Join our extensive list of clients who have their data privacy under control
Accelerate Your Data Protection Compliance
Save Time, Save Money and Relax: You’re In Safe Hands
Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.
Data Protection People's world-class GDPR Support Desk. If you're navigating the complex landscape of data protection, PCI DSS, and cybersecurity, our support desk is your reliable compass.
A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.
At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.
A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.
A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.
A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.
At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.
Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.
Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.
Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.
Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.
Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.
Diverse Sector Experience
Access to a Team of Industry Experts
At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.
Commercial Sector
Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.
SMEs
Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.
Third Sector
For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.
Multi Nationals
For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.
Public Sector
In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.
Why Use Our Outsourced DPO Services?
Save Time, Money and Guarantee Compliance
Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.
Why Choose Outsourcing?
An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.
Staying Headache-Free
Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.
Compliance Tailored to You
Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.
“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.
I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”
Mark Leete
Eastlight Community Homes
‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’.
‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’.
Charlene Haynes & Team
Tendring District Council
“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining,and David Hendry. A great, reliable and dependable service!”
Judy Barker
Dyslexia Action
“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.
Julie Ferguson
Veritau
“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”
Nia Roberts
Woodgate & Clarke
Data Protection People Blogs & Podcasts
Data Privacy Learning & Guidance
Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.
The ICO has approved a UK GDPR code of conduct for information sharing between public services in Wales. The Wales Accord on the Sharing of Personal Information (WASPI) code was approved on 24 September 2026 and announced on 28 September 2026.
What happened?
WASPI is an existing framework that helps organisations in Wales share personal information safely. More than 1,000 organisations are already signed up to it, according to the ICO.
Its new code of conduct has now been approved under Article 40 of the UK GDPR. A code of conduct is a set of sector rules, approved by the regulator, that shows how data protection law applies in practice. Members who follow an approved code have a recognised way to show accountability. The ICO’s Chris Hogan described it as “a clear and recognised way to demonstrate accountability”.
The key facts, from the ICO’s register of codes:
Reference: ICO-CC/002
Approved: 24 September 2026
Code owner: Digital Health and Care Wales
Monitoring body: the WASPI Service, which is still pending ICO approval
What does the code cover?
The code covers sharing personal information to deliver health, education, social care, safeguarding and other public services to people in Wales.
Code members must:
use the WASPI information sharing protocol (ISP) template, a standard document that sets out what is shared, why and how
put governance controls in place
go through a quality assurance process
accept ongoing monitoring
review their information sharing arrangements regularly
Who does it affect?
The code applies to organisations that share personal information to deliver public services in Wales and choose to sign up. That includes:
charities and voluntary organisations working alongside public services
The code concerns information sharing for services to people in Wales. An organisation’s address alone does not decide eligibility: check the code’s membership criteria with WASPI, particularly for cross-border arrangements. Organisations elsewhere can still use its approach as a prompt to review their own practices.
Why does it matter?
Sharing information between services is where data protection often goes wrong. Some staff hold back information that should be shared, for example in a safeguarding case. Others share without a clear lawful basis or a written agreement.
A code gives everyone the same template and the same checks. That makes it easier for staff to share with confidence and easier for organisations to prove they got it right.
Does joining WASPI replace your UK GDPR responsibilities?
No. A code supports accountability; it does not supply a lawful basis for every disclosure or remove your responsibility to assess each sharing arrangement. Record the purpose, lawful basis, safeguards and responsibilities before sharing.
What should organisations do now?
If you work in Wales and already use WASPI:
Check your information sharing protocols use the current WASPI template.
Make sure each protocol has a named owner and a review date.
Watch for the monitoring body’s approval. The regulator’s register still lists approval of the monitoring body as pending at the time of this review.
If you work in Wales and don’t use WASPI:
List the organisations you regularly share personal information with.
Consider whether joining the code would give you a clearer, consistent way to document that sharing.
If you work elsewhere in the UK:
Review your data sharing agreements. Are they current, consistent and easy for staff to find?
Compare them with the ICO’s data sharing code of practice, which applies across the UK.
We support local authorities and schools, academies and colleges with data sharing agreements, DPIAs and day-to-day data protection advice. If you’d like a review of your information sharing arrangements, talk to our team about the support you need.
The short answer: Since 1 October 2026, private registered providers of social housing in England must have a STAIRs publication scheme. It covers information they hold about governance, spending, homes, performance, services, registers and housing management. Providers do not have to create new records. Appropriate redaction is allowed. The separate requirements for tenant information requests begin on 1 April 2027.
What is a publication scheme?
A publication scheme explains what information your organisation makes available routinely and where tenants can find it. They should not have to make a formal request to understand how you run homes and services.
The requirements apply to private registered providers of social housing in England. This includes housing associations. The policy does not provide a general exemption for small providers.
Local authority landlords are already subject to the Freedom of Information Act. Do not assume STAIRs applies to every housing organisation across the UK. Check your registration and the services you provide.
What must it include?
Your scheme must cover information you hold within seven areas. The examples below help you identify existing material. They are not a substitute for checking the policy statement.
1. Governance and decision making
Explain who runs the organisation and how decisions are made. Examples include senior staff roles, governance arrangements, decision-making policies and information about tenant consultations.
2. Spending
Show how money is used. Existing financial reports, grant information and explanations of how service charge revenue is spent can help cover this area.
3. Housing stock management
Include information about managing and maintaining homes. Examples include maintenance plans, stock transfers and progress towards net zero.
4. Performance
Help tenants understand how services are performing. Examples include inspection outcomes, Tenant Satisfaction Measures, complaint figures, health and safety assessments and maintenance performance.
5. Housing services
Describe the services tenants can use. Link to existing advice, guidance and service information, including how tenants can access support.
6. Lists and registers
Review information held in legally required registers and other lists relating to social housing management. Assess what can reasonably be published without exposing protected information.
7. Social housing management
Include policies and strategies for managing social housing. Your existing housing management policies may already provide much of this information.
What does a publication scheme not require?
You do not have to create new records. Start with information your organisation already holds. This does not remove the need to identify it and make it accessible.
You do not have to publish every document without checks. Appropriate and reasonable redaction is permitted. Record why information is withheld and apply the policy statement’s safeguards.
It is not a one-off upload. Providers must review and update the information regularly. Assign an owner and choose a review cycle that fits your organisation.
How should you publish it?
Tenants must be able to identify and access the information. These five practical steps can help:
Create an easy-to-find starting point. A dedicated website page can link to information you already publish. Check that the links work.
Group information under the seven areas. Make it clear what each link contains and flag gaps for action.
Make access practical. Use plain English and accessible documents. Provide a route for tenants who need another format or cannot use the website.
Explain how to contact you. Include questions about missing information and the STAIRs review process.
Keep it current. Show a review date, assign owners and check for changes to policies, services and published figures.
These are implementation suggestions. A particular page layout or quarterly review cycle is not prescribed by the policy statement.
Missed 1 October? Here’s how to catch up.
If your scheme is not ready, start by identifying the gaps. Keep a clear record of your actions and who is responsible for them.
Order existing information. Check annual reports, policies, service pages, performance reports and governance material against the seven areas.
Prioritise missing items. Identify information you hold but have not made available. Give each action an owner and a realistic completion date.
Check before publishing. Review accuracy, accessibility and any information that needs redaction.
Publish checked material promptly. Keep working on gaps. A first version does not, by itself, establish that you have met every requirement.
Tell tenants where to find it. Explain the contact and review routes, then schedule your next check.
How do you protect personal data before publishing?
Transparency does not mean publishing personal information without a lawful reason. Review documents for names, contact details, complaint information and details that could identify a tenant indirectly.
Do not automatically remove every name. Some information, such as senior staff roles, may be appropriate to publish. Assess the purpose and legal basis for each disclosure.
Where redaction is needed, remove the information securely. Check comments, tracked changes, hidden data and searchable text. A coloured box over text may leave the underlying information accessible.
Keep a record of decisions and have someone check the final public version. Our STAIRs housing FAQs cover further practical questions.
How is a STAIRs request different from a SAR?
A STAIRs request concerns relevant information about the management of social housing. A subject access request (SAR) concerns a person’s own personal data.
For example, a request for a repairs policy is different from a request for personal information in a tenant’s repair records. One message may contain both.
Assess each part and route it correctly. The STAIRs policy directs providers towards the appropriate statutory route where a separate legal right of access applies. Do not apply the STAIRs 18-hour limit to a SAR.
From 1 April 2027, tenants or their designated representatives can make written requests for relevant information. Providers should acknowledge them promptly.
30 calendar days: Respond promptly and no later than 30 calendar days from receipt. Extra time is permitted only in exceptional circumstances specified in the policy. Explain any delay and when a response is expected.
18-hour staff-time limit: A provider may refuse where the work involved would exceed 18 hours. This is a refusal threshold, not an automatic charge. Record the reasoning behind any estimate.
Internal review: If the tenant is dissatisfied, they should first complain to the provider. The review should normally finish within 30 calendar days, with additional time possible in certain circumstances.
Housing Ombudsman: A tenant dissatisfied with the review can escalate under the Housing Ombudsman Scheme.
The publication scheme has its own review and escalation route already. Do not wait until April 2027 to explain how tenants can raise missing information.
Identify the information you hold under all seven areas.
Check what is already public and prioritise gaps.
Review personal data and record withholding decisions.
Check links, readability and access in other formats.
Explain the contact, review and escalation routes.
Tell tenants where to find the scheme.
Assign owners and regular review dates.
Prepare request-handling processes for April 2027.
Frequently asked questions
When did STAIRs publication schemes become mandatory?
The publication-scheme requirements apply from 1 October 2026 to private registered providers of social housing in England.
Do housing associations have to create new records?
No. The publication scheme covers information already held. Providers still need to identify relevant information and make it accessible.
Can we redact information before publishing?
Yes, where appropriate and reasonable. Apply the policy statement’s safeguards, assess personal data carefully and record the reasons for redaction.
When do tenant information requests begin?
The separate information-request requirements begin on 1 April 2027. Providers must respond promptly, normally within 30 calendar days of receipt.
Where do publication-scheme complaints go?
Tenants should first use their provider’s STAIRs review process. If dissatisfied with the review, they can escalate to the Housing Ombudsman under its Scheme.
Is STAIRs the same as the Freedom of Information Act?
No. STAIRs is a separate framework for private registered providers. It supports tenant access to housing management information but does not make those providers subject to FOI simply because STAIRs applies.
How can Data Protection People help?
Need help reviewing your publication scheme or preparing your team for information requests? We can help you work through information rights and data protection questions.
External Attack Surface Management, usually shortened to EASM, is the continuous discovery and monitoring of everything your organisation exposes to the internet, domains, subdomains, cloud services, servers and applications, including the ones nobody currently has on a list.
What “attack surface” actually means
Your external attack surface is every point an attacker could potentially reach from outside your network. That includes the systems your IT team knows about and manages deliberately, but it also includes things that accumulate without anyone fully tracking them, a test server spun up for a project and never decommissioned, a marketing microsite built by an agency years ago, a cloud storage bucket set up for a one-off task, a subdomain nobody remembers creating. None of these are necessarily malicious or even risky on their own, but each one is a potential entry point, and you can’t secure what you don’t know exists.
Why this differs from a pentest or a vulnerability scan
Penetration testing and vulnerability scanning both work against a defined, known scope, systems you’ve already identified and agreed to test. EASM works the other way round, it starts from the outside, mapping what’s actually visible on the internet under your organisation’s name, and works to identify assets you may not have deliberately included in any existing security process at all. It’s the discovery layer that should logically come before testing, since a pentest against a scope that’s missing half your real exposure only gives you confidence in the part you already knew about.
How EASM actually works
EASM tools and services continuously scan public sources, DNS records, certificate transparency logs, IP ranges and cloud provider metadata, to build and maintain a live map of everything associated with your organisation that’s reachable from outside. That map gets checked for common exposure issues, out of date software, exposed admin panels, misconfigured cloud storage, expired certificates and anything genuinely concerning gets flagged for investigation. Because it’s continuous rather than a one-off exercise, new exposure gets caught close to when it appears, not months later during the next scheduled review.
Why this has become more important
Organisations’ external footprints have grown substantially with the shift to cloud services, third-party tools and distributed teams who can spin up new infrastructure without necessarily going through a central IT process. That’s not a criticism of how modern organisations operate, it’s simply a consequence of how much easier it now is to stand up a new service, and it means the gap between what security teams officially track and what’s actually exposed has grown alongside it. EASM exists specifically to close that gap.
Questions organisations usually ask about EASM
How is this different from just asking IT for a list of our systems? An internally maintained list only ever reflects what was deliberately recorded, and in practice things get missed, a project ends, a subdomain stays live, a cloud account gets set up outside the usual process. EASM discovers assets independently of any internal list, which is exactly the point, it finds what the list doesn’t know about.
Is this a one-off exercise or does it need to run continuously? It works best as continuous monitoring rather than a single scan, since new external assets appear constantly as an organisation operates. A one-off discovery exercise gives you an accurate picture on the day it runs, but that picture starts going out of date almost immediately.
What happens once something unexpected is found? Typically the finding gets triaged, confirmed as genuinely belonging to your organisation, assessed for how exposed or risky it actually is, and then either brought under proper management or decommissioned if it’s no longer needed. Not everything found is a problem, some of it is simply forgotten infrastructure that just needs tidying up.
Do we need this if we already do regular penetration testing? The two work together rather than replacing each other. A pentest assesses depth against an agreed, known scope. EASM addresses breadth, finding what should be in scope in the first place. Testing against an incomplete scope only ever gives you confidence in the part you already knew about.
Is EASM right for your organisation
It’s particularly valuable for organisations of meaningful size or with a history of mergers, acquisitions, agency-built projects, or multiple teams independently provisioning their own infrastructure, all situations where an accurate, centrally held inventory of external assets is unlikely to exist without deliberate effort. Even smaller organisations benefit from an initial discovery exercise, since the honest answer to “do you know everything your organisation exposes to the internet” is very often no, and finding that out is the necessary first step before any other security work can be properly scoped.
Generative AI tools like ChatGPT, Microsoft Copilot and Gemini can be used in schools under UK GDPR if used safely and effectively, with appropriate data protection policies in place.
To remain GDPR-compliant, schools should avoid using free versions of generative AI tools, as they may lack the necessary safety features. Instead, schools should use enterprise tools integrated into a broader workspace of educational tools, such as Copilot in Microsoft 365 or Gemini in Google Workspace.
What Data Risks Do Generative AI Tools Present in Schools?
Generative AI tools themselves don’t pose data protection risks; the risks depend on how they are used. These include:
Data Breaches – If staff members paste sensitive data into AI tools without notifying parents and pupils that their data will be used in this way, it may constitute a data breach.
GDPR Compliance Risks – Many AI tools are operated by US companies, so without data residency controls, personal data may be processed and stored outside the UK, creating GDPR compliance risks.
Intellectual Property – When a student completes a piece of work, the intellectual property belongs to them. Submitting this work to a free generative AI tool for feedback could result in the data being used to improve the AI’s systems, potentially raising issues regarding intellectual property rights and data protection compliance.
What Data Protection Policies Should Schools Follow When Using Generative AI Tools?
Consult a Data Protection Officer
Before using generative AI for any activity, schools should consult their appointed Data Protection Officer (DPO). A DPO can review the chosen AI tool(s), ensure that appropriate data policies are in place and advise staff on how to use them effectively.
Carry Out a DPIA
The ICO requires a Data Protection Impact Assessment (DPIA) before using AI in high-risk processing activities, including any use of AI involving children’s personal data. A DPIA should outline how the data is processed and its purpose, assess necessity and identify and mitigate risks.
Be Transparent About Data
Government advice recommends that personal data not be used in generative AI tools in educational settings.
If it is necessary for schools to use personal data in AI tools, they must:
Be open and transparent about how they are considering using automation and AI
Ensure that pupils, parents and guardians understand that their personal data is being processed using AI
Seek consent to use data within AI
Use The Right Tools
Government advice further recommends that staff members only use AI tools provided by their institution. This is likely to include:
Microsoft Copilot under a Microsoft 365 for Education licence
Gemini under a Google Workspace for Education licence
These paid tools keep data within a managed school environment, don’t use data to train public AI models and respect existing security and privacy controls.
Provide Data Protection Training to Staff
Data protection training can help staff understand UK GDPR compliance and what constitutes a data breach. Staff must understand what data should never be entered into AI tools and which AI platforms are approved for work use.
Ensure Your School Is GDPR Compliant with Data Protection People
Generative AI can transform education, but it must be balanced with the responsibility to protect personal data and meet GDPR requirements.
Can AI help you write a Data Protection Impact Assessment? And how do you assess the privacy risks of the AI system itself?
In S2 Ep38 of Data Protection Made Easy, Caine Glancy and Catarina Santos (Cate) explore both sides of the conversation: carrying out DPIAs for AI projects and using AI to help prepare an assessment.
What We Discuss
Understanding how an AI system uses personal data, including its inputs, outputs and who can access them.
Asking practical questions about suppliers, retention and where information goes.
Using AI to organise information, suggest questions and identify gaps in a DPIA.
Why project-specific information and human review remain important.
Setting clear boundaries for how staff use AI tools.
Join Cate and Caine for a practical discussion about making informed decisions, checking assumptions and keeping people involved in the assessment process.
Our DPIA service helps you identify and assess privacy risks in new projects, systems or processes. We work with your team to document the assessment and recommend practical measures to reduce risks and support informed decisions.
Sector Spotlight Ep1: Caught Between the FCA and UK GDPR – What DPOs Need to Know
Financial services businesses face overlapping responsibilities. How do they bring financial regulation and data protection together in practice?
In the first episode of Sector Spotlight, DPP’s Mark Farrell joins Phillip Garlick, CEO of Product Partnerships Limited (PPL), to discuss the relationship between FCA requirements and UK GDPR.
Created as part of the partnership between Data Protection People and PPL, this episode brings together perspectives on data protection, retail finance and the practical realities of running a regulated business.
Explore the Conversation
Our promotional clips explore financial promotions, whether good compliance can support business growth, the cost of compliance in the financial sector, and AI’s promise and peril in data protection.
Watch or listen to the full episode to hear the wider conversation with Mark and Phillip.
Meet Phillip Garlick
Phillip is the CEO of Product Partnerships Limited, which delivers retail financial solutions and compliance support to consumer-facing businesses. PPL helps these firms offer finance to their customers and manage the regulatory responsibilities that come with it.
He has over 30 years’ experience in regulated, consumer-facing sectors, with a strong focus on governance, risk management and sustainable growth.
Phillip is a practising Chartered Director and Fellow of the Institute of Directors. He holds an Advanced Certificate in Governance & Risk from the International Compliance Association and an MBA from Leeds University.
About Sector Spotlight
Sector Spotlight is a separate series within Data Protection Made Easy, exploring data protection through conversations focused on particular sectors. This is episode 1 of the series, rather than an episode in our regular Season 2 numbering.
S2 Ep36: GDPR Radio – Data Protection News of the Week
Cate and Caine are back together on GDPR Radio, and Cate marks the occasion with a little singing before the conversation gets underway.
In S2 Ep36 of Data Protection Made Easy, Caine Glancy and Catarina Santos catch up on data protection news and share practical perspectives on what it means for organisations.
Expect a friendly discussion, familiar faces and plenty of conversation about the world of data protection.
S2 Ep35: AI Redaction Tools: The Mistakes Most SAR Systems Miss
AI redaction tools promise to make handling subject access requests easier. But what might they miss?
In S2 Ep35 of Data Protection Made Easy, Amber Sivill and Katerina Douni discuss AI redaction tools and the challenges organisations face when using them to support SAR responses.
Join them for a practical conversation about technology, redaction and the importance of checking information before it is shared.
We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.
S2 Ep41: GDPR Radio – Data Protection News of the Week
16 October 26 12:30 - 1:15 pm
S2 Ep40:Why Most DPIAs Get Signed Off Too Late to Matter
Get Support With Data Protection And Cyber Security
Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.