The UKs #1 Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

SAR Support

Explore our Subject Access Request (SAR) Handling Service and understand how Data Protection People can support your organisation

Contact Us

Data Protection Support

Data Protection People's world-class GDPR Support Desk. If you're navigating the complex landscape of data protection, PCI DSS, and cybersecurity, our support desk is your reliable compass.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us

Data Protection Audit & GDPR Audit Services

A range of high level reviews, detailed audits and mid-range assessments to test compliance with data protection laws and standards

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

PCI DSS

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Rob Wilkinson answering a call

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

When Subject Access Requests Become Part of the Dispute: Are Organisations Ready for AI-Assisted SARs?

When Subject Access Requests Become Part of the Dispute: Are Organisations Ready for AI-Assisted SARs?

Subject Access Requests (SARs) have always had the potential to be challenging.

They frequently arise when something has already gone wrong: an employment dispute, a complaint about treatment, a breakdown in a relationship with an organisation, concerns about a decision or potential legal proceedings.

What is changing is how easy it has become for an individual to produce a highly detailed request.

With readily available generative AI tools, someone with little or no knowledge of data protection law can produce, within seconds, a lengthy SAR referring to Article 15 of the UK GDPR, multiple systems, internal communications, named employees, search terms, audit trails, meeting notes and specific categories of information.

The same tools can then be used to review the response, identify potential gaps and draft a challenge or complaint.

For organisations, particularly those operating in the health and care sector, this raises an important question: are our SAR processes prepared for increasingly sophisticated requests, particularly when the SAR forms part of a wider dispute?

Has AI changed the SAR?

Legally, no. The right remains the same.

An individual is entitled to confirmation as to whether their personal information is being processed, access to that personal information and the supplementary information required under Article 15.

The ICO’s current guidance is clear about those basic principles. A SAR can be made verbally or in writing and does not require any particular form of words. Organisations will normally need to respond without undue delay and within one month.

What AI potentially changes is not the right itself, but the individual’s ability to formulate and pursue the request.

Consider the difference between: “Please provide the information you hold about me” and a multi-page request asking an organisation to search the mailboxes of 15 employees, Teams messages, meeting minutes, handwritten notes, call recordings, audit logs, deleted items and communications containing a list of specified search terms over several years.

The second request may look as though it has been prepared by a specialist. Increasingly, it may simply have been generated following a short conversation with an AI tool.

That does not make the request invalid. But neither does the level of detail in the request automatically determine how the organisation must conduct its searches.

That distinction is important.

When a SAR becomes part of a wider dispute

As a data protection consultant, one of the more difficult situations I see is where the SAR cannot realistically be separated from a wider dispute.

In healthcare, for example, a patient may be dissatisfied with their treatment or with the handling of a complaint. They may want to understand not only what appears in their clinical record, but what was said internally about them, who was involved in particular decisions and why those decisions were made.

Similarly, a member of staff may submit a SAR during an employment dispute or grievance.

The request may therefore be one part of a much wider disagreement between the individual and the organisation.

It can be tempting to describe these requests as being “weaponised”. However, organisations need to exercise some caution.

The existence of a dispute does not remove the individual’s right of access. Nor does the fact that the information may subsequently be used for a complaint or legal proceedings automatically make the SAR invalid.

The starting point should remain straightforward:

What personal information is the individual entitled to receive, and what reasonable and proportionate searches are required to find it?

A five-page request does not necessarily create a five-page legal obligation

This is where organisations sometimes make SARs considerably more difficult than they need to be.

A sophisticated request may contain instructions such as: “Search the email accounts of the following 12 employees using my full name, initials, NHS number and these 15 keywords.”

The organisation should consider what the requester is seeking and where their personal information is reasonably likely to be held. However, a requester does not automatically determine the organisation’s search methodology simply by providing a long list of instructions.

The right of access is fundamentally a right to personal information. It is not an unrestricted right to every document that mentions an individual. Nor does every reference to someone’s name necessarily mean that an entire document becomes their personal information.

This distinction can make an enormous difference to how a complex SAR is managed.

Reasonable and proportionate searches matter

This has become particularly relevant following the Data (Use and Access) Act 2025. The ICO’s current guidance expressly states that organisations must undertake a reasonable and proportionate search for the requested information. It also explains that organisations are not required to conduct searches that would be unreasonable or disproportionate to the importance of providing access to the information.

This does not give organisations permission to conduct superficial searches.

If an organisation decides that a particular search would be unreasonable or disproportionate, it needs to be able to justify that conclusion. However, the framework is important when dealing with requests containing extensive search instructions.

The question should not simply be: “The requester has asked us to search this. Do we have to?”

Instead, organisations should ask: “Taking account of the scope of the request and what we know about our information, what searches are reasonable and proportionate to identify the individual’s personal information?”

That requires judgement, and that judgement should be documented.

What about manifestly unfounded or excessive requests?

This is another area where organisations need to be careful. Receiving a 10-page SAR generated with the assistance of AI does not automatically make the request manifestly excessive.

The ICO says a request is not necessarily excessive simply because an individual requests a large amount of information. When considering whether a request is manifestly excessive, organisations need to consider all the circumstances, including the nature of the information, the context and relationship with the requester, the resources available and whether the request substantially repeats or overlaps with previous requests.

The threshold is deliberately high. The excessiveness must be clear or obvious, and the organisation needs strong justification for its conclusion.

There are circumstances where the purpose and context of a request can become relevant. Current ICO training materials, for example, give an example involving repeated requests where the evidence shows that the requester is attempting to cause disruption and put pressure on a DPO rather than genuinely seeking further personal information.

But this needs to be distinguished from someone who is simply persistent, angry, involved in a dispute or asking for a large amount of information. Those factors alone should not lead an organisation to label a SAR as manifestly unfounded.

AI can also make challenging the response easier

There is another development organisations should prepare for.

AI not only makes it easier to draft the initial request. It can also make it easier to scrutinise the response.

An individual can provide an AI tool with their original request and the organisation’s response and ask it to identify apparent gaps. They can ask it to draft follow-up correspondence, question exemptions relied upon by the organisation or help prepare a complaint to the ICO.

The quality of that advice will vary, and an AI-generated challenge is not necessarily legally correct.

But from an organisational perspective, there is an important lesson: SAR decisions need to withstand scrutiny.

That means keeping a clear record of what was searched, why particular custodians and systems were selected, what search terms were used where appropriate, what information was excluded and why, and the basis for any exemptions or restrictions applied.

A well-managed SAR should be defensible from its records without having to reconstruct the reasoning several months later.

Why healthcare organisations should pay particular attention

SARs in healthcare can already involve substantial amounts of highly sensitive information.

The ICO has dedicated guidance on the right of access, including the particular considerations that arise when dealing with health information. Its individual rights resources also specifically direct organisations to guidance concerning health, social work and education information.

A patient involved in a complaint about their care may want considerably more than a copy of the formal clinical record.

They may want correspondence between clinicians, internal discussions about their complaint, notes relating to decisions, communications with other organisations and information about how concerns they raised were handled.

That can create difficult questions around scope, third-party information, professional opinions, confidentiality and applicable restrictions.

It also makes poor information management considerably more visible.

An organisation that cannot establish where information about a patient may be held will find a sophisticated SAR particularly difficult to manage.

So how should organisations respond?

The answer is not to treat detailed SARs more aggressively. It is to manage them better.

Separate the SAR from the dispute

The person dealing with the SAR should understand the wider context, but avoid allowing that context to determine the response.

A difficult complainant can still make a valid SAR. An employee involved in litigation can still exercise their right of access. A patient who has made repeated complaints can still be entitled to their personal information.

Deal with the SAR as a statutory information rights request while managing the underlying complaint, grievance or litigation through the appropriate separate process.

Establish what the individual is actually asking for

Do not automatically translate every sentence in a lengthy request into a separate search exercise. Read the request as a whole.

What personal information are they seeking? What period does it cover? Which parts are clear? Where is that information reasonably likely to exist?

Where appropriate, clarification can make a significant difference to the search exercise.

Create a search strategy

For complex SARs, avoid simply forwarding the request to dozens of employees with the instruction: “Please send us anything you have about this person.”

Identify likely data sources and custodians, determine proportionate search terms and date ranges, and record what you have decided to search and why.

Remember: personal information, not documents

This distinction should be understood by everyone involved in the review.

Finding the requester’s name within a 30-page document does not necessarily mean the individual is entitled to the entire document. The review needs to identify the requester’s personal information within the material retrieved.

This is particularly important when dealing with internal correspondence containing information about several people.

Document proportionality decisions

If searching a particular system, mailbox, archive or category of information would be unreasonable or disproportionate, document the reasoning.

Record the likely relevance of the information, the scale of the search, alternative searches undertaken and why the organisation considers its approach reasonable.

Do not wait for an ICO complaint to reconstruct that reasoning.

Be cautious before relying on “manifestly unfounded” or “manifestly excessive”

These are not convenient labels for difficult SARs. The ICO expects organisations to consider each request individually and to have strong justification for refusing one on these grounds.

Escalate these decisions internally or obtain specialist advice where appropriate.

Keep an audit trail

For significant SARs, the SAR file should tell the story of the response. It should be possible to establish:

  • what was requested;
  • how scope was determined;
  • which systems and custodians were searched;
  • what searches were undertaken;
  • what was retrieved;
  • what decisions were made about personal and third-party information;
  • what exemptions or restrictions were considered and applied; and
  • why any searches were considered unreasonable or disproportionate.

This becomes particularly valuable if the response is subsequently challenged.

Do not fight the request. Strengthen the process.

It would be easy to view AI-assisted SARs negatively.

Individuals can now create lengthy requests, quote legislation, ask for information across numerous systems and challenge responses with considerably less effort than would previously have been required.

For organisations, that can undoubtedly create additional work.

But the technology has not changed the fundamental legal position.

A genuine SAR remains a SAR whether it was drafted by the individual, a solicitor, an online template or an AI tool. At the same time, organisations are not required simply to follow every search instruction contained within a sophisticated request.

They are required to understand the scope of the right, identify the individual’s personal information and undertake reasonable and proportionate searches for it.

The organisations that manage this well will not necessarily be those with the biggest SAR teams.

They will be those that know where their information is, have clear processes for scoping complex requests, document their decisions and understand when to challenge internally the assumption that “the requester asked for it, therefore we must search everything”.

As a consultant, that is where I believe organisations should be focusing their attention.

The question is not whether individuals will continue to use new tools to exercise their rights, because they will.

I think the more useful question is: if your next SAR is detailed, extensive and written with the sophistication of a specialist, is your organisation’s process robust enough to deal with it?

Further reading

When Two Rulebooks Collide: Data Protection and Financial Crime Regulation

When Two Rulebooks Collide: Data Protection and Financial Crime Regulation

Financial services firms are often expected to do two things at once: know more about their customers and collect less data about them.

This is the practical tension between financial crime regulation and data protection law. Both carry serious regulatory consequences, but they ask different questions of the same customer record.

Financial crime rules focus on whether a firm knows enough to identify and manage risk. Data protection law asks whether each item of personal data is necessary, lawful, secure and retained for no longer than needed.

The challenge affects customer onboarding, transaction monitoring, retention, technology, supplier management and the evidence a firm can produce when challenged. Firms that treat data protection and financial crime compliance as separate workstreams often only address the overlap when something goes wrong.

The Core Challenge

The practical question is whether a firm can show that each item of customer data has a defined regulatory purpose, a proportionate risk trigger, a controlled access route and a clear retention outcome.

This means considering where the two regimes overlap and where they create tension, particularly around collection, retention, outsourcing, governance and emerging technology.

Collection: Need to Know vs Just in Case

The first point of friction is collection.

The Money Laundering Regulations 2017 require customer due diligence and, in higher-risk situations, enhanced due diligence. In practice, this can mean collecting detailed information about source of funds, source of wealth, beneficial ownership, corporate structures and transaction behaviour.

At the same time, the UK GDPR requires organisations to collect personal data that is adequate, relevant and limited to what is necessary. This is known as data minimisation.

Data minimisation does not mean collecting as little information as possible in every situation. It means being able to explain why each data point is needed for a defined purpose.

Problems arise when firms collect more information simply because they can, or because teams are worried about getting anti-money laundering requirements wrong. This can lead to data being collected just in case without a clear risk-based reason.

A stronger approach is to apply the risk-based logic already built into the Money Laundering Regulations. Enhanced information gathering should be linked to a genuine, documented risk trigger. Standard-risk customers should not automatically be subject to the same level of collection.

For each category of data, firms should be able to explain:

  • Which legal or regulatory obligation supports collection
  • What risk factor triggered the request
  • Who can access the information
  • When the need for the information will be reviewed

Retention: Delete Less, Delete More

Retention is another area where financial crime obligations and data protection expectations can appear to conflict.

The UK GDPR requires personal data to be kept in an identifiable form for no longer than necessary. However, the Money Laundering Regulations require relevant records to be retained for five years after the end of a business relationship or the completion of an occasional transaction, subject to the detailed requirements of the Regulations.

This does not mean anti-money laundering obligations automatically override data protection law. It means firms need a precise retention analysis.

The lawful basis for retaining anti-money laundering records will often be compliance with a legal obligation under Article 6(1)(c) UK GDPR. However, a robust retention schedule should distinguish between different record types, including:

  • Customer identification records
  • Verification evidence
  • Risk assessments
  • Transaction monitoring alerts
  • Suspicious activity escalation material
  • Sanctions screening results
  • Call recordings
  • Suitability files and advice records

Each category may have a different legal basis, retention trigger and deletion point. Some records may need to be retained because anti-money laundering law requires it. Others may be retained because FCA rules, limitation periods or advice obligations apply. Others should be deleted, anonymised or access-restricted once their purpose has expired.

Delete records too early and the firm may be unable to evidence adequate due diligence or monitoring. Keep everything indefinitely and the firm risks unlawful over-retention, greater breach impact and weaker accountability.

Outsourcing, Suppliers and Operational Resilience

A single supplier can create several overlapping compliance requirements.

A cloud provider, KYC screening tool, transaction monitoring platform or credit reference relationship may require an Article 28 processor assessment, international transfer analysis where relevant, an information security review, financial crime due diligence, an outsourcing assessment and an operational resilience assessment.

These reviews overlap, but they are not the same.

Data protection asks about processing instructions, sub-processors, security, deletion, audit rights and international transfers. Financial crime asks whether a tool supports effective due diligence, screening, monitoring and escalation. Operational resilience asks whether the service supports an important business service, what happens if it fails and whether exit plans are credible.

Running these reviews separately can create duplicated effort and regulatory blind spots. A supplier may pass a data protection assessment but fail to meet operational resilience expectations. Another may offer strong functionality but have weak deletion controls, access management or transfer transparency.

The answer is integrated supplier governance. This means one intake process, one risk classification, one evidence pack and the right specialist sign-off at each stage.

The FCA and ICO’s March 2026 joint statement on vulnerability-related data makes a similar point. Data protection law does not prevent firms from delivering good outcomes under the Consumer Duty, but firms must still meet their data protection obligations. One regulatory regime should not become an excuse for failing another.

Independence Does Not Mean Isolation

Closer coordination should not compromise the independence of the Data Protection Officer.

Article 38 UK GDPR requires that a DPO is not instructed on how to perform their tasks and is not placed in a conflict of interest. However, independence of judgement is not the same as isolation from the process.

A DPO can remain independent while being involved early in retention design, supplier assessment, model governance, data protection impact assessments and data mapping.

In fact, late-stage review can weaken effective oversight. By the time a system is configured, data has been collected or a supplier has been appointed, the commercial decision may already be difficult to change.

The same applies to financial crime teams. Data protection should not be seen as a paper exercise that slows down effective controls. Good minimisation, access control and retention practices can make financial crime information more accurate, better governed and easier to evidence.

Emerging Technology

Privacy-enhancing technologies may eventually help firms reduce the tension between financial crime detection and data minimisation.

These are technologies designed to gain insight from data while reducing unnecessary exposure of the underlying information. Examples include federated learning, secure multi-party computation, fully homomorphic encryption and differentially private synthetic data.

They could be valuable for anti-money laundering and fraud detection, where suspicious patterns are often easier to identify across wider datasets. Developments such as Singapore’s COSMIC platform also show the direction of travel towards more controlled, purpose-specific information sharing.

However, these technologies should be treated as emerging developments rather than immediate compliance fixes. Many remain difficult to deploy at scale due to cost, technical complexity, immature supplier tooling, performance limitations and evolving regulatory expectations.

They also do not remove the need for strong governance. A firm using privacy-enhancing technology would still need a clear lawful basis, a documented assessment of necessity and proportionality, appropriate retention rules, supplier controls and security assurance.

What Good Practice Looks Like

Firms that manage this tension well tend to do five things.

  1. Maintain one reliable data inventory. A single data inventory should support both Article 30 records of processing and financial services governance records. Separate teams should not maintain inconsistent versions of the same information.
  2. Build retention schedules together. The DPO, MLRO, legal, operations and records teams should agree the legal basis, retention period and deletion point for each record category.
  3. Apply risk-based collection. Enhanced data gathering should be linked to documented risk triggers, not habit, fear or supplier defaults.
  4. Join up supplier governance. Data protection, financial crime, information security and operational resilience reviews should work through one coordinated process.
  5. Involve data protection early. Data protection should be part of model governance, transaction monitoring design and customer decision-making from the beginning. Automated or analytics-led controls should be explainable, proportionate and supported by clear data lineage.

One Operating Model, Not Two Separate Rulebooks

The firms best placed to manage this challenge recognise the overlap and deliberately design governance that works across both regimes.

The answer is not to prioritise data protection over financial crime regulation, or vice versa. It is to build an operating model that supports proportionate collection, lawful retention, controlled sharing, resilient outsourcing and evidence that can stand up to scrutiny.

For firms under pressure to detect financial crime, protect customers and minimise personal data, that joined-up approach is essential.

This article provides general information and is not legal advice.

Do Schools Need a Data Protection Officer?

Under UK GDPR, all schools must have a designated data protection officer (DPO). This can be achieved by:

  • Assigning the responsibility to a current staff member
  • Sharing a DPO between a group of schools and academies
  • Using an outsourced DPO service

What Is a DPO’s Responsibility In a School?

A DPO in a school is responsible for:

  • Monitoring compliance and conducting regular data audits.
  • Developing and updating data protection policies and privacy notices.
  • Answering data protection enquiries from staff, parents and pupils.
  • Advising staff on data protection rules and responsibilities.
  • Organising data protection training for staff.

Why Does a School Need a DPO?

Guidance on AI Technology

Tools such as ChatGPT and Microsoft Copilot are increasingly used in most workplaces, but their use in schools remains a grey area. Staff often want to know whether these tools can be used in schools and, if so, what controls need to be in place.

A DPO can carry out a Data Protection Impact Assessment (DPIA) to identify risks before advising schools on how best to implement AI technologies safely and effectively.

Support with Subject Access Requests

Schools often need support with SARs to understand:

  • Requests made by parents on behalf of their children.
  • When a child is mature enough to exercise their right to access information.
  • How to manage requests involving safeguarding information.
  • How to handle third-party information within pupil records.
  • What information shouldn’t be disclosed.

A DPO supports staff in managing complex SARs, whether they involve pupils, parents, other staff members or safeguarding information. This can include reviewing records, applying appropriate exemptions and advising on what information can be disclosed.

Provide Policies on Photography, Videos and Marketing

The rules around taking photographs and videos in schools are often misunderstood.

Schools must inform parents and guardians how photographs of their children will be used and have a valid ‘lawful basis’ for publishing them. While it is not illegal for parents to film and photograph their own children during school performances and sports days, some schools may have policies restricting this for safeguarding and child protection purposes.

A DPO helps schools create clear privacy policies and processes, establish safe storage rules and define a ‘lawful basis’ for capturing and using images, ensuring these practices comply with UK GDPR and Data Protection Act (DPA) standards.

Why Should a School Outsource a DPO?

Gain Access To Expert Knowledge

Schools rarely have internal data protection expertise. An outsourced DPO brings specialist knowledge without the need to train someone internally. They can also provide staff with the necessary UK GDPR and data protection training.

Eliminate Conflict of Interest

Data protection regulations require a DPO to act independently. Roles such as Headteacher or IT Manager can’t serve as a DPO because they make key decisions about the school’s data processing and systems, meaning they can’t objectively monitor their own practices. An outsourced DPO provides impartial advice and identifies security risks that internal employees might overlook.

Cost-Effective

Employing an internal DPO can be expensive, as most schools rarely require full-time data protection work. Outsourcing DPO services provides access to a wider team of experts while replacing a fixed salary with a predictable service fee tailored to the level of support needed.

Get Expert DPO Support from Data Protection People

At Data Protection People, we provide ongoing data protection support for education organisations. Whether you’re a school, Multi-Academy Trust (MAT), college or university, we can advise on everything from data processes and safeguarding procedures to SAR requests.

Get in touch with our data specialists today.

Workplace Monitoring DPIAs

Around one in three UK organisations now monitor employees’ digital activity, up from one in five just a few years ago. The government has opened a consultation on whether that growth needs new rules around it, a statutory code, a duty to consult workers, or just better guidance. It runs until the end of September, and it’s not proposing to change the law yet.

Here’s the bit that matters right now, though, regardless of what the consultation eventually decides: if your monitoring is likely to be high-risk (and, let’s face it, monitoring is likely to be deemed to be intrusive, a potential abuse of power, and difficult to effectively object to), you already need a Data Protection Impact Assessment. That obligation isn’t new and isn’t waiting on this consultation.

What I want to talk about isn’t the consultation itself, there’ll be plenty written about its eight principles and three options for intervention. It’s the DPIA employers are already required to do, and how often, in my experience, it ends up being a document written to justify a decision that’s already been made rather than one that tested it.

Here are a few honest questions your own workplace monitoring DPIA should be able to answer.

Is there real human involvement, or a rubber stamp?

The law already requires meaningful human oversight where monitoring feeds into decisions with a significant effect on someone. In practice, “human involvement” too often means a manager clicking approve on whatever the system flagged, without the time, training or genuine authority to disagree with it. If the person signing off couldn’t tell you why the system flagged what it flagged, that’s not oversight, it’s a signature.

Could you explain this to the people it monitors, in a sentence, without reaching for a privacy notice?

The consultation itself makes a good point here: a privacy notice isn’t the same as workers actually understanding what’s being collected and why. If your explanation only exists in a document nobody reads, you don’t have transparency, you have a compliance artefact. The test I’d apply is simpler: could someone on the team explain, in plain terms, what’s being monitored and what it’s used for, without looking anything up?

Was “least intrusive” actually tested, or decided after the tool was already chosen?

This is the one I see skipped most often. The tool gets picked first, usually because it’s already been bought, or IT already uses it for something else, and the DPIA gets written afterwards to justify it. A genuine assessment asks what you’re actually trying to achieve and works backwards to the least intrusive way of achieving it, not the other way round.

What actually happens when the system’s wrong about someone?

Every monitoring tool will misread someone eventually, a slow week that wasn’t laziness, a flagged message that wasn’t what it looked like. The question worth answering honestly is whether there’s a real route for someone to challenge that, or whether the data just sits there as fact once it’s been recorded.

None of this needs to wait for the consultation to conclude. If anything, this is a good moment to go back through the DPIAs already sitting in a folder somewhere and ask whether they’d survive being read properly, by a regulator, an employment tribunal, or the people they’re actually about.

I was asked to review a DPIA only this week about a fingerprint scanning system installed in a medium-sized workplace for the purpose of fire evacuation roll calls. Crikey, talk about a sledgehammer to crack a nut. “Why” was the obvious question to ask, but I seemed to be the only person interested in pursuing this line of enquiry.

I’m often told that the reason for using biometrics for time and attendance management in a workplace is to stop people clocking in or out for someone else. A typical scenario is that Billy knocks off early for a round of golf, and Frank clocks him out using his physical RFID pass hours after Billy has teed off. So in that scenario, Billy is alleging to remain in the workplace when he’s actually on the fairway. But that scenario doesn’t work for fire evacuation. Billy is hardly going to say, “Hey Frank, is that the fire alarm I hear? Listen, I’m going to stay here and sit it out. Do me a favour, take my pass and pretend I’ve left the building for the roll call!” Who in their right mind would do that?

So what’s the justification for using such advanced biometric technology to automate fire evacuation roll call information. Where is the risk assessment? In addition to the technical risk, you know how it is trying to unlock your phone. One, two, three, or more attempts is often the way it works. Imagine the queue to clock out.

Then there’s the risk of scope creep. What’s stopping the clocking data being used for monitoring time and attendance more generally? And that brings me to another conversation I had this week. “Hey Phil, I’m worried that Billy is going AWOL when he’s working from home as his Teams availability flag is set to unavailable which means his laptop is not active.” But a Teams flag isn’t there for monitoring productivity and presenteeism, for a start, Billy could be doing paperwork, or by contrast, he could be on the fairway with his Teams active on his mobile phone.

I guess the point I am rambling about is that DPIAs are a mechanism that has been around in the UK for almost 20 years and still, the vast majority of those I read fail to describe and explain the envisaged processing and are extremely weak in the risk identification section.

If it’s been a while since your monitoring DPIAs were properly stress-tested, that’s exactly the kind of thing we help clients work through.

Written by Phil Brining

S2 Ep31: What Happens When Your DPO Is OOO?

S2 Ep31: What Happens When Your DPO Is OOO?

The hidden liability gap: what happens when your DPO leaves?

Your organisation’s data protection responsibilities do not pause when its Data Protection Officer is unavailable.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Gbenga Onojobi discuss how organisations can maintain accountability when their DPO is on annual leave, absent unexpectedly or has left the organisation.

The Latest Data Protection News

Before exploring the main topic, Caine and Gbenga discuss several recent stories from across data protection and technology.

  • The proposed use of live facial recognition at Scottish football matches
  • The importance of human review when automated systems identify people
  • Concerns about addictive features on social media platforms
  • Unauthorised access to patient records by a former NHS employee

The discussion highlights a recurring concern. Technology may support decision-making, but organisations still need appropriate oversight, accountability and safeguards.

Does Accountability Leave With the DPO?

A DPO may take annual leave, become unwell, resign or retire. An outsourced DPO arrangement may also come to an end. However, the organisation remains responsible for its data protection compliance.

“The DPO leaving or being out of office does not remove the organisation’s responsibility. Accountability does not leave with them.”

Gbenga compares the DPO to a navigator on a ship. The navigator advises on the route and watches for danger, but the captain and the organisation remain responsible for the journey.

Why Organisations Need a Continuity Plan

Organisations need to plan for temporary and permanent DPO absences. Staff should know who can provide advice, receive an escalation and take ownership of urgent work.

This is particularly important for matters with strict deadlines, including personal data breaches, subject access requests and other individual rights requests.

“Being able to have another trusted individual who helps you, whether that is upwards or downwards, is really quite vital.”

Policies and procedures should explain what happens when the usual DPO contact is unavailable. The plan may involve a deputy, trained managers, data champions or access to external data protection support.

Data Protection Is Not One Person’s Responsibility

Caine and Gbenga discuss the risks of allowing every data protection matter to sit with the DPO.

Senior leaders remain accountable. Managers and staff also need to understand how data protection applies to their work and when an issue must be escalated.

Training should reflect each person’s responsibilities. Board members, managers, data champions and frontline staff do not need identical training. They need practical knowledge that helps them recognise and manage the situations they may face.

Independence and Conflicts of Interest

When a DPO leaves, appointing the nearest senior employee may appear to solve the immediate problem. However, organisations must consider whether that person has the necessary expertise, time and independence.

A person should not be expected to make decisions about how personal data is used and then independently monitor their own decisions.

“Organisations should not solve a vacancy by creating an additional conflict. A rushed appointment may fill the box while leaving the organisation with a DPO who cannot properly perform the role.”

Protecting Time-Sensitive Work

A subject access request can arrive anywhere in an organisation. It may be sent to HR, reception, a manager or through social media. It may also be made verbally.

The individual does not need to use the words “subject access request” for the request to be valid. This means staff need to recognise a possible request and know where to send it, even when the DPO is unavailable.

Clear ownership and an appropriate quality assurance process can reduce the risk of missed deadlines, inappropriate disclosures or information being withheld incorrectly.

Questions to Ask Your Organisation

  • Who provides cover when the DPO is unavailable?
  • Do staff know where to send urgent data protection matters?
  • Who monitors subject access request and breach deadlines?
  • Are key decisions, risks and responsibilities properly recorded?
  • Does any temporary replacement have suitable expertise and independence?
  • Can the organisation access additional support when internal capacity is limited?

The Final Takeaway

“A DPO leaving an organisation should not create a compliance vacuum. The organisation itself remains accountable.”

Good continuity means recording important knowledge, clearly allocating responsibilities and making sure somebody suitable is ready to step in.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He brings practical insight from helping organisations manage everyday data protection questions, breaches and individual rights requests.

Gbenga Onojobi

Gbenga is a Data Protection Consultant at Data Protection People. He supports organisations with practical compliance, governance and data protection risk management.

Watch or Listen

📺 Watch on YouTube: https://youtu.be/hqokBvSh-Ho

🎧 Listen on Spotify: https://open.spotify.com/episode/7ukmE70eDsPsMYQG39O8kf

S2 Ep30: GDPR Radio – Data Protection News of the Week

S2 Ep30: GDPR Radio – Data Protection News of the Week

Practical discussion on the latest data protection news

In this episode of GDPR Radio, Caine Glancy and Catarina Santos discuss recent developments affecting data protection, workplace monitoring, media reporting and information security.

They explore the risks behind misleading headlines, AI systems that claim to detect employee emotion, smart glasses and a reported NHS data breach involving an unsecured pager network.

What This Episode Covers

  • A Court of Appeal decision on misleading headlines and the fair processing of personal data
  • Why images and headlines can shape public perception before people read the full story
  • AI emotion-detection tools and the risks of monitoring employees based on facial expressions, voice or body language
  • Why organisations must consider necessity, fairness, transparency and less intrusive alternatives before introducing workplace monitoring
  • Smart glasses, hidden recording and the need for clear acceptable-use policies
  • Lessons from a reported NHS pager network data breach
  • Why access controls, staff awareness and practical policies all matter

Key Discussion Points

“Someone who only saw the headlines and photographs together could just reasonably get the impression that actually it was Vince, the person that the article was referring to.”

The hosts discuss why data protection law can apply even where a full article clarifies the facts. The way a headline, image and article appear together can still affect whether personal data has been processed fairly.

“Could you not achieve the same objective with a completely less intrusive way?”

Caine and Catarina question the value of emotion-detection technology in the workplace. They explore why one-to-one conversations, objective work outputs and appropriate management may be more proportionate than analysing an employee’s voice, face or behaviour.

“Technical controls can only go so far, which is why the emphasis in the law is on technical and organisational measures.”

The episode also looks at why information governance needs to work in practice. Policies must reflect how an organisation operates, staff need to understand them and clear action needs to follow when rules are not followed.

Why This Episode Matters

Data protection risks do not always start with a major cyber incident. They can arise through misleading content, new workplace technology, weak access controls or policies that exist on paper but are not understood in practice.

This episode helps organisations consider where their own controls may need attention and why proportionate, people-focused

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Artificial intelligence is changing how Data Protection Officers work.

AI tools can help with research, training, risk assessments and routine administration. However, they can also produce inaccurate advice, encourage confirmation bias and create new governance risks.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss how AI is affecting DPO workloads and why professional knowledge and meaningful human oversight remain essential.

What Does This Episode Cover?

During the episode, Caine and Amber discuss:

  • The increase in AI-generated Subject Access Requests
  • How AI is affecting DPO workloads
  • The risks of using AI for data protection advice
  • How AI could support RoPAs, DPIAs and LIAs
  • The importance of checking AI-generated policies
  • Confirmation bias in AI responses
  • Why human oversight and professional knowledge still matter

How Is AI Affecting Subject Access Requests?

The discussion explored the growing number of Subject Access Requests, or SARs, that appear to have been generated using AI.

These requests can look formal and detailed. However, they may ask for information that does not fall within the normal scope of a SAR.

Amber explained:

“It also fuels a lot of misunderstanding. A lot of the time, you see a request and most of it does not even fall under the scope of what a SAR generally covers.”

Caine also shared that SAR-related cases handled through the DPP Support Desk have increased significantly.

AI may make it easier for people to create requests, complaints and follow-up correspondence. This can place additional pressure on data protection teams, particularly where requests are vague or based on incorrect information.

Can DPOs Rely on AI for Data Protection Advice?

AI can provide a useful starting point. However, it should not replace professional knowledge.

Amber explained:

“You need to have the base knowledge in order to be able to use these systems.”

An experienced practitioner may recognise when an AI response refers to the wrong legislation, misses important context or provides an answer that is too confident.

Someone with less experience may not spot those problems.

Data protection decisions are rarely black and white. The correct answer often depends on the organisation, the processing activity and the people who may be affected.

Could AI Support RoPAs, DPIAs and LIAs?

AI may help DPOs complete some routine or administrative tasks.

For example, it could help pre-populate a Record of Processing Activities, or RoPA, using information about an organisation’s activities and data sharing.

It may also provide a starting point for a Data Protection Impact Assessment, or DPIA, and a Legitimate Interests Assessment, or LIA.

However, organisations must consider what information they enter into an AI system. DPIAs and other assessments may contain sensitive or confidential information.

Amber said:

“There is a limit as to what you can provide the model with in terms of confidentiality and not oversharing any information.”

Any AI-generated assessment must be checked against the organisation’s actual processing, systems and risks.

Why Does Human Oversight Matter?

AI can produce clear and convincing answers even when those answers are incomplete or incorrect.

It may also agree with the direction of a prompt instead of challenging the user’s assumptions. This is known as confirmation bias, which means favouring information that supports an existing view.

Caine explained:

“It is a fantastic tool that will hopefully be able to help in the role as a DPO. But what matters is that you can supplement it with your pre-existing knowledge.”

Amber added:

“The human element needs to be someone overlooking it who actually knows what they are talking about.”

Human oversight must be meaningful. The person reviewing an AI output needs the knowledge and authority to identify problems, challenge the result and make the final decision.

Is an AI-Generated Policy Better Than No Policy?

An AI-generated policy is not useful simply because it exists.

A policy must reflect how the organisation actually works. It must be practical, accurate and followed by staff.

Amber explained:

“If you have a policy in place and it does not align with your business, it is not workable and people are not following it, then there is ultimately not really anything there in place anyway.”

AI may help structure a first draft. However, the final policy should be reviewed by someone who understands the organisation, its legal duties and its operational risks.

What Should DPOs Take Away?

AI can support DPOs, but it should not replace them.

Organisations should:

  • Use AI to support work rather than make final decisions
  • Check AI outputs against current law and ICO guidance
  • Avoid entering unnecessary personal or confidential information
  • Keep meaningful human oversight in place
  • Document how AI tools are approved, monitored and reviewed
  • Make sure policies and assessments reflect real business practices

The DPO role is becoming broader and more connected to technology, governance and organisational risk.

AI creates opportunities to work more efficiently. It also makes professional judgement, scepticism and accountability more important.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He works with organisations every day to help them understand and respond to practical data protection challenges.

Amber Sivill

Amber is a Data Protection Consultant at Data Protection People. She supports organisations with data protection compliance, governance and emerging technology risks.

Watch or Listen to the Episode

Watch the full episode on YouTube or listen on Spotify.

Watch on YouTube

Listen on Spotify

Need Support With AI Governance?

If your organisation is adopting AI, Data Protection Made Easy can help you understand the risks, strengthen governance and meet your data protection responsibilities.

Contact Our Team

S2 Ep28 GDPR Radio – Data Protection News of the Week

S2 Ep28: GDPR Radio – Data Protection News of the Week

Amber Sivill and Mark Farrell discuss recent data breaches, AI risks and privacy enforcement.

From preventable spreadsheet errors to AI-generated decisions, this episode explores the changing risks facing organisations and data protection professionals.

Amber and Mark examine recent incidents involving government departments, exposed AI conversations, employee access to personal data and the growing use of facial recognition technology.

What This Episode Covers

In this episode, Amber and Mark discuss:

  • The Ministry of Defence data breach and the importance of basic software training
  • The cyber attack affecting the Department for Education
  • How AI can support both cyber attacks and defensive security measures
  • Claude conversations appearing in Google search results
  • AI-generated information being used in public-sector decisions
  • New transparency requirements under the EU AI Act
  • The risks created by unsecured paper records
  • Unauthorised employee access to personal data
  • AI-generated inferences and the future of anonymised data
  • Facial recognition, smart surveillance technology and privacy
  • Recent ICO action relating to nuisance marketing messages

When Basic Training Is Overlooked

The episode begins with the Ministry of Defence data breach involving information about Afghan relocation applicants.

Amber and Mark discuss reports that the breach could have been prevented through basic spreadsheet training. They also consider what this tells organisations about accountability and the importance of practical training.

Mark explains:

“AI is going to be leveraged to launch cyber attacks, it also has to be leveraged to combat them.”

The discussion also covers the cyber attack affecting the Department for Education. This demonstrates why organisations need both effective security systems and staff who understand how to recognise potential threats.

Privacy by Design and AI Tools

Amber and Mark discuss reports that shared Claude conversations appeared in Google search results.

The incident raises questions about transparency, default privacy settings and whether users understand when their conversations may become publicly available.

Amber says:

“You need to embed that sort of privacy, privacy by design, privacy by default, making sure that you know the default setting isn’t that my personal conversations are being shared publicly for other people to see.”

Organisations should understand how an AI service handles information before employees enter personal, confidential or commercially sensitive data into it.

AI Decisions and Regulatory Oversight

The hosts examine a case involving information believed to have been generated by AI and used during an asylum decision.

They discuss the risks of relying on AI-generated material without proper fact-checking or meaningful human oversight. Meaningful human oversight means a person genuinely reviews the information and can challenge or change the outcome.

The conversation also covers EU AI Act transparency requirements and the need for clearer UK rules.

Amber explains:

“I think this just goes to show that the current legislation doesn’t fit. I think it fits in so many ways in terms of the principles, but we need more specifics that are tailored towards AI use.”

Paper Records and Employee Access

Not every data protection incident involves sophisticated technology.

Amber and Mark discuss confidential paper records reportedly found in an unsecured former council building. They also examine cases involving employees accessing personal records without authorisation.

These stories show why organisations must protect information throughout its lifecycle. This includes digital files, archived documents and paper records.

Access controls should also ensure that employees can only view information they genuinely need for their role.

AI Inferences and Anonymised Data

The episode considers how AI may infer sensitive information from data that appears to be aggregated or anonymised.

Anonymised data is information that can no longer be linked to an identifiable person. However, more capable technology may make it easier to identify patterns or combine information from different sources.

Amber and Mark discuss whether existing definitions and safeguards will remain effective as AI develops.

Facial Recognition and Smart Surveillance

The hosts also examine AI-enabled street technology that can use cameras and facial recognition to identify people or detect potential offences.

These tools may support law enforcement and public safety. However, they also create questions about proportionality, transparency and function creep. Function creep happens when information or technology is gradually used for purposes beyond the reason it was originally introduced.

Mark summarises one of the central concerns:

“You behave differently when you’re being watched.”

Recent ICO Enforcement

The episode closes with recent action from the Information Commissioner’s Office relating to nuisance marketing about motor finance claims.

Amber and Mark discuss the use of search warrants and cooperation between different regulators. They also consider whether enforcement is being applied consistently across organisations and sectors.

Practical Takeaways for Organisations

Organisations should:

  • Include practical software skills in data protection training
  • Review the privacy settings of AI tools before using them
  • Avoid entering sensitive information into systems without appropriate safeguards
  • Apply meaningful human oversight to AI-supported decisions
  • Protect paper records as carefully as digital information
  • Regularly review employee access permissions
  • Assess whether anonymised information could be re-identified
  • Consider privacy risks before introducing surveillance technology

Watch or Listen

Watch or listen to the full episode of GDPR Radio:

📺 Watch the episode on YouTube

🎧 Listen to the episode on Spotify

Meet Your Hosts

Amber Sivill

Amber explores how emerging technology, AI governance and privacy risks affect organisations in practice.

Mark Farrell

Mark examines recent data protection developments and the practical lessons organisations can take from them.

Data Protection Made Easy

Data Protection Made Easy helps organisations understand and meet their responsibilities under UK GDPR and related data protection law.

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
What Happens When Your DPO Is OOO_
21 August 26 12:30 - 1:15 pm

S2 Ep31: What Happens When Your DPO Is OOO?

S2 Ep30 GDPR Radio - Data Protection News of the Week
14 August 26 12:30 - 1:15 pm

S2 Ep30: GDPR Radio – Data Protection News of the Week

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.