Eve Hobson

Eve Hobson

Multi-Media Content Executive

Eve Hobson is a Multimedia Content Executive at Data Protection People, having joined the business in 2021. She is responsible for managing the organisation's social media channels and creating engaging content, working closely with Marketing Manager Myles Dacres to support brand awareness, campaigns, and audience engagement.

Get to Know Eve

Eve joined Data Protection People in 2021 after completing her A Levels in Law, Sociology and English Language. She began her career with the business as a Support Desk Officer before moving into a Business Administration role. During this time, she became increasingly involved in marketing activities, sparking a passion for content creation and digital marketing.

Today, Eve works as a Multimedia Content Executive, managing all of Data Protection People's social media channels. She creates engaging content that supports the company's brand presence and audience engagement. She works closely with Marketing Manager Myles Dacres on a range of projects, including website SEO, campaign management, event promotion, podcast marketing, and wider digital marketing initiatives.
With several years of experience across customer service, administration, and marketing, Eve brings a well-rounded perspective to her role and enjoys finding creative ways to communicate complex topics clearly and effectively.

Outside of work, Eve enjoys exploring the countryside, wild camping with her partner and friends, spending time with family, and expressing her creativity through drawing and painting.

Experience

Eve has built a diverse range of experience across customer service, administration, and marketing throughout her career. Before joining Data Protection People, she completed her A Levels in Sociology, Law, and English Language while balancing three part-time jobs alongside her studies. These roles included working in retail, hospitality, and the NHS, helping her develop a strong work ethic, excellent communication skills, and the ability to adapt to different working environments.

Her retail experience provided valuable insight into customer service, sales, and understanding customer needs. Working within hospitality at a Working Men's Club, helped her build confidence when interacting with a wide range of people, manage busy periods effectively, and develop strong organisational skills. Alongside this, her role as a Domestic Assistant within the NHS taught her the importance of professionalism, attention to detail, teamwork, and maintaining high standards within a regulated environment.

Since joining Data Protection People in 2021, Eve has gained experience across several areas of the business. Beginning as a Support Desk Officer before moving into Business Administration and eventually Marketing, she has developed a broad understanding of how different departments work together to support business growth and client satisfaction.

In 2026, Eve successfully completed her Multi-Channel Marketer qualification, further strengthening her knowledge of modern marketing practices. Through her apprenticeship, she gained practical experience in areas including social media management, content creation, campaign planning, website management, SEO, analytics, audience engagement, and digital marketing strategy. She has also developed skills in using a variety of marketing platforms and tools to measure performance and optimise campaigns.

Today, Eve applies this knowledge to support Data Protection People's marketing activities, helping to create engaging content, grow the organisation's online presence, and communicate complex data protection topics in a way that is accessible and easy to understand.

Eve Hobson

"Something I've come to appreciate throughout my marketing career is the value of brand awareness. It's not always about immediate results, it's about creating trust, recognition, and a positive reputation that people remember when they need your services."

Eve Hobson
Multi-Media Content Executive

Eve's Posts

The First 72 Hours After a Breach

The First 72 Hours After a Breach, What Organisations Should Do Next

When a personal data breach occurs, the first few hours are often the most important.

The decisions made immediately after an incident can significantly influence the outcome, affecting regulatory obligations, reputational damage, customer trust and the overall response effort.

In a recent episode of the Data Protection Made Easy podcast, Caine Glancy and Catarina Pereira dos Santos discussed the practical actions organisations should take during the first 72 hours following a personal data breach.

The discussion explored breach containment, risk assessments, notifications, lessons learned and the common mistakes organisations make when responding to incidents.

Whilst every breach is different, the session reinforced a simple message. Organisations that respond quickly, assess risk properly and learn from incidents are often far better positioned to reduce harm and prevent future issues.

Containment should always come first

One of the most important points raised during the discussion was the need to contain an incident as quickly as possible.

Before organisations start thinking about reporting obligations, notifications or regulatory engagement, they need to understand what has happened and stop any ongoing unauthorised access, disclosure or loss of personal data.

As Catarina explained: “We need to contain it immediately.”

Containment actions will vary depending on the nature of the breach. This may involve recalling emails, disabling accounts, restricting access to systems, recovering documents or preventing further disclosure.

The key objective is to stop the incident from escalating whilst gathering enough information to understand what has happened.

Understanding the facts before assessing risk

Once the immediate situation has been contained, organisations need to establish the facts.

The discussion highlighted how many organisations rush straight to questions about whether a breach should be reported to the ICO without first understanding what has actually happened.

Before any meaningful risk assessment can take place, organisations need to identify what information was involved, who was affected, how the breach occurred, whether the information has been accessed and what mitigating actions have already been taken.

This information forms the foundation of any subsequent decision-making process.

Without context, it is almost impossible to determine whether a breach presents a risk to individuals or whether reporting obligations apply.

Not every breach is reportable

The session also addressed a common misconception. Not every personal data breach needs to be reported to the ICO.

Many organisations automatically assume that any breach involving personal data must be reported, whilst others incorrectly assume that low-risk incidents are not breaches at all.

In reality, every incident should be assessed on its own merits.

A misdirected email, accidental disclosure or inappropriate access may still constitute a personal data breach even if the risk to individuals is ultimately low.

The discussion reinforced the importance of assessing the specific circumstances rather than relying on assumptions.

As Caine explained, context is critical when evaluating risk and determining the appropriate response.

Why context matters when assessing risk

A recurring theme throughout the discussion was the importance of context.

Organisations often want a straightforward answer to whether a breach is reportable or whether affected individuals should be notified. However, data protection rarely works in absolutes.

Caine highlighted how difficult it can be to assess risk without understanding the full circumstances surrounding an incident.

A simple statement such as “an email was sent to the wrong person” does not provide enough information to determine the level of risk involved. Organisations need to understand the contents of the email, the sensitivity of the information, who received it and whether any mitigating actions have already been taken.

As Caine explained: “The key is always in the likely.”

Risk assessments should focus on what is realistically likely to happen as a result of the breach, rather than becoming overly focused on highly unlikely scenarios.

This is why context remains one of the most important elements of effective breach management.

When should organisations notify the ICO?

One of the most common questions raised following a breach is whether the incident needs to be reported to the Information Commissioner’s Office.

The discussion highlighted that organisations should avoid treating ICO reporting as an automatic response.

Instead, reporting decisions should be based on the outcome of a documented risk assessment and the likelihood of risk to individuals.

Where a breach is likely to result in a risk to the rights and freedoms of individuals, organisations are generally required to notify the ICO within 72 hours of becoming aware of the incident.

However, the hosts also acknowledged that many organisations struggle with this decision-making process, particularly when dealing with complex incidents or limited information.

For smaller organisations without dedicated privacy teams, understanding reporting thresholds can be one of the most challenging aspects of breach management.

Should affected individuals always be informed?

The session also explored another area that frequently causes uncertainty, notifying affected individuals.

Many organisations assume that if a breach has occurred, the individuals involved must automatically be informed. However, this is not always the case.

Whilst transparency remains a fundamental principle of data protection, notifications should have a clear purpose.

As Catarina explained, the purpose of notifying individuals is not simply to tell them that a breach has happened. It is to allow them to take action where there is an active risk to them.

If a breach creates a high risk to an individual’s rights and freedoms, notifying them may allow them to protect themselves from fraud, identity theft, financial loss or other harms.

Where there is no ongoing risk, organisations may decide that notification is unnecessary.

The discussion highlighted the importance of carefully balancing transparency, risk and potential distress when making these decisions.

The risks of over-notification

Whilst organisations are often concerned about under-reporting breaches, the discussion highlighted that over-notification can also create problems.

Informing individuals about every low-risk incident may cause unnecessary concern, particularly where no meaningful action is required on their part.

Some individuals may understandably assume the worst when they hear the phrase “data breach”, regardless of the actual level of risk involved.

In certain circumstances, notifying individuals about low-risk incidents may create confusion, anxiety and additional complaints without providing any practical benefit.

This is why notification decisions should always be proportionate and based on a thorough assessment of the circumstances.

As the discussion demonstrated, there is rarely a one-size-fits-all approach.

Caine reinforced this point by explaining: “Nothing in data protection is a one size fits all kind of thing.”

Every breach is an opportunity to learn

One of the strongest messages from the session was that organisations should view breaches as learning opportunities.

Even low-risk incidents can reveal weaknesses in processes, training, systems or controls.

Rather than simply recording an incident and moving on, organisations should take the time to identify trends and recurring issues.

As Caine explained: “The main thing really is treating it as lessons learned always.”

If multiple incidents occur for similar reasons, such as misdirected emails, access errors or process failures, this may indicate a wider issue that requires attention.

Reviewing breach data collectively often provides valuable insight into where improvements can be made.

The discussion highlighted how organisations can use incidents to strengthen controls, improve staff awareness and reduce the likelihood of future breaches.

Getting value from incidents

Closely linked to the lessons learned approach was the idea of extracting value from incidents wherever possible.

Breaches are rarely desirable, but they can provide useful information about organisational weaknesses and areas for improvement.

As Caine commented: “You’ve got to try and claim some benefit back from it where you can.”

This might involve updating procedures, improving training, introducing additional technical controls or reviewing existing risk assessments.

By treating breaches as opportunities for continuous improvement, organisations can often strengthen their overall data protection framework.

What organisations should do after a breach

Once the immediate response has been completed, the discussion highlighted the importance of reviewing the incident in full.

This should include documenting what happened, assessing the effectiveness of the response, identifying any improvements and updating relevant policies or procedures where necessary.

Organisations should also consider whether additional staff training, awareness campaigns or technical measures may help prevent similar incidents in the future.

The first 72 hours are important, but the actions taken afterwards are often what determine whether an organisation genuinely learns from an incident.

A practical approach to breach management

The session reinforced a practical and proportionate approach to managing personal data breaches.

Contain the incident, establish the facts, assess the risk, determine whether reporting obligations apply and identify opportunities for improvement.

Whilst every breach is different, organisations that follow these principles are often better positioned to respond effectively, reduce harm and strengthen compliance over time.

Most importantly, the discussion highlighted that effective breach management is not just about regulatory compliance. It is about protecting individuals, maintaining trust and continuously improving organisational practices.


Need support managing personal data breaches?

Managing a personal data breach can be challenging, particularly when organisations are under pressure to assess risk, make reporting decisions and communicate effectively with regulators and affected individuals.

Our Data Protection Support Service, Outsourced DPO Service and Training and Awareness Services help organisations build effective breach management processes, improve governance and strengthen compliance.

Whether you’re responding to an incident, reviewing your breach procedures or looking to improve organisational awareness, our team can help you manage data protection with confidence.


Frequently Asked Questions About Personal Data Breaches

What should organisations do immediately after discovering a data breach?

The first priority should be containing the incident to prevent any further unauthorised access, disclosure, loss or destruction of personal data. Once contained, organisations should establish the facts and begin assessing risk.

Does every personal data breach need to be reported to the ICO?

No. Organisations should assess whether the breach is likely to result in a risk to the rights and freedoms of individuals. Not all breaches meet the threshold for ICO notification.

How quickly must a breach be reported to the ICO?

Where a breach is reportable, organisations are generally required to notify the ICO within 72 hours of becoming aware of the incident.

Do organisations always need to notify affected individuals?

No. Individuals generally need to be informed where the breach is likely to result in a high risk to their rights and freedoms. Notification decisions should be based on a documented risk assessment.

Why is a risk assessment important following a breach?

A risk assessment helps organisations understand the potential impact on affected individuals and determine whether reporting or notification obligations apply.

What can organisations learn from data breaches?

Even low-risk incidents can reveal weaknesses in processes, systems, training or controls. Reviewing breaches helps organisations identify trends, strengthen governance and reduce future risk.

Training That Actually Changes Behaviour

Training That Actually Changes Behaviour, Why Effective Data Protection Training Goes Beyond Compliance

Data protection training is often treated as a compliance exercise, something that must be completed, recorded and repeated each year. However, as discussed during a recent episode of the Data Protection Made Easy podcast, training only delivers real value when it changes behaviour.

Hosted by Caine Glancy and Catarina Pereira dos Santos, the session explored why traditional training approaches often fail to influence day-to-day decision-making and what organisations can do to create lasting behavioural change.

Whilst completion rates and quiz scores may demonstrate that training has taken place, they do not always show whether employees understand how to apply data protection principles in real situations. The discussion highlighted the importance of moving beyond tick-box compliance and creating training that is practical, engaging and relevant to the people receiving it.

If your organisation is looking to strengthen its data protection culture, our Data Protection Training and Awareness Services, Data Protection Support Service and Outsourced DPO Service can help build awareness, confidence and compliance across your organisation.

Why most data protection training fails

One of the key themes from the discussion was the difference between providing information and creating behavioural change.

Whilst it is relatively straightforward to explain the requirements of the UK GDPR, helping people understand how those requirements apply to their daily responsibilities is often far more challenging.

Catarina explained that effective training cannot simply focus on theory and legal requirements alone, stating: “It needs to be practical. It needs to be a thing that’s practical and achievable for everyone.”

Employees deal with personal data every day through emails, customer interactions, records management, Subject Access Requests and information sharing. If training does not connect directly to these activities, it is unlikely to influence behaviour when it matters most.

Why behavioural change matters

Successful training should not be measured solely by attendance records or assessment results.

The real objective is to help staff recognise risks, make informed decisions and apply data protection requirements confidently in practice.

As discussed during the episode, organisations should consider whether employees are able to identify personal data breaches, understand when a Subject Access Request has been received and make appropriate decisions when handling personal data.

Catarina highlighted the challenge many organisations face when measuring success, commenting: “On the measuring of the training side of things, actually I’m a superstar. I’ve passed it, I’ve done it on a regular basis.”

Without these practical outcomes, even the highest completion rates may provide a false sense of confidence.

Moving beyond tick-box compliance

Training records may show that staff have attended sessions, completed e-learning modules and passed assessments, but this does not necessarily mean that knowledge has translated into action.

An employee may achieve a strong quiz score yet continue to make avoidable mistakes, such as sending information to the wrong recipient, failing to recognise a personal data breach or misunderstanding their responsibilities under data protection legislation.

This is why effective training must focus on practical understanding rather than simply demonstrating attendance.

As Catarina explained: “What actually changes the behaviour is not just the records.”

Organisations should aim to create learning experiences that help employees understand the risks most relevant to their role and provide them with the confidence to respond appropriately when those situations arise.

Practical training creates lasting change

Throughout the discussion, both hosts emphasised the value of practical learning.

Interactive workshops, scenario-based exercises and practical demonstrations often deliver stronger outcomes than traditional presentation-led training alone.

Catarina highlighted the importance of hands-on learning, explaining: “There is nothing else as doing it in practical.”

Subject Access Requests provide a useful example. Rather than simply explaining the legislation, participants can work through realistic requests, identify relevant personal data, consider exemptions and discuss how they would respond.

People may not remember every slide from a training session, but they often remember the situations they worked through themselves.

Caine reinforced this point, stating: “The best training is when you can get people talking and you can get them thinking about it afterwards.”

Why one-size-fits-all training rarely works

Another important topic covered during the episode was the need to tailor training to different audiences.

Different teams interact with personal data in different ways, which means their risks and responsibilities are often very different.

The information required by Human Resources teams may differ significantly from the needs of Marketing, IT, Customer Service or Senior Leadership teams.

Caine explained: “You’ve got to know who you’re talking to.”

He went on to emphasise the importance of role-specific training, adding: “What they need to know is what’s going to relate to their role.”

Employees are more likely to engage when they can clearly see how the content relates to their day-to-day responsibilities. Using department-specific examples and practical scenarios helps make training more relevant and memorable.

The role of the trainer

The conversation also explored an often-overlooked factor in successful learning, the trainer themselves.

Even well-designed training programmes can struggle to engage learners if they are delivered without energy, enthusiasm or practical insight.

Caine explained: “Training is only really as good as the person who is delivering it.”

Effective trainers help participants understand why data protection matters, encourage discussion and create an environment where people feel comfortable asking questions.

Importantly, successful delivery is not about personality alone. It is about demonstrating genuine passion for the topic and helping learners understand how the subject applies to their own experiences and challenges.

As Caine highlighted: “You have to bring energy and you have to bring excitement to the topic to make them care about it.”

Training alone is not enough

One of the most important takeaways from the episode was that training should not be viewed as a one-off event.

Catarina stressed this point, explaining: “The training is not just a one time thing.”

People forget information, processes change and new risks emerge. Organisations that rely solely on annual refresher training often find that important messages fade long before the next session takes place.

Regular communications, awareness campaigns, newsletters, posters, team discussions and practical reminders help keep data protection visible and relevant.

Catarina explained: “You should be expecting to have awareness campaigns, posters, sending emails, newsletters in a constant way.”

A strong data protection culture is built through continuous reinforcement rather than a single annual training session.

Leadership sets the tone

The episode also highlighted the importance of leadership involvement.

When senior leaders actively support data protection initiatives, attend training sessions and reinforce key messages, employees are more likely to recognise the importance of compliance and good information governance.

Caine explained the value of leadership engagement, stating: “If you can get the buy-in from them, it will always trickle down.”

Managers also play an important role in embedding learning after training has taken place. They are often best placed to reinforce expectations, answer questions and identify areas where additional support may be needed.

Creating meaningful behavioural change requires commitment from every level of the organisation.

Measuring training success differently

Many organisations continue to measure training success through attendance figures, completion rates and assessment scores.

Whilst these metrics provide useful information, they only tell part of the story.

The more important question is whether behaviour has changed. Are staff reporting incidents more quickly? Are fewer emails being sent to the wrong recipients? Are Subject Access Requests being identified earlier? Are teams considering privacy risks at the start of projects rather than after problems occur?

These indicators often provide a much clearer picture of whether training is having a meaningful impact.

As Catarina highlighted throughout the discussion, meaningful success is demonstrated through practical outcomes rather than training records alone.

Creating training that delivers real results

The discussion reinforced a simple but important message. Effective data protection training is not about achieving compliance for compliance’s sake. It is about helping people understand their responsibilities and giving them the confidence to make better decisions when handling personal data.

Caine summarised one of the key principles discussed during the session, stating: “Training can never be one size fits all.”

Organisations that focus on practical learning, ongoing awareness, tailored content and strong leadership support are far more likely to create lasting behavioural change.

For organisations looking to strengthen their approach, our Data Protection Training and Awareness Services, Data Protection Support Service and Outsourced DPO Service can help create effective training programmes that move beyond compliance and support a stronger data protection culture.


Frequently Asked Questions About Data Protection Training

Why is data protection training important?

Data protection training helps employees understand how to handle personal data correctly, recognise risks, identify potential breaches and comply with data protection legislation.

How often should staff receive data protection training?

Most organisations provide annual refresher training, but ongoing awareness activities throughout the year are equally important to reinforce learning and maintain good practices.

What makes data protection training effective?

Effective training is practical, relevant to the audience, interactive and supported by ongoing awareness activities that reinforce key messages.

Should different teams receive different training?

Yes. Different departments face different risks and responsibilities. Tailoring training to specific roles often improves engagement and learning outcomes.

How can organisations measure whether training is working?

Rather than focusing solely on attendance and completion rates, organisations should look for behavioural indicators such as improved incident reporting, reduced errors and stronger awareness of data protection responsibilities.

Can training alone create a strong data protection culture?

No. Training is only one part of the solution. Ongoing awareness, leadership support and regular reinforcement are all essential for creating a strong and sustainable data protection culture.

What Auditors Find And Why

What Auditors Always Find, And Why: Lessons from Real GDPR Audits

Many organisations view GDPR audits as a compliance exercise, a checklist that confirms whether policies, procedures and documentation exist. In reality, effective audits go much further than simply reviewing paperwork.

In a recent episode of the Data Protection Made Easy podcast, Catarina Pereira dos Santos and Catherine Santos explored what GDPR auditors consistently uncover when assessing organisations and why the same issues continue to appear across different sectors.

The discussion covered retention failures, staff awareness, third-party management, personal device usage, governance gaps and the common misconception that having documentation automatically means an organisation is compliant.

Drawing on real audit experiences, the session highlighted how organisations can use audits to identify weaknesses, improve accountability and strengthen their overall approach to data protection.

For organisations looking to assess their compliance position, our Data Protection Support Service, Outsourced DPO Service and Training and Awareness Services can help identify risks and support ongoing compliance.

A GDPR audit is more than a checklist

One of the first points raised during the discussion was that a genuine GDPR audit involves much more than reviewing documentation.

Catherine explained: “It’s not a checklist for sure.”

Whilst policies, procedures and records remain important, an audit should also assess how data protection operates in practice. This includes speaking with employees, understanding data flows and evaluating whether documented processes are actually being followed.

As Catherine highlighted, audits often provide an opportunity to understand how mature data protection is within an organisation and whether staff genuinely understand their responsibilities.

Simply having documentation in place does not automatically demonstrate compliance if employees are unaware of the processes they are expected to follow.

Documentation alone does not equal compliance

A recurring theme throughout the episode was the difference between having documentation and implementing it effectively.

The hosts discussed how organisations frequently present policies, procedures and registers during audits, only for employees to reveal that they have never seen them.

As Catherine explained, one of the most common responses during interviews is: “Do we have such a policy? I didn’t know.”

This creates a significant compliance risk. Policies are only effective if they are understood, communicated and embedded within everyday working practices.

An organisation may have an excellent Information Security Policy, Data Breach Procedure or Retention Schedule, but if staff are unaware of them, compliance becomes difficult to demonstrate in practice.

Why employee engagement matters

The discussion highlighted the importance of speaking with employees during an audit.

Unlike a gap analysis or documentation review, a GDPR audit should assess how data protection is understood and applied throughout the organisation.

Employees often provide valuable insight into how personal information is actually handled, revealing differences between documented processes and day-to-day reality.

These conversations can also act as informal awareness sessions, helping staff better understand their responsibilities and providing an opportunity to ask questions.

The hosts emphasised that compliance is not achieved through policies alone. It depends on people understanding what they need to do and why.

Retention remains one of the biggest audit findings

When discussing the issues they encounter most frequently, both hosts quickly identified retention as a recurring challenge.

Many organisations have retention policies in place, but implementation often tells a different story.

Employees may understand that records should be deleted after a certain period, yet the actual deletion process never takes place.

The discussion included examples of organisations retaining emails for decades, storing outdated information indefinitely and relying on manual deletion processes that are rarely followed consistently.

Without effective retention practices, organisations risk keeping personal information for longer than necessary and increasing their exposure to data protection risks.

Third-party management is frequently overlooked

Another area highlighted during the discussion was third-party management.

Many organisations maintain supplier registers and records of processing activities, but auditors often discover inconsistencies when testing the information.

The hosts shared examples where organisations claimed to have Data Processing Agreements in place for all suppliers, only for further investigation to reveal unsigned templates or agreements that had never actually been implemented.

This demonstrates why auditors must test evidence rather than simply accept documentation at face value.

Third-party relationships often represent significant compliance risks, particularly where personal data is being processed externally or transferred internationally.

The risks of personal device usage

The discussion also explored one of the most common findings in modern workplaces, employees using personal devices for business purposes.

As Catherine explained: “The organisation doesn’t know that some employees use their phones for work.”

This creates a range of challenges. Personal devices may contain customer information, contracts, emails or communications that are completely outside the organisation’s governance framework.

It can also create difficulties when responding to Subject Access Requests, managing retention periods and investigating incidents.

Without appropriate Bring Your Own Device policies and controls, organisations may struggle to understand where personal data is being stored and processed.

WhatsApp, shadow IT and hidden data flows

The hosts also highlighted the increasing use of WhatsApp and other informal communication tools.

Whilst these platforms may improve efficiency, they can also introduce governance challenges when organisations fail to formally recognise or manage their use.

Examples discussed included contractors using WhatsApp to share photographs, employees communicating with customers through personal devices and business information being exchanged through channels that are not covered by existing policies.

These hidden data flows can create significant compliance risks if organisations are unaware of how information is being processed.

Effective governance requires organisations to understand where personal information is being stored, shared and accessed, regardless of whether that activity takes place through official systems or informal channels.

Why people shouldn’t fear audits

One of the most interesting parts of the discussion focused on the perception of audits themselves.

Many employees view auditors as investigators looking for mistakes or individuals responsible for assigning blame.

The hosts acknowledged that the word “audit” often creates anxiety, particularly where organisations have recently experienced a breach or compliance issue.

However, they stressed that audits should be viewed as opportunities for improvement rather than exercises in criticism.

As Catarina explained when speaking to employees during audits: “I am not here to judge you.”

The purpose of an audit is to identify risks, highlight opportunities for improvement and help organisations strengthen their compliance position.

When approached positively, audits can provide valuable insight into how organisations handle personal information and where additional support may be needed.

Turning findings into action

Finding issues during an audit is only the beginning of the process.

The real value comes from understanding those findings, prioritising actions and implementing meaningful improvements.

The discussion highlighted the importance of clear reporting, practical recommendations and helping organisations understand where risks are most significant.

Not every finding represents a high-risk compliance issue. Some can be addressed quickly, whilst others may require longer-term planning and investment.

Effective audit reports should help organisations understand not only what needs to improve, but also where they should focus their efforts first.

Why audits are essential for accountability

Whilst UK GDPR does not explicitly require organisations to conduct annual audits, the discussion highlighted how audits support one of the most important principles within the legislation, accountability.

Organisations must be able to demonstrate compliance. To do this effectively, they need mechanisms that test controls, assess risks and evaluate whether policies are operating as intended.

Audits provide an opportunity to challenge assumptions, verify compliance claims and identify gaps before they become larger issues.

Ultimately, the discussion reinforced that audits should not be seen as a negative exercise. They are an opportunity to learn, improve and build a stronger data protection culture.


Frequently Asked Questions About GDPR Audits

What is a GDPR audit?

A GDPR audit is a structured assessment of an organisation’s data protection practices, policies, procedures and operational controls to determine how effectively personal information is being managed.

Are GDPR audits legally required?

UK GDPR does not explicitly require annual audits, but audits are often used to support accountability obligations and demonstrate compliance.

What do GDPR auditors look for?

Auditors typically assess governance arrangements, policies, training, records management, retention practices, security measures, third-party management and employee awareness.

Why is retention often a common audit finding?

Many organisations have retention policies in place, but fail to consistently apply them in practice, leading to unnecessary retention of personal information.

Can an organisation be compliant if it has policies but employees do not follow them?

No. Compliance depends on policies being implemented effectively and understood by employees, not simply existing as documents.

What is the benefit of a GDPR audit?

A GDPR audit helps organisations identify weaknesses, strengthen controls, improve accountability and reduce the likelihood of compliance failures or data breaches.

GDPR Toolkit

Why Your Business Needs a GDPR Toolkit

Navigating the complexities of the GDPR can feel overwhelming. For businesses of all sizes, ensuring you meet the UK General Data Protection Regulation’s (UK GDPR) requirements is crucial. But where do you begin?

The Challenge: Untangling the GDPR Web

The UK GDPR outlines a set of regulations designed to protect the personal data of UK citizens. Failure to comply can result in hefty fines and reputational damage. Understanding and implementing these regulations requires time, expertise, and a clear understanding of your specific data processing activities.

The Solution: A One-Stop Shop for GDPR Compliance

This is where a GDPR Toolkit from Data Protection People steps in. We’ve designed this comprehensive resource to be your one-stop shop for achieving and maintaining GDPR compliance.

Benefits for Your Business: Confidence and Peace of Mind

  • Streamlined Compliance: Our meticulously crafted framework provides all the essential tools you need, from customisable templates to pre-drafted data breach notifications. This saves you valuable time and resources, allowing you to focus on your core business activities.

  • Empowered Staff: Our toolkit includes staff awareness training, ensuring your team understands their role in data protection. A well-informed workforce minimises the risk of human error and safeguards your data.

  • Reduced Risk: By implementing the best practices outlined in the toolkit, you significantly reduce the risk of data breaches and non-compliance fines. This translates to peace of mind and protection for your business reputation.

Why Choose Data Protection People and our GDPR Toolkit?

Data Protection People is a leading UK Data Protection Consultancy with a proven track record of success. Our team of experienced consultants works with clients across the UK and internationally.

Data Protection Made Easy: Our Guiding Principle

We understand the complexities of data protection. That’s why our motto is “data protection made easy.” Our toolkit simplifies these intricate regulations, making them accessible for businesses of all sizes.

Here’s what sets us apart:

  • Expert-Led Development: Developed by industry experts, our toolkit reflects the latest GDPR guidance and best practices.

  • Customisable Templates: We provide a comprehensive library of customisable templates, adaptable to your specific data processing activities.

  • Ongoing Support: We offer ongoing support to ensure you get the most out of your toolkit and stay up-to-date with evolving regulations.

Investing in Your Future

GDPR Toolkit is an investment in the future of your business. By prioritising data protection compliance, you demonstrate your commitment to customer trust and build stronger client relationships.

Taking the Next Step

Ready to simplify GDPR compliance and gain peace of mind? Contact Data Protection People today to learn more about our GDPR Toolkit. Let us guide you through the maze of data privacy regulations and empower your business to thrive.

Is Your Breach Response a Black Hole?

Is Your Breach Response a Black Hole? UK DPOs Face Shocking Delays (and Fines)

With UK GDPR regulations placing data protection at the forefront, organisations are facing a new reality: data breaches can be not just a security risk, but a significant financial one and the consequences for organisations can be severe. But a new study reveals a disturbing trend: UK organisations are taking significantly longer to contain data breaches compared to the global average. This delay can be disastrous, leading to compromised data, hefty fines under UK GDPR, and irreparable damage to customer trust. Don’t let your breach response become a black hole! This blog explores the issue and offers solutions.

The Alarming Statistics

A recent study by  IBM’s 2022 data security report, found that the average UK organisation takes a staggering 277 days  -roughly 9 months – for businesses to identify and report a data breach. Stolen or compromised credentials were the most common cause of a data breach in 2022, and these types of attacks took around 327 days to identify. It costs roughly $4.35 million to recover from a data breach and attacks on the healthcare industry were the highest.”  This means critical time is wasted while sensitive data remains exposed, increasing the risk of exploitation by malicious actors.

The Ripple Effect of Delay

The longer a data breach goes undetected and uncontained, the more severe the consequences. Here’s what’s at stake:

  • Increased Risk of Exploitation: Every minute a breach goes unnoticed is an opportunity for hackers to steal sensitive data, like financial information or personal details. This can lead to identity theft, fraud, and reputational damage for your organisation.
  • Hefty Fines under UK GDPR: The UK GDPR enforces strict regulations on data protection. Organisations that fail to report breaches within 72 hours, face fines up to £17.5M or 4% of annual global turnover. This whichever one is greater.
  • Shattered Customer Trust: When a data breach occurs, customers lose faith in an organisation’s ability to protect their personal information. This can lead to a decline in sales, customer churn, and difficulty attracting new business.

Why Are UK Organisations Lagging Behind?

DPOs are often responsible for a wide range of data protection tasks beyond breach response. This can leave them stretched thin and unable to dedicate the necessary time and attention to developing a robust breach response plan or conducting regular security audits.

Taking Control: How to Streamline Your Breach Response

Don’t let a data breach become an existential threat for your organisation. Here are some steps you can take to ensure a swift and compliant resolution:

  • Develop a Comprehensive Breach Response Plan: A well-defined plan outlines the steps to be taken in the event of a breach, including identification, containment, eradication, and notification. It should also include clear roles and responsibilities for all personnel involved.
  • Invest in Security Awareness Training: Empower your employees to be the first line of defence against data breaches. Regular training on data security best practices, phishing scams, and password hygiene can significantly reduce the risk of human error leading to a breach.
  • Regular Penetration Testing and Vulnerability Assessments: Proactive identification of vulnerabilities in your IT systems helps you patch them before they can be exploited by attackers.
  • Partner with a GDPR Breach Response Specialist: Companies like Data Protection People offer a range of services to help organisations prepare for and respond to data breaches. We can assist with developing breach response plans, conducting training, and providing guidance on regulatory compliance with the UK GDPR.

Don’t Wait for Disaster to Strike

Data breaches are an unfortunate reality of the current technological landscape, but the impact can be minimised with proper preparation. By taking the steps outlined above, you can ensure your organisation has a robust breach response plan in place. This helps mitigate the risks and navigate a data breach efficiently.

Contact Data Protection People today. Learn how we can help you make your breach response bulletproof. Check out our “GDPR Breach Guide” to get started on building a comprehensive plan.

Remember: A swift and effective response to a data breach can save your organisation from significant financial and reputational damage. Don’t wait until it’s too late.

World Password Day: A Guide to Bulletproof Passwords

World Password Day: A Guide to Bulletproof Passwords

Strong password practices are essential for ensuring the security of our online identities and data. Weak passwords leave sensitive information vulnerable to data breaches and cyberattacks.  This guide equips you with the knowledge and tools to transform from a password punching bag into a champion of online security. We’ll delve into the importance of length, the dangers of password reuse, and explore powerful strategies like password managers and multi-factor authentication.

1. Prioritise Length:

While complexity plays a role, prioritising length is crucial. Imagine a combination lock – the more digits, the harder to crack. Aim for at least 16 characters for each password. This significantly increases the time and effort required for brute-force attacks, where hackers systematically try every possible combination.

2. Embrace Uniqueness:

Resist the urge to reuse passwords across different accounts. A data breach on a single platform can expose your login credentials. If you’ve reused those credentials for other accounts (like your bank or social media), those accounts become vulnerable too. Hackers can easily test your stolen login information on other platforms, potentially gaining access to a wealth of your personal information.

3. Leverage Complexity:

Length is essential, but don’t underestimate the power of complexity. Incorporate a combination of uppercase and lowercase letters, numbers, and symbols. This creates a stronger barrier against hacking attempts, making your password significantly more difficult to guess.

4. Utilise Password Managers:

Remembering numerous unique passwords can be a challenge. Consider using a password manager. These secure applications store and encrypt your login credentials, eliminating the need to remember them all while keeping them safe and readily accessible.

5. Double Down with Multi-Factor Authentication:

Many platforms offer multi-factor authentication (MFA) as an extra security layer. This requires an additional verification step beyond just your password, such as a code sent to your phone or a fingerprint/Face ID scan. Consider MFA as a secondary security checkpoint, adding another hurdle for potential intruders.

Employee Checklist: Mastering Password Management

Now that you’re armed with this knowledge, here’s a quick checklist to ensure your passwords are top-notch:

  • Conduct a Password Audit: Review your current passwords. Are they strong and unique?
  • Enhance Password Strength: Consider using a password generator to create complex, lengthy passwords for each account.
  • Secure Password Storage: If not using a password manager already, explore secure options to store your credentials.
  • Enable MFA: Wherever available, activate multi-factor authentication for an extra layer of protection.
  • Maintain Vigilance: Be wary of phishing attempts. Never share your password information in response to unsolicited emails or calls.

By following these simple steps, you can significantly improve your online security posture and safeguard both your personal and company data. Remember, strong passwords are the first line of defence in the fight against cybercrime. Let’s work together to build a robust security framework around our digital assets!

Need Additional Support?

For further guidance on password management best practices or a comprehensive data security strategy, our experienced Data Protection Officers (DPO) are here to assist. Contact our DPO services department to discuss your specific needs.

Exploring Individual Rights

Exploring Individual Rights

The ever-evolving field of data protection law can be a minefield for businesses of all sizes. Balancing the rights of individuals with the operational needs of your organisation is a constant challenge, especially when it comes to fulfilling individual rights requests. During this week’s episode of the Data Protection Made Easy podcast we will be Exploring Individual Rights.

This upcoming podcast, designed specifically for Data Protection Officers (DPOs) and Data Champions, delves into the complexities surrounding individual rights in UK data protection law. We’ll explore real-world scenarios, practical solutions, and best practices to help you navigate these requirements efficiently and effectively.

Balancing Act: Respecting Individual Rights While Meeting Business Needs

The General Data Protection Regulation (GDPR) grants individuals a powerful set of rights regarding their personal data. These rights include access, rectification (correcting inaccuracies), restriction of processing, and even erasure (the “Right to be Forgotten”). While upholding these rights is essential for building trust and fostering responsible data practices, fulfilling them can sometimes create friction with day-to-day business operations.

Our upcoming podcast dives head-first into the challenges faced by organisations when responding to individual rights requests. Here are some of the key hurdles we’ll discuss, along with potential solutions for DPOs and Data Champions:

Resource Constraints: Verifying requests, gathering information from disparate systems, and responding within the legal timeframe can be incredibly time-consuming and resource-intensive, especially for smaller businesses. This can lead to backlogs and delays in fulfilling requests.

  • Solutions: Prioritise requests based on urgency and potential impact. Streamline verification processes to expedite confirmation of data subject identities. Utilise data mapping exercises to understand where personal data resides within the organisation, allowing for faster retrieval.

Data Location and Accessibility: Personal data can be scattered across various databases, cloud storage solutions, and even physical records. This fragmented data landscape makes it difficult to locate and retrieve specific information quickly when responding to individual rights requests.

  • Solutions: Implement a comprehensive data mapping exercise to create a clear picture of where personal data is stored and how it flows throughout the organisation. Invest in data management tools that can centralise data storage and simplify search functionalities.

Third-Party Involvement: Fulfilling an individual’s right to access, rectify, or erase data might require coordination with third-party vendors who also hold the data subject’s information. This adds another layer of complexity to the process, requiring communication and potential data sharing with external entities.

  • Solutions: Establish clear contractual agreements with third-party vendors outlining data protection responsibilities. These agreements should address data subject rights and how requests will be handled collaboratively. Consider implementing data sharing agreements that facilitate secure and efficient data transfers when necessary.

Streamlining the Response of individual rights: Practical Solutions for DPOs and Data Champions

The good news is, there are concrete steps you can take to streamline the process of handling individual rights requests, minimise disruption, and ensure compliance with data protection regulations. Our upcoming podcast will delve into these practical solutions, empowering DPOs and Data Champions to navigate these requests efficiently:

1. Standardised Procedures: The Power of Consistency

Developing clear and well-documented internal processes for handling individual rights requests is a game-changer. These standardised procedures act as a roadmap, ensuring consistency across your organisation and saving valuable time. Here’s how:

  • Reduced Training Time: Clearly defined procedures make training new staff members on handling individual rights requests more efficient. Consistency ensures everyone is on the same page, minimising errors and delays.
  • Improved Efficiency: Standardised processes establish a clear workflow for handling requests, streamlining each step from verification to fulfillment. This reduces the risk of tasks being overlooked or duplicated.
  • Enhanced Accuracy: Well-documented procedures help staff handle requests accurately and consistently, reducing the likelihood of errors that could lead to legal repercussions or reputational damage.

2. Technology Solutions: Leverage Automation for Efficiency

Data management tools can be your secret weapon in streamlining individual rights requests. These tools automate various tasks, freeing up valuable staff resources to focus on higher-level activities. Here are some functionalities to explore:

  • Data Search and Retrieval: Leverage data discovery features to locate relevant personal data quickly and efficiently, even if it’s spread across multiple systems.
  • Data Redaction: Utilise automated redaction tools to anonymise sensitive information before providing data to the data subject, ensuring compliance with data minimisation principles.
  • Reporting and Audit Trails: Implement data management tools that generate reports and maintain audit trails, simplifying record-keeping and demonstrating compliance with data subject rights.

3. Communication is Key: Building Trust Through Transparency

Clear and consistent communication with the data subject throughout the process is crucial. Here’s how effective communication fosters trust and reduces frustration:

  • Setting Realistic Timelines: Be upfront about the timeframe for responding to requests. This helps manage the data subject’s expectations and avoids unnecessary inquiries.
  • Regular Updates: Keep the data subject informed throughout the process. Provide regular updates on the status of their request, even if it’s just to acknowledge receipt and confirm it’s being addressed.
  • Clear and Concise Language: Use plain language that is easy for the data subject to understand. Avoid technical jargon and legal terminology whenever possible.

The Right to Erasure: When “Forgotten” Isn’t So Simple

The “Right to Erasure,” also known as the “Right to be Forgotten,” empowers individuals to request the deletion of their personal data under certain circumstances. While this sounds straightforward, fulfilling erasure requests can be surprisingly complex. Our upcoming podcast dives into scenarios where achieving complete erasure might be difficult, and explores alternative solutions for DPOs and Data Champions to navigate these situations while complying with data protection law.

Here’s why achieving complete erasure can be challenging:

  • Legal and Regulatory Retention Requirements: Businesses may have legal or regulatory obligations to retain certain types of personal data for a specific period. For example, financial institutions might need to keep transaction records for tax or anti-money laundering purposes. In such cases, complete erasure is not possible.

  • Backups and Archived Data: Data backups and archives create a grey area for the Right to Erasure. While actively used data can be erased, backups and archived data pose challenges. Striking a balance between fulfilling erasure requests and adhering to data retention policies is crucial.

Alternative Solutions for DPOs and Data Champions:

  • Data Anonymisation: In situations where complete erasure isn’t possible, anonymisation can be a viable alternative. This involves removing any personally identifiable information (PII) from the data, rendering it impossible to link it back to the individual. Anonymised data can still be used for statistical or research purposes, while protecting the individual’s privacy.

  • Clear Communication and Justifications: When complete erasure is not possible due to legal or technical reasons, clear communication with the data subject is essential. DPOs should provide a clear and concise explanation for why their request cannot be fully met. Transparency fosters trust and helps manage expectations.

The Importance of Data Retention Policies:

Having clear and up-to-date data retention policies in place is crucial for navigating the Right to Erasure. These policies should outline:

  • The specific types of personal data collected by the organisation.
  • The legal and regulatory requirements for data retention.
  • The criteria for determining when personal data can be erased.

Subject Access Requests (SARs): Mastering the Maze of Personal Data

Subject Access Requests (SARs) empower individuals to access the personal data a business holds on them. This right to transparency is crucial for building trust, but fulfilling SARs can be a time-consuming and resource-intensive process for organisations. Our upcoming podcast equips DPOs and Data Champions with best practices to navigate SARs efficiently:

1. Streamlined Verification: Preventing Unauthorised Access

Verifying the identity of the data subject is the first crucial step in handling a SAR. Streamlining this process ensures you’re providing information to the rightful individual and prevents unauthorised access to sensitive data. Here’s how:

  • Multi-Factor Authentication: Implement robust verification methods other than just passwords. Utilise multi-factor authentication (MFA) to add an extra layer of security, requiring additional verification factors like codes sent to a phone or email.
  • Clear Instructions: Provide clear and concise instructions on how individuals can submit verification documents within your SAR response process. This reduces delays and ensures you receive the necessary information to verify identities promptly.

2. Clarity is Key: Providing Data in an Understandable Format

The information provided in response to an SAR should be clear, concise, and easy for the data subject to understand, even if they lack a technical background. Here’s how to ensure clarity:

  • Plain Language: Avoid technical jargon and legal terminology whenever possible. Use clear and concise language that the average person can understand.
  • Structured Format: Present the information in a well-structured and organised format. Consider using tables, headings, and bullet points to improve readability.
  • Defining Terminology: If including technical terms is unavoidable, provide clear definitions within the SAR response document itself.

3. Data Mapping: The Secret Weapon for Efficiency

Having a clear understanding of where personal data is stored and how it’s used within your organisation is a game-changer for handling SARs efficiently. Data mapping involves creating a comprehensive inventory of your data landscape. Here’s how it benefits DPOs and Data Champions:

  • Faster Retrieval: Knowing where specific data resides eliminates the need to search through multiple systems, significantly reducing the time it takes to locate and retrieve relevant information for SAR responses.
  • Reduced Errors: A clear data map minimises the risk of overlooking data sources, ensuring a more thorough and accurate response to the SAR.
  • Improved Compliance: Data mapping supports overall data governance efforts, making it easier to demonstrate compliance with data protection regulations during audits or investigations.

Building a Culture of Data Protection: Proactive Strategies for DPOs and Data Champions

While effectively handling individual rights requests is crucial, our upcoming podcast delves deeper, emphasising the importance of proactive data protection. By fostering a culture of data privacy within your organisation, you can minimise risks, streamline processes, and build trust with customers and regulators. Here, we’ll explore key strategies DPOs and Data Champions can implement:

1. Empowering Staff Through Education

Staff training programs are the cornerstone of a strong data protection culture. Educating employees on data protection principles, individual rights, and internal procedures equips them to handle personal data responsibly:

  • Data Protection Fundamentals: Train staff on core data protection principles like data minimisation, purpose limitation, and lawful processing. This empowers them to make informed decisions about data collection and handling.
  • Individual Rights Awareness: Ensure staff understand the individual rights enshrined in data protection regulations, such as the right to access and the right to erasure. This knowledge allows them to effectively respond to inquiries and requests.
  • Internal Policy Training: Train staff on your organisation’s internal data handling policies and procedures. This fosters consistency and ensures everyone is on the same page regarding data protection practices.

2. Proactive Risk Management with Privacy Impact Assessments (PIAs)

Privacy Impact Assessments (PIAs) are a proactive approach to data protection. By conducting PIAs for new projects and initiatives that involve personal data, you can identify and mitigate potential risks before they arise:

  • Early Risk Identification: PIAs help identify potential privacy risks associated with collecting, using, or storing personal data. This allows for early intervention and implementation of appropriate safeguards.
  • Data Protection by Design: PIAs encourage integrating data protection considerations into the design phase of new projects. This ensures data privacy is prioritised from the outset.
  • Enhanced Compliance: Regular PIAs demonstrate your organisation’s commitment to data protection and can be valuable evidence during audits or investigations.

3. Clear and Accessible Internal Policies

Having clear, up-to-date, and easily accessible internal policies on data handling and individual rights empowers staff to make informed decisions in their daily work:

  • Comprehensive Policies: Develop internal policies that cover the entire data lifecycle, from collection to storage, use, and erasure.
  • Accessibility is Key: Ensure policies are readily available to all staff in a user-friendly format, such as on a central company intranet or knowledge base.
  • Regular Reviews and Updates: Regularly review and update internal policies to reflect any changes in data protection regulations or your organisation’s practices.

Can AI be Racist?

Technology continues to reshape our world, offering solutions that streamline daily tasks and enhance security. However, with every innovation comes a responsibility to acknowledge its potential downsides. This blog post dives into the question can AI be Racist? and focuses two key areas where the ethical use of technology is paramount: facial recognition and data privacy.

The Shadowy Side of Facial Recognition: Can AI Be Biased?

Facial recognition (FR) technology promises a world of convenience, from unlocking smartphones to streamlining security checks at airports. But concerns linger about its inherent bias. Here’s why:

  • Biased Data, Biased Results: Facial recognition (FR) thrives on vast amounts of data to identify faces. However, the real challenge is if this data primarily reflects a certain race or ethnicity, the system struggles with faces outside that group. This can lead to misidentification and unfair targeting of minorities.

  • Perpetuating Racial Profiling: FR’s integration with law enforcement raises concerns about racial profiling. Historically marginalised communities already face disproportionate scrutiny. FR can exacerbate this by amplifying biases already present within the justice system.

  • Privacy Concerns: The widespread use of FR raises serious privacy issues. Facial data is highly personal, and its collection and use without proper safeguards can lead to mass surveillance and a chilling effect on free movement.  Imagine a world where facial recognition cameras track you everywhere you go. This raises serious concerns about the erosion of personal liberty. Would you feel safe or constantly under surveillance?

Can AI itself be racist? AI is a tool, and like any tool, it reflects the biases of its creators and the data it’s trained on. To mitigate these risks, we need:

Diverse Datasets: Training data for FR algorithms should be inclusive, reflecting the variety of human faces across races, ethnicities, genders, and age groups. This ensures the system can accurately identify everyone, regardless of background.

Transparency and Oversight: Clear guidelines and regulations are needed to govern the development and use of FR technology. Independent oversight bodies can ensure responsible implementation and prevent misuse.

Public Dialogue: Open discussions are crucial to ensure that FR serves society fairly and ethically. Let’s Start a Conversation About Facial Recognition. We need to openly discuss the potential benefits and drawbacks of this technology. By having these conversations, we can ensure that FR is used in a way that respects human rights and protects individual privacy.

Balancing Data Privacy with Employee Well-being in a Mental Health Crisis

The workplace has a responsibility to support employee well-being. However, we must balance data privacy with employee well-being. Here’s how organisations can create a supportive environment while respecting individual privacy:

  • Empower Employees Through Data Transparency: Your employees deserve to know exactly what data is collected during work hours. Build trust by clearly communicating the information you gather, how it’s used, and who has access to it. This transparency empowers employees to make informed decisions about their data privacy.
  • Support Employees in Crisis, Not Punish Them: During a mental health crisis, data collection should solely focus on providing immediate support to the employee. Punitive measures have no place in this situation. Your primary goal should be to connect the employee with resources and ensure their well-being. The primary goal is to connect the employee with resources and ensure their well-being.
  • Opt-in Systems: Consider systems where employees can choose to share data relevant to their mental health needs with a designated support team. This empowers employees to seek help while maintaining control over their data.
  • Data Security: To safeguard this sensitive information, ensure robust data security measures are in place. This includes encryption, access controls, and regular audits to prevent unauthorised access or data breaches.

Decoding the Legalese: Lawful Basis for Data Sharing Made Easy

Data sharing is essential for businesses to operate effectively. However, navigating the legalities, particularly around the General Data Protection Regulation (GDPR), can be complex. Here’s a simplified breakdown of the lawful basis for data sharing under GDPR:

You Must Get Explicit Consent: Individuals have the right to control their data. Before sharing any personal information, you need to obtain their clear and specific consent. This means asking for their permission in a way that’s easy to understand and allows them to freely choose.

Sharing to Fulfill a Contract: When you enter into a contract with us, we may need to share your data to fulfill that contract. For example, if you order something online, we might share your address with a delivery company to get it to you. For example, you can share customer information with a delivery service to complete an order they placed.

Sharing When Required by Law: Sometimes, the law requires you to share data. This could involve reporting financial transactions to tax authorities.

Sharing for Legitimate Reasons (with Limits): You can share data for your own legitimate interests, but only if those interests don’t outweigh individual privacy rights. An example could be sharing anonymised data for market research purposes.

Conclusion

Technology offers immense potential to improve our lives. However, its ethical implementation is crucial. By addressing bias in facial recognition, respecting data privacy in the workplace, and understanding the lawful basis for data sharing, we can ensure technology serves humanity for the better.

Concerned about navigating the complexities of data privacy? Our data protection support services can help. We offer a comprehensive suite of solutions to ensure your organisation is compliant and ethical in its data practices. Contact us today to learn more!