UK Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

SAR Support

Explore our Subject Access Request (SAR) Handling Service and understand how Data Protection People can support your organisation

Contact Us

Data Protection Support

Data Protection People's world-class GDPR Support Desk. If you're navigating the complex landscape of data protection, PCI DSS, and cybersecurity, our support desk is your reliable compass.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us

Data Protection Audit & GDPR Audit Services

A range of high level reviews, detailed audits and mid-range assessments to test compliance with data protection laws and standards

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

PCI DSS

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Caratina consulting

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

WASPI UK GDPR Code of Conduct: What It Means for Public Service Data Sharing

The ICO has approved a UK GDPR code of conduct for information sharing between public services in Wales. The Wales Accord on the Sharing of Personal Information (WASPI) code was approved on 24 September 2026 and announced on 28 September 2026.

What happened?

WASPI is an existing framework that helps organisations in Wales share personal information safely. More than 1,000 organisations are already signed up to it, according to the ICO.

Its new code of conduct has now been approved under Article 40 of the UK GDPR. A code of conduct is a set of sector rules, approved by the regulator, that shows how data protection law applies in practice. Members who follow an approved code have a recognised way to show accountability. The ICO’s Chris Hogan described it as “a clear and recognised way to demonstrate accountability”.

The key facts, from the ICO’s register of codes:

  • Reference: ICO-CC/002
  • Approved: 24 September 2026
  • Code owner: Digital Health and Care Wales
  • Monitoring body: the WASPI Service, which is still pending ICO approval

What does the code cover?

The code covers sharing personal information to deliver health, education, social care, safeguarding and other public services to people in Wales.

Code members must:

  • use the WASPI information sharing protocol (ISP) template, a standard document that sets out what is shared, why and how
  • put governance controls in place
  • go through a quality assurance process
  • accept ongoing monitoring
  • review their information sharing arrangements regularly

Who does it affect?

The code applies to organisations that share personal information to deliver public services in Wales and choose to sign up. That includes:

  • schools and education providers
  • social care providers
  • local authorities
  • health bodies
  • housing providers
  • charities and voluntary organisations working alongside public services

The code concerns information sharing for services to people in Wales. An organisation’s address alone does not decide eligibility: check the code’s membership criteria with WASPI, particularly for cross-border arrangements. Organisations elsewhere can still use its approach as a prompt to review their own practices.

Why does it matter?

Sharing information between services is where data protection often goes wrong. Some staff hold back information that should be shared, for example in a safeguarding case. Others share without a clear lawful basis or a written agreement.

A code gives everyone the same template and the same checks. That makes it easier for staff to share with confidence and easier for organisations to prove they got it right.

Does joining WASPI replace your UK GDPR responsibilities?

No. A code supports accountability; it does not supply a lawful basis for every disclosure or remove your responsibility to assess each sharing arrangement. Record the purpose, lawful basis, safeguards and responsibilities before sharing.

What should organisations do now?

If you work in Wales and already use WASPI:

  • Check your information sharing protocols use the current WASPI template.
  • Make sure each protocol has a named owner and a review date.
  • Watch for the monitoring body’s approval. The regulator’s register still lists approval of the monitoring body as pending at the time of this review.

If you work in Wales and don’t use WASPI:

  • List the organisations you regularly share personal information with.
  • Consider whether joining the code would give you a clearer, consistent way to document that sharing.

If you work elsewhere in the UK:

  • Review your data sharing agreements. Are they current, consistent and easy for staff to find?
  • Compare them with the ICO’s data sharing code of practice, which applies across the UK.

For one-off requests, such as from the police, see our guide to ad-hoc data sharing requests.

How DPP can help

We support local authorities and schools, academies and colleges with data sharing agreements, DPIAs and day-to-day data protection advice. If you’d like a review of your information sharing arrangements, talk to our team about the support you need.

Discuss your information sharing arrangements

Sources and further guidance

WASPI entry in the ICO’s register of approved codes

Regulator announcement, 28 September 2026

Content reviewed: 2 October 2026.

STAIRs publication scheme: what housing associations must publish from 1 October 2026

The short answer: Since 1 October 2026, private registered providers of social housing in England must have a STAIRs publication scheme. It covers information they hold about governance, spending, homes, performance, services, registers and housing management. Providers do not have to create new records. Appropriate redaction is allowed. The separate requirements for tenant information requests begin on 1 April 2027.

What is a publication scheme?

A publication scheme explains what information your organisation makes available routinely and where tenants can find it. They should not have to make a formal request to understand how you run homes and services.

The government’s STAIRs policy statement sets out the requirements. STAIRs now forms part of the Regulator of Social Housing’s Transparency, Influence and Accountability Standard.

For the wider background, read STAIRs: What Housing Associations Need to Know. This article focuses on the publication scheme itself.

Who needs a STAIRs publication scheme?

The requirements apply to private registered providers of social housing in England. This includes housing associations. The policy does not provide a general exemption for small providers.

Local authority landlords are already subject to the Freedom of Information Act. Do not assume STAIRs applies to every housing organisation across the UK. Check your registration and the services you provide.

What must it include?

Your scheme must cover information you hold within seven areas. The examples below help you identify existing material. They are not a substitute for checking the policy statement.

1. Governance and decision making

Explain who runs the organisation and how decisions are made. Examples include senior staff roles, governance arrangements, decision-making policies and information about tenant consultations.

2. Spending

Show how money is used. Existing financial reports, grant information and explanations of how service charge revenue is spent can help cover this area.

3. Housing stock management

Include information about managing and maintaining homes. Examples include maintenance plans, stock transfers and progress towards net zero.

4. Performance

Help tenants understand how services are performing. Examples include inspection outcomes, Tenant Satisfaction Measures, complaint figures, health and safety assessments and maintenance performance.

5. Housing services

Describe the services tenants can use. Link to existing advice, guidance and service information, including how tenants can access support.

6. Lists and registers

Review information held in legally required registers and other lists relating to social housing management. Assess what can reasonably be published without exposing protected information.

7. Social housing management

Include policies and strategies for managing social housing. Your existing housing management policies may already provide much of this information.

What does a publication scheme not require?

You do not have to create new records. Start with information your organisation already holds. This does not remove the need to identify it and make it accessible.

You do not have to publish every document without checks. Appropriate and reasonable redaction is permitted. Record why information is withheld and apply the policy statement’s safeguards.

It is not a one-off upload. Providers must review and update the information regularly. Assign an owner and choose a review cycle that fits your organisation.

How should you publish it?

Tenants must be able to identify and access the information. These five practical steps can help:

  1. Create an easy-to-find starting point. A dedicated website page can link to information you already publish. Check that the links work.
  2. Group information under the seven areas. Make it clear what each link contains and flag gaps for action.
  3. Make access practical. Use plain English and accessible documents. Provide a route for tenants who need another format or cannot use the website.
  4. Explain how to contact you. Include questions about missing information and the STAIRs review process.
  5. Keep it current. Show a review date, assign owners and check for changes to policies, services and published figures.

These are implementation suggestions. A particular page layout or quarterly review cycle is not prescribed by the policy statement.

Missed 1 October? Here’s how to catch up.

If your scheme is not ready, start by identifying the gaps. Keep a clear record of your actions and who is responsible for them.

  1. Order existing information. Check annual reports, policies, service pages, performance reports and governance material against the seven areas.
  2. Prioritise missing items. Identify information you hold but have not made available. Give each action an owner and a realistic completion date.
  3. Check before publishing. Review accuracy, accessibility and any information that needs redaction.
  4. Publish checked material promptly. Keep working on gaps. A first version does not, by itself, establish that you have met every requirement.
  5. Tell tenants where to find it. Explain the contact and review routes, then schedule your next check.

If you need help identifying gaps, explore our STAIRs Readiness Assessment.

How do you protect personal data before publishing?

Transparency does not mean publishing personal information without a lawful reason. Review documents for names, contact details, complaint information and details that could identify a tenant indirectly.

Do not automatically remove every name. Some information, such as senior staff roles, may be appropriate to publish. Assess the purpose and legal basis for each disclosure.

Where redaction is needed, remove the information securely. Check comments, tracked changes, hidden data and searchable text. A coloured box over text may leave the underlying information accessible.

Keep a record of decisions and have someone check the final public version. Our STAIRs housing FAQs cover further practical questions.

How is a STAIRs request different from a SAR?

A STAIRs request concerns relevant information about the management of social housing. A subject access request (SAR) concerns a person’s own personal data.

For example, a request for a repairs policy is different from a request for personal information in a tenant’s repair records. One message may contain both.

Assess each part and route it correctly. The STAIRs policy directs providers towards the appropriate statutory route where a separate legal right of access applies. Do not apply the STAIRs 18-hour limit to a SAR.

The ICO’s right of access guidance explains the separate SAR requirements.

What changes on 1 April 2027?

From 1 April 2027, tenants or their designated representatives can make written requests for relevant information. Providers should acknowledge them promptly.

  • 30 calendar days: Respond promptly and no later than 30 calendar days from receipt. Extra time is permitted only in exceptional circumstances specified in the policy. Explain any delay and when a response is expected.
  • 18-hour staff-time limit: A provider may refuse where the work involved would exceed 18 hours. This is a refusal threshold, not an automatic charge. Record the reasoning behind any estimate.
  • Internal review: If the tenant is dissatisfied, they should first complain to the provider. The review should normally finish within 30 calendar days, with additional time possible in certain circumstances.
  • Housing Ombudsman: A tenant dissatisfied with the review can escalate under the Housing Ombudsman Scheme.

The publication scheme has its own review and escalation route already. Do not wait until April 2027 to explain how tenants can raise missing information.

For earlier sector context, see our STAIRs update for housing associations.

Your STAIRs publication scheme checklist

  • Identify the information you hold under all seven areas.
  • Check what is already public and prioritise gaps.
  • Review personal data and record withholding decisions.
  • Check links, readability and access in other formats.
  • Explain the contact, review and escalation routes.
  • Tell tenants where to find the scheme.
  • Assign owners and regular review dates.
  • Prepare request-handling processes for April 2027.

Frequently asked questions

When did STAIRs publication schemes become mandatory?

The publication-scheme requirements apply from 1 October 2026 to private registered providers of social housing in England.

Do housing associations have to create new records?

No. The publication scheme covers information already held. Providers still need to identify relevant information and make it accessible.

Can we redact information before publishing?

Yes, where appropriate and reasonable. Apply the policy statement’s safeguards, assess personal data carefully and record the reasons for redaction.

When do tenant information requests begin?

The separate information-request requirements begin on 1 April 2027. Providers must respond promptly, normally within 30 calendar days of receipt.

Where do publication-scheme complaints go?

Tenants should first use their provider’s STAIRs review process. If dissatisfied with the review, they can escalate to the Housing Ombudsman under its Scheme.

Is STAIRs the same as the Freedom of Information Act?

No. STAIRs is a separate framework for private registered providers. It supports tenant access to housing management information but does not make those providers subject to FOI simply because STAIRs applies.

How can Data Protection People help?

Need help reviewing your publication scheme or preparing your team for information requests? We can help you work through information rights and data protection questions.

Speak to our team about Information Rights Support.

Sources

Finding What’s Exposed With EASM

External Attack Surface Management, usually shortened to EASM, is the continuous discovery and monitoring of everything your organisation exposes to the internet, domains, subdomains, cloud services, servers and applications, including the ones nobody currently has on a list.

What “attack surface” actually means

Your external attack surface is every point an attacker could potentially reach from outside your network. That includes the systems your IT team knows about and manages deliberately, but it also includes things that accumulate without anyone fully tracking them, a test server spun up for a project and never decommissioned, a marketing microsite built by an agency years ago, a cloud storage bucket set up for a one-off task, a subdomain nobody remembers creating. None of these are necessarily malicious or even risky on their own, but each one is a potential entry point, and you can’t secure what you don’t know exists.

Why this differs from a pentest or a vulnerability scan

Penetration testing and vulnerability scanning both work against a defined, known scope, systems you’ve already identified and agreed to test. EASM works the other way round, it starts from the outside, mapping what’s actually visible on the internet under your organisation’s name, and works to identify assets you may not have deliberately included in any existing security process at all. It’s the discovery layer that should logically come before testing, since a pentest against a scope that’s missing half your real exposure only gives you confidence in the part you already knew about.

How EASM actually works

EASM tools and services continuously scan public sources, DNS records, certificate transparency logs, IP ranges and cloud provider metadata, to build and maintain a live map of everything associated with your organisation that’s reachable from outside. That map gets checked for common exposure issues, out of date software, exposed admin panels, misconfigured cloud storage, expired certificates and anything genuinely concerning gets flagged for investigation. Because it’s continuous rather than a one-off exercise, new exposure gets caught close to when it appears, not months later during the next scheduled review.

Why this has become more important

Organisations’ external footprints have grown substantially with the shift to cloud services, third-party tools and distributed teams who can spin up new infrastructure without necessarily going through a central IT process. That’s not a criticism of how modern organisations operate, it’s simply a consequence of how much easier it now is to stand up a new service, and it means the gap between what security teams officially track and what’s actually exposed has grown alongside it. EASM exists specifically to close that gap.

Questions organisations usually ask about EASM

How is this different from just asking IT for a list of our systems? An internally maintained list only ever reflects what was deliberately recorded, and in practice things get missed, a project ends, a subdomain stays live, a cloud account gets set up outside the usual process. EASM discovers assets independently of any internal list, which is exactly the point, it finds what the list doesn’t know about.

Is this a one-off exercise or does it need to run continuously? It works best as continuous monitoring rather than a single scan, since new external assets appear constantly as an organisation operates. A one-off discovery exercise gives you an accurate picture on the day it runs, but that picture starts going out of date almost immediately.

What happens once something unexpected is found? Typically the finding gets triaged, confirmed as genuinely belonging to your organisation, assessed for how exposed or risky it actually is, and then either brought under proper management or decommissioned if it’s no longer needed. Not everything found is a problem, some of it is simply forgotten infrastructure that just needs tidying up.

Do we need this if we already do regular penetration testing? The two work together rather than replacing each other. A pentest assesses depth against an agreed, known scope. EASM addresses breadth, finding what should be in scope in the first place. Testing against an incomplete scope only ever gives you confidence in the part you already knew about.

Is EASM right for your organisation

It’s particularly valuable for organisations of meaningful size or with a history of mergers, acquisitions, agency-built projects, or multiple teams independently provisioning their own infrastructure, all situations where an accurate, centrally held inventory of external assets is unlikely to exist without deliberate effort. Even smaller organisations benefit from an initial discovery exercise, since the honest answer to “do you know everything your organisation exposes to the internet” is very often no, and finding that out is the necessary first step before any other security work can be properly scoped.

If you want an accurate picture of what your organisation actually exposes to the outside world, our External Attack Surface Management service is built to find out.

Can Schools Use Generative AI Tools Under UK GDPR?

Generative AI tools like ChatGPT, Microsoft Copilot and Gemini can be used in schools under UK GDPR if used safely and effectively, with appropriate data protection policies in place.

To remain GDPR-compliant, schools should avoid using free versions of generative AI tools, as they may lack the necessary safety features. Instead, schools should use enterprise tools integrated into a broader workspace of educational tools, such as Copilot in Microsoft 365 or Gemini in Google Workspace.

What Data Risks Do Generative AI Tools Present in Schools?

Generative AI tools themselves don’t pose data protection risks; the risks depend on how they are used. These include:

  • Data Breaches – If staff members paste sensitive data into AI tools without notifying parents and pupils that their data will be used in this way, it may constitute a data breach.
  • GDPR Compliance Risks – Many AI tools are operated by US companies, so without data residency controls, personal data may be processed and stored outside the UK, creating GDPR compliance risks.
  • Intellectual Property – When a student completes a piece of work, the intellectual property belongs to them. Submitting this work to a free generative AI tool for feedback could result in the data being used to improve the AI’s systems, potentially raising issues regarding intellectual property rights and data protection compliance.

What Data Protection Policies Should Schools Follow When Using Generative AI Tools?

Consult a Data Protection Officer

Before using generative AI for any activity, schools should consult their appointed Data Protection Officer (DPO). A DPO can review the chosen AI tool(s), ensure that appropriate data policies are in place and advise staff on how to use them effectively.

Carry Out a DPIA

The ICO requires a Data Protection Impact Assessment (DPIA) before using AI in high-risk processing activities, including any use of AI involving children’s personal data. A DPIA should outline how the data is processed and its purpose, assess necessity and identify and mitigate risks.

Be Transparent About Data

Government advice recommends that personal data not be used in generative AI tools in educational settings.

If it is necessary for schools to use personal data in AI tools, they must:

  • Be open and transparent about how they are considering using automation and AI
  • Ensure that pupils, parents and guardians understand that their personal data is being processed using AI
  • Seek consent to use data within AI

Use The Right Tools

Government advice further recommends that staff members only use AI tools provided by their institution. This is likely to include:

  • Microsoft Copilot under a Microsoft 365 for Education licence
  • Gemini under a Google Workspace for Education licence

These paid tools keep data within a managed school environment, don’t use data to train public AI models and respect existing security and privacy controls.

Provide Data Protection Training to Staff

Data protection training can help staff understand UK GDPR compliance and what constitutes a data breach. Staff must understand what data should never be entered into AI tools and which AI platforms are approved for work use.

Ensure Your School Is GDPR Compliant with Data Protection People

Generative AI can transform education, but it must be balanced with the responsibility to protect personal data and meet GDPR requirements.

At Data Protection People, we have extensive experience working with the education sector and can help schools implement generative AI securely. From outsourced DPO services to ongoing data protection advice, we can ensure your use of AI is compliant. Contact us today to understand how we can support you.

S2 Ep38: AI Systems and DPIAs

S2 Ep38: AI Systems and DPIAs

Can AI help you write a Data Protection Impact Assessment? And how do you assess the privacy risks of the AI system itself?

In S2 Ep38 of Data Protection Made Easy, Caine Glancy and Catarina Santos (Cate) explore both sides of the conversation: carrying out DPIAs for AI projects and using AI to help prepare an assessment.

What We Discuss

  • Understanding how an AI system uses personal data, including its inputs, outputs and who can access them.
  • Asking practical questions about suppliers, retention and where information goes.
  • Using AI to organise information, suggest questions and identify gaps in a DPIA.
  • Why project-specific information and human review remain important.
  • Setting clear boundaries for how staff use AI tools.

Join Cate and Caine for a practical discussion about making informed decisions, checking assumptions and keeping people involved in the assessment process.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Join Our Community

Our free Friday sessions bring people together to discuss data protection topics, share practical advice and ask questions.

Explore Upcoming Sessions

Need Support With Your DPIA?

Our DPIA service helps you identify and assess privacy risks in new projects, systems or processes. We work with your team to document the assessment and recommend practical measures to reduce risks and support informed decisions.

Contact Data Protection People

S2 Ep37: Sector Spotlight Ep1: Caught Between the FCA and UK GDPR – What DPOs Need to Know

Sector Spotlight Ep1: Caught Between the FCA and UK GDPR – What DPOs Need to Know

Financial services businesses face overlapping responsibilities. How do they bring financial regulation and data protection together in practice?

In the first episode of Sector Spotlight, DPP’s Mark Farrell joins Phillip Garlick, CEO of Product Partnerships Limited (PPL), to discuss the relationship between FCA requirements and UK GDPR.

Created as part of the partnership between Data Protection People and PPL, this episode brings together perspectives on data protection, retail finance and the practical realities of running a regulated business.

Explore the Conversation

Our promotional clips explore financial promotions, whether good compliance can support business growth, the cost of compliance in the financial sector, and AI’s promise and peril in data protection.

Watch or listen to the full episode to hear the wider conversation with Mark and Phillip.

Meet Phillip Garlick

Phillip is the CEO of Product Partnerships Limited, which delivers retail financial solutions and compliance support to consumer-facing businesses. PPL helps these firms offer finance to their customers and manage the regulatory responsibilities that come with it.

He has over 30 years’ experience in regulated, consumer-facing sectors, with a strong focus on governance, risk management and sustainable growth.

Phillip is a practising Chartered Director and Fellow of the Institute of Directors. He holds an Advanced Certificate in Governance & Risk from the International Compliance Association and an MBA from Leeds University.

About Sector Spotlight

Sector Spotlight is a separate series within Data Protection Made Easy, exploring data protection through conversations focused on particular sectors. This is episode 1 of the series, rather than an episode in our regular Season 2 numbering.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Need Data Protection Support?

If your organisation needs help navigating its data protection responsibilities, speak to our team about the support available.

Contact Data Protection People

S2 Ep36: GDPR Radio – Data Protection News of the Week

S2 Ep36: GDPR Radio – Data Protection News of the Week

Cate and Caine are back together on GDPR Radio, and Cate marks the occasion with a little singing before the conversation gets underway.

In S2 Ep36 of Data Protection Made Easy, Caine Glancy and Catarina Santos catch up on data protection news and share practical perspectives on what it means for organisations.

Expect a friendly discussion, familiar faces and plenty of conversation about the world of data protection.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Join Our Community

Our free Friday sessions bring people together to discuss data protection topics, share practical advice and ask questions.

Explore Upcoming Sessions

Need Data Protection Support?

If your organisation needs help with a data protection question or challenge, speak to our team about the support available.

Contact Data Protection People

S2 Ep35: AI Redaction Tools: The Mistakes Most SAR Systems Miss

S2 Ep35: AI Redaction Tools: The Mistakes Most SAR Systems Miss

AI redaction tools promise to make handling subject access requests easier. But what might they miss?

In S2 Ep35 of Data Protection Made Easy, Amber Sivill and Katerina Douni discuss AI redaction tools and the challenges organisations face when using them to support SAR responses.

Join them for a practical conversation about technology, redaction and the importance of checking information before it is shared.

Watch or Listen to the Episode

Watch the Full Episode on YouTube

Listen to the Full Episode on Spotify

Join Our Community

Our free Friday sessions bring people together to discuss data protection topics, share practical advice and ask questions.

Explore Upcoming Sessions

Need Support With Subject Access Requests?

If your organisation needs help managing subject access requests or reviewing its redaction process, speak to our team about the support available.

Contact Data Protection People

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
_GDPR Radio - Data Protection News of the Week (1)
23 October 26 12:30 - 1:15 pm

S2 Ep41: GDPR Radio – Data Protection News of the Week

Why Most DPIAs Get Signed Off Too Late to Matter
16 October 26 12:30 - 1:15 pm

S2 Ep40:Why Most DPIAs Get Signed Off Too Late to Matter

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.