Eve Hobson

Eve Hobson

Multi-Media Content Executive

Eve Hobson is a Multimedia Content Executive at Data Protection People, having joined the business in 2021. She is responsible for managing the organisation's social media channels and creating engaging content, working closely with Marketing Manager Myles Dacres to support brand awareness, campaigns, and audience engagement.

Get to Know Eve

Eve joined Data Protection People in 2021 after completing her A Levels in Law, Sociology and English Language. She began her career with the business as a Support Desk Officer before moving into a Business Administration role. During this time, she became increasingly involved in marketing activities, sparking a passion for content creation and digital marketing.

Today, Eve works as a Multimedia Content Executive, managing all of Data Protection People's social media channels. She creates engaging content that supports the company's brand presence and audience engagement. She works closely with Marketing Manager Myles Dacres on a range of projects, including website SEO, campaign management, event promotion, podcast marketing, and wider digital marketing initiatives.
With several years of experience across customer service, administration, and marketing, Eve brings a well-rounded perspective to her role and enjoys finding creative ways to communicate complex topics clearly and effectively.

Outside of work, Eve enjoys exploring the countryside, wild camping with her partner and friends, spending time with family, and expressing her creativity through drawing and painting.

Experience

Eve has built a diverse range of experience across customer service, administration, and marketing throughout her career. Before joining Data Protection People, she completed her A Levels in Sociology, Law, and English Language while balancing three part-time jobs alongside her studies. These roles included working in retail, hospitality, and the NHS, helping her develop a strong work ethic, excellent communication skills, and the ability to adapt to different working environments.

Her retail experience provided valuable insight into customer service, sales, and understanding customer needs. Working within hospitality at a Working Men's Club, helped her build confidence when interacting with a wide range of people, manage busy periods effectively, and develop strong organisational skills. Alongside this, her role as a Domestic Assistant within the NHS taught her the importance of professionalism, attention to detail, teamwork, and maintaining high standards within a regulated environment.

Since joining Data Protection People in 2021, Eve has gained experience across several areas of the business. Beginning as a Support Desk Officer before moving into Business Administration and eventually Marketing, she has developed a broad understanding of how different departments work together to support business growth and client satisfaction.

In 2026, Eve successfully completed her Multi-Channel Marketer qualification, further strengthening her knowledge of modern marketing practices. Through her apprenticeship, she gained practical experience in areas including social media management, content creation, campaign planning, website management, SEO, analytics, audience engagement, and digital marketing strategy. She has also developed skills in using a variety of marketing platforms and tools to measure performance and optimise campaigns.

Today, Eve applies this knowledge to support Data Protection People's marketing activities, helping to create engaging content, grow the organisation's online presence, and communicate complex data protection topics in a way that is accessible and easy to understand.

Eve Hobson

"Something I've come to appreciate throughout my marketing career is the value of brand awareness. It's not always about immediate results, it's about creating trust, recognition, and a positive reputation that people remember when they need your services."

Eve Hobson
Multi-Media Content Executive

Eve's Posts

Claude Shared Chats Appeared in Google Search: What Organisations Need to Know

Claude Shared Chats Appeared in Google Search: What Organisations Need to Know

Reports published on 27 July 2026 say that some publicly shared Claude conversations appeared in Google Search results.

This does not mean every private Claude conversation was exposed. Anthropic states that Claude chats are private by default. The risk relates to conversations that users deliberately chose to share by creating a public link.

Although this was not a security breach affecting all users, it is an important reminder that organisations need to consider how information is shared from AI tools, not just what employees enter into them.

What Happened to the Claude Conversations?

Claude allows users to create a shareable snapshot of a conversation.

When a user selects Share, Claude generates a public link that can be viewed by anyone who has access to it. Recent reports found that some of these publicly shared conversations had also appeared in Google Search results.

This increased the potential audience for those conversations. A link originally intended for a small number of people could become discoverable by individuals who had never received it directly.

Public links can spread beyond their intended audience. They may be shared on websites, forums or social media, making them accessible to search engines.

Further information is available from:

Were Private Claude Chats Leaked?

There is no evidence that all private Claude conversations became public.

According to Anthropic, conversations remain private unless a user deliberately creates a public share link. Once a conversation is shared publicly, anyone with the link can view it.

The concern raised by this story is that some public links became discoverable through search, rather than remaining accessible only to people who had been sent the link.

It is important to distinguish between:

  • A private conversation stored in a Claude account
  • A conversation that a user has deliberately turned into a public snapshot using a public link
  • A publicly shared conversation that later becomes discoverable through a search engine

This distinction matters. Organisations should respond to the real risk without suggesting that every Claude user has experienced a personal data breach.

What Information Is Shared?

According to Anthropic, a shared snapshot includes all messages exchanged before the conversation was shared. It may also include content created during the conversation.

Messages added after the snapshot is created remain private unless the conversation is shared again.

Anthropic also states that:

  • Attached files are not included in the shared snapshot
  • The conversation and Claude’s responses remain visible
  • Raw information retrieved through connected tools remains hidden
  • Users on Team and Enterprise plans can only share chats with members of the same organisation

However, even if an attached file is not shared, personal data or confidential information taken from that file may still appear within the conversation or in Claude’s responses.

Why Does This Matter for Organisations?

Many employees now use AI tools to help with everyday work, such as drafting documents, summarising information and preparing reports.

Those conversations may contain:

  • Personal data about customers or employees
  • Confidential business information
  • Internal plans or meeting notes
  • Client information
  • Security details
  • Unpublished financial or commercial information

Someone may understand that a colleague can open a shared link without appreciating that the link could later become accessible to a much wider audience.

This creates potential risks, including unauthorised disclosure, loss of confidentiality and possible exposure of personal data.

Not every shared conversation will amount to a personal data breach. Whether it does depends on the information involved, who could access it and the likely impact on the individuals concerned.

Even where no personal data is involved, the disclosure of confidential business information or commercially sensitive material may still create contractual, regulatory or commercial risks.

What Should Claude Users Do Now?

Anthropic provides a way for users to review their shared conversations.

  1. Open Claude and go to Settings.
  2. Select Privacy.
  3. Find Shared chats and select Manage.
  4. Review every conversation that has been shared.
  5. Remove any public links that are no longer needed.
  6. Check whether any shared conversation contains personal, confidential or security-related information.

Claude users can also access their shared conversations through the official Claude shared-chats page. Users may need to sign in before they can view or manage their shared conversations.

Removing a shared link prevents further access using that link. However, organisations should not assume that references to the page will disappear immediately from search engines or other websites.

If sensitive information has been exposed, the organisation should record the incident and begin its internal incident response process.

What Should an Organisation Do if Personal Data Was Shared?

If a shared Claude conversation contains personal data, the organisation should establish what happened as quickly as possible.

The immediate steps should include:

  • Disable the public share link
  • Preserve the information needed to investigate the incident
  • Identify the personal data involved
  • Establish who may have accessed the conversation
  • Assess the possible impact on the people concerned
  • Record the incident and the decisions made

The ICO states that organisations should assess the likelihood and severity of any risk to individuals’ rights and freedoms.

If a personal data breach is likely to result in a risk to people, it must be reported to the ICO without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.

Where the breach is likely to result in a high risk to individuals, the organisation may also need to inform those affected.

Not every incident needs to be reported. The decision should follow a documented risk assessment based on the circumstances of each case.

Use the ICO’s personal data breach assessment guidance.

What Should AI Policies Cover?

Many organisations focus on what employees are allowed to enter into an AI tool. That is only part of the picture.

An effective policy should also explain:

  • Whether employees are permitted to create public share links
  • What information must never be included in a shared conversation
  • Who can authorise external sharing
  • How shared links should be reviewed and removed
  • How long shared conversations should remain available
  • How employees should report accidental disclosure
  • Which AI tools and account types have been approved for business use

Organisations should also review sharing settings during AI procurement and risk assessments.

Any feature that allows information to be shared publicly or with anyone holding a link should be treated as an external disclosure unless suitable access controls are in place.

What Training Should Staff Receive?

Staff do not need a technical explanation of how search engines work. They do need to understand how AI platforms should be used, what information can be shared and the risks associated with public sharing.

Training should explain that:

  • AI conversations should not contain unnecessary personal data or confidential information
  • There is an important difference between saving a conversation privately and creating a public share link
  • Public links can be shared beyond the original recipient
  • Shared content may become searchable online
  • Removing the original link does not always remove every copy or reference
  • Suspected disclosures should be reported immediately

Using practical examples is likely to be more effective than simply telling employees to use AI responsibly.

Key Takeaways

The Claude shared-chat story is not evidence that every private AI conversation became public. It does show that a public sharing feature can create wider exposure than a user expects.

Organisations should review whether public AI conversations have been shared, update their internal policies where necessary and ensure employees understand the consequences of using sharing features.

Good information governance should cover the entire lifecycle of information. This includes what is entered into a tool, what the tool produces, who can access it, how it is shared and when it should be removed.

Sources

Need Support With AI and Data Protection?

If your organisation needs help reviewing AI use, internal policies or a potential personal data incident, speak to the Data Protection Made Easy team.

Speak to Our Team

AI and data regulation: what organisations need to know

AI and data regulation: what organisations need to know

The UK government has opened a call for evidence on data regulation in the age of AI and other data-intensive technologies.

Published by the Department for Science, Innovation and Technology on 15 July 2026, the call for evidence asks how current data regulation interacts with emerging technologies, where uncertainty remains and whether further guidance or reform may be needed.

For organisations using, testing or considering AI, this is a timely reminder that AI governance and data protection cannot be treated as separate issues.

What has happened?

The call for evidence looks at how personal and non-personal data regulation affects AI and other data-intensive technologies.

It asks for practical examples of how existing rules apply in real settings, including where organisations face uncertainty, friction or barriers to responsible data use.

It also considers how legal, technical and governance arrangements could support data sharing and reuse while managing potential harms.

You can read the call for evidence on GOV.UK here: Data regulation in the age of AI and other data-intensive technologies.

Why does this matter?

AI systems rely on data. In many cases, they rely on large volumes of data from different sources, used in ways that may not have been expected when the data was first collected.

That creates a practical challenge for organisations.

They need to understand not only what the technology can do, but whether the data behind it is being used lawfully, fairly and transparently.

For example, an organisation may need to consider whether the data was collected for a compatible purpose, whether people have been told how their data may be used, whether outputs can be explained and whether bias, accuracy or security risks have been assessed.

This is not simply a compliance exercise. It is about trust, accountability and good decision-making.

What questions should organisations be asking?

Before using AI or data-intensive tools, organisations should be able to answer some basic questions about the data involved.

  • What data is being used?
  • Does it include personal data?
  • Why is the data being used?
  • Is there a lawful basis for using it?
  • Has the purpose changed since the data was collected?
  • Can the organisation explain how decisions or outputs are produced?
  • Who is accountable for the tool and its outcomes?
  • How are bias, accuracy, transparency and security risks being managed?
  • Has a Data Protection Impact Assessment been considered?

A Data Protection Impact Assessment, often called a DPIA, is a process used to identify and reduce data protection risks before processing begins. It is especially important where new technology may affect people’s rights or freedoms.

Good AI governance starts with good data governance

AI governance means the rules, roles and checks an organisation uses to make sure AI is used safely and responsibly.

Data governance means the way an organisation manages data, including who owns it, how it is accessed, how it is used, how it is protected and when it should be deleted.

The two are closely linked.

If an organisation does not understand its data, it will struggle to explain its AI. If it cannot explain its AI, it may struggle to evidence compliance, respond to concerns or build trust with customers, staff, regulators and the public.

This is why data protection should be involved early in AI projects, not added at the end.

Catarina Santos, Consultant Manager at Data Protection People, said:

“Whilst this call for evidence does not introduce any new guidance or changes to the law, it is a positive step. It provides an opportunity to identify where the current framework may not be clear enough and to better understand the challenges organisations face when using AI. Listening to the experiences of businesses, regulators and other stakeholders should help shape future guidance and ensure that any changes strike the right balance between encouraging innovation and protecting individuals’ personal data.”

What should organisations do now?

The call for evidence does not change the law today. However, it is a useful signal of where future debate, guidance and possible reform may focus.

Organisations should use this moment to review how they assess AI tools and data-intensive technologies.

Practical steps include:

  • Mapping what data is used in AI tools.
  • Checking whether personal data is involved.
  • Reviewing lawful basis and transparency information.
  • Considering whether a DPIA is needed.
  • Recording who is accountable for each tool.
  • Reviewing supplier and processor arrangements.
  • Training staff on when AI use creates data protection risk.

Good AI use depends on clear roles, clear records and clear decisions.

FAQ

What is the government call for evidence about?

It is about how data regulation interacts with AI and other data-intensive technologies. The government is asking for practical examples of what works, where uncertainty remains and where further guidance or reform may be needed.

Does this change the law?

No. A call for evidence does not change the law. It is a way for government to gather information before deciding whether further guidance, policy changes or legal reform may be needed.

Why does this matter for organisations using AI?

It matters because AI often depends on large amounts of data. Organisations need to understand what data they are using, why they are using it and how they will manage legal, ethical and security risks.

What is AI governance?

AI governance means the rules, roles and checks an organisation uses to make sure AI is used safely, responsibly and in line with the law.

What is data governance?

Data governance means how an organisation manages data. This includes ownership, access, use, protection, retention and deletion.

When should data protection be considered in an AI project?

Data protection should be considered at the start of an AI project. This helps organisations identify risks early, document decisions and avoid problems later in the project.

Data Protection Made EasyAt Data Protection People, we help organisations understand data protection in practical terms.

If your organisation is reviewing AI tools, updating governance or trying to understand how data protection applies to new technology, we can help make the next steps clearer.

 

The First 72 Hours After a Breach

The First 72 Hours After a Breach, What Organisations Should Do Next

When a personal data breach occurs, the first few hours are often the most important.

The decisions made immediately after an incident can significantly influence the outcome, affecting regulatory obligations, reputational damage, customer trust and the overall response effort.

In a recent episode of the Data Protection Made Easy podcast, Caine Glancy and Catarina Pereira dos Santos discussed the practical actions organisations should take during the first 72 hours following a personal data breach.

The discussion explored breach containment, risk assessments, notifications, lessons learned and the common mistakes organisations make when responding to incidents.

Whilst every breach is different, the session reinforced a simple message. Organisations that respond quickly, assess risk properly and learn from incidents are often far better positioned to reduce harm and prevent future issues.

Containment should always come first

One of the most important points raised during the discussion was the need to contain an incident as quickly as possible.

Before organisations start thinking about reporting obligations, notifications or regulatory engagement, they need to understand what has happened and stop any ongoing unauthorised access, disclosure or loss of personal data.

As Catarina explained: “We need to contain it immediately.”

Containment actions will vary depending on the nature of the breach. This may involve recalling emails, disabling accounts, restricting access to systems, recovering documents or preventing further disclosure.

The key objective is to stop the incident from escalating whilst gathering enough information to understand what has happened.

Understanding the facts before assessing risk

Once the immediate situation has been contained, organisations need to establish the facts.

The discussion highlighted how many organisations rush straight to questions about whether a breach should be reported to the ICO without first understanding what has actually happened.

Before any meaningful risk assessment can take place, organisations need to identify what information was involved, who was affected, how the breach occurred, whether the information has been accessed and what mitigating actions have already been taken.

This information forms the foundation of any subsequent decision-making process.

Without context, it is almost impossible to determine whether a breach presents a risk to individuals or whether reporting obligations apply.

Not every breach is reportable

The session also addressed a common misconception. Not every personal data breach needs to be reported to the ICO.

Many organisations automatically assume that any breach involving personal data must be reported, whilst others incorrectly assume that low-risk incidents are not breaches at all.

In reality, every incident should be assessed on its own merits.

A misdirected email, accidental disclosure or inappropriate access may still constitute a personal data breach even if the risk to individuals is ultimately low.

The discussion reinforced the importance of assessing the specific circumstances rather than relying on assumptions.

As Caine explained, context is critical when evaluating risk and determining the appropriate response.

Why context matters when assessing risk

A recurring theme throughout the discussion was the importance of context.

Organisations often want a straightforward answer to whether a breach is reportable or whether affected individuals should be notified. However, data protection rarely works in absolutes.

Caine highlighted how difficult it can be to assess risk without understanding the full circumstances surrounding an incident.

A simple statement such as “an email was sent to the wrong person” does not provide enough information to determine the level of risk involved. Organisations need to understand the contents of the email, the sensitivity of the information, who received it and whether any mitigating actions have already been taken.

As Caine explained: “The key is always in the likely.”

Risk assessments should focus on what is realistically likely to happen as a result of the breach, rather than becoming overly focused on highly unlikely scenarios.

This is why context remains one of the most important elements of effective breach management.

When should organisations notify the ICO?

One of the most common questions raised following a breach is whether the incident needs to be reported to the Information Commissioner’s Office.

The discussion highlighted that organisations should avoid treating ICO reporting as an automatic response.

Instead, reporting decisions should be based on the outcome of a documented risk assessment and the likelihood of risk to individuals.

Where a breach is likely to result in a risk to the rights and freedoms of individuals, organisations are generally required to notify the ICO within 72 hours of becoming aware of the incident.

However, the hosts also acknowledged that many organisations struggle with this decision-making process, particularly when dealing with complex incidents or limited information.

For smaller organisations without dedicated privacy teams, understanding reporting thresholds can be one of the most challenging aspects of breach management.

Should affected individuals always be informed?

The session also explored another area that frequently causes uncertainty, notifying affected individuals.

Many organisations assume that if a breach has occurred, the individuals involved must automatically be informed. However, this is not always the case.

Whilst transparency remains a fundamental principle of data protection, notifications should have a clear purpose.

As Catarina explained, the purpose of notifying individuals is not simply to tell them that a breach has happened. It is to allow them to take action where there is an active risk to them.

If a breach creates a high risk to an individual’s rights and freedoms, notifying them may allow them to protect themselves from fraud, identity theft, financial loss or other harms.

Where there is no ongoing risk, organisations may decide that notification is unnecessary.

The discussion highlighted the importance of carefully balancing transparency, risk and potential distress when making these decisions.

The risks of over-notification

Whilst organisations are often concerned about under-reporting breaches, the discussion highlighted that over-notification can also create problems.

Informing individuals about every low-risk incident may cause unnecessary concern, particularly where no meaningful action is required on their part.

Some individuals may understandably assume the worst when they hear the phrase “data breach”, regardless of the actual level of risk involved.

In certain circumstances, notifying individuals about low-risk incidents may create confusion, anxiety and additional complaints without providing any practical benefit.

This is why notification decisions should always be proportionate and based on a thorough assessment of the circumstances.

As the discussion demonstrated, there is rarely a one-size-fits-all approach.

Caine reinforced this point by explaining: “Nothing in data protection is a one size fits all kind of thing.”

Every breach is an opportunity to learn

One of the strongest messages from the session was that organisations should view breaches as learning opportunities.

Even low-risk incidents can reveal weaknesses in processes, training, systems or controls.

Rather than simply recording an incident and moving on, organisations should take the time to identify trends and recurring issues.

As Caine explained: “The main thing really is treating it as lessons learned always.”

If multiple incidents occur for similar reasons, such as misdirected emails, access errors or process failures, this may indicate a wider issue that requires attention.

Reviewing breach data collectively often provides valuable insight into where improvements can be made.

The discussion highlighted how organisations can use incidents to strengthen controls, improve staff awareness and reduce the likelihood of future breaches.

Getting value from incidents

Closely linked to the lessons learned approach was the idea of extracting value from incidents wherever possible.

Breaches are rarely desirable, but they can provide useful information about organisational weaknesses and areas for improvement.

As Caine commented: “You’ve got to try and claim some benefit back from it where you can.”

This might involve updating procedures, improving training, introducing additional technical controls or reviewing existing risk assessments.

By treating breaches as opportunities for continuous improvement, organisations can often strengthen their overall data protection framework.

What organisations should do after a breach

Once the immediate response has been completed, the discussion highlighted the importance of reviewing the incident in full.

This should include documenting what happened, assessing the effectiveness of the response, identifying any improvements and updating relevant policies or procedures where necessary.

Organisations should also consider whether additional staff training, awareness campaigns or technical measures may help prevent similar incidents in the future.

The first 72 hours are important, but the actions taken afterwards are often what determine whether an organisation genuinely learns from an incident.

A practical approach to breach management

The session reinforced a practical and proportionate approach to managing personal data breaches.

Contain the incident, establish the facts, assess the risk, determine whether reporting obligations apply and identify opportunities for improvement.

Whilst every breach is different, organisations that follow these principles are often better positioned to respond effectively, reduce harm and strengthen compliance over time.

Most importantly, the discussion highlighted that effective breach management is not just about regulatory compliance. It is about protecting individuals, maintaining trust and continuously improving organisational practices.


Need support managing personal data breaches?

Managing a personal data breach can be challenging, particularly when organisations are under pressure to assess risk, make reporting decisions and communicate effectively with regulators and affected individuals.

Our Data Protection Support Service, Outsourced DPO Service and Training and Awareness Services help organisations build effective breach management processes, improve governance and strengthen compliance.

Whether you’re responding to an incident, reviewing your breach procedures or looking to improve organisational awareness, our team can help you manage data protection with confidence.


Frequently Asked Questions About Personal Data Breaches

What should organisations do immediately after discovering a data breach?

The first priority should be containing the incident to prevent any further unauthorised access, disclosure, loss or destruction of personal data. Once contained, organisations should establish the facts and begin assessing risk.

Does every personal data breach need to be reported to the ICO?

No. Organisations should assess whether the breach is likely to result in a risk to the rights and freedoms of individuals. Not all breaches meet the threshold for ICO notification.

How quickly must a breach be reported to the ICO?

Where a breach is reportable, organisations are generally required to notify the ICO within 72 hours of becoming aware of the incident.

Do organisations always need to notify affected individuals?

No. Individuals generally need to be informed where the breach is likely to result in a high risk to their rights and freedoms. Notification decisions should be based on a documented risk assessment.

Why is a risk assessment important following a breach?

A risk assessment helps organisations understand the potential impact on affected individuals and determine whether reporting or notification obligations apply.

What can organisations learn from data breaches?

Even low-risk incidents can reveal weaknesses in processes, systems, training or controls. Reviewing breaches helps organisations identify trends, strengthen governance and reduce future risk.

What Auditors Find And Why

What Auditors Always Find, And Why: Lessons from Real GDPR Audits

Many organisations view GDPR audits as a compliance exercise, a checklist that confirms whether policies, procedures and documentation exist. In reality, effective audits go much further than simply reviewing paperwork.

In a recent episode of the Data Protection Made Easy podcast, Catarina Pereira dos Santos and Catherine Santos explored what GDPR auditors consistently uncover when assessing organisations and why the same issues continue to appear across different sectors.

The discussion covered retention failures, staff awareness, third-party management, personal device usage, governance gaps and the common misconception that having documentation automatically means an organisation is compliant.

Drawing on real audit experiences, the session highlighted how organisations can use audits to identify weaknesses, improve accountability and strengthen their overall approach to data protection.

For organisations looking to assess their compliance position, our Data Protection Support Service, Outsourced DPO Service and Training and Awareness Services can help identify risks and support ongoing compliance.

A GDPR audit is more than a checklist

One of the first points raised during the discussion was that a genuine GDPR audit involves much more than reviewing documentation.

Catherine explained: “It’s not a checklist for sure.”

Whilst policies, procedures and records remain important, an audit should also assess how data protection operates in practice. This includes speaking with employees, understanding data flows and evaluating whether documented processes are actually being followed.

As Catherine highlighted, audits often provide an opportunity to understand how mature data protection is within an organisation and whether staff genuinely understand their responsibilities.

Simply having documentation in place does not automatically demonstrate compliance if employees are unaware of the processes they are expected to follow.

Documentation alone does not equal compliance

A recurring theme throughout the episode was the difference between having documentation and implementing it effectively.

The hosts discussed how organisations frequently present policies, procedures and registers during audits, only for employees to reveal that they have never seen them.

As Catherine explained, one of the most common responses during interviews is: “Do we have such a policy? I didn’t know.”

This creates a significant compliance risk. Policies are only effective if they are understood, communicated and embedded within everyday working practices.

An organisation may have an excellent Information Security Policy, Data Breach Procedure or Retention Schedule, but if staff are unaware of them, compliance becomes difficult to demonstrate in practice.

Why employee engagement matters

The discussion highlighted the importance of speaking with employees during an audit.

Unlike a gap analysis or documentation review, a GDPR audit should assess how data protection is understood and applied throughout the organisation.

Employees often provide valuable insight into how personal information is actually handled, revealing differences between documented processes and day-to-day reality.

These conversations can also act as informal awareness sessions, helping staff better understand their responsibilities and providing an opportunity to ask questions.

The hosts emphasised that compliance is not achieved through policies alone. It depends on people understanding what they need to do and why.

Retention remains one of the biggest audit findings

When discussing the issues they encounter most frequently, both hosts quickly identified retention as a recurring challenge.

Many organisations have retention policies in place, but implementation often tells a different story.

Employees may understand that records should be deleted after a certain period, yet the actual deletion process never takes place.

The discussion included examples of organisations retaining emails for decades, storing outdated information indefinitely and relying on manual deletion processes that are rarely followed consistently.

Without effective retention practices, organisations risk keeping personal information for longer than necessary and increasing their exposure to data protection risks.

Third-party management is frequently overlooked

Another area highlighted during the discussion was third-party management.

Many organisations maintain supplier registers and records of processing activities, but auditors often discover inconsistencies when testing the information.

The hosts shared examples where organisations claimed to have Data Processing Agreements in place for all suppliers, only for further investigation to reveal unsigned templates or agreements that had never actually been implemented.

This demonstrates why auditors must test evidence rather than simply accept documentation at face value.

Third-party relationships often represent significant compliance risks, particularly where personal data is being processed externally or transferred internationally.

The risks of personal device usage

The discussion also explored one of the most common findings in modern workplaces, employees using personal devices for business purposes.

As Catherine explained: “The organisation doesn’t know that some employees use their phones for work.”

This creates a range of challenges. Personal devices may contain customer information, contracts, emails or communications that are completely outside the organisation’s governance framework.

It can also create difficulties when responding to Subject Access Requests, managing retention periods and investigating incidents.

Without appropriate Bring Your Own Device policies and controls, organisations may struggle to understand where personal data is being stored and processed.

WhatsApp, shadow IT and hidden data flows

The hosts also highlighted the increasing use of WhatsApp and other informal communication tools.

Whilst these platforms may improve efficiency, they can also introduce governance challenges when organisations fail to formally recognise or manage their use.

Examples discussed included contractors using WhatsApp to share photographs, employees communicating with customers through personal devices and business information being exchanged through channels that are not covered by existing policies.

These hidden data flows can create significant compliance risks if organisations are unaware of how information is being processed.

Effective governance requires organisations to understand where personal information is being stored, shared and accessed, regardless of whether that activity takes place through official systems or informal channels.

Why people shouldn’t fear audits

One of the most interesting parts of the discussion focused on the perception of audits themselves.

Many employees view auditors as investigators looking for mistakes or individuals responsible for assigning blame.

The hosts acknowledged that the word “audit” often creates anxiety, particularly where organisations have recently experienced a breach or compliance issue.

However, they stressed that audits should be viewed as opportunities for improvement rather than exercises in criticism.

As Catarina explained when speaking to employees during audits: “I am not here to judge you.”

The purpose of an audit is to identify risks, highlight opportunities for improvement and help organisations strengthen their compliance position.

When approached positively, audits can provide valuable insight into how organisations handle personal information and where additional support may be needed.

Turning findings into action

Finding issues during an audit is only the beginning of the process.

The real value comes from understanding those findings, prioritising actions and implementing meaningful improvements.

The discussion highlighted the importance of clear reporting, practical recommendations and helping organisations understand where risks are most significant.

Not every finding represents a high-risk compliance issue. Some can be addressed quickly, whilst others may require longer-term planning and investment.

Effective audit reports should help organisations understand not only what needs to improve, but also where they should focus their efforts first.

Why audits are essential for accountability

Whilst UK GDPR does not explicitly require organisations to conduct annual audits, the discussion highlighted how audits support one of the most important principles within the legislation, accountability.

Organisations must be able to demonstrate compliance. To do this effectively, they need mechanisms that test controls, assess risks and evaluate whether policies are operating as intended.

Audits provide an opportunity to challenge assumptions, verify compliance claims and identify gaps before they become larger issues.

Ultimately, the discussion reinforced that audits should not be seen as a negative exercise. They are an opportunity to learn, improve and build a stronger data protection culture.


Frequently Asked Questions About GDPR Audits

What is a GDPR audit?

A GDPR audit is a structured assessment of an organisation’s data protection practices, policies, procedures and operational controls to determine how effectively personal information is being managed.

Are GDPR audits legally required?

UK GDPR does not explicitly require annual audits, but audits are often used to support accountability obligations and demonstrate compliance.

What do GDPR auditors look for?

Auditors typically assess governance arrangements, policies, training, records management, retention practices, security measures, third-party management and employee awareness.

Why is retention often a common audit finding?

Many organisations have retention policies in place, but fail to consistently apply them in practice, leading to unnecessary retention of personal information.

Can an organisation be compliant if it has policies but employees do not follow them?

No. Compliance depends on policies being implemented effectively and understood by employees, not simply existing as documents.

What is the benefit of a GDPR audit?

A GDPR audit helps organisations identify weaknesses, strengthen controls, improve accountability and reduce the likelihood of compliance failures or data breaches.

GDPR Toolkit

Why Your Business Needs a GDPR Toolkit

Navigating the complexities of the GDPR can feel overwhelming. For businesses of all sizes, ensuring you meet the UK General Data Protection Regulation’s (UK GDPR) requirements is crucial. But where do you begin?

The Challenge: Untangling the GDPR Web

The UK GDPR outlines a set of regulations designed to protect the personal data of UK citizens. Failure to comply can result in hefty fines and reputational damage. Understanding and implementing these regulations requires time, expertise, and a clear understanding of your specific data processing activities.

The Solution: A One-Stop Shop for GDPR Compliance

This is where a GDPR Toolkit from Data Protection People steps in. We’ve designed this comprehensive resource to be your one-stop shop for achieving and maintaining GDPR compliance.

Benefits for Your Business: Confidence and Peace of Mind

  • Streamlined Compliance: Our meticulously crafted framework provides all the essential tools you need, from customisable templates to pre-drafted data breach notifications. This saves you valuable time and resources, allowing you to focus on your core business activities.

  • Empowered Staff: Our toolkit includes staff awareness training, ensuring your team understands their role in data protection. A well-informed workforce minimises the risk of human error and safeguards your data.

  • Reduced Risk: By implementing the best practices outlined in the toolkit, you significantly reduce the risk of data breaches and non-compliance fines. This translates to peace of mind and protection for your business reputation.

Why Choose Data Protection People and our GDPR Toolkit?

Data Protection People is a leading UK Data Protection Consultancy with a proven track record of success. Our team of experienced consultants works with clients across the UK and internationally.

Data Protection Made Easy: Our Guiding Principle

We understand the complexities of data protection. That’s why our motto is “data protection made easy.” Our toolkit simplifies these intricate regulations, making them accessible for businesses of all sizes.

Here’s what sets us apart:

  • Expert-Led Development: Developed by industry experts, our toolkit reflects the latest GDPR guidance and best practices.

  • Customisable Templates: We provide a comprehensive library of customisable templates, adaptable to your specific data processing activities.

  • Ongoing Support: We offer ongoing support to ensure you get the most out of your toolkit and stay up-to-date with evolving regulations.

Investing in Your Future

GDPR Toolkit is an investment in the future of your business. By prioritising data protection compliance, you demonstrate your commitment to customer trust and build stronger client relationships.

Taking the Next Step

Ready to simplify GDPR compliance and gain peace of mind? Contact Data Protection People today to learn more about our GDPR Toolkit. Let us guide you through the maze of data privacy regulations and empower your business to thrive.

Is Your Breach Response a Black Hole?

Is Your Breach Response a Black Hole? UK DPOs Face Shocking Delays (and Fines)

With UK GDPR regulations placing data protection at the forefront, organisations are facing a new reality: data breaches can be not just a security risk, but a significant financial one and the consequences for organisations can be severe. But a new study reveals a disturbing trend: UK organisations are taking significantly longer to contain data breaches compared to the global average. This delay can be disastrous, leading to compromised data, hefty fines under UK GDPR, and irreparable damage to customer trust. Don’t let your breach response become a black hole! This blog explores the issue and offers solutions.

The Alarming Statistics

A recent study by  IBM’s 2022 data security report, found that the average UK organisation takes a staggering 277 days  -roughly 9 months – for businesses to identify and report a data breach. Stolen or compromised credentials were the most common cause of a data breach in 2022, and these types of attacks took around 327 days to identify. It costs roughly $4.35 million to recover from a data breach and attacks on the healthcare industry were the highest.”  This means critical time is wasted while sensitive data remains exposed, increasing the risk of exploitation by malicious actors.

The Ripple Effect of Delay

The longer a data breach goes undetected and uncontained, the more severe the consequences. Here’s what’s at stake:

  • Increased Risk of Exploitation: Every minute a breach goes unnoticed is an opportunity for hackers to steal sensitive data, like financial information or personal details. This can lead to identity theft, fraud, and reputational damage for your organisation.
  • Hefty Fines under UK GDPR: The UK GDPR enforces strict regulations on data protection. Organisations that fail to report breaches within 72 hours, face fines up to £17.5M or 4% of annual global turnover. This whichever one is greater.
  • Shattered Customer Trust: When a data breach occurs, customers lose faith in an organisation’s ability to protect their personal information. This can lead to a decline in sales, customer churn, and difficulty attracting new business.

Why Are UK Organisations Lagging Behind?

DPOs are often responsible for a wide range of data protection tasks beyond breach response. This can leave them stretched thin and unable to dedicate the necessary time and attention to developing a robust breach response plan or conducting regular security audits.

Taking Control: How to Streamline Your Breach Response

Don’t let a data breach become an existential threat for your organisation. Here are some steps you can take to ensure a swift and compliant resolution:

  • Develop a Comprehensive Breach Response Plan: A well-defined plan outlines the steps to be taken in the event of a breach, including identification, containment, eradication, and notification. It should also include clear roles and responsibilities for all personnel involved.
  • Invest in Security Awareness Training: Empower your employees to be the first line of defence against data breaches. Regular training on data security best practices, phishing scams, and password hygiene can significantly reduce the risk of human error leading to a breach.
  • Regular Penetration Testing and Vulnerability Assessments: Proactive identification of vulnerabilities in your IT systems helps you patch them before they can be exploited by attackers.
  • Partner with a GDPR Breach Response Specialist: Companies like Data Protection People offer a range of services to help organisations prepare for and respond to data breaches. We can assist with developing breach response plans, conducting training, and providing guidance on regulatory compliance with the UK GDPR.

Don’t Wait for Disaster to Strike

Data breaches are an unfortunate reality of the current technological landscape, but the impact can be minimised with proper preparation. By taking the steps outlined above, you can ensure your organisation has a robust breach response plan in place. This helps mitigate the risks and navigate a data breach efficiently.

Contact Data Protection People today. Learn how we can help you make your breach response bulletproof. Check out our “GDPR Breach Guide” to get started on building a comprehensive plan.

Remember: A swift and effective response to a data breach can save your organisation from significant financial and reputational damage. Don’t wait until it’s too late.

World Password Day: A Guide to Bulletproof Passwords

World Password Day: A Guide to Bulletproof Passwords

Strong password practices are essential for ensuring the security of our online identities and data. Weak passwords leave sensitive information vulnerable to data breaches and cyberattacks.  This guide equips you with the knowledge and tools to transform from a password punching bag into a champion of online security. We’ll delve into the importance of length, the dangers of password reuse, and explore powerful strategies like password managers and multi-factor authentication.

1. Prioritise Length:

While complexity plays a role, prioritising length is crucial. Imagine a combination lock – the more digits, the harder to crack. Aim for at least 16 characters for each password. This significantly increases the time and effort required for brute-force attacks, where hackers systematically try every possible combination.

2. Embrace Uniqueness:

Resist the urge to reuse passwords across different accounts. A data breach on a single platform can expose your login credentials. If you’ve reused those credentials for other accounts (like your bank or social media), those accounts become vulnerable too. Hackers can easily test your stolen login information on other platforms, potentially gaining access to a wealth of your personal information.

3. Leverage Complexity:

Length is essential, but don’t underestimate the power of complexity. Incorporate a combination of uppercase and lowercase letters, numbers, and symbols. This creates a stronger barrier against hacking attempts, making your password significantly more difficult to guess.

4. Utilise Password Managers:

Remembering numerous unique passwords can be a challenge. Consider using a password manager. These secure applications store and encrypt your login credentials, eliminating the need to remember them all while keeping them safe and readily accessible.

5. Double Down with Multi-Factor Authentication:

Many platforms offer multi-factor authentication (MFA) as an extra security layer. This requires an additional verification step beyond just your password, such as a code sent to your phone or a fingerprint/Face ID scan. Consider MFA as a secondary security checkpoint, adding another hurdle for potential intruders.

Employee Checklist: Mastering Password Management

Now that you’re armed with this knowledge, here’s a quick checklist to ensure your passwords are top-notch:

  • Conduct a Password Audit: Review your current passwords. Are they strong and unique?
  • Enhance Password Strength: Consider using a password generator to create complex, lengthy passwords for each account.
  • Secure Password Storage: If not using a password manager already, explore secure options to store your credentials.
  • Enable MFA: Wherever available, activate multi-factor authentication for an extra layer of protection.
  • Maintain Vigilance: Be wary of phishing attempts. Never share your password information in response to unsolicited emails or calls.

By following these simple steps, you can significantly improve your online security posture and safeguard both your personal and company data. Remember, strong passwords are the first line of defence in the fight against cybercrime. Let’s work together to build a robust security framework around our digital assets!

Need Additional Support?

For further guidance on password management best practices or a comprehensive data security strategy, our experienced Data Protection Officers (DPO) are here to assist. Contact our DPO services department to discuss your specific needs.

Exploring Individual Rights

Exploring Individual Rights

The ever-evolving field of data protection law can be a minefield for businesses of all sizes. Balancing the rights of individuals with the operational needs of your organisation is a constant challenge, especially when it comes to fulfilling individual rights requests. During this week’s episode of the Data Protection Made Easy podcast we will be Exploring Individual Rights.

This upcoming podcast, designed specifically for Data Protection Officers (DPOs) and Data Champions, delves into the complexities surrounding individual rights in UK data protection law. We’ll explore real-world scenarios, practical solutions, and best practices to help you navigate these requirements efficiently and effectively.

Balancing Act: Respecting Individual Rights While Meeting Business Needs

The General Data Protection Regulation (GDPR) grants individuals a powerful set of rights regarding their personal data. These rights include access, rectification (correcting inaccuracies), restriction of processing, and even erasure (the “Right to be Forgotten”). While upholding these rights is essential for building trust and fostering responsible data practices, fulfilling them can sometimes create friction with day-to-day business operations.

Our upcoming podcast dives head-first into the challenges faced by organisations when responding to individual rights requests. Here are some of the key hurdles we’ll discuss, along with potential solutions for DPOs and Data Champions:

Resource Constraints: Verifying requests, gathering information from disparate systems, and responding within the legal timeframe can be incredibly time-consuming and resource-intensive, especially for smaller businesses. This can lead to backlogs and delays in fulfilling requests.

  • Solutions: Prioritise requests based on urgency and potential impact. Streamline verification processes to expedite confirmation of data subject identities. Utilise data mapping exercises to understand where personal data resides within the organisation, allowing for faster retrieval.

Data Location and Accessibility: Personal data can be scattered across various databases, cloud storage solutions, and even physical records. This fragmented data landscape makes it difficult to locate and retrieve specific information quickly when responding to individual rights requests.

  • Solutions: Implement a comprehensive data mapping exercise to create a clear picture of where personal data is stored and how it flows throughout the organisation. Invest in data management tools that can centralise data storage and simplify search functionalities.

Third-Party Involvement: Fulfilling an individual’s right to access, rectify, or erase data might require coordination with third-party vendors who also hold the data subject’s information. This adds another layer of complexity to the process, requiring communication and potential data sharing with external entities.

  • Solutions: Establish clear contractual agreements with third-party vendors outlining data protection responsibilities. These agreements should address data subject rights and how requests will be handled collaboratively. Consider implementing data sharing agreements that facilitate secure and efficient data transfers when necessary.

Streamlining the Response of individual rights: Practical Solutions for DPOs and Data Champions

The good news is, there are concrete steps you can take to streamline the process of handling individual rights requests, minimise disruption, and ensure compliance with data protection regulations. Our upcoming podcast will delve into these practical solutions, empowering DPOs and Data Champions to navigate these requests efficiently:

1. Standardised Procedures: The Power of Consistency

Developing clear and well-documented internal processes for handling individual rights requests is a game-changer. These standardised procedures act as a roadmap, ensuring consistency across your organisation and saving valuable time. Here’s how:

  • Reduced Training Time: Clearly defined procedures make training new staff members on handling individual rights requests more efficient. Consistency ensures everyone is on the same page, minimising errors and delays.
  • Improved Efficiency: Standardised processes establish a clear workflow for handling requests, streamlining each step from verification to fulfillment. This reduces the risk of tasks being overlooked or duplicated.
  • Enhanced Accuracy: Well-documented procedures help staff handle requests accurately and consistently, reducing the likelihood of errors that could lead to legal repercussions or reputational damage.

2. Technology Solutions: Leverage Automation for Efficiency

Data management tools can be your secret weapon in streamlining individual rights requests. These tools automate various tasks, freeing up valuable staff resources to focus on higher-level activities. Here are some functionalities to explore:

  • Data Search and Retrieval: Leverage data discovery features to locate relevant personal data quickly and efficiently, even if it’s spread across multiple systems.
  • Data Redaction: Utilise automated redaction tools to anonymise sensitive information before providing data to the data subject, ensuring compliance with data minimisation principles.
  • Reporting and Audit Trails: Implement data management tools that generate reports and maintain audit trails, simplifying record-keeping and demonstrating compliance with data subject rights.

3. Communication is Key: Building Trust Through Transparency

Clear and consistent communication with the data subject throughout the process is crucial. Here’s how effective communication fosters trust and reduces frustration:

  • Setting Realistic Timelines: Be upfront about the timeframe for responding to requests. This helps manage the data subject’s expectations and avoids unnecessary inquiries.
  • Regular Updates: Keep the data subject informed throughout the process. Provide regular updates on the status of their request, even if it’s just to acknowledge receipt and confirm it’s being addressed.
  • Clear and Concise Language: Use plain language that is easy for the data subject to understand. Avoid technical jargon and legal terminology whenever possible.

The Right to Erasure: When “Forgotten” Isn’t So Simple

The “Right to Erasure,” also known as the “Right to be Forgotten,” empowers individuals to request the deletion of their personal data under certain circumstances. While this sounds straightforward, fulfilling erasure requests can be surprisingly complex. Our upcoming podcast dives into scenarios where achieving complete erasure might be difficult, and explores alternative solutions for DPOs and Data Champions to navigate these situations while complying with data protection law.

Here’s why achieving complete erasure can be challenging:

  • Legal and Regulatory Retention Requirements: Businesses may have legal or regulatory obligations to retain certain types of personal data for a specific period. For example, financial institutions might need to keep transaction records for tax or anti-money laundering purposes. In such cases, complete erasure is not possible.

  • Backups and Archived Data: Data backups and archives create a grey area for the Right to Erasure. While actively used data can be erased, backups and archived data pose challenges. Striking a balance between fulfilling erasure requests and adhering to data retention policies is crucial.

Alternative Solutions for DPOs and Data Champions:

  • Data Anonymisation: In situations where complete erasure isn’t possible, anonymisation can be a viable alternative. This involves removing any personally identifiable information (PII) from the data, rendering it impossible to link it back to the individual. Anonymised data can still be used for statistical or research purposes, while protecting the individual’s privacy.

  • Clear Communication and Justifications: When complete erasure is not possible due to legal or technical reasons, clear communication with the data subject is essential. DPOs should provide a clear and concise explanation for why their request cannot be fully met. Transparency fosters trust and helps manage expectations.

The Importance of Data Retention Policies:

Having clear and up-to-date data retention policies in place is crucial for navigating the Right to Erasure. These policies should outline:

  • The specific types of personal data collected by the organisation.
  • The legal and regulatory requirements for data retention.
  • The criteria for determining when personal data can be erased.

Subject Access Requests (SARs): Mastering the Maze of Personal Data

Subject Access Requests (SARs) empower individuals to access the personal data a business holds on them. This right to transparency is crucial for building trust, but fulfilling SARs can be a time-consuming and resource-intensive process for organisations. Our upcoming podcast equips DPOs and Data Champions with best practices to navigate SARs efficiently:

1. Streamlined Verification: Preventing Unauthorised Access

Verifying the identity of the data subject is the first crucial step in handling a SAR. Streamlining this process ensures you’re providing information to the rightful individual and prevents unauthorised access to sensitive data. Here’s how:

  • Multi-Factor Authentication: Implement robust verification methods other than just passwords. Utilise multi-factor authentication (MFA) to add an extra layer of security, requiring additional verification factors like codes sent to a phone or email.
  • Clear Instructions: Provide clear and concise instructions on how individuals can submit verification documents within your SAR response process. This reduces delays and ensures you receive the necessary information to verify identities promptly.

2. Clarity is Key: Providing Data in an Understandable Format

The information provided in response to an SAR should be clear, concise, and easy for the data subject to understand, even if they lack a technical background. Here’s how to ensure clarity:

  • Plain Language: Avoid technical jargon and legal terminology whenever possible. Use clear and concise language that the average person can understand.
  • Structured Format: Present the information in a well-structured and organised format. Consider using tables, headings, and bullet points to improve readability.
  • Defining Terminology: If including technical terms is unavoidable, provide clear definitions within the SAR response document itself.

3. Data Mapping: The Secret Weapon for Efficiency

Having a clear understanding of where personal data is stored and how it’s used within your organisation is a game-changer for handling SARs efficiently. Data mapping involves creating a comprehensive inventory of your data landscape. Here’s how it benefits DPOs and Data Champions:

  • Faster Retrieval: Knowing where specific data resides eliminates the need to search through multiple systems, significantly reducing the time it takes to locate and retrieve relevant information for SAR responses.
  • Reduced Errors: A clear data map minimises the risk of overlooking data sources, ensuring a more thorough and accurate response to the SAR.
  • Improved Compliance: Data mapping supports overall data governance efforts, making it easier to demonstrate compliance with data protection regulations during audits or investigations.

Building a Culture of Data Protection: Proactive Strategies for DPOs and Data Champions

While effectively handling individual rights requests is crucial, our upcoming podcast delves deeper, emphasising the importance of proactive data protection. By fostering a culture of data privacy within your organisation, you can minimise risks, streamline processes, and build trust with customers and regulators. Here, we’ll explore key strategies DPOs and Data Champions can implement:

1. Empowering Staff Through Education

Staff training programs are the cornerstone of a strong data protection culture. Educating employees on data protection principles, individual rights, and internal procedures equips them to handle personal data responsibly:

  • Data Protection Fundamentals: Train staff on core data protection principles like data minimisation, purpose limitation, and lawful processing. This empowers them to make informed decisions about data collection and handling.
  • Individual Rights Awareness: Ensure staff understand the individual rights enshrined in data protection regulations, such as the right to access and the right to erasure. This knowledge allows them to effectively respond to inquiries and requests.
  • Internal Policy Training: Train staff on your organisation’s internal data handling policies and procedures. This fosters consistency and ensures everyone is on the same page regarding data protection practices.

2. Proactive Risk Management with Privacy Impact Assessments (PIAs)

Privacy Impact Assessments (PIAs) are a proactive approach to data protection. By conducting PIAs for new projects and initiatives that involve personal data, you can identify and mitigate potential risks before they arise:

  • Early Risk Identification: PIAs help identify potential privacy risks associated with collecting, using, or storing personal data. This allows for early intervention and implementation of appropriate safeguards.
  • Data Protection by Design: PIAs encourage integrating data protection considerations into the design phase of new projects. This ensures data privacy is prioritised from the outset.
  • Enhanced Compliance: Regular PIAs demonstrate your organisation’s commitment to data protection and can be valuable evidence during audits or investigations.

3. Clear and Accessible Internal Policies

Having clear, up-to-date, and easily accessible internal policies on data handling and individual rights empowers staff to make informed decisions in their daily work:

  • Comprehensive Policies: Develop internal policies that cover the entire data lifecycle, from collection to storage, use, and erasure.
  • Accessibility is Key: Ensure policies are readily available to all staff in a user-friendly format, such as on a central company intranet or knowledge base.
  • Regular Reviews and Updates: Regularly review and update internal policies to reflect any changes in data protection regulations or your organisation’s practices.