Eve Hobson

Eve Hobson

Multi-Media Content Executive

Eve Hobson is a Multimedia Content Executive at Data Protection People, having joined the business in 2021. She is responsible for managing the organisation's social media channels and creating engaging content, working closely with Marketing Manager Myles Dacres to support brand awareness, campaigns, and audience engagement.

Get to Know Eve

Eve joined Data Protection People in 2021 after completing her A Levels in Law, Sociology and English Language. She began her career with the business as a Support Desk Officer before moving into a Business Administration role. During this time, she became increasingly involved in marketing activities, sparking a passion for content creation and digital marketing.

Today, Eve works as a Multimedia Content Executive, managing all of Data Protection People's social media channels. She creates engaging content that supports the company's brand presence and audience engagement. She works closely with Marketing Manager Myles Dacres on a range of projects, including website SEO, campaign management, event promotion, podcast marketing, and wider digital marketing initiatives.
With several years of experience across customer service, administration, and marketing, Eve brings a well-rounded perspective to her role and enjoys finding creative ways to communicate complex topics clearly and effectively.

Outside of work, Eve enjoys exploring the countryside, wild camping with her partner and friends, spending time with family, and expressing her creativity through drawing and painting.

Experience

Eve has built a diverse range of experience across customer service, administration, and marketing throughout her career. Before joining Data Protection People, she completed her A Levels in Sociology, Law, and English Language while balancing three part-time jobs alongside her studies. These roles included working in retail, hospitality, and the NHS, helping her develop a strong work ethic, excellent communication skills, and the ability to adapt to different working environments.

Her retail experience provided valuable insight into customer service, sales, and understanding customer needs. Working within hospitality at a Working Men's Club, helped her build confidence when interacting with a wide range of people, manage busy periods effectively, and develop strong organisational skills. Alongside this, her role as a Domestic Assistant within the NHS taught her the importance of professionalism, attention to detail, teamwork, and maintaining high standards within a regulated environment.

Since joining Data Protection People in 2021, Eve has gained experience across several areas of the business. Beginning as a Support Desk Officer before moving into Business Administration and eventually Marketing, she has developed a broad understanding of how different departments work together to support business growth and client satisfaction.

In 2026, Eve successfully completed her Multi-Channel Marketer qualification, further strengthening her knowledge of modern marketing practices. Through her apprenticeship, she gained practical experience in areas including social media management, content creation, campaign planning, website management, SEO, analytics, audience engagement, and digital marketing strategy. She has also developed skills in using a variety of marketing platforms and tools to measure performance and optimise campaigns.

Today, Eve applies this knowledge to support Data Protection People's marketing activities, helping to create engaging content, grow the organisation's online presence, and communicate complex data protection topics in a way that is accessible and easy to understand.

Eve Hobson

"Something I've come to appreciate throughout my marketing career is the value of brand awareness. It's not always about immediate results, it's about creating trust, recognition, and a positive reputation that people remember when they need your services."

Eve Hobson
Multi-Media Content Executive

Eve's Posts

Claude Shared Chats Appeared in Google Search: What Organisations Need to Know

Claude Shared Chats Appeared in Google Search: What Organisations Need to Know

Reports published on 27 July 2026 say that some publicly shared Claude conversations appeared in Google Search results.

This does not mean every private Claude conversation was exposed. Anthropic states that Claude chats are private by default. The risk relates to conversations that users deliberately chose to share by creating a public link.

Although this was not a security breach affecting all users, it is an important reminder that organisations need to consider how information is shared from AI tools, not just what employees enter into them.

What Happened to the Claude Conversations?

Claude allows users to create a shareable snapshot of a conversation.

When a user selects Share, Claude generates a public link that can be viewed by anyone who has access to it. Recent reports found that some of these publicly shared conversations had also appeared in Google Search results.

This increased the potential audience for those conversations. A link originally intended for a small number of people could become discoverable by individuals who had never received it directly.

Public links can spread beyond their intended audience. They may be shared on websites, forums or social media, making them accessible to search engines.

Further information is available from:

Were Private Claude Chats Leaked?

There is no evidence that all private Claude conversations became public.

According to Anthropic, conversations remain private unless a user deliberately creates a public share link. Once a conversation is shared publicly, anyone with the link can view it.

The concern raised by this story is that some public links became discoverable through search, rather than remaining accessible only to people who had been sent the link.

It is important to distinguish between:

  • A private conversation stored in a Claude account
  • A conversation that a user has deliberately turned into a public snapshot using a public link
  • A publicly shared conversation that later becomes discoverable through a search engine

This distinction matters. Organisations should respond to the real risk without suggesting that every Claude user has experienced a personal data breach.

What Information Is Shared?

According to Anthropic, a shared snapshot includes all messages exchanged before the conversation was shared. It may also include content created during the conversation.

Messages added after the snapshot is created remain private unless the conversation is shared again.

Anthropic also states that:

  • Attached files are not included in the shared snapshot
  • The conversation and Claude’s responses remain visible
  • Raw information retrieved through connected tools remains hidden
  • Users on Team and Enterprise plans can only share chats with members of the same organisation

However, even if an attached file is not shared, personal data or confidential information taken from that file may still appear within the conversation or in Claude’s responses.

Why Does This Matter for Organisations?

Many employees now use AI tools to help with everyday work, such as drafting documents, summarising information and preparing reports.

Those conversations may contain:

  • Personal data about customers or employees
  • Confidential business information
  • Internal plans or meeting notes
  • Client information
  • Security details
  • Unpublished financial or commercial information

Someone may understand that a colleague can open a shared link without appreciating that the link could later become accessible to a much wider audience.

This creates potential risks, including unauthorised disclosure, loss of confidentiality and possible exposure of personal data.

Not every shared conversation will amount to a personal data breach. Whether it does depends on the information involved, who could access it and the likely impact on the individuals concerned.

Even where no personal data is involved, the disclosure of confidential business information or commercially sensitive material may still create contractual, regulatory or commercial risks.

What Should Claude Users Do Now?

Anthropic provides a way for users to review their shared conversations.

  1. Open Claude and go to Settings.
  2. Select Privacy.
  3. Find Shared chats and select Manage.
  4. Review every conversation that has been shared.
  5. Remove any public links that are no longer needed.
  6. Check whether any shared conversation contains personal, confidential or security-related information.

Claude users can also access their shared conversations through the official Claude shared-chats page. Users may need to sign in before they can view or manage their shared conversations.

Removing a shared link prevents further access using that link. However, organisations should not assume that references to the page will disappear immediately from search engines or other websites.

If sensitive information has been exposed, the organisation should record the incident and begin its internal incident response process.

What Should an Organisation Do if Personal Data Was Shared?

If a shared Claude conversation contains personal data, the organisation should establish what happened as quickly as possible.

The immediate steps should include:

  • Disable the public share link
  • Preserve the information needed to investigate the incident
  • Identify the personal data involved
  • Establish who may have accessed the conversation
  • Assess the possible impact on the people concerned
  • Record the incident and the decisions made

The ICO states that organisations should assess the likelihood and severity of any risk to individuals’ rights and freedoms.

If a personal data breach is likely to result in a risk to people, it must be reported to the ICO without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.

Where the breach is likely to result in a high risk to individuals, the organisation may also need to inform those affected.

Not every incident needs to be reported. The decision should follow a documented risk assessment based on the circumstances of each case.

Use the ICO’s personal data breach assessment guidance.

What Should AI Policies Cover?

Many organisations focus on what employees are allowed to enter into an AI tool. That is only part of the picture.

An effective policy should also explain:

  • Whether employees are permitted to create public share links
  • What information must never be included in a shared conversation
  • Who can authorise external sharing
  • How shared links should be reviewed and removed
  • How long shared conversations should remain available
  • How employees should report accidental disclosure
  • Which AI tools and account types have been approved for business use

Organisations should also review sharing settings during AI procurement and risk assessments.

Any feature that allows information to be shared publicly or with anyone holding a link should be treated as an external disclosure unless suitable access controls are in place.

What Training Should Staff Receive?

Staff do not need a technical explanation of how search engines work. They do need to understand how AI platforms should be used, what information can be shared and the risks associated with public sharing.

Training should explain that:

  • AI conversations should not contain unnecessary personal data or confidential information
  • There is an important difference between saving a conversation privately and creating a public share link
  • Public links can be shared beyond the original recipient
  • Shared content may become searchable online
  • Removing the original link does not always remove every copy or reference
  • Suspected disclosures should be reported immediately

Using practical examples is likely to be more effective than simply telling employees to use AI responsibly.

Key Takeaways

The Claude shared-chat story is not evidence that every private AI conversation became public. It does show that a public sharing feature can create wider exposure than a user expects.

Organisations should review whether public AI conversations have been shared, update their internal policies where necessary and ensure employees understand the consequences of using sharing features.

Good information governance should cover the entire lifecycle of information. This includes what is entered into a tool, what the tool produces, who can access it, how it is shared and when it should be removed.

Sources

Need Support With AI and Data Protection?

If your organisation needs help reviewing AI use, internal policies or a potential personal data incident, speak to the Data Protection Made Easy team.

Speak to Our Team

AI and data regulation: what organisations need to know

AI and data regulation: what organisations need to know

The UK government has opened a call for evidence on data regulation in the age of AI and other data-intensive technologies.

Published by the Department for Science, Innovation and Technology on 15 July 2026, the call for evidence asks how current data regulation interacts with emerging technologies, where uncertainty remains and whether further guidance or reform may be needed.

For organisations using, testing or considering AI, this is a timely reminder that AI governance and data protection cannot be treated as separate issues.

What has happened?

The call for evidence looks at how personal and non-personal data regulation affects AI and other data-intensive technologies.

It asks for practical examples of how existing rules apply in real settings, including where organisations face uncertainty, friction or barriers to responsible data use.

It also considers how legal, technical and governance arrangements could support data sharing and reuse while managing potential harms.

You can read the call for evidence on GOV.UK here: Data regulation in the age of AI and other data-intensive technologies.

Why does this matter?

AI systems rely on data. In many cases, they rely on large volumes of data from different sources, used in ways that may not have been expected when the data was first collected.

That creates a practical challenge for organisations.

They need to understand not only what the technology can do, but whether the data behind it is being used lawfully, fairly and transparently.

For example, an organisation may need to consider whether the data was collected for a compatible purpose, whether people have been told how their data may be used, whether outputs can be explained and whether bias, accuracy or security risks have been assessed.

This is not simply a compliance exercise. It is about trust, accountability and good decision-making.

What questions should organisations be asking?

Before using AI or data-intensive tools, organisations should be able to answer some basic questions about the data involved.

  • What data is being used?
  • Does it include personal data?
  • Why is the data being used?
  • Is there a lawful basis for using it?
  • Has the purpose changed since the data was collected?
  • Can the organisation explain how decisions or outputs are produced?
  • Who is accountable for the tool and its outcomes?
  • How are bias, accuracy, transparency and security risks being managed?
  • Has a Data Protection Impact Assessment been considered?

A Data Protection Impact Assessment, often called a DPIA, is a process used to identify and reduce data protection risks before processing begins. It is especially important where new technology may affect people’s rights or freedoms.

Good AI governance starts with good data governance

AI governance means the rules, roles and checks an organisation uses to make sure AI is used safely and responsibly.

Data governance means the way an organisation manages data, including who owns it, how it is accessed, how it is used, how it is protected and when it should be deleted.

The two are closely linked.

If an organisation does not understand its data, it will struggle to explain its AI. If it cannot explain its AI, it may struggle to evidence compliance, respond to concerns or build trust with customers, staff, regulators and the public.

This is why data protection should be involved early in AI projects, not added at the end.

Catarina Santos, Consultant Manager at Data Protection People, said:

“Whilst this call for evidence does not introduce any new guidance or changes to the law, it is a positive step. It provides an opportunity to identify where the current framework may not be clear enough and to better understand the challenges organisations face when using AI. Listening to the experiences of businesses, regulators and other stakeholders should help shape future guidance and ensure that any changes strike the right balance between encouraging innovation and protecting individuals’ personal data.”

What should organisations do now?

The call for evidence does not change the law today. However, it is a useful signal of where future debate, guidance and possible reform may focus.

Organisations should use this moment to review how they assess AI tools and data-intensive technologies.

Practical steps include:

  • Mapping what data is used in AI tools.
  • Checking whether personal data is involved.
  • Reviewing lawful basis and transparency information.
  • Considering whether a DPIA is needed.
  • Recording who is accountable for each tool.
  • Reviewing supplier and processor arrangements.
  • Training staff on when AI use creates data protection risk.

Good AI use depends on clear roles, clear records and clear decisions.

FAQ

What is the government call for evidence about?

It is about how data regulation interacts with AI and other data-intensive technologies. The government is asking for practical examples of what works, where uncertainty remains and where further guidance or reform may be needed.

Does this change the law?

No. A call for evidence does not change the law. It is a way for government to gather information before deciding whether further guidance, policy changes or legal reform may be needed.

Why does this matter for organisations using AI?

It matters because AI often depends on large amounts of data. Organisations need to understand what data they are using, why they are using it and how they will manage legal, ethical and security risks.

What is AI governance?

AI governance means the rules, roles and checks an organisation uses to make sure AI is used safely, responsibly and in line with the law.

What is data governance?

Data governance means how an organisation manages data. This includes ownership, access, use, protection, retention and deletion.

When should data protection be considered in an AI project?

Data protection should be considered at the start of an AI project. This helps organisations identify risks early, document decisions and avoid problems later in the project.

Data Protection Made EasyAt Data Protection People, we help organisations understand data protection in practical terms.

If your organisation is reviewing AI tools, updating governance or trying to understand how data protection applies to new technology, we can help make the next steps clearer.

 

The First 72 Hours After a Breach

The First 72 Hours After a Breach, What Organisations Should Do Next

When a personal data breach occurs, the first few hours are often the most important.

The decisions made immediately after an incident can significantly influence the outcome, affecting regulatory obligations, reputational damage, customer trust and the overall response effort.

In a recent episode of the Data Protection Made Easy podcast, Caine Glancy and Catarina Pereira dos Santos discussed the practical actions organisations should take during the first 72 hours following a personal data breach.

The discussion explored breach containment, risk assessments, notifications, lessons learned and the common mistakes organisations make when responding to incidents.

Whilst every breach is different, the session reinforced a simple message. Organisations that respond quickly, assess risk properly and learn from incidents are often far better positioned to reduce harm and prevent future issues.

Containment should always come first

One of the most important points raised during the discussion was the need to contain an incident as quickly as possible.

Before organisations start thinking about reporting obligations, notifications or regulatory engagement, they need to understand what has happened and stop any ongoing unauthorised access, disclosure or loss of personal data.

As Catarina explained: “We need to contain it immediately.”

Containment actions will vary depending on the nature of the breach. This may involve recalling emails, disabling accounts, restricting access to systems, recovering documents or preventing further disclosure.

The key objective is to stop the incident from escalating whilst gathering enough information to understand what has happened.

Understanding the facts before assessing risk

Once the immediate situation has been contained, organisations need to establish the facts.

The discussion highlighted how many organisations rush straight to questions about whether a breach should be reported to the ICO without first understanding what has actually happened.

Before any meaningful risk assessment can take place, organisations need to identify what information was involved, who was affected, how the breach occurred, whether the information has been accessed and what mitigating actions have already been taken.

This information forms the foundation of any subsequent decision-making process.

Without context, it is almost impossible to determine whether a breach presents a risk to individuals or whether reporting obligations apply.

Not every breach is reportable

The session also addressed a common misconception. Not every personal data breach needs to be reported to the ICO.

Many organisations automatically assume that any breach involving personal data must be reported, whilst others incorrectly assume that low-risk incidents are not breaches at all.

In reality, every incident should be assessed on its own merits.

A misdirected email, accidental disclosure or inappropriate access may still constitute a personal data breach even if the risk to individuals is ultimately low.

The discussion reinforced the importance of assessing the specific circumstances rather than relying on assumptions.

As Caine explained, context is critical when evaluating risk and determining the appropriate response.

Why context matters when assessing risk

A recurring theme throughout the discussion was the importance of context.

Organisations often want a straightforward answer to whether a breach is reportable or whether affected individuals should be notified. However, data protection rarely works in absolutes.

Caine highlighted how difficult it can be to assess risk without understanding the full circumstances surrounding an incident.

A simple statement such as “an email was sent to the wrong person” does not provide enough information to determine the level of risk involved. Organisations need to understand the contents of the email, the sensitivity of the information, who received it and whether any mitigating actions have already been taken.

As Caine explained: “The key is always in the likely.”

Risk assessments should focus on what is realistically likely to happen as a result of the breach, rather than becoming overly focused on highly unlikely scenarios.

This is why context remains one of the most important elements of effective breach management.

When should organisations notify the ICO?

One of the most common questions raised following a breach is whether the incident needs to be reported to the Information Commissioner’s Office.

The discussion highlighted that organisations should avoid treating ICO reporting as an automatic response.

Instead, reporting decisions should be based on the outcome of a documented risk assessment and the likelihood of risk to individuals.

Where a breach is likely to result in a risk to the rights and freedoms of individuals, organisations are generally required to notify the ICO within 72 hours of becoming aware of the incident.

However, the hosts also acknowledged that many organisations struggle with this decision-making process, particularly when dealing with complex incidents or limited information.

For smaller organisations without dedicated privacy teams, understanding reporting thresholds can be one of the most challenging aspects of breach management.

Should affected individuals always be informed?

The session also explored another area that frequently causes uncertainty, notifying affected individuals.

Many organisations assume that if a breach has occurred, the individuals involved must automatically be informed. However, this is not always the case.

Whilst transparency remains a fundamental principle of data protection, notifications should have a clear purpose.

As Catarina explained, the purpose of notifying individuals is not simply to tell them that a breach has happened. It is to allow them to take action where there is an active risk to them.

If a breach creates a high risk to an individual’s rights and freedoms, notifying them may allow them to protect themselves from fraud, identity theft, financial loss or other harms.

Where there is no ongoing risk, organisations may decide that notification is unnecessary.

The discussion highlighted the importance of carefully balancing transparency, risk and potential distress when making these decisions.

The risks of over-notification

Whilst organisations are often concerned about under-reporting breaches, the discussion highlighted that over-notification can also create problems.

Informing individuals about every low-risk incident may cause unnecessary concern, particularly where no meaningful action is required on their part.

Some individuals may understandably assume the worst when they hear the phrase “data breach”, regardless of the actual level of risk involved.

In certain circumstances, notifying individuals about low-risk incidents may create confusion, anxiety and additional complaints without providing any practical benefit.

This is why notification decisions should always be proportionate and based on a thorough assessment of the circumstances.

As the discussion demonstrated, there is rarely a one-size-fits-all approach.

Caine reinforced this point by explaining: “Nothing in data protection is a one size fits all kind of thing.”

Every breach is an opportunity to learn

One of the strongest messages from the session was that organisations should view breaches as learning opportunities.

Even low-risk incidents can reveal weaknesses in processes, training, systems or controls.

Rather than simply recording an incident and moving on, organisations should take the time to identify trends and recurring issues.

As Caine explained: “The main thing really is treating it as lessons learned always.”

If multiple incidents occur for similar reasons, such as misdirected emails, access errors or process failures, this may indicate a wider issue that requires attention.

Reviewing breach data collectively often provides valuable insight into where improvements can be made.

The discussion highlighted how organisations can use incidents to strengthen controls, improve staff awareness and reduce the likelihood of future breaches.

Getting value from incidents

Closely linked to the lessons learned approach was the idea of extracting value from incidents wherever possible.

Breaches are rarely desirable, but they can provide useful information about organisational weaknesses and areas for improvement.

As Caine commented: “You’ve got to try and claim some benefit back from it where you can.”

This might involve updating procedures, improving training, introducing additional technical controls or reviewing existing risk assessments.

By treating breaches as opportunities for continuous improvement, organisations can often strengthen their overall data protection framework.

What organisations should do after a breach

Once the immediate response has been completed, the discussion highlighted the importance of reviewing the incident in full.

This should include documenting what happened, assessing the effectiveness of the response, identifying any improvements and updating relevant policies or procedures where necessary.

Organisations should also consider whether additional staff training, awareness campaigns or technical measures may help prevent similar incidents in the future.

The first 72 hours are important, but the actions taken afterwards are often what determine whether an organisation genuinely learns from an incident.

A practical approach to breach management

The session reinforced a practical and proportionate approach to managing personal data breaches.

Contain the incident, establish the facts, assess the risk, determine whether reporting obligations apply and identify opportunities for improvement.

Whilst every breach is different, organisations that follow these principles are often better positioned to respond effectively, reduce harm and strengthen compliance over time.

Most importantly, the discussion highlighted that effective breach management is not just about regulatory compliance. It is about protecting individuals, maintaining trust and continuously improving organisational practices.


Need support managing personal data breaches?

Managing a personal data breach can be challenging, particularly when organisations are under pressure to assess risk, make reporting decisions and communicate effectively with regulators and affected individuals.

Our Data Protection Support Service, Outsourced DPO Service and Training and Awareness Services help organisations build effective breach management processes, improve governance and strengthen compliance.

Whether you’re responding to an incident, reviewing your breach procedures or looking to improve organisational awareness, our team can help you manage data protection with confidence.


Frequently Asked Questions About Personal Data Breaches

What should organisations do immediately after discovering a data breach?

The first priority should be containing the incident to prevent any further unauthorised access, disclosure, loss or destruction of personal data. Once contained, organisations should establish the facts and begin assessing risk.

Does every personal data breach need to be reported to the ICO?

No. Organisations should assess whether the breach is likely to result in a risk to the rights and freedoms of individuals. Not all breaches meet the threshold for ICO notification.

How quickly must a breach be reported to the ICO?

Where a breach is reportable, organisations are generally required to notify the ICO within 72 hours of becoming aware of the incident.

Do organisations always need to notify affected individuals?

No. Individuals generally need to be informed where the breach is likely to result in a high risk to their rights and freedoms. Notification decisions should be based on a documented risk assessment.

Why is a risk assessment important following a breach?

A risk assessment helps organisations understand the potential impact on affected individuals and determine whether reporting or notification obligations apply.

What can organisations learn from data breaches?

Even low-risk incidents can reveal weaknesses in processes, systems, training or controls. Reviewing breaches helps organisations identify trends, strengthen governance and reduce future risk.

Training That Actually Changes Behaviour

Training That Actually Changes Behaviour, Why Effective Data Protection Training Goes Beyond Compliance

Data protection training is often treated as a compliance exercise, something that must be completed, recorded and repeated each year. However, as discussed during a recent episode of the Data Protection Made Easy podcast, training only delivers real value when it changes behaviour.

Hosted by Caine Glancy and Catarina Pereira dos Santos, the session explored why traditional training approaches often fail to influence day-to-day decision-making and what organisations can do to create lasting behavioural change.

Whilst completion rates and quiz scores may demonstrate that training has taken place, they do not always show whether employees understand how to apply data protection principles in real situations. The discussion highlighted the importance of moving beyond tick-box compliance and creating training that is practical, engaging and relevant to the people receiving it.

If your organisation is looking to strengthen its data protection culture, our Data Protection Training and Awareness Services, Data Protection Support Service and Outsourced DPO Service can help build awareness, confidence and compliance across your organisation.

Why most data protection training fails

One of the key themes from the discussion was the difference between providing information and creating behavioural change.

Whilst it is relatively straightforward to explain the requirements of the UK GDPR, helping people understand how those requirements apply to their daily responsibilities is often far more challenging.

Catarina explained that effective training cannot simply focus on theory and legal requirements alone, stating: “It needs to be practical. It needs to be a thing that’s practical and achievable for everyone.”

Employees deal with personal data every day through emails, customer interactions, records management, Subject Access Requests and information sharing. If training does not connect directly to these activities, it is unlikely to influence behaviour when it matters most.

Why behavioural change matters

Successful training should not be measured solely by attendance records or assessment results.

The real objective is to help staff recognise risks, make informed decisions and apply data protection requirements confidently in practice.

As discussed during the episode, organisations should consider whether employees are able to identify personal data breaches, understand when a Subject Access Request has been received and make appropriate decisions when handling personal data.

Catarina highlighted the challenge many organisations face when measuring success, commenting: “On the measuring of the training side of things, actually I’m a superstar. I’ve passed it, I’ve done it on a regular basis.”

Without these practical outcomes, even the highest completion rates may provide a false sense of confidence.

Moving beyond tick-box compliance

Training records may show that staff have attended sessions, completed e-learning modules and passed assessments, but this does not necessarily mean that knowledge has translated into action.

An employee may achieve a strong quiz score yet continue to make avoidable mistakes, such as sending information to the wrong recipient, failing to recognise a personal data breach or misunderstanding their responsibilities under data protection legislation.

This is why effective training must focus on practical understanding rather than simply demonstrating attendance.

As Catarina explained: “What actually changes the behaviour is not just the records.”

Organisations should aim to create learning experiences that help employees understand the risks most relevant to their role and provide them with the confidence to respond appropriately when those situations arise.

Practical training creates lasting change

Throughout the discussion, both hosts emphasised the value of practical learning.

Interactive workshops, scenario-based exercises and practical demonstrations often deliver stronger outcomes than traditional presentation-led training alone.

Catarina highlighted the importance of hands-on learning, explaining: “There is nothing else as doing it in practical.”

Subject Access Requests provide a useful example. Rather than simply explaining the legislation, participants can work through realistic requests, identify relevant personal data, consider exemptions and discuss how they would respond.

People may not remember every slide from a training session, but they often remember the situations they worked through themselves.

Caine reinforced this point, stating: “The best training is when you can get people talking and you can get them thinking about it afterwards.”

Why one-size-fits-all training rarely works

Another important topic covered during the episode was the need to tailor training to different audiences.

Different teams interact with personal data in different ways, which means their risks and responsibilities are often very different.

The information required by Human Resources teams may differ significantly from the needs of Marketing, IT, Customer Service or Senior Leadership teams.

Caine explained: “You’ve got to know who you’re talking to.”

He went on to emphasise the importance of role-specific training, adding: “What they need to know is what’s going to relate to their role.”

Employees are more likely to engage when they can clearly see how the content relates to their day-to-day responsibilities. Using department-specific examples and practical scenarios helps make training more relevant and memorable.

The role of the trainer

The conversation also explored an often-overlooked factor in successful learning, the trainer themselves.

Even well-designed training programmes can struggle to engage learners if they are delivered without energy, enthusiasm or practical insight.

Caine explained: “Training is only really as good as the person who is delivering it.”

Effective trainers help participants understand why data protection matters, encourage discussion and create an environment where people feel comfortable asking questions.

Importantly, successful delivery is not about personality alone. It is about demonstrating genuine passion for the topic and helping learners understand how the subject applies to their own experiences and challenges.

As Caine highlighted: “You have to bring energy and you have to bring excitement to the topic to make them care about it.”

Training alone is not enough

One of the most important takeaways from the episode was that training should not be viewed as a one-off event.

Catarina stressed this point, explaining: “The training is not just a one time thing.”

People forget information, processes change and new risks emerge. Organisations that rely solely on annual refresher training often find that important messages fade long before the next session takes place.

Regular communications, awareness campaigns, newsletters, posters, team discussions and practical reminders help keep data protection visible and relevant.

Catarina explained: “You should be expecting to have awareness campaigns, posters, sending emails, newsletters in a constant way.”

A strong data protection culture is built through continuous reinforcement rather than a single annual training session.

Leadership sets the tone

The episode also highlighted the importance of leadership involvement.

When senior leaders actively support data protection initiatives, attend training sessions and reinforce key messages, employees are more likely to recognise the importance of compliance and good information governance.

Caine explained the value of leadership engagement, stating: “If you can get the buy-in from them, it will always trickle down.”

Managers also play an important role in embedding learning after training has taken place. They are often best placed to reinforce expectations, answer questions and identify areas where additional support may be needed.

Creating meaningful behavioural change requires commitment from every level of the organisation.

Measuring training success differently

Many organisations continue to measure training success through attendance figures, completion rates and assessment scores.

Whilst these metrics provide useful information, they only tell part of the story.

The more important question is whether behaviour has changed. Are staff reporting incidents more quickly? Are fewer emails being sent to the wrong recipients? Are Subject Access Requests being identified earlier? Are teams considering privacy risks at the start of projects rather than after problems occur?

These indicators often provide a much clearer picture of whether training is having a meaningful impact.

As Catarina highlighted throughout the discussion, meaningful success is demonstrated through practical outcomes rather than training records alone.

Creating training that delivers real results

The discussion reinforced a simple but important message. Effective data protection training is not about achieving compliance for compliance’s sake. It is about helping people understand their responsibilities and giving them the confidence to make better decisions when handling personal data.

Caine summarised one of the key principles discussed during the session, stating: “Training can never be one size fits all.”

Organisations that focus on practical learning, ongoing awareness, tailored content and strong leadership support are far more likely to create lasting behavioural change.

For organisations looking to strengthen their approach, our Data Protection Training and Awareness Services, Data Protection Support Service and Outsourced DPO Service can help create effective training programmes that move beyond compliance and support a stronger data protection culture.


Frequently Asked Questions About Data Protection Training

Why is data protection training important?

Data protection training helps employees understand how to handle personal data correctly, recognise risks, identify potential breaches and comply with data protection legislation.

How often should staff receive data protection training?

Most organisations provide annual refresher training, but ongoing awareness activities throughout the year are equally important to reinforce learning and maintain good practices.

What makes data protection training effective?

Effective training is practical, relevant to the audience, interactive and supported by ongoing awareness activities that reinforce key messages.

Should different teams receive different training?

Yes. Different departments face different risks and responsibilities. Tailoring training to specific roles often improves engagement and learning outcomes.

How can organisations measure whether training is working?

Rather than focusing solely on attendance and completion rates, organisations should look for behavioural indicators such as improved incident reporting, reduced errors and stronger awareness of data protection responsibilities.

Can training alone create a strong data protection culture?

No. Training is only one part of the solution. Ongoing awareness, leadership support and regular reinforcement are all essential for creating a strong and sustainable data protection culture.

What Auditors Find And Why

What Auditors Always Find, And Why: Lessons from Real GDPR Audits

Many organisations view GDPR audits as a compliance exercise, a checklist that confirms whether policies, procedures and documentation exist. In reality, effective audits go much further than simply reviewing paperwork.

In a recent episode of the Data Protection Made Easy podcast, Catarina Pereira dos Santos and Catherine Santos explored what GDPR auditors consistently uncover when assessing organisations and why the same issues continue to appear across different sectors.

The discussion covered retention failures, staff awareness, third-party management, personal device usage, governance gaps and the common misconception that having documentation automatically means an organisation is compliant.

Drawing on real audit experiences, the session highlighted how organisations can use audits to identify weaknesses, improve accountability and strengthen their overall approach to data protection.

For organisations looking to assess their compliance position, our Data Protection Support Service, Outsourced DPO Service and Training and Awareness Services can help identify risks and support ongoing compliance.

A GDPR audit is more than a checklist

One of the first points raised during the discussion was that a genuine GDPR audit involves much more than reviewing documentation.

Catherine explained: “It’s not a checklist for sure.”

Whilst policies, procedures and records remain important, an audit should also assess how data protection operates in practice. This includes speaking with employees, understanding data flows and evaluating whether documented processes are actually being followed.

As Catherine highlighted, audits often provide an opportunity to understand how mature data protection is within an organisation and whether staff genuinely understand their responsibilities.

Simply having documentation in place does not automatically demonstrate compliance if employees are unaware of the processes they are expected to follow.

Documentation alone does not equal compliance

A recurring theme throughout the episode was the difference between having documentation and implementing it effectively.

The hosts discussed how organisations frequently present policies, procedures and registers during audits, only for employees to reveal that they have never seen them.

As Catherine explained, one of the most common responses during interviews is: “Do we have such a policy? I didn’t know.”

This creates a significant compliance risk. Policies are only effective if they are understood, communicated and embedded within everyday working practices.

An organisation may have an excellent Information Security Policy, Data Breach Procedure or Retention Schedule, but if staff are unaware of them, compliance becomes difficult to demonstrate in practice.

Why employee engagement matters

The discussion highlighted the importance of speaking with employees during an audit.

Unlike a gap analysis or documentation review, a GDPR audit should assess how data protection is understood and applied throughout the organisation.

Employees often provide valuable insight into how personal information is actually handled, revealing differences between documented processes and day-to-day reality.

These conversations can also act as informal awareness sessions, helping staff better understand their responsibilities and providing an opportunity to ask questions.

The hosts emphasised that compliance is not achieved through policies alone. It depends on people understanding what they need to do and why.

Retention remains one of the biggest audit findings

When discussing the issues they encounter most frequently, both hosts quickly identified retention as a recurring challenge.

Many organisations have retention policies in place, but implementation often tells a different story.

Employees may understand that records should be deleted after a certain period, yet the actual deletion process never takes place.

The discussion included examples of organisations retaining emails for decades, storing outdated information indefinitely and relying on manual deletion processes that are rarely followed consistently.

Without effective retention practices, organisations risk keeping personal information for longer than necessary and increasing their exposure to data protection risks.

Third-party management is frequently overlooked

Another area highlighted during the discussion was third-party management.

Many organisations maintain supplier registers and records of processing activities, but auditors often discover inconsistencies when testing the information.

The hosts shared examples where organisations claimed to have Data Processing Agreements in place for all suppliers, only for further investigation to reveal unsigned templates or agreements that had never actually been implemented.

This demonstrates why auditors must test evidence rather than simply accept documentation at face value.

Third-party relationships often represent significant compliance risks, particularly where personal data is being processed externally or transferred internationally.

The risks of personal device usage

The discussion also explored one of the most common findings in modern workplaces, employees using personal devices for business purposes.

As Catherine explained: “The organisation doesn’t know that some employees use their phones for work.”

This creates a range of challenges. Personal devices may contain customer information, contracts, emails or communications that are completely outside the organisation’s governance framework.

It can also create difficulties when responding to Subject Access Requests, managing retention periods and investigating incidents.

Without appropriate Bring Your Own Device policies and controls, organisations may struggle to understand where personal data is being stored and processed.

WhatsApp, shadow IT and hidden data flows

The hosts also highlighted the increasing use of WhatsApp and other informal communication tools.

Whilst these platforms may improve efficiency, they can also introduce governance challenges when organisations fail to formally recognise or manage their use.

Examples discussed included contractors using WhatsApp to share photographs, employees communicating with customers through personal devices and business information being exchanged through channels that are not covered by existing policies.

These hidden data flows can create significant compliance risks if organisations are unaware of how information is being processed.

Effective governance requires organisations to understand where personal information is being stored, shared and accessed, regardless of whether that activity takes place through official systems or informal channels.

Why people shouldn’t fear audits

One of the most interesting parts of the discussion focused on the perception of audits themselves.

Many employees view auditors as investigators looking for mistakes or individuals responsible for assigning blame.

The hosts acknowledged that the word “audit” often creates anxiety, particularly where organisations have recently experienced a breach or compliance issue.

However, they stressed that audits should be viewed as opportunities for improvement rather than exercises in criticism.

As Catarina explained when speaking to employees during audits: “I am not here to judge you.”

The purpose of an audit is to identify risks, highlight opportunities for improvement and help organisations strengthen their compliance position.

When approached positively, audits can provide valuable insight into how organisations handle personal information and where additional support may be needed.

Turning findings into action

Finding issues during an audit is only the beginning of the process.

The real value comes from understanding those findings, prioritising actions and implementing meaningful improvements.

The discussion highlighted the importance of clear reporting, practical recommendations and helping organisations understand where risks are most significant.

Not every finding represents a high-risk compliance issue. Some can be addressed quickly, whilst others may require longer-term planning and investment.

Effective audit reports should help organisations understand not only what needs to improve, but also where they should focus their efforts first.

Why audits are essential for accountability

Whilst UK GDPR does not explicitly require organisations to conduct annual audits, the discussion highlighted how audits support one of the most important principles within the legislation, accountability.

Organisations must be able to demonstrate compliance. To do this effectively, they need mechanisms that test controls, assess risks and evaluate whether policies are operating as intended.

Audits provide an opportunity to challenge assumptions, verify compliance claims and identify gaps before they become larger issues.

Ultimately, the discussion reinforced that audits should not be seen as a negative exercise. They are an opportunity to learn, improve and build a stronger data protection culture.


Frequently Asked Questions About GDPR Audits

What is a GDPR audit?

A GDPR audit is a structured assessment of an organisation’s data protection practices, policies, procedures and operational controls to determine how effectively personal information is being managed.

Are GDPR audits legally required?

UK GDPR does not explicitly require annual audits, but audits are often used to support accountability obligations and demonstrate compliance.

What do GDPR auditors look for?

Auditors typically assess governance arrangements, policies, training, records management, retention practices, security measures, third-party management and employee awareness.

Why is retention often a common audit finding?

Many organisations have retention policies in place, but fail to consistently apply them in practice, leading to unnecessary retention of personal information.

Can an organisation be compliant if it has policies but employees do not follow them?

No. Compliance depends on policies being implemented effectively and understood by employees, not simply existing as documents.

What is the benefit of a GDPR audit?

A GDPR audit helps organisations identify weaknesses, strengthen controls, improve accountability and reduce the likelihood of compliance failures or data breaches.

GDPR Toolkit

Why Your Business Needs a GDPR Toolkit

Navigating the complexities of the GDPR can feel overwhelming. For businesses of all sizes, ensuring you meet the UK General Data Protection Regulation’s (UK GDPR) requirements is crucial. But where do you begin?

The Challenge: Untangling the GDPR Web

The UK GDPR outlines a set of regulations designed to protect the personal data of UK citizens. Failure to comply can result in hefty fines and reputational damage. Understanding and implementing these regulations requires time, expertise, and a clear understanding of your specific data processing activities.

The Solution: A One-Stop Shop for GDPR Compliance

This is where a GDPR Toolkit from Data Protection People steps in. We’ve designed this comprehensive resource to be your one-stop shop for achieving and maintaining GDPR compliance.

Benefits for Your Business: Confidence and Peace of Mind

  • Streamlined Compliance: Our meticulously crafted framework provides all the essential tools you need, from customisable templates to pre-drafted data breach notifications. This saves you valuable time and resources, allowing you to focus on your core business activities.

  • Empowered Staff: Our toolkit includes staff awareness training, ensuring your team understands their role in data protection. A well-informed workforce minimises the risk of human error and safeguards your data.

  • Reduced Risk: By implementing the best practices outlined in the toolkit, you significantly reduce the risk of data breaches and non-compliance fines. This translates to peace of mind and protection for your business reputation.

Why Choose Data Protection People and our GDPR Toolkit?

Data Protection People is a leading UK Data Protection Consultancy with a proven track record of success. Our team of experienced consultants works with clients across the UK and internationally.

Data Protection Made Easy: Our Guiding Principle

We understand the complexities of data protection. That’s why our motto is “data protection made easy.” Our toolkit simplifies these intricate regulations, making them accessible for businesses of all sizes.

Here’s what sets us apart:

  • Expert-Led Development: Developed by industry experts, our toolkit reflects the latest GDPR guidance and best practices.

  • Customisable Templates: We provide a comprehensive library of customisable templates, adaptable to your specific data processing activities.

  • Ongoing Support: We offer ongoing support to ensure you get the most out of your toolkit and stay up-to-date with evolving regulations.

Investing in Your Future

GDPR Toolkit is an investment in the future of your business. By prioritising data protection compliance, you demonstrate your commitment to customer trust and build stronger client relationships.

Taking the Next Step

Ready to simplify GDPR compliance and gain peace of mind? Contact Data Protection People today to learn more about our GDPR Toolkit. Let us guide you through the maze of data privacy regulations and empower your business to thrive.

Is Your Breach Response a Black Hole?

Is Your Breach Response a Black Hole? UK DPOs Face Shocking Delays (and Fines)

With UK GDPR regulations placing data protection at the forefront, organisations are facing a new reality: data breaches can be not just a security risk, but a significant financial one and the consequences for organisations can be severe. But a new study reveals a disturbing trend: UK organisations are taking significantly longer to contain data breaches compared to the global average. This delay can be disastrous, leading to compromised data, hefty fines under UK GDPR, and irreparable damage to customer trust. Don’t let your breach response become a black hole! This blog explores the issue and offers solutions.

The Alarming Statistics

A recent study by  IBM’s 2022 data security report, found that the average UK organisation takes a staggering 277 days  -roughly 9 months – for businesses to identify and report a data breach. Stolen or compromised credentials were the most common cause of a data breach in 2022, and these types of attacks took around 327 days to identify. It costs roughly $4.35 million to recover from a data breach and attacks on the healthcare industry were the highest.”  This means critical time is wasted while sensitive data remains exposed, increasing the risk of exploitation by malicious actors.

The Ripple Effect of Delay

The longer a data breach goes undetected and uncontained, the more severe the consequences. Here’s what’s at stake:

  • Increased Risk of Exploitation: Every minute a breach goes unnoticed is an opportunity for hackers to steal sensitive data, like financial information or personal details. This can lead to identity theft, fraud, and reputational damage for your organisation.
  • Hefty Fines under UK GDPR: The UK GDPR enforces strict regulations on data protection. Organisations that fail to report breaches within 72 hours, face fines up to £17.5M or 4% of annual global turnover. This whichever one is greater.
  • Shattered Customer Trust: When a data breach occurs, customers lose faith in an organisation’s ability to protect their personal information. This can lead to a decline in sales, customer churn, and difficulty attracting new business.

Why Are UK Organisations Lagging Behind?

DPOs are often responsible for a wide range of data protection tasks beyond breach response. This can leave them stretched thin and unable to dedicate the necessary time and attention to developing a robust breach response plan or conducting regular security audits.

Taking Control: How to Streamline Your Breach Response

Don’t let a data breach become an existential threat for your organisation. Here are some steps you can take to ensure a swift and compliant resolution:

  • Develop a Comprehensive Breach Response Plan: A well-defined plan outlines the steps to be taken in the event of a breach, including identification, containment, eradication, and notification. It should also include clear roles and responsibilities for all personnel involved.
  • Invest in Security Awareness Training: Empower your employees to be the first line of defence against data breaches. Regular training on data security best practices, phishing scams, and password hygiene can significantly reduce the risk of human error leading to a breach.
  • Regular Penetration Testing and Vulnerability Assessments: Proactive identification of vulnerabilities in your IT systems helps you patch them before they can be exploited by attackers.
  • Partner with a GDPR Breach Response Specialist: Companies like Data Protection People offer a range of services to help organisations prepare for and respond to data breaches. We can assist with developing breach response plans, conducting training, and providing guidance on regulatory compliance with the UK GDPR.

Don’t Wait for Disaster to Strike

Data breaches are an unfortunate reality of the current technological landscape, but the impact can be minimised with proper preparation. By taking the steps outlined above, you can ensure your organisation has a robust breach response plan in place. This helps mitigate the risks and navigate a data breach efficiently.

Contact Data Protection People today. Learn how we can help you make your breach response bulletproof. Check out our “GDPR Breach Guide” to get started on building a comprehensive plan.

Remember: A swift and effective response to a data breach can save your organisation from significant financial and reputational damage. Don’t wait until it’s too late.

World Password Day: A Guide to Bulletproof Passwords

World Password Day: A Guide to Bulletproof Passwords

Strong password practices are essential for ensuring the security of our online identities and data. Weak passwords leave sensitive information vulnerable to data breaches and cyberattacks.  This guide equips you with the knowledge and tools to transform from a password punching bag into a champion of online security. We’ll delve into the importance of length, the dangers of password reuse, and explore powerful strategies like password managers and multi-factor authentication.

1. Prioritise Length:

While complexity plays a role, prioritising length is crucial. Imagine a combination lock – the more digits, the harder to crack. Aim for at least 16 characters for each password. This significantly increases the time and effort required for brute-force attacks, where hackers systematically try every possible combination.

2. Embrace Uniqueness:

Resist the urge to reuse passwords across different accounts. A data breach on a single platform can expose your login credentials. If you’ve reused those credentials for other accounts (like your bank or social media), those accounts become vulnerable too. Hackers can easily test your stolen login information on other platforms, potentially gaining access to a wealth of your personal information.

3. Leverage Complexity:

Length is essential, but don’t underestimate the power of complexity. Incorporate a combination of uppercase and lowercase letters, numbers, and symbols. This creates a stronger barrier against hacking attempts, making your password significantly more difficult to guess.

4. Utilise Password Managers:

Remembering numerous unique passwords can be a challenge. Consider using a password manager. These secure applications store and encrypt your login credentials, eliminating the need to remember them all while keeping them safe and readily accessible.

5. Double Down with Multi-Factor Authentication:

Many platforms offer multi-factor authentication (MFA) as an extra security layer. This requires an additional verification step beyond just your password, such as a code sent to your phone or a fingerprint/Face ID scan. Consider MFA as a secondary security checkpoint, adding another hurdle for potential intruders.

Employee Checklist: Mastering Password Management

Now that you’re armed with this knowledge, here’s a quick checklist to ensure your passwords are top-notch:

  • Conduct a Password Audit: Review your current passwords. Are they strong and unique?
  • Enhance Password Strength: Consider using a password generator to create complex, lengthy passwords for each account.
  • Secure Password Storage: If not using a password manager already, explore secure options to store your credentials.
  • Enable MFA: Wherever available, activate multi-factor authentication for an extra layer of protection.
  • Maintain Vigilance: Be wary of phishing attempts. Never share your password information in response to unsolicited emails or calls.

By following these simple steps, you can significantly improve your online security posture and safeguard both your personal and company data. Remember, strong passwords are the first line of defence in the fight against cybercrime. Let’s work together to build a robust security framework around our digital assets!

Need Additional Support?

For further guidance on password management best practices or a comprehensive data security strategy, our experienced Data Protection Officers (DPO) are here to assist. Contact our DPO services department to discuss your specific needs.