The UKs #1 Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

GDPR Training

Data Protection People have a wide range of training services catering for every need. Whether its general training for operational or admin staff or specific training for specialist roles, we have something for you. watch the short video below to meet the team and find out more about our training services.

Contact Us

Information Management Software

DataWise is the original privacy tech platform designed to simplify GDPR compliance management. Since its inception in 2011, DataWise has continuously evolved, solidifying its reputation as the pioneering "privacy tech" solution.

Contact Us

Data Protection Consultancy

Unlock Compliance Excellence with Our GDPR Consultancy Services. Navigating the intricate realm of data protection laws and standards demands expert guidance.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

ISO 27001

Our tailored program, guided by industry-certified experts, supports your ISO 27001 compliance journey. Whether you need advice on certification scope, assistance with remediation work, or comprehensive ISO 27001 consultancy, we’re here to guide you every step of the way.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Rob Wilkinson answering a call

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

How Can Data Protection Risks Affect Printing Service Providers?

How Can Data Protection Risks Affect Printing Service Providers?

Whether producing photographs, wedding invitations, business cards, direct mail, marketing materials or personalised documents, printing service providers routinely receive files containing names, postal addresses, email addresses, telephone numbers and, in some cases, special category personal data, e.g. membership records for a political party or campaign.

Given the nature and volume of the information entrusted to them, organisations operating within the printing industry should ensure that data protection is embedded into their operational processes from the outset.

Compliance should not be viewed merely as a regulatory obligation but as an integral part of business operations. In practice, this requires implementing appropriate technical and organisational measures, configuring printing equipment with data protection-focused settings by default and ensuring that personal data is processed in accordance with the UK GDPR and the Data Protection Act 2018.

Set out below are some of the principal data protection risks that organisations operating in the printing sector should consider.

1. Data Retention

One of the most significant compliance risks concerns the retention of customer data.

Printing companies frequently receive photographs, mailing lists and other files for the purpose of completing a particular order. Once that purpose has been fulfilled, organisations should ensure that personal data is not retained for longer than is necessary unless there is a lawful basis for continued retention.

The UK GDPR requires organisations that process personal information, whether acting as controllers or processors, to comply with the storage limitation principle. This means ensuring that personal data is not kept for longer than is necessary for the purposes for which it is processed unless there is a lawful reason for continued retention.

Retaining customer files indefinitely without an established retention policy or a legitimate business justification may therefore constitute a breach of the legislation.

From a risk management perspective, excessive data retention also increases the potential impact of a personal data breach. The greater the volume of historic customer information retained, the greater the number of individuals likely to be affected in the event of unauthorised access or a cyber incident.

Such incidents may expose organisations not only to regulatory scrutiny by the Information Commissioner’s Office (ICO) but also to reputational damage and loss of customer confidence.

2. Data Stored on Printing Devices

Data protection measures should extend beyond email systems, online ordering platforms and file transfer services.

Modern multifunction printers frequently contain internal hard drives or solid-state drives (SSDs) capable of retaining copies of print, scan and copy jobs.

In addition, organisations may use cloud-managed print solutions, retained scan repositories and manufacturer cloud services, all of which can store or process documents containing personal data.

Unless these systems are appropriately configured and personal data is securely erased or deleted in accordance with documented retention periods, information may remain accessible long after the relevant work has been completed.

For this reason, organisations should ensure that printing devices form part of their information security programme.

Appropriate measures may include:

  • Encrypted storage
  • Secure print functionality
  • Controlled administrator access
  • Regular firmware updates
  • Secure deletion of stored print jobs

3. Disposal of Printing Equipment

When printers, scanners, multifunction devices or servers reach the end of their operational life, organisations should ensure that all storage media are securely sanitised before disposal, resale or return to leasing providers.

Failure to securely erase stored information may result in personal data being recovered by unauthorised third parties.

Such incidents may amount to a personal data breach requiring assessment under the UK GDPR and, where applicable, notification to the Information Commissioner’s Office and affected individuals.

Organisations should therefore implement documented asset disposal procedures and obtain appropriate certification where third-party disposal providers are engaged.

4. Confidentiality, Access Control and Staff Awareness

Employees working within printing environments routinely have access to customer artwork and documents containing personal information.

Consequently, organisations should ensure that access to such information is limited strictly to those individuals who require it for the performance of their duties.

The following measures can help reduce the likelihood of unauthorised access:

  • Robust role-based access controls
  • Confidentiality obligations within employment contracts
  • Regular privacy training
  • Documented internal procedures

It is equally important to recognise that personal data does not need to be copied, disclosed externally or published for a reportable incident to arise.

Unauthorised internal access to customer information may itself constitute a personal data breach under the UK GDPR, depending on the circumstances. Organisations should investigate and manage these incidents in accordance with their incident response procedures.

How Can Data Protection People Assist Printing Organisations?

As discussed above, organisations operating within the printing industry are exposed to a range of data protection and information security risks.

Given the volume and nature of the personal data they process, obtaining specialist data protection advice can assist organisations in demonstrating compliance with the UK GDPR while reducing operational and regulatory risk.

At Data Protection People, we work closely with organisations to develop practical, proportionate compliance frameworks tailored to their business operations.

Our support may include:

  • Identifying and documenting personal data processing activities: This enables organisations to understand how personal data flows throughout the business and maintain accurate Records of Processing Activities (RoPA), where required.
  • Assessing data protection and security risks: We can recommend appropriate technical and organisational measures to protect personal data throughout its lifecycle.
  • Developing data retention and deletion policies: This helps ensure that personal data is retained only for as long as necessary and disposed of securely in accordance with the storage limitation principle under the UK GDPR.
  • Reviewing existing business processes and internal procedures: This helps organisations embed data protection obligations into day-to-day operations and adopt a privacy-by-design approach where appropriate.
  • Preparing or reviewing data protection documentation: This may include privacy notices, internal policies, processor agreements and data processing procedures.
  • Supporting organisations with data subject rights requests: This includes requests for access, erasure, rectification, restriction of processing and objection.
  • Providing practical guidance following personal data breaches: This may include incident assessment, regulatory notification obligations and remediation measures.
  • Delivering staff awareness training: This helps employees understand their responsibilities when handling customer information and reduces the likelihood of human error.

Building Data Protection Into Printing Operations

Printing organisations process significant volumes of personal data and must ensure that appropriate safeguards are in place throughout the entire data lifecycle.

Compliance with the UK GDPR and the Data Protection Act 2018 extends beyond securing customer files. It requires effective governance, appropriate technical and organisational measures, clear retention practices and ongoing staff awareness.

By adopting a proactive, risk-based approach to data protection, organisations can reduce the likelihood of personal data breaches, demonstrate accountability and strengthen customer trust.

Ultimately, robust data protection practices are not only a legal requirement but also an essential element of responsible business operations.

Speak to Our Team

If your organisation needs support with data protection, information security or staff training, contact Data Protection People.

Contact Our Team

AI in Housing: The NHF Report Explained

The National Housing Federation has published a new report, The State of AI in Housing 2025, produced with IT services provider Phoenix, looking at how housing associations are adopting artificial intelligence, the opportunities it offers, the risks it creates, and how ready the sector actually is. It is not new legislation and does not create new legal duties, but it is genuinely useful sector insight for any housing provider already using AI, considering it, or finding that colleagues are quietly experimenting with it already.

AI adoption in housing is already well underway

The headline finding is that AI is not a future consideration for housing, it is already in day-to-day use. The report found that 47% of respondents are using AI in their daily operations, with a further 23% not using it yet but planning to. Current use cases span internal administration, data handling, compliance checks, resident communications and service delivery.

Confidence and governance haven’t kept pace with adoption

The report also shows a sector that is moving faster than its own readiness. 87% of respondents rated their knowledge of AI as low, and 44% have no AI policy in place at all. That gap, widespread use alongside limited confidence and limited governance, is the part of the report worth paying closest attention to. AI can genuinely help a housing provider save time, support staff and improve services, but it should never be treated as a straightforward technology purchase or a way around existing data protection obligations.

The same data protection questions still apply

Whatever the tool, the same questions need answering before personal data goes anywhere near it. What is the purpose? Is the use necessary? What is the lawful basis? Have people been told clearly what is happening with their data? Is the information secure? And are you confident the tool itself is accurate and fair?

These questions carry extra weight in housing specifically, given the nature of the data involved, often including residents’ health, financial circumstances, vulnerabilities, safeguarding concerns and household situations.

Where the real risks sit

The report highlights privacy and security, bias and discrimination, accountability, and inaccurate AI-generated information as the key areas to watch. AI can produce an answer that sounds entirely convincing while being wrong, and it can reflect bias baked into the data it was trained on. That matters most where AI could influence decisions about residents, allocations, arrears, complaints handling, vulnerability assessments or safeguarding.

The safest approach is straightforward: do not let AI make high-impact decisions about individuals without a proper assessment, meaningful human involvement, and a clear route for someone to challenge the outcome.

A sensible way to adopt AI, according to the report’s own case studies

The organisations getting this right in the report’s case studies followed a similar pattern: start with a lower-risk use case, secure genuine leadership support, involve staff early, and put governance in place before the project expands rather than after.

Four steps worth taking now

Based on the report’s findings, four immediate actions stand out for any housing provider:

    • Find out which AI tools are actually being used across the organisation, including tools staff may be using independently without anyone else knowing.
    • Put clear guidance in place so staff know exactly what can and cannot be entered into an AI tool. Personal, confidential and special category data should never go into an unapproved tool.
    • Carry out proper due diligence on any AI supplier, understanding the contract, where data is processed, whether there are international transfers, and what security measures are actually in place.
    • Assess higher-risk uses properly. Where an AI project could create a high risk to people’s rights and freedoms, a Data Protection Impact Assessment may be required before processing begins.

Adopt AI thoughtfully, not cautiously or carelessly

The message from the report isn’t to avoid AI, it’s to adopt it thoughtfully. Innovation and data protection aren’t competing priorities. Good governance, clear policies, trained staff and proper oversight are what give a housing provider the confidence to use AI in a way that protects residents, supports staff and builds trust.

For housing associations without the in-house resource to build that governance from scratch, this is exactly the kind of gap an outsourced DPO is built to close, bringing practical AI policy development, supplier due diligence and DPIA support without needing to build the capability internally. If you’re considering an AI project, reviewing a supplier, or need support with an AI policy or DPIA, speak to your Data Protection Officer or get in touch with the Data Protection People team.

How AI Is Reshaping the DPO Role in 2026

By Amber Sivill, Data Protection Consultant and AI Specialist at Data Protection People

Artificial intelligence is not only changing the way organisations handle information, it is changing the way individuals understand, exercise and challenge their individual rights. That shift is now landing firmly on the DPO’s desk. Ahead of this Friday’s podcast episode on how AI is reshaping the DPO role, I wanted to share what I am seeing in practice, and why I think the roles and responsibilities of a DPO are becoming more strategic, visible, and more closely connected to AI governance than ever before.

Subject access requests are changing shape, not just volume

Most DPOs I speak to will recognise the same trend: subject access requests are coming in fast and strong, and the requests themselves are becoming more broad complex. Some of that is the result of greater public awareness of data rights. But it is increasingly clear that data subjects are using AI tools to assist them with drafting more detailed and legally focused requests.

A request that once said, “please send me my data”, may now arrive with references to specific processing activities, legislation, ICO guidance and carefully worded follow-up questions. That does not mean the individual is being difficult. In many cases, they have simply had support from an AI tool to articulate what they are asking for. For organisations, the practical effect is clear: SARs can take longer to assess, scope and respond to, even where the underlying request is perfectly legitimate.

The regulatory position has also moved on. Since February of this year, the Data (Use and Access Act) 2025 has given organisations more room to take a reasonable and proportionate approach to searches, rather than treating every request as requiring an exhaustive search of every system and record. It also allows organisations to “stop-the-clock” whilst waiting for identity verification or clarification where a request is unclear. Whilst those changes provide more flexibility to organisations, they do not remove the need for a robust process or adequate resources to address a request. In my experience, many complaints arise not because an organisation neglected their responsibilities under data protection law, but because expectations were not managed, communication was unclear, or the SAR process did not hold up under pressure.

The workplace risk nobody’s policy covers yet

The SAR challenge is only part of the picture. The other, and often less visible, issue is what is happening inside organisations. Staff are increasingly experimenting with consumer AI tools to save time, summarise information, draft communications and sense-check their work. That behaviour is understandable, particularly where approved tools are not available, but it creates real data protection risk when there are no clear rules around what can and cannot be shared.

In practical terms, this might mean someone pasting a client email thread into a personal AI account to help draft a reply. It might mean uploading a contract, pricing document or HR note to create a quick summary. In the moment, that may feel like a harmless productivity shortcut. From a data protection perspective, however, personal data and confidential business information may have left the organisation’s control, with little or no record of what was shared, where it went, or how it may be used afterwards.

This is where policy, training and governance need to catch up with day-to-day behaviour. If an organisation has no approved AI tools, no written position on staff use, and no practical examples of what is and is not acceptable, employees will make their own judgement calls. That is not just a training gap. It is a governance gap, and it is exactly the kind of issue a DPO should be helping the organisation to identify and close.

Where AI is actually helping, not just complicating things

It would be too simplistic to present AI only as a risk. Used properly, it can also support better data protection practice. The organisations making the strongest progress are not necessarily the ones banning AI outright. They are the ones setting sensible boundaries, choosing appropriate tools, and making sure human oversight remains built into the process.

For example, AI-assisted triage can be genuinely useful in SAR handling. It can help identify likely duplicate documents, flag material that may contain third-party data, and support the first review of large data sets. It can also help organisations spot patterns across complaints, requests and internal queries that may point to a wider process issue. Used carefully, those capabilities can give DPOs more time to focus on judgement, accountability and risk, rather than manual administration.

The key point is that AI should not be treated as a shortcut around governance. It should be assessed in the same practical way as any other tool or processor: what data does it use, where does that data go, what controls are in place, and what role does human review play in the final decision?

What this means for your organisation

None of this is a reason to panic. It is a reason to take stock. If SARs are becoming harder to scope, if staff are using AI tools without clear guidance, or if your organisation does not have the internal capacity to keep pace with the rate of change, it may be time to look at whether your current data protection arrangements are still fit for purpose. An experienced outsourced DPO can bring both the day-to-day capacity and the AI-specific knowledge needed to turn uncertainty into a practical, proportionate plan.

We will be exploring this in more detail on this Friday’s episode of the Data Protection Made Easy podcast, including what we are seeing across client organisations and what a sensible, usable AI policy looks like in practice.

Player Data Rights Under UK GDPR: A Guide for Sports Clubs

Player Data Rights Under UK GDPR: A Guide for Sports Clubs

Pre-season is underway. Across football, rugby and other contact sports, clubs are strapping GPS vests and bicep-worn heart rate monitors onto players again.

As a result, an old question returns: who does player performance data belong to? The club? The analytics company? The wearable manufacturer? The betting firm that profits from it? Or the player it’s actually about?

The honest answer is nobody.

UK law does not treat personal data as property. UK GDPR does not give anyone ownership of personal data. Instead, it defines personal data as information that “relates to” an identified individual, not information that belongs to one. That distinction is deliberate.

However, players do have rights. They can ask how organisations use their data, access it, correct it, object to its use and, in some circumstances, have it deleted.

Meanwhile, the organisations handling that information act as controllers or processors. They have legal obligations, not property rights. That is exactly where the tension sits.

This responsibility does not sit with clubs alone. A club acts as a controller for the data it collects. However, analytics companies and wearable providers may also act as controllers if they use the data for their own purposes, such as refining products or benchmarking across clients.

Where a club and provider process the same data for a shared purpose, they become joint controllers under Article 26. They must agree who is responsible for each obligation and explain this clearly to players.

Therefore, clubs cannot simply assume that a provider is “processing on our behalf.” They need to check.

Why This Keeps Coming Up

Project Red Card has brought this issue into sharp focus.

Hundreds of current and former professional footballers have challenged gaming, betting and data companies over the unconsented use of their personal data.

Media coverage has reported potential exposure running into the hundreds of millions of pounds. Players are seeking to recover lost income going back six years, which is the statutory limit for such claims in the UK.

At the same time, players and their unions are making the same argument. PFA England chief executive has said players need to be “at the heart of these decisions around data use both on and off the pitch.”

FIFPRO’s own survey found that most professional footballers want access to their performance data to help them improve. However, they are also concerned about how organisations collect and use it. Many feel they do not have clear information about their rights.

Put simply, players are not against data collection. They want a say in it.

The Rights in Practice

Under UK GDPR, players have the right to know how organisations use their data. They can also make a subject access request to any organisation processing their information, not just their club.

In addition, they can ask an organisation to correct inaccurate data. They can object to processing under Article 21 and, in certain circumstances, request the deletion of their information.

FIFPRO developed its Charter of Player Data Rights with FIFA. The Charter sets out a near-identical list of rights.

Therefore, this is not just DPP’s position. It is the standard the game’s own governing bodies are pushing towards.

Where Clubs Get Exposed

Clubs usually have a lawful basis for collecting player data. However, the risk often appears further downstream.

Once a club licenses data to Football DataCo, shares it with an analytics provider or passes it to a commercial partner, each transfer needs its own lawful basis.

For example, a third-party provider may continue using player data after a contract ends. It may use the information for “product improvement” or include it in an aggregated dataset because nobody checked the exit terms.

As a result, the club may be unable to explain who holds the data or what they use it for. A player or union is entitled to challenge exactly this kind of gap.

Health data raises the stakes further. Heart rate, injury risk and recovery data are special category data under Article 9. This means organisations must meet a higher legal standard and will usually need a DPIA.

Euro 2024 showed how easily this can go wrong. A wearable manufacturer publicly posted one player’s heart rate and another player’s sleep data on social media. This attracted scrutiny over how far a provider’s control over player data should extend.

Finally, many technology providers operate outside the UK. Consequently, clubs may need restricted transfer mechanisms. This could include an International Data Transfer Agreement supported by a genuine Transfer Risk Assessment, not a box-ticking exercise.

This is live, active work across the sector right now.

How Data Protection People Can Help

At Data Protection People, we work on these issues now.

We review and negotiate data processing agreements with analytics providers, wearable manufacturers and commercial partners. Crucially, we cover what happens when the relationship ends, including the retention, deletion and return of data.

We also put International Data Transfer Agreements and Transfer Risk Assessments in place when data moves outside the UK.

In addition, we carry out DPIAs before organisations introduce new tracking technology, not after they have already rolled it out to the training ground.

Where a club is unsure whether a provider acts as a processor, an independent controller or a joint controller, we help establish the correct relationship. This is often one of the first things worth checking because it changes the contractual requirements and determines who is accountable if something goes wrong.

We currently advise football clubs on exactly this kind of work. With the new season starting and clubs signing fresh wearable and analytics contracts across the division, now is the point in the calendar when getting it right matters most.

Otherwise, the paperwork may remain buried until the next renewal comes around.

Nobody owns personal data. However, every player has rights over theirs. Clubs, providers and betting companies must be able to show that they respect those rights.

Sources

S2 Ep28 GDPR Radio – Data Protection News of the Week

S2 Ep28: GDPR Radio – Data Protection News of the Week

Amber Sivill and Mark Farrell discuss recent data breaches, AI risks and privacy enforcement.

From preventable spreadsheet errors to AI-generated decisions, this episode explores the changing risks facing organisations and data protection professionals.

Amber and Mark examine recent incidents involving government departments, exposed AI conversations, employee access to personal data and the growing use of facial recognition technology.

What This Episode Covers

In this episode, Amber and Mark discuss:

  • The Ministry of Defence data breach and the importance of basic software training
  • The cyber attack affecting the Department for Education
  • How AI can support both cyber attacks and defensive security measures
  • Claude conversations appearing in Google search results
  • AI-generated information being used in public-sector decisions
  • New transparency requirements under the EU AI Act
  • The risks created by unsecured paper records
  • Unauthorised employee access to personal data
  • AI-generated inferences and the future of anonymised data
  • Facial recognition, smart surveillance technology and privacy
  • Recent ICO action relating to nuisance marketing messages

When Basic Training Is Overlooked

The episode begins with the Ministry of Defence data breach involving information about Afghan relocation applicants.

Amber and Mark discuss reports that the breach could have been prevented through basic spreadsheet training. They also consider what this tells organisations about accountability and the importance of practical training.

Mark explains:

“AI is going to be leveraged to launch cyber attacks, it also has to be leveraged to combat them.”

The discussion also covers the cyber attack affecting the Department for Education. This demonstrates why organisations need both effective security systems and staff who understand how to recognise potential threats.

Privacy by Design and AI Tools

Amber and Mark discuss reports that shared Claude conversations appeared in Google search results.

The incident raises questions about transparency, default privacy settings and whether users understand when their conversations may become publicly available.

Amber says:

“You need to embed that sort of privacy, privacy by design, privacy by default, making sure that you know the default setting isn’t that my personal conversations are being shared publicly for other people to see.”

Organisations should understand how an AI service handles information before employees enter personal, confidential or commercially sensitive data into it.

AI Decisions and Regulatory Oversight

The hosts examine a case involving information believed to have been generated by AI and used during an asylum decision.

They discuss the risks of relying on AI-generated material without proper fact-checking or meaningful human oversight. Meaningful human oversight means a person genuinely reviews the information and can challenge or change the outcome.

The conversation also covers EU AI Act transparency requirements and the need for clearer UK rules.

Amber explains:

“I think this just goes to show that the current legislation doesn’t fit. I think it fits in so many ways in terms of the principles, but we need more specifics that are tailored towards AI use.”

Paper Records and Employee Access

Not every data protection incident involves sophisticated technology.

Amber and Mark discuss confidential paper records reportedly found in an unsecured former council building. They also examine cases involving employees accessing personal records without authorisation.

These stories show why organisations must protect information throughout its lifecycle. This includes digital files, archived documents and paper records.

Access controls should also ensure that employees can only view information they genuinely need for their role.

AI Inferences and Anonymised Data

The episode considers how AI may infer sensitive information from data that appears to be aggregated or anonymised.

Anonymised data is information that can no longer be linked to an identifiable person. However, more capable technology may make it easier to identify patterns or combine information from different sources.

Amber and Mark discuss whether existing definitions and safeguards will remain effective as AI develops.

Facial Recognition and Smart Surveillance

The hosts also examine AI-enabled street technology that can use cameras and facial recognition to identify people or detect potential offences.

These tools may support law enforcement and public safety. However, they also create questions about proportionality, transparency and function creep. Function creep happens when information or technology is gradually used for purposes beyond the reason it was originally introduced.

Mark summarises one of the central concerns:

“You behave differently when you’re being watched.”

Recent ICO Enforcement

The episode closes with recent action from the Information Commissioner’s Office relating to nuisance marketing about motor finance claims.

Amber and Mark discuss the use of search warrants and cooperation between different regulators. They also consider whether enforcement is being applied consistently across organisations and sectors.

Practical Takeaways for Organisations

Organisations should:

  • Include practical software skills in data protection training
  • Review the privacy settings of AI tools before using them
  • Avoid entering sensitive information into systems without appropriate safeguards
  • Apply meaningful human oversight to AI-supported decisions
  • Protect paper records as carefully as digital information
  • Regularly review employee access permissions
  • Assess whether anonymised information could be re-identified
  • Consider privacy risks before introducing surveillance technology

Watch or Listen

Watch or listen to the full episode of GDPR Radio:

📺 Watch the episode on YouTube

🎧 Listen to the episode on Spotify

Meet Your Hosts

Amber Sivill

Amber explores how emerging technology, AI governance and privacy risks affect organisations in practice.

Mark Farrell

Mark examines recent data protection developments and the practical lessons organisations can take from them.

Data Protection Made Easy

Data Protection Made Easy helps organisations understand and meet their responsibilities under UK GDPR and related data protection law.

S2 Ep27: Creating Training Which Changes Behaviour

Creating Training Which Changes Behaviour

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Data protection training should do more than record attendance. It should help people recognise risks, understand their responsibilities and know what action to take.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss why generic training often fails to engage staff. They explore how organisations can make training practical, relevant and easier to apply during everyday work.

Why Generic Training Often Falls Short

Training can be technically accurate without being effective.

A presentation may explain the law correctly, but staff are unlikely to remember it if the content does not relate to their role. Long presentations, legal language and broad examples can make data protection feel more complicated than it needs to be.

Amber explained:

“Poor training for me is where organisations design training and it may be very well researched, but it is not tailored.”

Training should connect data protection requirements to real decisions. Staff need to understand how the subject affects their work, their customers and the personal data they handle.

Make Training Relevant to Each Role

Different teams use personal data in different ways.

Human resources teams, senior managers, IT staff and customer service teams may face very different risks. Giving everyone exactly the same training can leave important gaps.

Amber said:

“Tailoring it to different departments and different scenarios, and bringing some sort of personal element in, really makes people think.”

Role-based training allows an organisation to focus on the situations each team is likely to encounter. This could include recognising a subject access request, reporting a personal data breach or handling sensitive information securely.

Build Trust Rather Than Fear

Training should make people feel able to ask questions and report mistakes.

Using fear to encourage compliance can have the opposite effect. Staff may become less willing to report an incident if they believe they will automatically be blamed or disciplined.

Amber explained:

“Leading by fearmongering can push people towards being less open and honest about the things they may be doing wrong or the difficulties they are facing.”

A supportive approach does not remove accountability. It helps staff understand that mistakes should be reported quickly so the organisation can assess the risk and respond appropriately.

Caine highlighted the importance of education alongside formal training:

“Education is also the time spent with people to help them understand an element of the law that is relevant to them and their role.”

Make Training Conversational

People often learn more when they can ask questions and discuss realistic examples.

A conversational session gives the trainer an opportunity to understand where staff are struggling. It also helps employees connect data protection principles with situations they have experienced.

Amber said:

“It needs to be more conversational and more on a case-by-case basis.”

Quizzes, practical exercises, visuals and group discussions can all help. A mixture of formats also supports different learning styles.

Support Staff After the Session

Training should not end when the presentation closes.

Staff need somewhere to find clear information when they face a data protection question. This could be a company handbook, an intranet page or a central collection of practical guidance.

Amber explained:

“It is always good to have some sort of central archive, a company handbook or an intranet, where people can easily access that information.”

Resources should answer practical questions, including:

  • How to recognise a potential personal data breach
  • Who to contact when something goes wrong
  • How to recognise a request for personal information
  • Where to find the organisation’s policies and procedures
  • What responsibilities apply to a particular role

Create a Culture of Accountability

Effective training needs support from across the organisation.

The Data Protection Officer cannot build a strong data protection culture alone. Senior leaders, line managers, IT teams and other key employees all have a part to play.

Amber described accountability as the overarching principle:

“Ultimately, it is about accountability. You look at what has gone wrong, what you could do better next time and what you can put in place.”

When leaders take training seriously, staff are more likely to do the same. This helps turn data protection from an annual exercise into part of everyday decision-making.

Key Takeaways

Effective data protection training should:

  • Relate directly to the employee’s role
  • Use clear language rather than legal jargon
  • Include practical examples and realistic scenarios
  • Encourage questions and open conversations
  • Help staff feel confident reporting mistakes
  • Use different formats to support different learning styles
  • Provide guidance that remains available after the session
  • Receive visible support from senior leaders and managers

Good training does not simply tell people what the law says. It helps them understand what good data protection looks like in practice.

Watch or Listen to the Full Episode

Watch the full conversation on YouTube or listen through Spotify.

Explore Data Protection Training

Data Protection Made Easy provides training designed to help organisations understand their responsibilities and apply data protection requirements in practice.

View Training Courses

S2 Ep26: GDPR Radio- Data Protection News of the Week

GDPR Radio: Data Protection News of the Week

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Catarina Santos discussed the latest stories shaping data protection, cyber security, AI regulation and online safety.

From changes at the Information Commission to cyber sentencing, political marketing, AI guidance and addictive app design, the episode explored what these developments mean for organisations and the people whose data they handle.

What Could Changes At The Information Commission Mean?

One of the first topics discussed was the appointment of seven non-executive directors to the Information Commission board and what this could mean for the future direction of the regulator.

“I really do hope whoever comes in and chairs this board is able to keep a rein on individuals’ rights and make sure that there’s not a really obvious imbalance here.”

Caine explained that any shift towards innovation still needs to be balanced with strong protection for individual rights.

Catarina also linked this to the wider direction of the regulator.

“The fact that we are appointing the new board chair probably will provide an opportunity to try to rebuild that trust and confidence in the regulator.”

This matters because the regulator plays a key role in how organisations understand and apply data protection law. If the Information Commission changes direction, organisations will need clear guidance on what that means in practice.

Why The TfL Cyber Attack Still Matters

Catarina then discussed the sentencing of two members of the Scattered Spider cybercrime group following the cyber attack on Transport for London.

“The impact goes way beyond the numbers of the customers involved.”

The attack involved personal data relating to around 10 million customers and affected around 27,000 employees. It was also estimated to have cost Transport for London £39 million.

Caine explained that cyber incidents like this are a reminder to review technical and organisational measures.

“All these stories about cyber attacks are just a little reminder to make sure that all your measures remain audited and remain strong.”

The discussion focused on access controls, which are rules that limit who can view, use or change information, and penetration testing, which is a controlled test used to find security weaknesses before attackers do.

Political Marketing And Purpose Limitation

The episode also covered a reported GDPR issue involving a Portsmouth councillor, a restaurant linked to his partner and messages promoting Reform UK.

Caine explained the concern clearly.

“Not only are they promoting something that is wholly outside of the scope of what they were doing in respect to the partner’s restaurant, but also in respect to a political party.”

Catarina highlighted purpose limitation, which means personal data should only be used for the reason it was collected unless there is a clear lawful reason to use it for something else.

“They are surely not expecting then the details to be used for any other campaign afterwards.”

This becomes especially important when political views may be involved. Political opinion can be special category data, which means it needs extra protection because it is sensitive.

The UK Government’s Call For Evidence On AI

A major story in the episode was the UK Government’s call for evidence on data regulation in the age of AI and other data-driven technologies.

Catarina explained that this does not change the law.

“This is not a consultation on new laws, anything around changing UK GDPR or any legal framework.”

Instead, the Government is asking businesses, regulators, academics and other organisations to share their experiences of using AI and explain where the current framework may be unclear or difficult to apply.

Catarina described it as a positive step.

“I think this is a very, very good step where you are actively asking the organisations and people that are actually working directly with these platforms and with AI in general.”

Caine agreed that clearer guidance is needed.

“Getting more stuff on the law and the guidance allows us to also be more helpful with you guys as well.”

For organisations using AI, this is important because many are already trying to apply existing data protection principles to tools that are developing quickly.

Anti-Doping Decisions And GDPR

The hosts also discussed a Court of Justice of the European Union ruling from 2024 about anti-doping rules and whether publishing athletes’ personal data online can be compatible with GDPR.

Catarina explained that publication can be compatible with GDPR, but only if the right checks are made first.

“The proportionality I think is key, the balance between the potential publication and the athletes’ rights and freedoms and interests on the other side.”

Proportionality means making sure an action does not go further than necessary to achieve its aim.

Caine considered the other side of the issue, including transparency in sport and the risk to clubs.

“Doping could carry a potential risk to the club itself.”

Catarina also raised the long-term impact of putting this information online.

“Once it’s published online, even if you delete it, it will never leave the internet.”

The discussion showed why organisations must think carefully before making personal data public, even where there is a strong reason to do so.

Meta, Addictive Design And Online Safety

The final story focused on Meta and the European Commission’s preliminary view that Meta may have breached the Digital Services Act.

The Digital Services Act is an EU law that places duties on online platforms to manage risks linked to their services.

Caine explained that the concerns related to features such as infinite scrolling, autoplay, push notifications and personalised content.

“The way that the social media app is designed bottom to top, it thinks it is doing too much to keep users engaged.”

He also questioned whether existing controls go far enough.

“What is it that they’re expecting Meta to do? What does Meta need to do now?”

Catarina raised concerns about children, vulnerable users, targeted content and connected technology such as smart glasses.

“There are so many concerns and the main one is definitely whether platforms are actually doing enough to protect children.”

The discussion ended with a wider privacy question about technology in the workplace.

“What’s the difference between wearing Meta glasses at work and everyone else that has a mobile phone that can record covertly anywhere?”

It is a useful reminder that privacy risks often appear before workplace expectations and regulation have fully caught up.

Looking Ahead

This episode showed how broad data protection has become.

It now connects to AI, cyber security, political campaigning, sport, social media design, workplace technology and public trust.

For organisations, the message is simple. Data protection is not just about policies. It is about how decisions are made, how risks are assessed and how people’s rights are protected in real situations.

Frequently Asked Questions

What was this episode of GDPR Radio about?

This episode covered key data protection news, including the Information Commission, the TfL cyber attack, political marketing, AI regulation, anti-doping decisions and Meta’s app design.

What is purpose limitation under GDPR?

Purpose limitation means personal data should only be used for the reason it was collected unless there is a clear lawful reason to use it for another purpose.

Why does the UK Government’s AI call for evidence matter?

It matters because organisations are already using AI and need clearer guidance on how existing data protection rules apply to new technology.

What is proportionality in data protection?

Proportionality means making sure an action is appropriate and does not go further than needed, especially where it affects someone’s rights.

Why are app design features a data protection issue?

App design features can influence how people behave online. If those features affect vulnerable users, children or personal data use, they can raise privacy and safety concerns.

Need Support With Data Protection, AI Or Cyber Security?

Data protection issues are becoming more connected.

AI, cyber security, marketing, employee access, online platforms and emerging technology all create new risks for organisations to manage.

Data Protection Made Easy helps organisations understand their responsibilities and take practical steps to improve compliance.

Whether you need support with UK GDPR, AI governance, cyber security or data protection training, our consultants can help make the process clearer and easier to manage.

Spotify logo

 

YouTube logo

Spreadsheets to Strategy: How to Make Your RoPA Work for You

Spreadsheets to Strategy: How to Make Your RoPA Work for You

For many organisations, creating a Record of Processing Activities (RoPA) feels like one of the most daunting parts of data protection compliance.

Often viewed as nothing more than a lengthy spreadsheet completed to satisfy Article 30 UK GDPR requirements, RoPAs frequently become outdated, overly complicated and rarely used once they have been created.

In a recent episode of the Data Protection Made Easy podcast, Catarina Pereira dos Santos and Himanshi Gulati discussed why organisations should rethink their approach. Rather than treating a RoPA as a compliance exercise, they explained how it can become one of the most valuable governance tools within an organisation.

From improving understanding of business processes to supporting Subject Access Requests, DPIAs and supplier reviews, a well-maintained RoPA can provide far more value than many organisations realise.

Why Do So Many Organisations Dislike Their RoPA?

One of the first topics discussed was the poor reputation that RoPAs have developed.

Catarina explained that many organisations immediately see a RoPA as a burden rather than a useful business tool.

“I work as a data protection consultant and every single time I mention RoPA to clients, they have such a bad reputation. They see it as a monster and just want to stay away from it.”

Himanshi suggested that the issue is not the RoPA itself, but the process organisations often follow to create one.

“I don’t really think that people dislike the RoPA itself. They dislike the process.”

She explained that many organisations immediately picture endless spreadsheets, large numbers of processing activities and uncertainty over who is responsible for maintaining the document.

A RoPA Should Help You Understand Your Business

Rather than approaching a RoPA as a legal requirement alone, the discussion encouraged organisations to think about what the document is actually designed to achieve.

According to Himanshi, the most effective RoPAs are built around understanding how personal data moves throughout the organisation.

“I think it’s very easy if you don’t see it as a legal requirement… you really have to understand your business and how the data is flowing.”

Understanding processing activities, data flows and ownership provides organisations with much greater visibility over their compliance position and often highlights risks that may otherwise go unnoticed.

Stop Treating It Like A Tick Box Exercise

Throughout the discussion, both hosts stressed that a RoPA should not simply exist because Article 30 requires it.

Instead, it should become part of day-to-day governance.

Himanshi explained that organisations often leave the RoPA until last, focusing on policies and procedures first.

However, she argued that the RoPA should often become the starting point because it provides the context needed for many other compliance activities.

“It’s not just filling up spreadsheets… it really gives you context.”

Why Ownership Matters

One of the biggest challenges discussed was ownership.

Many organisations assume that because a RoPA relates to data protection, maintaining it should be entirely the responsibility of the DPO or privacy team.

The hosts challenged this assumption.

Catarina explained that whilst the privacy team may oversee the document, individual departments are far better placed to understand how personal data is actually processed within their own areas.

Process owners should therefore play an active role in maintaining their sections of the RoPA, ensuring it reflects how the organisation really operates.

Without that ownership, documents quickly become inaccurate and lose much of their value.

Workshops Often Reveal More Than Expected

The conversation highlighted how collaborative workshops frequently uncover processing activities that departments had not initially considered.

Himanshi shared an example of working with a marketing team that initially believed they did not process much personal data beyond sending emails.

However, further discussion revealed they were collecting competition entries, storing winner information, sharing data internally and publishing photographs on social media.

These discoveries demonstrated why conversations with departments are often far more valuable than asking them to complete a spreadsheet in isolation.

There Is No Perfect Template

Another important theme throughout the discussion was that there is no single correct format for a RoPA.

Whilst regulators provide guidance on the information that should be included, organisations have flexibility over how they record and manage that information.

Rather than copying another organisation’s template, businesses should build a RoPA that reflects their own processing activities and remains practical to update over time.

As Himanshi explained, every organisation processes personal data differently, meaning every RoPA should be tailored to suit the business.

A Good RoPA Should Work For You

Towards the end of the discussion, the hosts explored what actually makes a good RoPA.

Rather than measuring success by the number of processing activities recorded, they suggested organisations should ask a much simpler question.

Does the RoPA help people understand how the organisation processes personal data?

Can it support everyday compliance activities such as responding to Subject Access Requests, carrying out DPIAs, reviewing suppliers and identifying risks?

If the answer is yes, the RoPA is doing exactly what it was designed to do.

As Himanshi summarised:

“If you are able to understand your processing activities, understand your risks and carry out your day-to-day activities, that’s what a good RoPA will be.”

Looking Ahead

Creating a Record of Processing Activities should never be viewed as simply completing another compliance document.

When maintained properly, a RoPA becomes a living record of how an organisation handles personal data. It supports better governance, improves accountability and helps organisations identify risks before they become problems.

Rather than seeing it as another spreadsheet, organisations should view their RoPA as a strategic tool that supports almost every aspect of their wider data protection programme.

Frequently Asked Questions

What is a Record of Processing Activities (RoPA)?

A RoPA is a document that records how an organisation collects, uses, stores and shares personal data. Article 30 UK GDPR requires many organisations to maintain one.

Why do organisations struggle with RoPAs?

Many organisations see them as large spreadsheet exercises rather than practical business tools. A lack of ownership and unclear processes often make them difficult to maintain.

Who should be responsible for maintaining a RoPA?

Whilst the DPO or privacy team may oversee the document, individual departments should take ownership of their own processing activities to ensure the information remains accurate.

Should every organisation use the same RoPA template?

No. Every organisation processes personal data differently. A RoPA should reflect how your own organisation operates rather than copying another business’s template.

How can a RoPA support wider compliance?

A well-maintained RoPA can support Subject Access Requests, DPIAs, supplier reviews, risk assessments and ongoing governance by providing a clear picture of how personal data is processed across the organisation.

Need Help Creating Or Reviewing Your RoPA?

Building and maintaining a Record of Processing Activities can be challenging, especially when organisations are managing multiple departments, changing processes and increasing compliance requirements.

Our Data Protection Support Service and Outsourced DPO Service help organisations create practical, accurate RoPAs that support day-to-day compliance, not just regulatory requirements.

Whether you’re creating your first RoPA or reviewing an existing one, our consultants can help you build a record that works for your organisation, not against it.

Spotify logo spotify symbol #7056 - Free Transparent PNG Logos

The History of the YouTube Logo: From Its Origins to Today ...

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
S2 Ep29 How AI Is Reshaping the DPO Role in 2026 (1)
07 August 26 12:30 - 1:15 pm

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Creating Training That Changes Behaviour
24 July 26 12:30 - 1:15 pm

Creating Training That Changes Behaviour

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.