UK Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

SAR Support

Explore our Subject Access Request (SAR) Handling Service and understand how Data Protection People can support your organisation

Contact Us

Data Protection Support

Data Protection People's world-class GDPR Support Desk. If you're navigating the complex landscape of data protection, PCI DSS, and cybersecurity, our support desk is your reliable compass.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us

Data Protection Audit & GDPR Audit Services

A range of high level reviews, detailed audits and mid-range assessments to test compliance with data protection laws and standards

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

PCI DSS

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Caratina consulting

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

ASOS App Notification: What We Know and What Remains Unclear

Getting a notification through an app like ASOS seems like fairly standard practice, whether it’s informing you about new deals on that jacket you’re eyeing up or reminding you about its current offers and deals but I’d bet you wouldn’t expect that notification to announce that ASOS had been hacked. The issue with this news piece now is that whilst this notification is alarming it does not, by itself, show what systems or data may have been compromised.

ASOS customers received a notification through the retailer’s app on 6 October saying the company had been “hacked”. The notification itself has currently been described as fraudulent by a customer service representative. A report by Sky News said the message claimed an attacker had compromised a Snowflake instance and threatened to leak information.

At this point, the notification and the claims in it do not establish what happened beyond the message being sent through the app. The extent of any risk, and whether any data or systems were affected, remains unclear.

What does the notification tell us?

It tells us that customers received a threatening message through a channel they would normally associate with ASOS. It does not confirm the attacker’s claims or establish whether personal data was accessed, although in this instance it does seem incredibly likely.

During a developing incident of this size, organisations and customers need to know what is confirmed, what is being investigated and what remains unknown. Treating an unverified claim as fact could mislead people and that will be the last thing ASOS will want to do but dismissing it without evidence could also leave them unprepared.

What remains unknown?

The information available at this point does not establish what systems or accounts may have been affected, whether personal data was accessed or taken, or what risk there may be to customers. Until more information is available, the claims in the notification should be treated as unconfirmed. The risk cannot be assessed from the notification alone.

What should organisations connected to ASOS do?

There is no specific action for organisations generally based on the notification alone. However, any organisation that uses ASOS as a supplier should stay alert for further information and carry out its own fact-finding as details emerge.

That means checking whether any data it shared with ASOS could be affected, using reliable information as it becomes available. The notification by itself does not show that supplier data has been affected.

Trust depends on clear updates

A threatening message through a familiar app can create uncertainty, even when the message itself is described as fraudulent. In this case, the available information does not yet show the extent of any risk or what, if anything, was compromised.

As more information becomes available, updates should distinguish confirmed facts from claims that remain under investigation. For organisations with a supplier relationship, careful fact-finding can help establish whether their own data may be affected.

One thing I would recommend is that people steer away from making a purchase at this point in time until we know more about the scope and severity of this incident.

Need support with data protection or cyber security? Contact Data Protection People to discuss how we can help.

Cyber Incident Reporting in Financial Services

When a financial services firm suffers a cyber incident, the first question is usually technical: what has happened, and how do we contain it? Close behind comes a regulatory question that is getting harder to answer: who do we have to tell, and by when?

For years the data protection answer has been familiar. Report a personal data breach to the ICO within 72 hours. From 18 March 2027, most FCA-regulated firms will also have a 24-hour operational incident reporting duty. And the Cyber Security and Resilience Bill, now in the House of Lords, will put many of the sector’s key technology suppliers under their own 24-hour regime.

Each regime has its own test, its own regulator and its own clock. In this post we look at how they fit together, where they diverge, and what firms can do now so that one incident does not become three separate scrambles to provide information.

The Three Clocks

The table below sets out the three regimes side by side. The FCA regime applies directly to regulated firms. The Cyber Security and Resilience Bill mainly reaches financial services firms through their suppliers.

Cyber Incident Reporting: Three Regimes Compared
Reporting Requirement UK GDPR FCA/PRA Operational Incident Reporting Cyber Security and Resilience Bill
Who reports Controllers (processors tell their controller) All firms with a Part 4A permission, payment service providers and some others Operators of essential services, plus newly in-scope data centres and medium and large managed service providers
What triggers it A personal data breach likely to result in a risk to people’s rights and freedoms An operational incident the firm reasonably believes poses a risk of intolerable consumer harm, to safety and soundness, or to market stability and integrity A significant incident, including some incidents that could have had a significant impact
First report due Without undue delay and, where feasible, within 72 hours of becoming aware As soon as practicable, expected within 24 hours of deciding a threshold is met (4 hours from detection for payment service providers) Initial notification within 24 hours, full report within 72 hours
Report to ICO (and affected individuals where the risk is high) FCA via Connect, one submission shared with the PRA where relevant The sector regulator, copied to the NCSC (and affected customers for data centres and managed service providers)
Status In force Applies from 18 March 2027 In the House of Lords; detail to follow in secondary legislation

Two details stand out. The FCA clock runs from when the firm decides a threshold is met, while the ICO clock runs from when it becomes aware of a breach. And the FCA rules expressly treat loss of confidentiality of customer data as a type of operational incident, so a data breach can engage both regimes at once.

Different Tests, Different Answers

The regimes ask different questions. UK GDPR asks about risk to individuals. The FCA asks about serious harm to consumers, firms and markets. The Bill asks about the security and continuity of essential services. So the same incident can be reportable to one regulator and not another.

A few scenarios show how this plays out:

  • A misdirected email. Fifty customers’ account statements are sent to the wrong recipient. That is very likely a reportable personal data breach. It is unlikely to meet the FCA’s thresholds, which the FCA says are intended only for serious incidents.
  • Ransomware without exfiltration. Systems are encrypted and customers cannot access services for a day, but no data leaves the firm. This may well meet the FCA’s consumer harm threshold. It is also a personal data breach, because loss of availability counts, and whether it is reportable to the ICO depends on the risk to individuals.
  • A blocked intrusion. An attacker gets into a supplier’s network but is stopped before reaching customer data. There is no personal data breach and nothing for the FCA, which has said firms do not have to report near misses under these rules. But the supplier may have a duty under the Bill, which captures some incidents by their potential impact.

The FCA has also said firms must not skip a report just because an incident falls below their internal severity rating. It points to signals such as involving a Senior Manager or activating crisis procedures as signs a threshold may be met. In our view, those same signals should prompt a fresh look at the data protection position too.

There is a structural point as well. FCA reports are made per regulated entity, so a group with several authorised firms may need several reports. Under UK GDPR, the question is which entities are controllers of the affected data. The two answers will not always match.

Your Suppliers May Report First

Third parties are now central to incident risk in financial services. The FCA says incidents originating at third parties have recently been the top root cause for firms. It also says over 40% of the cyber incidents reported to it in 2025 involved a third party.

Most financial services firms are not themselves in scope of the NIS regime. Many of their suppliers soon will be. The Bill brings in data centres above set capacity thresholds and medium and large managed service providers, such as outsourced IT, helpdesk and managed security providers. Those suppliers will have their own 24-hour duty to notify their regulator and the NCSC, and a duty to tell affected customers.

That creates an awkward possibility. A supplier could be reporting an incident to a regulator before its financial services customer has been told about it, let alone worked out what it means.

For the data protection team, this is where Article 28 contracts matter. A processor must tell the controller about a personal data breach without undue delay. Contracts often give processors longer than a firm can now afford, and some say nothing about incidents that do not involve personal data. A firm facing a 24-hour FCA expectation needs supplier clauses that match. The FCA reporting form even asks firms to name the third party where an incident originated with one.

One Incident, One Story

The biggest practical risk is not missing a deadline. It is telling different regulators different things.

In the first hours of an incident, facts are thin and change quickly. A firm might tell the FCA at hour 20 that no customer data appears to be affected, then tell the ICO at hour 70 that data was exfiltrated. Both reports may be accurate when made. But read side by side, they can look like a firm that was slow, confused or less than candid.

Regulators may compare notes. The FCA’s enhanced reporting form asks which other regulatory bodies have been notified. The FCA’s rules on inaccurate, false or misleading information apply to these reports. And Principle 11 requires firms to deal with the FCA openly.

Customers are a fourth audience. Under UK GDPR, people must be told without undue delay where a breach is likely to result in a high risk to them. Under the Bill, data centres and managed service providers will have to tell affected customers too. What customers hear should line up with what regulators hear.

The answer is a single incident record that every report draws from. It should log what was known and when, and be updated as facts change. Each regulator then gets a report tailored to its own test, but built on the same facts and timeline.

What to Do Before 18 March 2027

The FCA has given firms 12 months to prepare, and around half of that has already gone. These are the steps we would prioritise.

  • Build one triage process. At the first sign of an incident, run the UK GDPR, FCA and (for suppliers) Bill tests together, rather than in separate teams at separate times.
  • Put the DPO in the room early. The data protection assessment should start in the first hours, not once the operational picture has settled.
  • Record decisions and timings. Log when the firm became aware of a breach and when it decided an FCA threshold was met. Those are different moments, and each regulator will ask about its own.
  • Map reporting entities. Work out which group entities are FCA-regulated reporting firms and which are controllers, before an incident forces the question.
  • Review supplier contracts. Check that breach and incident notification clauses are fast enough for a 24-hour clock and cover incidents that do not involve personal data.
  • Prepare holding wording. Draft template reports for the ICO, the FCA and customers that share a common factual core.
  • Test it. Run a test exercise against all three clocks, including a scenario that starts at a supplier.

Final Thoughts

Cyber security, operational resilience and data protection have often been run by different teams with different playbooks. The new reporting landscape makes that harder to sustain. One incident can now engage three regimes within the same three days.

Firms that treat this as one problem, with one triage process, one incident record and one set of facts, will find the clocks much easier to manage.

If you would like help aligning your breach response and incident reporting ahead of March 2027, get in touch with our financial services team at Data Protection People.

Sources

How Should Charities Handle Complex Subject Access Requests?

Charities handling complex Subject Access Requests (SARs) need to identify the requester’s personal data while carefully considering third-party information, safeguarding concerns, confidentiality and any exemptions that apply.

  • Complex charity SARs often involve third-party data and safeguarding information.
  • Redaction should protect other people’s personal data without unnecessarily removing the individual’s information.
  • Whistleblower, multi-agency and child SARs may require additional consideration.
  • Assess the scope and circumstances of each SAR on a case-by-case basis.

How Should Charities Handle Third-Party Data in SARs?

Third-party data in a charity SAR should be considered separately from the individual’s own personal data, with relevant information redacted where disclosure would unfairly reveal another person’s information. Failure to redact third-party information effectively could lead to a data breach.

How Do You Redact Third-Party Information in a Safeguarding File?

Safeguarding records may contain the individual’s information alongside information about beneficiaries, family members, staff or other individuals. Charities should first assess which information is not the individual’s, then redact it using appropriate software, or use a SAR support service that offers review and redaction services.

Do personal WhatsApp messages or private emails need to be included?

Communications on a private account or messaging platform are not automatically excluded. If they have been used to discuss charity business and may contain relevant personal data, then they should be included in the SAR. Charities should focus on identifying relevant records and assessing them appropriately.

How Should Charities Handle Safeguarding and Whistleblower SARs?

Safeguarding and whistleblower SARs require careful consideration because disclosure may expose another person or compromise sensitive information.

How do you protect a whistleblower when their information appears in a SAR?

Where the individual is an alleged perpetrator, and the file contains whistleblower information, charities can either redact the whistleblower’s personal information or apply relevant exemptions (such as mixed personal data or confidentiality rules) under data protection laws.

If disclosing those documents would breach legal confidentiality obligations or compromise a protected public-interest disclosure, then you have grounds to apply exemptions.

Should a charity disclose a full multi-agency meeting record?

When a meeting involves the council, the police and the charity, for example, it can be tricky to understand what can be disclosed. Charities should consider both third-party information and their own records rather than assuming the entire document must be disclosed.

When Can a Charity Limit or Refuse a SAR?

A charity may be able to limit or refuse disclosure in specific circumstances, but this depends on the nature of the request, the information involved and the relevant legal requirements.

What should a charity do when a former volunteer submits a SAR after a dispute?

Respond as normal. A dispute doesn’t automatically remove the right of access, so charities should focus on identifying the individual’s personal data and considering any applicable exemptions.

When is a repeat SAR manifestly excessive?

A repeat SAR is manifestly excessive when it duplicates the contents of a previous request and a reasonable interval has not passed, or when it substantially overlaps with pending requests without any change in circumstances, new data or a legitimate reason from the individual.

It’s not excessive if the previous response was mishandled or if new information has come to light.

Who can make a SAR for a child or another person?

A SAR for a child, or another person, can only be made by a third party with the appropriate legal authority or clear consent. For example, for a child under the age of 12, a person with parental responsibility can make the SAR on their behalf, provided it is in the child’s best interests. Charities should weigh up confidentiality, court orders and the child’s welfare before releasing anything.

When it comes to making a SAR for another adult, any adult can submit a request, provided they have proof of authorisation or consent from the data subject. If the adult lacks the mental capacity to manage their own affairs, a registered Lasting (or Enduring) Power of Attorney can cover property, financial or health matters. Alternatively, a person who has been formally appointed by the Court of Protection can put in a request on their behalf.

What Should Charities Check Before Responding to a Complex SAR?

Before responding, charities must check:

  • Identity and authority – Confirm the individual’s identity or ensure that a third party has the correct authorisation.
  • System check. Charities should search all digital, physical and third-party platforms where data might reside, including emails, case management systems and donor databases.
  • Clarification needs. Decide whether the request is broad or ambiguous, and if appropriate, contact the individual to narrow the scope (without breaching statutory rules).
  • Third-party data and redaction. Identify and redact information belonging to other individuals.
  • Statutory exemptions. Review whether any specific exemptions apply and document the rationale for any withheld data.
  • Extension timeline. Assess whether a two-month extension is needed due to complexity, but remember to inform the individual within the initial one-month window.

Get Charity SAR Support With Data Protection People

We understand the pressures charities face when it comes to complex SARs. Whether it’s tight budgets, small teams or both, we can help support charities in a number of areas, including e-discovery of relevant documents, review and redaction or optimising processes within your team. Get in touch today.

WASPI UK GDPR Code of Conduct: What It Means for Public Service Data Sharing

The ICO has approved a UK GDPR code of conduct for information sharing between public services in Wales. The Wales Accord on the Sharing of Personal Information (WASPI) code was approved on 24 September 2026 and announced on 28 September 2026.

What happened?

WASPI is an existing framework that helps organisations in Wales share personal information safely. More than 1,000 organisations are already signed up to it, according to the ICO.

Its new code of conduct has now been approved under Article 40 of the UK GDPR. A code of conduct is a set of sector rules, approved by the regulator, that shows how data protection law applies in practice. Members who follow an approved code have a recognised way to show accountability. The ICO’s Chris Hogan described it as “a clear and recognised way to demonstrate accountability”.

The key facts, from the ICO’s register of codes:

  • Reference: ICO-CC/002
  • Approved: 24 September 2026
  • Code owner: Digital Health and Care Wales
  • Monitoring body: the WASPI Service, which is still pending ICO approval

What does the code cover?

The code covers sharing personal information to deliver health, education, social care, safeguarding and other public services to people in Wales.

Code members must:

  • use the WASPI information sharing protocol (ISP) template, a standard document that sets out what is shared, why and how
  • put governance controls in place
  • go through a quality assurance process
  • accept ongoing monitoring
  • review their information sharing arrangements regularly

Who does it affect?

The code applies to organisations that share personal information to deliver public services in Wales and choose to sign up. That includes:

  • schools and education providers
  • social care providers
  • local authorities
  • health bodies
  • housing providers
  • charities and voluntary organisations working alongside public services

The code concerns information sharing for services to people in Wales. An organisation’s address alone does not decide eligibility: check the code’s membership criteria with WASPI, particularly for cross-border arrangements. Organisations elsewhere can still use its approach as a prompt to review their own practices.

Why does it matter?

Sharing information between services is where data protection often goes wrong. Some staff hold back information that should be shared, for example in a safeguarding case. Others share without a clear lawful basis or a written agreement.

A code gives everyone the same template and the same checks. That makes it easier for staff to share with confidence and easier for organisations to prove they got it right.

Does joining WASPI replace your UK GDPR responsibilities?

No. A code supports accountability; it does not supply a lawful basis for every disclosure or remove your responsibility to assess each sharing arrangement. Record the purpose, lawful basis, safeguards and responsibilities before sharing.

What should organisations do now?

If you work in Wales and already use WASPI:

  • Check your information sharing protocols use the current WASPI template.
  • Make sure each protocol has a named owner and a review date.
  • Watch for the monitoring body’s approval. The regulator’s register still lists approval of the monitoring body as pending at the time of this review.

If you work in Wales and don’t use WASPI:

  • List the organisations you regularly share personal information with.
  • Consider whether joining the code would give you a clearer, consistent way to document that sharing.

If you work elsewhere in the UK:

  • Review your data sharing agreements. Are they current, consistent and easy for staff to find?
  • Compare them with the ICO’s data sharing code of practice, which applies across the UK.

For one-off requests, such as from the police, see our guide to ad-hoc data sharing requests.

How DPP can help

We support local authorities and schools, academies and colleges with data sharing agreements, DPIAs and day-to-day data protection advice. If you’d like a review of your information sharing arrangements, talk to our team about the support you need.

Discuss your information sharing arrangements

Sources and further guidance

WASPI entry in the ICO’s register of approved codes

Regulator announcement, 28 September 2026

Content reviewed: 2 October 2026.

S2 Ep38: AI Systems and DPIAs

S2 Ep38: AI Systems and DPIAs

Can AI help you write a Data Protection Impact Assessment? And how do you assess the privacy risks of the AI system itself?

In S2 Ep38 of Data Protection Made Easy, Caine Glancy and Catarina Santos (Cate) explore both sides of the conversation: carrying out DPIAs for AI projects and using AI to help prepare an assessment.

What We Discuss

  • Understanding how an AI system uses personal data, including its inputs, outputs and who can access them.
  • Asking practical questions about suppliers, retention and where information goes.
  • Using AI to organise information, suggest questions and identify gaps in a DPIA.
  • Why project-specific information and human review remain important.
  • Setting clear boundaries for how staff use AI tools.

Join Cate and Caine for a practical discussion about making informed decisions, checking assumptions and keeping people involved in the assessment process.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Join Our Community

Our free Friday sessions bring people together to discuss data protection topics, share practical advice and ask questions.

Explore Upcoming Sessions

Need Support With Your DPIA?

Our DPIA service helps you identify and assess privacy risks in new projects, systems or processes. We work with your team to document the assessment and recommend practical measures to reduce risks and support informed decisions.

Contact Data Protection People

S2 Ep37: Sector Spotlight Ep1: Caught Between the FCA and UK GDPR – What DPOs Need to Know

Sector Spotlight Ep1: Caught Between the FCA and UK GDPR – What DPOs Need to Know

Financial services businesses face overlapping responsibilities. How do they bring financial regulation and data protection together in practice?

In the first episode of Sector Spotlight, DPP’s Mark Farrell joins Phillip Garlick, CEO of Product Partnerships Limited (PPL), to discuss the relationship between FCA requirements and UK GDPR.

Created as part of the partnership between Data Protection People and PPL, this episode brings together perspectives on data protection, retail finance and the practical realities of running a regulated business.

Explore the Conversation

Our promotional clips explore financial promotions, whether good compliance can support business growth, the cost of compliance in the financial sector, and AI’s promise and peril in data protection.

Watch or listen to the full episode to hear the wider conversation with Mark and Phillip.

Meet Phillip Garlick

Phillip is the CEO of Product Partnerships Limited, which delivers retail financial solutions and compliance support to consumer-facing businesses. PPL helps these firms offer finance to their customers and manage the regulatory responsibilities that come with it.

He has over 30 years’ experience in regulated, consumer-facing sectors, with a strong focus on governance, risk management and sustainable growth.

Phillip is a practising Chartered Director and Fellow of the Institute of Directors. He holds an Advanced Certificate in Governance & Risk from the International Compliance Association and an MBA from Leeds University.

About Sector Spotlight

Sector Spotlight is a separate series within Data Protection Made Easy, exploring data protection through conversations focused on particular sectors. This is episode 1 of the series, rather than an episode in our regular Season 2 numbering.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Need Data Protection Support?

If your organisation needs help navigating its data protection responsibilities, speak to our team about the support available.

Contact Data Protection People

S2 Ep36: GDPR Radio – Data Protection News of the Week

S2 Ep36: GDPR Radio – Data Protection News of the Week

Cate and Caine are back together on GDPR Radio, and Cate marks the occasion with a little singing before the conversation gets underway.

In S2 Ep36 of Data Protection Made Easy, Caine Glancy and Catarina Santos catch up on data protection news and share practical perspectives on what it means for organisations.

Expect a friendly discussion, familiar faces and plenty of conversation about the world of data protection.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Join Our Community

Our free Friday sessions bring people together to discuss data protection topics, share practical advice and ask questions.

Explore Upcoming Sessions

Need Data Protection Support?

If your organisation needs help with a data protection question or challenge, speak to our team about the support available.

Contact Data Protection People

S2 Ep35: AI Redaction Tools: The Mistakes Most SAR Systems Miss

S2 Ep35: AI Redaction Tools: The Mistakes Most SAR Systems Miss

AI redaction tools promise to make handling subject access requests easier. But what might they miss?

In S2 Ep35 of Data Protection Made Easy, Amber Sivill and Katerina Douni discuss AI redaction tools and the challenges organisations face when using them to support SAR responses.

Join them for a practical conversation about technology, redaction and the importance of checking information before it is shared.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Join Our Community

Our free Friday sessions bring people together to discuss data protection topics, share practical advice and ask questions.

Explore Upcoming Sessions

Need Support With Subject Access Requests?

If your organisation needs help managing subject access requests or reviewing its redaction process, speak to our team about the support available.

Contact Data Protection People

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
_GDPR Radio - Data Protection News of the Week (1)
23 October 26 12:30 - 1:15 pm

S2 Ep41: GDPR Radio – Data Protection News of the Week

Why Most DPIAs Get Signed Off Too Late to Matter
16 October 26 12:30 - 1:15 pm

S2 Ep40:Why Most DPIAs Get Signed Off Too Late to Matter

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.