defensible path, and one the UK has already demonstrated through the Data (Use and Access) Act 2025’s changes to automated decision-making provisions, is targeted adaptation within the existing framework rather than a wholesale switch to a lighter regime developed before AI-scale processing existed.

Would Scrapping GDPR Remove Cookie Banners?

Not by itself.

The specific UK rules governing cookies and similar technologies sit mainly within the Privacy and Electronic Communications Regulations 2003, commonly known as PECR. The UK GDPR applies alongside PECR and provides the standard for valid consent where consent is required.

The Data (Use and Access) Act 2025 has already introduced additional exceptions for certain low-risk storage and access technologies. However, removing the UK GDPR alone would not automatically remove cookie consent requirements unless PECR were also changed.

Would UK Businesses Really Leave GDPR Behind?

Not necessarily.

A UK business offering goods or services to individuals in the EU, or monitoring their behaviour there, may still fall directly within the territorial scope of the EU GDPR.

For some internationally active businesses, replacing the UK GDPR could therefore mean complying with a new domestic privacy regime while continuing to meet EU GDPR requirements separately. This is an important part of the wider debate. Simplifying domestic rules does not necessarily mean simplifying compliance for every UK business.

There is also the question of potential cost savings. The idea that a simpler regime would automatically mean lower costs overlooks the fact that the EU GDPR would continue to apply to many UK businesses.

Those businesses may gain little practical or financial relief from a lighter UK regime. Instead, they could be required to meet two distinct standards, potentially at a greater cost than satisfying one.

Where This Leaves Businesses

For now, nothing changes. The UK GDPR, Data Protection Act 2018 and PECR remain the applicable framework, as amended by the Data (Use and Access) Act 2025.

New Zealand demonstrates that GDPR is not the only privacy model capable of receiving an EU adequacy decision. However, replacing the UK GDPR would involve much more than removing lawful-basis assessments or simplifying privacy notices.

Any future regime would still need to answer the same practical questions: what personal information organisations may collect, what they can use it for, how it must be protected, what rights individuals should have, and how personal data can continue to move between the UK and other countries.

The bigger question is therefore not simply whether the UK could scrap the UK GDPR, but whether doing so would actually make compliance simpler for the businesses expected to operate under whatever comes next.

Sources

Reform UK: Reform’s Plan to Rescue Britain’s Small Businesses

Politico: Nigel Farage Wants to Scrap GDPR for the UK

New Zealand: Privacy Act 2020

European Commission: Report on the First Review of Adequacy Decisions, January 2024

European Commission: UK Adequacy Decision Renewal, December 2025

GOV.UK: Data (Use and Access) Act 2025 – Data Protection and Privacy Changes

GOV.UK: UK Business Data Survey 2026

ICO: Guidance on Cookies and Storage and Access Technologies

How DPP Helped Progeny Build a Mature Data Protection and Information Governance Framework

The Challenge

DPP’s engagement with Progeny has centred on establishing and maturing Progeny’s data protection and information governance framework across the Asset and Wealth Management businesses.

What DPP Did

DPP has undertaken a large-scale data mapping project to identify processing activities, data flows, retention requirements, security measures, international transfers and lawful bases for processing. Detailed workshops have taken place with Finance, HR, Marketing, IT, Estates Management, Strategic Operations, Digital and Advisory Services amongst other departments, from which a comprehensive and up to date Record of Processing Activities (ROPA, the internal log of what personal data an organisation holds and why) has been produced.

Alongside the data mapping programme, substantial advisory support has been provided in relation to information governance, privacy compliance and emerging technologies. This has included reviewing and enhancing key policies such as Progeny’s Data Retention and Destruction Standard, Data Classification Standard and DPIA Policy (Data Protection Impact Assessment Policy, the process for identifying and reducing privacy risk before a new project goes live), as well as providing specialist advice on proposed AI integrations to ensure risk management is embedded from the outset. This has involved assessing UK GDPR implications, international transfer considerations, DPIA requirements, staff guidance needs and wider regulatory obligations relevant to the financial services sector.

Additional support has also been provided on data subject rights processes, including SAR (Subject Access Request) and DSAR handling, redaction services, rights request procedures and governance documentation.

The Outcome

Establishing the ROPA has provided the foundation for wider governance initiatives, including the development of an organisation-wide retention schedule and information asset register, which are the focus of recent efforts. This work has helped Progeny continue to develop a more mature and operationalised privacy framework.

DPP continues to work closely with Progeny to mature its data protection and information governance frameworks and drive towards the highest standard of compliance and best practice.

“Mark is really invested in the role he provides as DPO and the Service Desk always reply promptly and with well reasoned responses.”

Martin Ankers, Progeny

Get in touch

If your organisation needs support building or maturing its data protection and information governance framework, DPP’s Outsourced DPO service can help.

Woodgate & Clark Case Study

The Challenge

Woodgate & Clark is a UK loss adjusting and claims management business, supporting insurers with claims across commercial property, specialist property and liability, along with other lines of business. Handling claims at this scale means handling significant volumes of personal data, and W&C’s role shifts depending on the relationship. Sometimes it’s a controller, responsible for its own business activities. Mostly it’s a processor, handling claims on behalf of insurers. In some client relationships it’s a joint controller, sharing responsibility with another organisation.

Following a merger in 2023, different parts of the business were coming together. W&C needed a clear picture of what data protection practices were already in place and where they needed to be aligned across the newly combined organisation.

What DPP Did

DPP started with a detailed compliance audit across the business. The audit found real strengths already in place, including information security, breach management, DPIAs (Data Protection Impact Assessments, used to identify and reduce privacy risk before a new project or process goes live) and data subject rights. It also identified where further work was needed: ROPAs (Records of Processing Activities, the internal log of what personal data an organisation holds and why), privacy information, processor management and international transfers.

From there, DPP worked alongside the W&C team on an ongoing basis, providing support and independent review across:

  • The ROPA
  • Privacy notices
  • Data protection and information security policies
  • Retention arrangements
  • Wider governance

A key part of the work was helping W&C move to a more consistent approach across the whole business. That meant developing a single, consolidated ROPA that reflects how the organisation actually operates today, and that clearly accounts for its different roles as controller, processor and joint controller depending on the relationship.

The Outcome

W&C now has a much more established privacy governance framework and strong internal compliance capability. Most of the original remediation work identified in the audit has been addressed, and core governance documentation is in place. The focus has moved from building the foundations to embedding, maintaining and continually improving them.

Day-to-day data protection work is now largely managed in-house at W&C, with DPP continuing to provide specialist advice, independent assurance and additional support when it’s needed, including ongoing work on the ROPA, LIAs (Legitimate Interest Assessments, used to justify processing personal data under legitimate interest rather than consent), DPIAs and the wider governance framework as the business continues to evolve.

“Everyone is so helpful and friendly and takes the time to understand the specific requirements and challenges of our business.”

Nia Roberts, Woodgate & Clark

Get in touch

If your organisation is working through a merger, acquisition or restructure and data protection compliance needs to catch up, DPP’s Data Protection Support Service can help.

S2 Ep32: GDPR Radio- Data Protection News Of The Week

S2 Ep32: GDPR Radio – Data Protection News of the Week

Caine Glancy and Amber Sivill discuss the latest developments affecting data protection professionals.

In this episode of the Data Protection Made Easy podcast, Caine and Amber examine several stories raising important questions about privacy, cyber security, artificial intelligence and accountability.

Their conversation covers proposed changes to UK data protection law, a cyber incident affecting airport customers, facial recognition technology, smart glasses, personal data breaches and online safety.

Could the UK Replace GDPR?

The episode begins with a discussion about reports that Reform UK wants to replace GDPR with a lighter-touch approach.

Caine and Amber consider whether data protection law genuinely prevents organisations from innovating. They also discuss what weaker enforcement and reduced individual rights could mean in practice.

Amber explains that GDPR is based on principles. This allows organisations to consider the purpose, necessity and risk involved in their processing.

“Whenever you look at anything within GDPR or data protection, it is always a matter of risk, what is proportionate to that risk and what is necessary.”

What Can Organisations Learn From the Airport Cyber Incident?

Caine and Amber discuss a reported cyber incident involving customer information collected through airport Wi-Fi registrations and car park bookings.

The conversation focuses on the volume of information affected, how connected systems can increase the impact of an incident and why organisations should only collect the personal data they genuinely need.

Amber also raises the importance of separating systems and databases. This is known as network segmentation, which means dividing a network into smaller sections to limit unauthorised access.

Should Retention Periods Be Based on Systems or Purposes?

The hosts explore whether organisations should assign retention periods to entire systems or connect them to individual processing purposes.

A single system may hold several types of personal data. Each type may be needed for a different reason and for a different length of time.

“Storage limitation is based on the purpose of processing and how long you require the information for that purpose.”

Amber explains that a more detailed approach can help organisations meet legal requirements and avoid retaining information for longer than necessary.

What Are the Risks of Automated Identity Checks?

The episode examines a case involving an eVisa identification problem which reportedly prevented a UK resident from boarding a return flight.

Caine and Amber consider the risks of relying on automated identity systems. These include inaccurate matches, a lack of effective human review and difficulties correcting errors.

They connect this discussion to the wider use of facial recognition by police forces and other organisations.

Smart Glasses, Facial Recognition and Covert Recording

Caine and Amber discuss smart glasses that can record people or use facial recognition technology.

Although this technology may support accessibility and language interpretation, it can also create privacy concerns when people do not know they are being recorded.

The hosts consider whether every function is necessary and whether useful features could operate without recording or identifying individuals.

Why Does Context Matter When Assessing a Data Breach?

The Metropolitan Police reportedly exposed the email addresses of people receiving updates about the investigation into Mohamed Al-Fayed.

An email address may appear low risk when viewed alone. However, the surrounding circumstances could reveal a connection to an investigation, witness group or affected individual.

“The context is ultimately so important with everything. It is a big decider when assessing risk.”

This example shows why organisations need clear breach-reporting processes. A proper assessment should consider who is affected, what the information may reveal and the possible consequences for those individuals.

Can Better Training Reduce Email-Related Breaches?

Caine and Amber discuss how simple email mistakes can lead to serious incidents, including using CC instead of BCC.

They explain that effective training should build awareness without making employees afraid to report mistakes or ask questions.

“If you do not know something, how do you know it is wrong?”

Staff need practical guidance, clear reporting routes and the confidence to raise concerns quickly.

Age Assurance and the Online Safety Debate

The episode closes with a discussion about age-assurance measures under the Online Safety Act.

Caine and Amber consider whether strict controls could push children towards less responsible websites. They also discuss the challenge of protecting children without creating systems that people simply try to bypass.

The discussion highlights the need for proportionate controls which protect users while recognising how people behave online.

Key Takeaways

  • Data protection law allows organisations to assess risk and act proportionately
  • Organisations should only collect personal data they genuinely need
  • Retention periods should reflect the purpose of processing
  • Automated identity systems need accuracy checks and effective human oversight
  • The context of a breach can make seemingly ordinary information highly sensitive
  • Training should help employees recognise and report mistakes without creating fear
  • New technologies need privacy safeguards from the beginning

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He brings practical insight from supporting organisations with their everyday data protection responsibilities.

Amber Sivill

Amber joins Caine to examine the practical risks behind the latest data protection stories and explain what organisations should consider.

About the Data Protection Made Easy Podcast

The Data Protection Made Easy podcast turns complex privacy and data protection topics into clear, practical conversations.

GDPR Radio examines recent news, regulatory developments and emerging technology to help organisations understand what has happened and why it matters.

S2 Ep31: What Happens When Your DPO Is OOO?

S2 Ep31: What Happens When Your DPO Is OOO?

The hidden liability gap: what happens when your DPO leaves?

Your organisation’s data protection responsibilities do not pause when its Data Protection Officer is unavailable.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Gbenga Onojobi discuss how organisations can maintain accountability when their DPO is on annual leave, absent unexpectedly or has left the organisation.

The Latest Data Protection News

Before exploring the main topic, Caine and Gbenga discuss several recent stories from across data protection and technology.

  • The proposed use of live facial recognition at Scottish football matches
  • The importance of human review when automated systems identify people
  • Concerns about addictive features on social media platforms
  • Unauthorised access to patient records by a former NHS employee

The discussion highlights a recurring concern. Technology may support decision-making, but organisations still need appropriate oversight, accountability and safeguards.

Does Accountability Leave With the DPO?

A DPO may take annual leave, become unwell, resign or retire. An outsourced DPO arrangement may also come to an end. However, the organisation remains responsible for its data protection compliance.

“The DPO leaving or being out of office does not remove the organisation’s responsibility. Accountability does not leave with them.”

Gbenga compares the DPO to a navigator on a ship. The navigator advises on the route and watches for danger, but the captain and the organisation remain responsible for the journey.

Why Organisations Need a Continuity Plan

Organisations need to plan for temporary and permanent DPO absences. Staff should know who can provide advice, receive an escalation and take ownership of urgent work.

This is particularly important for matters with strict deadlines, including personal data breaches, subject access requests and other individual rights requests.

“Being able to have another trusted individual who helps you, whether that is upwards or downwards, is really quite vital.”

Policies and procedures should explain what happens when the usual DPO contact is unavailable. The plan may involve a deputy, trained managers, data champions or access to external data protection support.

Data Protection Is Not One Person’s Responsibility

Caine and Gbenga discuss the risks of allowing every data protection matter to sit with the DPO.

Senior leaders remain accountable. Managers and staff also need to understand how data protection applies to their work and when an issue must be escalated.

Training should reflect each person’s responsibilities. Board members, managers, data champions and frontline staff do not need identical training. They need practical knowledge that helps them recognise and manage the situations they may face.

Independence and Conflicts of Interest

When a DPO leaves, appointing the nearest senior employee may appear to solve the immediate problem. However, organisations must consider whether that person has the necessary expertise, time and independence.

A person should not be expected to make decisions about how personal data is used and then independently monitor their own decisions.

“Organisations should not solve a vacancy by creating an additional conflict. A rushed appointment may fill the box while leaving the organisation with a DPO who cannot properly perform the role.”

Protecting Time-Sensitive Work

A subject access request can arrive anywhere in an organisation. It may be sent to HR, reception, a manager or through social media. It may also be made verbally.

The individual does not need to use the words “subject access request” for the request to be valid. This means staff need to recognise a possible request and know where to send it, even when the DPO is unavailable.

Clear ownership and an appropriate quality assurance process can reduce the risk of missed deadlines, inappropriate disclosures or information being withheld incorrectly.

Questions to Ask Your Organisation

  • Who provides cover when the DPO is unavailable?
  • Do staff know where to send urgent data protection matters?
  • Who monitors subject access request and breach deadlines?
  • Are key decisions, risks and responsibilities properly recorded?
  • Does any temporary replacement have suitable expertise and independence?
  • Can the organisation access additional support when internal capacity is limited?

The Final Takeaway

“A DPO leaving an organisation should not create a compliance vacuum. The organisation itself remains accountable.”

Good continuity means recording important knowledge, clearly allocating responsibilities and making sure somebody suitable is ready to step in.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He brings practical insight from helping organisations manage everyday data protection questions, breaches and individual rights requests.

Gbenga Onojobi

Gbenga is a Data Protection Consultant at Data Protection People. He supports organisations with practical compliance, governance and data protection risk management.

Watch or Listen

📺 Watch on YouTube: https://youtu.be/hqokBvSh-Ho

🎧 Listen on Spotify: https://open.spotify.com/episode/7ukmE70eDsPsMYQG39O8kf

S2 Ep30: GDPR Radio – Data Protection News of the Week

S2 Ep30: GDPR Radio – Data Protection News of the Week

Practical discussion on the latest data protection news

In this episode of GDPR Radio, Caine Glancy and Catarina Santos discuss recent developments affecting data protection, workplace monitoring, media reporting and information security.

They explore the risks behind misleading headlines, AI systems that claim to detect employee emotion, smart glasses and a reported NHS data breach involving an unsecured pager network.

What This Episode Covers

  • A Court of Appeal decision on misleading headlines and the fair processing of personal data
  • Why images and headlines can shape public perception before people read the full story
  • AI emotion-detection tools and the risks of monitoring employees based on facial expressions, voice or body language
  • Why organisations must consider necessity, fairness, transparency and less intrusive alternatives before introducing workplace monitoring
  • Smart glasses, hidden recording and the need for clear acceptable-use policies
  • Lessons from a reported NHS pager network data breach
  • Why access controls, staff awareness and practical policies all matter

Key Discussion Points

“Someone who only saw the headlines and photographs together could just reasonably get the impression that actually it was Vince, the person that the article was referring to.”

The hosts discuss why data protection law can apply even where a full article clarifies the facts. The way a headline, image and article appear together can still affect whether personal data has been processed fairly.

“Could you not achieve the same objective with a completely less intrusive way?”

Caine and Catarina question the value of emotion-detection technology in the workplace. They explore why one-to-one conversations, objective work outputs and appropriate management may be more proportionate than analysing an employee’s voice, face or behaviour.

“Technical controls can only go so far, which is why the emphasis in the law is on technical and organisational measures.”

The episode also looks at why information governance needs to work in practice. Policies must reflect how an organisation operates, staff need to understand them and clear action needs to follow when rules are not followed.

Why This Episode Matters

Data protection risks do not always start with a major cyber incident. They can arise through misleading content, new workplace technology, weak access controls or policies that exist on paper but are not understood in practice.

This episode helps organisations consider where their own controls may need attention and why proportionate, people-focused

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Artificial intelligence is changing how Data Protection Officers work.

AI tools can help with research, training, risk assessments and routine administration. However, they can also produce inaccurate advice, encourage confirmation bias and create new governance risks.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss how AI is affecting DPO workloads and why professional knowledge and meaningful human oversight remain essential.

What Does This Episode Cover?

During the episode, Caine and Amber discuss:

  • The increase in AI-generated Subject Access Requests
  • How AI is affecting DPO workloads
  • The risks of using AI for data protection advice
  • How AI could support RoPAs, DPIAs and LIAs
  • The importance of checking AI-generated policies
  • Confirmation bias in AI responses
  • Why human oversight and professional knowledge still matter

How Is AI Affecting Subject Access Requests?

The discussion explored the growing number of Subject Access Requests, or SARs, that appear to have been generated using AI.

These requests can look formal and detailed. However, they may ask for information that does not fall within the normal scope of a SAR.

Amber explained:

“It also fuels a lot of misunderstanding. A lot of the time, you see a request and most of it does not even fall under the scope of what a SAR generally covers.”

Caine also shared that SAR-related cases handled through the DPP Support Desk have increased significantly.

AI may make it easier for people to create requests, complaints and follow-up correspondence. This can place additional pressure on data protection teams, particularly where requests are vague or based on incorrect information.

Can DPOs Rely on AI for Data Protection Advice?

AI can provide a useful starting point. However, it should not replace professional knowledge.

Amber explained:

“You need to have the base knowledge in order to be able to use these systems.”

An experienced practitioner may recognise when an AI response refers to the wrong legislation, misses important context or provides an answer that is too confident.

Someone with less experience may not spot those problems.

Data protection decisions are rarely black and white. The correct answer often depends on the organisation, the processing activity and the people who may be affected.

Could AI Support RoPAs, DPIAs and LIAs?

AI may help DPOs complete some routine or administrative tasks.

For example, it could help pre-populate a Record of Processing Activities, or RoPA, using information about an organisation’s activities and data sharing.

It may also provide a starting point for a Data Protection Impact Assessment, or DPIA, and a Legitimate Interests Assessment, or LIA.

However, organisations must consider what information they enter into an AI system. DPIAs and other assessments may contain sensitive or confidential information.

Amber said:

“There is a limit as to what you can provide the model with in terms of confidentiality and not oversharing any information.”

Any AI-generated assessment must be checked against the organisation’s actual processing, systems and risks.

Why Does Human Oversight Matter?

AI can produce clear and convincing answers even when those answers are incomplete or incorrect.

It may also agree with the direction of a prompt instead of challenging the user’s assumptions. This is known as confirmation bias, which means favouring information that supports an existing view.

Caine explained:

“It is a fantastic tool that will hopefully be able to help in the role as a DPO. But what matters is that you can supplement it with your pre-existing knowledge.”

Amber added:

“The human element needs to be someone overlooking it who actually knows what they are talking about.”

Human oversight must be meaningful. The person reviewing an AI output needs the knowledge and authority to identify problems, challenge the result and make the final decision.

Is an AI-Generated Policy Better Than No Policy?

An AI-generated policy is not useful simply because it exists.

A policy must reflect how the organisation actually works. It must be practical, accurate and followed by staff.

Amber explained:

“If you have a policy in place and it does not align with your business, it is not workable and people are not following it, then there is ultimately not really anything there in place anyway.”

AI may help structure a first draft. However, the final policy should be reviewed by someone who understands the organisation, its legal duties and its operational risks.

What Should DPOs Take Away?

AI can support DPOs, but it should not replace them.

Organisations should:

  • Use AI to support work rather than make final decisions
  • Check AI outputs against current law and ICO guidance
  • Avoid entering unnecessary personal or confidential information
  • Keep meaningful human oversight in place
  • Document how AI tools are approved, monitored and reviewed
  • Make sure policies and assessments reflect real business practices

The DPO role is becoming broader and more connected to technology, governance and organisational risk.

AI creates opportunities to work more efficiently. It also makes professional judgement, scepticism and accountability more important.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He works with organisations every day to help them understand and respond to practical data protection challenges.

Amber Sivill

Amber is a Data Protection Consultant at Data Protection People. She supports organisations with data protection compliance, governance and emerging technology risks.

Watch or Listen to the Episode

Watch the full episode on YouTube or listen on Spotify.

Watch on YouTube

Listen on Spotify

Need Support With AI Governance?

If your organisation is adopting AI, Data Protection Made Easy can help you understand the risks, strengthen governance and meet your data protection responsibilities.

Contact Our Team

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
_GDPR Radio - Data Protection News of the Week
23 October 26 12:30 - 1:15 pm

S2 Ep40: GDPR Radio – Data Protection News of the Week

Why Most DPIAs Get Signed Off Too Late to Matter
16 October 26 12:30 - 1:15 pm

S2 Ep39:Why Most DPIAs Get Signed Off Too Late to Matter

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.