The UKs #1 Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

GDPR Training

Data Protection People have a wide range of training services catering for every need. Whether its general training for operational or admin staff or specific training for specialist roles, we have something for you. watch the short video below to meet the team and find out more about our training services.

Contact Us

Information Management Software

DataWise is the original privacy tech platform designed to simplify GDPR compliance management. Since its inception in 2011, DataWise has continuously evolved, solidifying its reputation as the pioneering "privacy tech" solution.

Contact Us

Data Protection Consultancy

Unlock Compliance Excellence with Our GDPR Consultancy Services. Navigating the intricate realm of data protection laws and standards demands expert guidance.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

ISO 27001

Our tailored program, guided by industry-certified experts, supports your ISO 27001 compliance journey. Whether you need advice on certification scope, assistance with remediation work, or comprehensive ISO 27001 consultancy, we’re here to guide you every step of the way.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Rob Wilkinson answering a call

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

How Can Data Protection Risks Affect Printing Service Providers?

How Can Data Protection Risks Affect Printing Service Providers?

Whether producing photographs, wedding invitations, business cards, direct mail, marketing materials or personalised documents, printing service providers routinely receive files containing names, postal addresses, email addresses, telephone numbers and, in some cases, special category personal data, e.g. membership records for a political party or campaign.

Given the nature and volume of the information entrusted to them, organisations operating within the printing industry should ensure that data protection is embedded into their operational processes from the outset.

Compliance should not be viewed merely as a regulatory obligation but as an integral part of business operations. In practice, this requires implementing appropriate technical and organisational measures, configuring printing equipment with data protection-focused settings by default and ensuring that personal data is processed in accordance with the UK GDPR and the Data Protection Act 2018.

Set out below are some of the principal data protection risks that organisations operating in the printing sector should consider.

1. Data Retention

One of the most significant compliance risks concerns the retention of customer data.

Printing companies frequently receive photographs, mailing lists and other files for the purpose of completing a particular order. Once that purpose has been fulfilled, organisations should ensure that personal data is not retained for longer than is necessary unless there is a lawful basis for continued retention.

The UK GDPR requires organisations that process personal information, whether acting as controllers or processors, to comply with the storage limitation principle. This means ensuring that personal data is not kept for longer than is necessary for the purposes for which it is processed unless there is a lawful reason for continued retention.

Retaining customer files indefinitely without an established retention policy or a legitimate business justification may therefore constitute a breach of the legislation.

From a risk management perspective, excessive data retention also increases the potential impact of a personal data breach. The greater the volume of historic customer information retained, the greater the number of individuals likely to be affected in the event of unauthorised access or a cyber incident.

Such incidents may expose organisations not only to regulatory scrutiny by the Information Commissioner’s Office (ICO) but also to reputational damage and loss of customer confidence.

2. Data Stored on Printing Devices

Data protection measures should extend beyond email systems, online ordering platforms and file transfer services.

Modern multifunction printers frequently contain internal hard drives or solid-state drives (SSDs) capable of retaining copies of print, scan and copy jobs.

In addition, organisations may use cloud-managed print solutions, retained scan repositories and manufacturer cloud services, all of which can store or process documents containing personal data.

Unless these systems are appropriately configured and personal data is securely erased or deleted in accordance with documented retention periods, information may remain accessible long after the relevant work has been completed.

For this reason, organisations should ensure that printing devices form part of their information security programme.

Appropriate measures may include:

  • Encrypted storage
  • Secure print functionality
  • Controlled administrator access
  • Regular firmware updates
  • Secure deletion of stored print jobs

3. Disposal of Printing Equipment

When printers, scanners, multifunction devices or servers reach the end of their operational life, organisations should ensure that all storage media are securely sanitised before disposal, resale or return to leasing providers.

Failure to securely erase stored information may result in personal data being recovered by unauthorised third parties.

Such incidents may amount to a personal data breach requiring assessment under the UK GDPR and, where applicable, notification to the Information Commissioner’s Office and affected individuals.

Organisations should therefore implement documented asset disposal procedures and obtain appropriate certification where third-party disposal providers are engaged.

4. Confidentiality, Access Control and Staff Awareness

Employees working within printing environments routinely have access to customer artwork and documents containing personal information.

Consequently, organisations should ensure that access to such information is limited strictly to those individuals who require it for the performance of their duties.

The following measures can help reduce the likelihood of unauthorised access:

  • Robust role-based access controls
  • Confidentiality obligations within employment contracts
  • Regular privacy training
  • Documented internal procedures

It is equally important to recognise that personal data does not need to be copied, disclosed externally or published for a reportable incident to arise.

Unauthorised internal access to customer information may itself constitute a personal data breach under the UK GDPR, depending on the circumstances. Organisations should investigate and manage these incidents in accordance with their incident response procedures.

How Can Data Protection People Assist Printing Organisations?

As discussed above, organisations operating within the printing industry are exposed to a range of data protection and information security risks.

Given the volume and nature of the personal data they process, obtaining specialist data protection advice can assist organisations in demonstrating compliance with the UK GDPR while reducing operational and regulatory risk.

At Data Protection People, we work closely with organisations to develop practical, proportionate compliance frameworks tailored to their business operations.

Our support may include:

  • Identifying and documenting personal data processing activities: This enables organisations to understand how personal data flows throughout the business and maintain accurate Records of Processing Activities (RoPA), where required.
  • Assessing data protection and security risks: We can recommend appropriate technical and organisational measures to protect personal data throughout its lifecycle.
  • Developing data retention and deletion policies: This helps ensure that personal data is retained only for as long as necessary and disposed of securely in accordance with the storage limitation principle under the UK GDPR.
  • Reviewing existing business processes and internal procedures: This helps organisations embed data protection obligations into day-to-day operations and adopt a privacy-by-design approach where appropriate.
  • Preparing or reviewing data protection documentation: This may include privacy notices, internal policies, processor agreements and data processing procedures.
  • Supporting organisations with data subject rights requests: This includes requests for access, erasure, rectification, restriction of processing and objection.
  • Providing practical guidance following personal data breaches: This may include incident assessment, regulatory notification obligations and remediation measures.
  • Delivering staff awareness training: This helps employees understand their responsibilities when handling customer information and reduces the likelihood of human error.

Building Data Protection Into Printing Operations

Printing organisations process significant volumes of personal data and must ensure that appropriate safeguards are in place throughout the entire data lifecycle.

Compliance with the UK GDPR and the Data Protection Act 2018 extends beyond securing customer files. It requires effective governance, appropriate technical and organisational measures, clear retention practices and ongoing staff awareness.

By adopting a proactive, risk-based approach to data protection, organisations can reduce the likelihood of personal data breaches, demonstrate accountability and strengthen customer trust.

Ultimately, robust data protection practices are not only a legal requirement but also an essential element of responsible business operations.

Speak to Our Team

If your organisation needs support with data protection, information security or staff training, contact Data Protection People.

Contact Our Team

AI in Housing: The NHF Report Explained

The National Housing Federation has published a new report, The State of AI in Housing 2025, produced with IT services provider Phoenix, looking at how housing associations are adopting artificial intelligence, the opportunities it offers, the risks it creates, and how ready the sector actually is. It is not new legislation and does not create new legal duties, but it is genuinely useful sector insight for any housing provider already using AI, considering it, or finding that colleagues are quietly experimenting with it already.

AI adoption in housing is already well underway

The headline finding is that AI is not a future consideration for housing, it is already in day-to-day use. The report found that 47% of respondents are using AI in their daily operations, with a further 23% not using it yet but planning to. Current use cases span internal administration, data handling, compliance checks, resident communications and service delivery.

Confidence and governance haven’t kept pace with adoption

The report also shows a sector that is moving faster than its own readiness. 87% of respondents rated their knowledge of AI as low, and 44% have no AI policy in place at all. That gap, widespread use alongside limited confidence and limited governance, is the part of the report worth paying closest attention to. AI can genuinely help a housing provider save time, support staff and improve services, but it should never be treated as a straightforward technology purchase or a way around existing data protection obligations.

The same data protection questions still apply

Whatever the tool, the same questions need answering before personal data goes anywhere near it. What is the purpose? Is the use necessary? What is the lawful basis? Have people been told clearly what is happening with their data? Is the information secure? And are you confident the tool itself is accurate and fair?

These questions carry extra weight in housing specifically, given the nature of the data involved, often including residents’ health, financial circumstances, vulnerabilities, safeguarding concerns and household situations.

Where the real risks sit

The report highlights privacy and security, bias and discrimination, accountability, and inaccurate AI-generated information as the key areas to watch. AI can produce an answer that sounds entirely convincing while being wrong, and it can reflect bias baked into the data it was trained on. That matters most where AI could influence decisions about residents, allocations, arrears, complaints handling, vulnerability assessments or safeguarding.

The safest approach is straightforward: do not let AI make high-impact decisions about individuals without a proper assessment, meaningful human involvement, and a clear route for someone to challenge the outcome.

A sensible way to adopt AI, according to the report’s own case studies

The organisations getting this right in the report’s case studies followed a similar pattern: start with a lower-risk use case, secure genuine leadership support, involve staff early, and put governance in place before the project expands rather than after.

Four steps worth taking now

Based on the report’s findings, four immediate actions stand out for any housing provider:

    • Find out which AI tools are actually being used across the organisation, including tools staff may be using independently without anyone else knowing.
    • Put clear guidance in place so staff know exactly what can and cannot be entered into an AI tool. Personal, confidential and special category data should never go into an unapproved tool.
    • Carry out proper due diligence on any AI supplier, understanding the contract, where data is processed, whether there are international transfers, and what security measures are actually in place.
    • Assess higher-risk uses properly. Where an AI project could create a high risk to people’s rights and freedoms, a Data Protection Impact Assessment may be required before processing begins.

Adopt AI thoughtfully, not cautiously or carelessly

The message from the report isn’t to avoid AI, it’s to adopt it thoughtfully. Innovation and data protection aren’t competing priorities. Good governance, clear policies, trained staff and proper oversight are what give a housing provider the confidence to use AI in a way that protects residents, supports staff and builds trust.

For housing associations without the in-house resource to build that governance from scratch, this is exactly the kind of gap an outsourced DPO is built to close, bringing practical AI policy development, supplier due diligence and DPIA support without needing to build the capability internally. If you’re considering an AI project, reviewing a supplier, or need support with an AI policy or DPIA, speak to your Data Protection Officer or get in touch with the Data Protection People team.

How AI Is Reshaping the DPO Role in 2026

By Amber Sivill, Data Protection Consultant and AI Specialist at Data Protection People

Artificial intelligence is not only changing the way organisations handle information, it is changing the way individuals understand, exercise and challenge their individual rights. That shift is now landing firmly on the DPO’s desk. Ahead of this Friday’s podcast episode on how AI is reshaping the DPO role, I wanted to share what I am seeing in practice, and why I think the roles and responsibilities of a DPO are becoming more strategic, visible, and more closely connected to AI governance than ever before.

Subject access requests are changing shape, not just volume

Most DPOs I speak to will recognise the same trend: subject access requests are coming in fast and strong, and the requests themselves are becoming more broad complex. Some of that is the result of greater public awareness of data rights. But it is increasingly clear that data subjects are using AI tools to assist them with drafting more detailed and legally focused requests.

A request that once said, “please send me my data”, may now arrive with references to specific processing activities, legislation, ICO guidance and carefully worded follow-up questions. That does not mean the individual is being difficult. In many cases, they have simply had support from an AI tool to articulate what they are asking for. For organisations, the practical effect is clear: SARs can take longer to assess, scope and respond to, even where the underlying request is perfectly legitimate.

The regulatory position has also moved on. Since February of this year, the Data (Use and Access Act) 2025 has given organisations more room to take a reasonable and proportionate approach to searches, rather than treating every request as requiring an exhaustive search of every system and record. It also allows organisations to “stop-the-clock” whilst waiting for identity verification or clarification where a request is unclear. Whilst those changes provide more flexibility to organisations, they do not remove the need for a robust process or adequate resources to address a request. In my experience, many complaints arise not because an organisation neglected their responsibilities under data protection law, but because expectations were not managed, communication was unclear, or the SAR process did not hold up under pressure.

The workplace risk nobody’s policy covers yet

The SAR challenge is only part of the picture. The other, and often less visible, issue is what is happening inside organisations. Staff are increasingly experimenting with consumer AI tools to save time, summarise information, draft communications and sense-check their work. That behaviour is understandable, particularly where approved tools are not available, but it creates real data protection risk when there are no clear rules around what can and cannot be shared.

In practical terms, this might mean someone pasting a client email thread into a personal AI account to help draft a reply. It might mean uploading a contract, pricing document or HR note to create a quick summary. In the moment, that may feel like a harmless productivity shortcut. From a data protection perspective, however, personal data and confidential business information may have left the organisation’s control, with little or no record of what was shared, where it went, or how it may be used afterwards.

This is where policy, training and governance need to catch up with day-to-day behaviour. If an organisation has no approved AI tools, no written position on staff use, and no practical examples of what is and is not acceptable, employees will make their own judgement calls. That is not just a training gap. It is a governance gap, and it is exactly the kind of issue a DPO should be helping the organisation to identify and close.

Where AI is actually helping, not just complicating things

It would be too simplistic to present AI only as a risk. Used properly, it can also support better data protection practice. The organisations making the strongest progress are not necessarily the ones banning AI outright. They are the ones setting sensible boundaries, choosing appropriate tools, and making sure human oversight remains built into the process.

For example, AI-assisted triage can be genuinely useful in SAR handling. It can help identify likely duplicate documents, flag material that may contain third-party data, and support the first review of large data sets. It can also help organisations spot patterns across complaints, requests and internal queries that may point to a wider process issue. Used carefully, those capabilities can give DPOs more time to focus on judgement, accountability and risk, rather than manual administration.

The key point is that AI should not be treated as a shortcut around governance. It should be assessed in the same practical way as any other tool or processor: what data does it use, where does that data go, what controls are in place, and what role does human review play in the final decision?

What this means for your organisation

None of this is a reason to panic. It is a reason to take stock. If SARs are becoming harder to scope, if staff are using AI tools without clear guidance, or if your organisation does not have the internal capacity to keep pace with the rate of change, it may be time to look at whether your current data protection arrangements are still fit for purpose. An experienced outsourced DPO can bring both the day-to-day capacity and the AI-specific knowledge needed to turn uncertainty into a practical, proportionate plan.

We will be exploring this in more detail on this Friday’s episode of the Data Protection Made Easy podcast, including what we are seeing across client organisations and what a sensible, usable AI policy looks like in practice.

Player Data Rights Under UK GDPR: A Guide for Sports Clubs

Player Data Rights Under UK GDPR: A Guide for Sports Clubs

Pre-season is underway. Across football, rugby and other contact sports, clubs are strapping GPS vests and bicep-worn heart rate monitors onto players again.

As a result, an old question returns: who does player performance data belong to? The club? The analytics company? The wearable manufacturer? The betting firm that profits from it? Or the player it’s actually about?

The honest answer is nobody.

UK law does not treat personal data as property. UK GDPR does not give anyone ownership of personal data. Instead, it defines personal data as information that “relates to” an identified individual, not information that belongs to one. That distinction is deliberate.

However, players do have rights. They can ask how organisations use their data, access it, correct it, object to its use and, in some circumstances, have it deleted.

Meanwhile, the organisations handling that information act as controllers or processors. They have legal obligations, not property rights. That is exactly where the tension sits.

This responsibility does not sit with clubs alone. A club acts as a controller for the data it collects. However, analytics companies and wearable providers may also act as controllers if they use the data for their own purposes, such as refining products or benchmarking across clients.

Where a club and provider process the same data for a shared purpose, they become joint controllers under Article 26. They must agree who is responsible for each obligation and explain this clearly to players.

Therefore, clubs cannot simply assume that a provider is “processing on our behalf.” They need to check.

Why This Keeps Coming Up

Project Red Card has brought this issue into sharp focus.

Hundreds of current and former professional footballers have challenged gaming, betting and data companies over the unconsented use of their personal data.

Media coverage has reported potential exposure running into the hundreds of millions of pounds. Players are seeking to recover lost income going back six years, which is the statutory limit for such claims in the UK.

At the same time, players and their unions are making the same argument. PFA England chief executive has said players need to be “at the heart of these decisions around data use both on and off the pitch.”

FIFPRO’s own survey found that most professional footballers want access to their performance data to help them improve. However, they are also concerned about how organisations collect and use it. Many feel they do not have clear information about their rights.

Put simply, players are not against data collection. They want a say in it.

The Rights in Practice

Under UK GDPR, players have the right to know how organisations use their data. They can also make a subject access request to any organisation processing their information, not just their club.

In addition, they can ask an organisation to correct inaccurate data. They can object to processing under Article 21 and, in certain circumstances, request the deletion of their information.

FIFPRO developed its Charter of Player Data Rights with FIFA. The Charter sets out a near-identical list of rights.

Therefore, this is not just DPP’s position. It is the standard the game’s own governing bodies are pushing towards.

Where Clubs Get Exposed

Clubs usually have a lawful basis for collecting player data. However, the risk often appears further downstream.

Once a club licenses data to Football DataCo, shares it with an analytics provider or passes it to a commercial partner, each transfer needs its own lawful basis.

For example, a third-party provider may continue using player data after a contract ends. It may use the information for “product improvement” or include it in an aggregated dataset because nobody checked the exit terms.

As a result, the club may be unable to explain who holds the data or what they use it for. A player or union is entitled to challenge exactly this kind of gap.

Health data raises the stakes further. Heart rate, injury risk and recovery data are special category data under Article 9. This means organisations must meet a higher legal standard and will usually need a DPIA.

Euro 2024 showed how easily this can go wrong. A wearable manufacturer publicly posted one player’s heart rate and another player’s sleep data on social media. This attracted scrutiny over how far a provider’s control over player data should extend.

Finally, many technology providers operate outside the UK. Consequently, clubs may need restricted transfer mechanisms. This could include an International Data Transfer Agreement supported by a genuine Transfer Risk Assessment, not a box-ticking exercise.

This is live, active work across the sector right now.

How Data Protection People Can Help

At Data Protection People, we work on these issues now.

We review and negotiate data processing agreements with analytics providers, wearable manufacturers and commercial partners. Crucially, we cover what happens when the relationship ends, including the retention, deletion and return of data.

We also put International Data Transfer Agreements and Transfer Risk Assessments in place when data moves outside the UK.

In addition, we carry out DPIAs before organisations introduce new tracking technology, not after they have already rolled it out to the training ground.

Where a club is unsure whether a provider acts as a processor, an independent controller or a joint controller, we help establish the correct relationship. This is often one of the first things worth checking because it changes the contractual requirements and determines who is accountable if something goes wrong.

We currently advise football clubs on exactly this kind of work. With the new season starting and clubs signing fresh wearable and analytics contracts across the division, now is the point in the calendar when getting it right matters most.

Otherwise, the paperwork may remain buried until the next renewal comes around.

Nobody owns personal data. However, every player has rights over theirs. Clubs, providers and betting companies must be able to show that they respect those rights.

Sources

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Artificial intelligence is changing how Data Protection Officers work.

AI tools can help with research, training, risk assessments and routine administration. However, they can also produce inaccurate advice, encourage confirmation bias and create new governance risks.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss how AI is affecting DPO workloads and why professional knowledge and meaningful human oversight remain essential.

What Does This Episode Cover?

During the episode, Caine and Amber discuss:

  • The increase in AI-generated Subject Access Requests
  • How AI is affecting DPO workloads
  • The risks of using AI for data protection advice
  • How AI could support RoPAs, DPIAs and LIAs
  • The importance of checking AI-generated policies
  • Confirmation bias in AI responses
  • Why human oversight and professional knowledge still matter

How Is AI Affecting Subject Access Requests?

The discussion explored the growing number of Subject Access Requests, or SARs, that appear to have been generated using AI.

These requests can look formal and detailed. However, they may ask for information that does not fall within the normal scope of a SAR.

Amber explained:

“It also fuels a lot of misunderstanding. A lot of the time, you see a request and most of it does not even fall under the scope of what a SAR generally covers.”

Caine also shared that SAR-related cases handled through the DPP Support Desk have increased significantly.

AI may make it easier for people to create requests, complaints and follow-up correspondence. This can place additional pressure on data protection teams, particularly where requests are vague or based on incorrect information.

Can DPOs Rely on AI for Data Protection Advice?

AI can provide a useful starting point. However, it should not replace professional knowledge.

Amber explained:

“You need to have the base knowledge in order to be able to use these systems.”

An experienced practitioner may recognise when an AI response refers to the wrong legislation, misses important context or provides an answer that is too confident.

Someone with less experience may not spot those problems.

Data protection decisions are rarely black and white. The correct answer often depends on the organisation, the processing activity and the people who may be affected.

Could AI Support RoPAs, DPIAs and LIAs?

AI may help DPOs complete some routine or administrative tasks.

For example, it could help pre-populate a Record of Processing Activities, or RoPA, using information about an organisation’s activities and data sharing.

It may also provide a starting point for a Data Protection Impact Assessment, or DPIA, and a Legitimate Interests Assessment, or LIA.

However, organisations must consider what information they enter into an AI system. DPIAs and other assessments may contain sensitive or confidential information.

Amber said:

“There is a limit as to what you can provide the model with in terms of confidentiality and not oversharing any information.”

Any AI-generated assessment must be checked against the organisation’s actual processing, systems and risks.

Why Does Human Oversight Matter?

AI can produce clear and convincing answers even when those answers are incomplete or incorrect.

It may also agree with the direction of a prompt instead of challenging the user’s assumptions. This is known as confirmation bias, which means favouring information that supports an existing view.

Caine explained:

“It is a fantastic tool that will hopefully be able to help in the role as a DPO. But what matters is that you can supplement it with your pre-existing knowledge.”

Amber added:

“The human element needs to be someone overlooking it who actually knows what they are talking about.”

Human oversight must be meaningful. The person reviewing an AI output needs the knowledge and authority to identify problems, challenge the result and make the final decision.

Is an AI-Generated Policy Better Than No Policy?

An AI-generated policy is not useful simply because it exists.

A policy must reflect how the organisation actually works. It must be practical, accurate and followed by staff.

Amber explained:

“If you have a policy in place and it does not align with your business, it is not workable and people are not following it, then there is ultimately not really anything there in place anyway.”

AI may help structure a first draft. However, the final policy should be reviewed by someone who understands the organisation, its legal duties and its operational risks.

What Should DPOs Take Away?

AI can support DPOs, but it should not replace them.

Organisations should:

  • Use AI to support work rather than make final decisions
  • Check AI outputs against current law and ICO guidance
  • Avoid entering unnecessary personal or confidential information
  • Keep meaningful human oversight in place
  • Document how AI tools are approved, monitored and reviewed
  • Make sure policies and assessments reflect real business practices

The DPO role is becoming broader and more connected to technology, governance and organisational risk.

AI creates opportunities to work more efficiently. It also makes professional judgement, scepticism and accountability more important.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He works with organisations every day to help them understand and respond to practical data protection challenges.

Amber Sivill

Amber is a Data Protection Consultant at Data Protection People. She supports organisations with data protection compliance, governance and emerging technology risks.

Watch or Listen to the Episode

Watch the full episode on YouTube or listen on Spotify.

Watch on YouTube

Listen on Spotify

Need Support With AI Governance?

If your organisation is adopting AI, Data Protection Made Easy can help you understand the risks, strengthen governance and meet your data protection responsibilities.

Contact Our Team

S2 Ep28 GDPR Radio – Data Protection News of the Week

S2 Ep28: GDPR Radio – Data Protection News of the Week

Amber Sivill and Mark Farrell discuss recent data breaches, AI risks and privacy enforcement.

From preventable spreadsheet errors to AI-generated decisions, this episode explores the changing risks facing organisations and data protection professionals.

Amber and Mark examine recent incidents involving government departments, exposed AI conversations, employee access to personal data and the growing use of facial recognition technology.

What This Episode Covers

In this episode, Amber and Mark discuss:

  • The Ministry of Defence data breach and the importance of basic software training
  • The cyber attack affecting the Department for Education
  • How AI can support both cyber attacks and defensive security measures
  • Claude conversations appearing in Google search results
  • AI-generated information being used in public-sector decisions
  • New transparency requirements under the EU AI Act
  • The risks created by unsecured paper records
  • Unauthorised employee access to personal data
  • AI-generated inferences and the future of anonymised data
  • Facial recognition, smart surveillance technology and privacy
  • Recent ICO action relating to nuisance marketing messages

When Basic Training Is Overlooked

The episode begins with the Ministry of Defence data breach involving information about Afghan relocation applicants.

Amber and Mark discuss reports that the breach could have been prevented through basic spreadsheet training. They also consider what this tells organisations about accountability and the importance of practical training.

Mark explains:

“AI is going to be leveraged to launch cyber attacks, it also has to be leveraged to combat them.”

The discussion also covers the cyber attack affecting the Department for Education. This demonstrates why organisations need both effective security systems and staff who understand how to recognise potential threats.

Privacy by Design and AI Tools

Amber and Mark discuss reports that shared Claude conversations appeared in Google search results.

The incident raises questions about transparency, default privacy settings and whether users understand when their conversations may become publicly available.

Amber says:

“You need to embed that sort of privacy, privacy by design, privacy by default, making sure that you know the default setting isn’t that my personal conversations are being shared publicly for other people to see.”

Organisations should understand how an AI service handles information before employees enter personal, confidential or commercially sensitive data into it.

AI Decisions and Regulatory Oversight

The hosts examine a case involving information believed to have been generated by AI and used during an asylum decision.

They discuss the risks of relying on AI-generated material without proper fact-checking or meaningful human oversight. Meaningful human oversight means a person genuinely reviews the information and can challenge or change the outcome.

The conversation also covers EU AI Act transparency requirements and the need for clearer UK rules.

Amber explains:

“I think this just goes to show that the current legislation doesn’t fit. I think it fits in so many ways in terms of the principles, but we need more specifics that are tailored towards AI use.”

Paper Records and Employee Access

Not every data protection incident involves sophisticated technology.

Amber and Mark discuss confidential paper records reportedly found in an unsecured former council building. They also examine cases involving employees accessing personal records without authorisation.

These stories show why organisations must protect information throughout its lifecycle. This includes digital files, archived documents and paper records.

Access controls should also ensure that employees can only view information they genuinely need for their role.

AI Inferences and Anonymised Data

The episode considers how AI may infer sensitive information from data that appears to be aggregated or anonymised.

Anonymised data is information that can no longer be linked to an identifiable person. However, more capable technology may make it easier to identify patterns or combine information from different sources.

Amber and Mark discuss whether existing definitions and safeguards will remain effective as AI develops.

Facial Recognition and Smart Surveillance

The hosts also examine AI-enabled street technology that can use cameras and facial recognition to identify people or detect potential offences.

These tools may support law enforcement and public safety. However, they also create questions about proportionality, transparency and function creep. Function creep happens when information or technology is gradually used for purposes beyond the reason it was originally introduced.

Mark summarises one of the central concerns:

“You behave differently when you’re being watched.”

Recent ICO Enforcement

The episode closes with recent action from the Information Commissioner’s Office relating to nuisance marketing about motor finance claims.

Amber and Mark discuss the use of search warrants and cooperation between different regulators. They also consider whether enforcement is being applied consistently across organisations and sectors.

Practical Takeaways for Organisations

Organisations should:

  • Include practical software skills in data protection training
  • Review the privacy settings of AI tools before using them
  • Avoid entering sensitive information into systems without appropriate safeguards
  • Apply meaningful human oversight to AI-supported decisions
  • Protect paper records as carefully as digital information
  • Regularly review employee access permissions
  • Assess whether anonymised information could be re-identified
  • Consider privacy risks before introducing surveillance technology

Watch or Listen

Watch or listen to the full episode of GDPR Radio:

📺 Watch the episode on YouTube

🎧 Listen to the episode on Spotify

Meet Your Hosts

Amber Sivill

Amber explores how emerging technology, AI governance and privacy risks affect organisations in practice.

Mark Farrell

Mark examines recent data protection developments and the practical lessons organisations can take from them.

Data Protection Made Easy

Data Protection Made Easy helps organisations understand and meet their responsibilities under UK GDPR and related data protection law.

S2 Ep27: Creating Training Which Changes Behaviour

Creating Training Which Changes Behaviour

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Data protection training should do more than record attendance. It should help people recognise risks, understand their responsibilities and know what action to take.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss why generic training often fails to engage staff. They explore how organisations can make training practical, relevant and easier to apply during everyday work.

Why Generic Training Often Falls Short

Training can be technically accurate without being effective.

A presentation may explain the law correctly, but staff are unlikely to remember it if the content does not relate to their role. Long presentations, legal language and broad examples can make data protection feel more complicated than it needs to be.

Amber explained:

“Poor training for me is where organisations design training and it may be very well researched, but it is not tailored.”

Training should connect data protection requirements to real decisions. Staff need to understand how the subject affects their work, their customers and the personal data they handle.

Make Training Relevant to Each Role

Different teams use personal data in different ways.

Human resources teams, senior managers, IT staff and customer service teams may face very different risks. Giving everyone exactly the same training can leave important gaps.

Amber said:

“Tailoring it to different departments and different scenarios, and bringing some sort of personal element in, really makes people think.”

Role-based training allows an organisation to focus on the situations each team is likely to encounter. This could include recognising a subject access request, reporting a personal data breach or handling sensitive information securely.

Build Trust Rather Than Fear

Training should make people feel able to ask questions and report mistakes.

Using fear to encourage compliance can have the opposite effect. Staff may become less willing to report an incident if they believe they will automatically be blamed or disciplined.

Amber explained:

“Leading by fearmongering can push people towards being less open and honest about the things they may be doing wrong or the difficulties they are facing.”

A supportive approach does not remove accountability. It helps staff understand that mistakes should be reported quickly so the organisation can assess the risk and respond appropriately.

Caine highlighted the importance of education alongside formal training:

“Education is also the time spent with people to help them understand an element of the law that is relevant to them and their role.”

Make Training Conversational

People often learn more when they can ask questions and discuss realistic examples.

A conversational session gives the trainer an opportunity to understand where staff are struggling. It also helps employees connect data protection principles with situations they have experienced.

Amber said:

“It needs to be more conversational and more on a case-by-case basis.”

Quizzes, practical exercises, visuals and group discussions can all help. A mixture of formats also supports different learning styles.

Support Staff After the Session

Training should not end when the presentation closes.

Staff need somewhere to find clear information when they face a data protection question. This could be a company handbook, an intranet page or a central collection of practical guidance.

Amber explained:

“It is always good to have some sort of central archive, a company handbook or an intranet, where people can easily access that information.”

Resources should answer practical questions, including:

  • How to recognise a potential personal data breach
  • Who to contact when something goes wrong
  • How to recognise a request for personal information
  • Where to find the organisation’s policies and procedures
  • What responsibilities apply to a particular role

Create a Culture of Accountability

Effective training needs support from across the organisation.

The Data Protection Officer cannot build a strong data protection culture alone. Senior leaders, line managers, IT teams and other key employees all have a part to play.

Amber described accountability as the overarching principle:

“Ultimately, it is about accountability. You look at what has gone wrong, what you could do better next time and what you can put in place.”

When leaders take training seriously, staff are more likely to do the same. This helps turn data protection from an annual exercise into part of everyday decision-making.

Key Takeaways

Effective data protection training should:

  • Relate directly to the employee’s role
  • Use clear language rather than legal jargon
  • Include practical examples and realistic scenarios
  • Encourage questions and open conversations
  • Help staff feel confident reporting mistakes
  • Use different formats to support different learning styles
  • Provide guidance that remains available after the session
  • Receive visible support from senior leaders and managers

Good training does not simply tell people what the law says. It helps them understand what good data protection looks like in practice.

Watch or Listen to the Full Episode

Watch the full conversation on YouTube or listen through Spotify.

Explore Data Protection Training

Data Protection Made Easy provides training designed to help organisations understand their responsibilities and apply data protection requirements in practice.

View Training Courses

S2 Ep26: GDPR Radio- Data Protection News of the Week

GDPR Radio: Data Protection News of the Week

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Catarina Santos discussed the latest stories shaping data protection, cyber security, AI regulation and online safety.

From changes at the Information Commission to cyber sentencing, political marketing, AI guidance and addictive app design, the episode explored what these developments mean for organisations and the people whose data they handle.

What Could Changes At The Information Commission Mean?

One of the first topics discussed was the appointment of seven non-executive directors to the Information Commission board and what this could mean for the future direction of the regulator.

“I really do hope whoever comes in and chairs this board is able to keep a rein on individuals’ rights and make sure that there’s not a really obvious imbalance here.”

Caine explained that any shift towards innovation still needs to be balanced with strong protection for individual rights.

Catarina also linked this to the wider direction of the regulator.

“The fact that we are appointing the new board chair probably will provide an opportunity to try to rebuild that trust and confidence in the regulator.”

This matters because the regulator plays a key role in how organisations understand and apply data protection law. If the Information Commission changes direction, organisations will need clear guidance on what that means in practice.

Why The TfL Cyber Attack Still Matters

Catarina then discussed the sentencing of two members of the Scattered Spider cybercrime group following the cyber attack on Transport for London.

“The impact goes way beyond the numbers of the customers involved.”

The attack involved personal data relating to around 10 million customers and affected around 27,000 employees. It was also estimated to have cost Transport for London £39 million.

Caine explained that cyber incidents like this are a reminder to review technical and organisational measures.

“All these stories about cyber attacks are just a little reminder to make sure that all your measures remain audited and remain strong.”

The discussion focused on access controls, which are rules that limit who can view, use or change information, and penetration testing, which is a controlled test used to find security weaknesses before attackers do.

Political Marketing And Purpose Limitation

The episode also covered a reported GDPR issue involving a Portsmouth councillor, a restaurant linked to his partner and messages promoting Reform UK.

Caine explained the concern clearly.

“Not only are they promoting something that is wholly outside of the scope of what they were doing in respect to the partner’s restaurant, but also in respect to a political party.”

Catarina highlighted purpose limitation, which means personal data should only be used for the reason it was collected unless there is a clear lawful reason to use it for something else.

“They are surely not expecting then the details to be used for any other campaign afterwards.”

This becomes especially important when political views may be involved. Political opinion can be special category data, which means it needs extra protection because it is sensitive.

The UK Government’s Call For Evidence On AI

A major story in the episode was the UK Government’s call for evidence on data regulation in the age of AI and other data-driven technologies.

Catarina explained that this does not change the law.

“This is not a consultation on new laws, anything around changing UK GDPR or any legal framework.”

Instead, the Government is asking businesses, regulators, academics and other organisations to share their experiences of using AI and explain where the current framework may be unclear or difficult to apply.

Catarina described it as a positive step.

“I think this is a very, very good step where you are actively asking the organisations and people that are actually working directly with these platforms and with AI in general.”

Caine agreed that clearer guidance is needed.

“Getting more stuff on the law and the guidance allows us to also be more helpful with you guys as well.”

For organisations using AI, this is important because many are already trying to apply existing data protection principles to tools that are developing quickly.

Anti-Doping Decisions And GDPR

The hosts also discussed a Court of Justice of the European Union ruling from 2024 about anti-doping rules and whether publishing athletes’ personal data online can be compatible with GDPR.

Catarina explained that publication can be compatible with GDPR, but only if the right checks are made first.

“The proportionality I think is key, the balance between the potential publication and the athletes’ rights and freedoms and interests on the other side.”

Proportionality means making sure an action does not go further than necessary to achieve its aim.

Caine considered the other side of the issue, including transparency in sport and the risk to clubs.

“Doping could carry a potential risk to the club itself.”

Catarina also raised the long-term impact of putting this information online.

“Once it’s published online, even if you delete it, it will never leave the internet.”

The discussion showed why organisations must think carefully before making personal data public, even where there is a strong reason to do so.

Meta, Addictive Design And Online Safety

The final story focused on Meta and the European Commission’s preliminary view that Meta may have breached the Digital Services Act.

The Digital Services Act is an EU law that places duties on online platforms to manage risks linked to their services.

Caine explained that the concerns related to features such as infinite scrolling, autoplay, push notifications and personalised content.

“The way that the social media app is designed bottom to top, it thinks it is doing too much to keep users engaged.”

He also questioned whether existing controls go far enough.

“What is it that they’re expecting Meta to do? What does Meta need to do now?”

Catarina raised concerns about children, vulnerable users, targeted content and connected technology such as smart glasses.

“There are so many concerns and the main one is definitely whether platforms are actually doing enough to protect children.”

The discussion ended with a wider privacy question about technology in the workplace.

“What’s the difference between wearing Meta glasses at work and everyone else that has a mobile phone that can record covertly anywhere?”

It is a useful reminder that privacy risks often appear before workplace expectations and regulation have fully caught up.

Looking Ahead

This episode showed how broad data protection has become.

It now connects to AI, cyber security, political campaigning, sport, social media design, workplace technology and public trust.

For organisations, the message is simple. Data protection is not just about policies. It is about how decisions are made, how risks are assessed and how people’s rights are protected in real situations.

Frequently Asked Questions

What was this episode of GDPR Radio about?

This episode covered key data protection news, including the Information Commission, the TfL cyber attack, political marketing, AI regulation, anti-doping decisions and Meta’s app design.

What is purpose limitation under GDPR?

Purpose limitation means personal data should only be used for the reason it was collected unless there is a clear lawful reason to use it for another purpose.

Why does the UK Government’s AI call for evidence matter?

It matters because organisations are already using AI and need clearer guidance on how existing data protection rules apply to new technology.

What is proportionality in data protection?

Proportionality means making sure an action is appropriate and does not go further than needed, especially where it affects someone’s rights.

Why are app design features a data protection issue?

App design features can influence how people behave online. If those features affect vulnerable users, children or personal data use, they can raise privacy and safety concerns.

Need Support With Data Protection, AI Or Cyber Security?

Data protection issues are becoming more connected.

AI, cyber security, marketing, employee access, online platforms and emerging technology all create new risks for organisations to manage.

Data Protection Made Easy helps organisations understand their responsibilities and take practical steps to improve compliance.

Whether you need support with UK GDPR, AI governance, cyber security or data protection training, our consultants can help make the process clearer and easier to manage.

Spotify logo

 

YouTube logo

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
S2 Ep30 GDPR Radio - Data Protection News of the Week
14 August 26 12:30 - 1:15 pm

S2 Ep30: GDPR Radio – Data Protection News of the Week

S2 Ep29 How AI Is Reshaping the DPO Role in 2026 (1)
07 August 26 12:30 - 1:15 pm

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.