Woodgate & Clark Case Study
Written by Himanshi Gulati
Woodgate & Clark is a UK loss adjusting and claims management business. After its 2023 merger, DPP ran a full compliance audit and helped build a consolidated data protection framework across the newly combined organisation. W&C now manages most of its day-to-day compliance in-house, with DPP providing specialist advice and independent assurance when it’s needed.
The Challenge
Woodgate & Clark is a UK loss adjusting and claims management business, supporting insurers with claims across commercial property, specialist property and liability, along with other lines of business. Handling claims at this scale means handling significant volumes of personal data, and W&C’s role shifts depending on the relationship. Sometimes it’s a controller, responsible for its own business activities. Mostly it’s a processor, handling claims on behalf of insurers. In some client relationships it’s a joint controller, sharing responsibility with another organisation.
Following a merger in 2023, different parts of the business were coming together. W&C needed a clear picture of what data protection practices were already in place and where they needed to be aligned across the newly combined organisation.
What DPP Did
DPP started with a detailed compliance audit across the business. The audit found real strengths already in place, including information security, breach management, DPIAs (Data Protection Impact Assessments, used to identify and reduce privacy risk before a new project or process goes live) and data subject rights. It also identified where further work was needed: ROPAs (Records of Processing Activities, the internal log of what personal data an organisation holds and why), privacy information, processor management and international transfers.
From there, DPP worked alongside the W&C team on an ongoing basis, providing support and independent review across:
- The ROPA
- Privacy notices
- Data protection and information security policies
- Retention arrangements
- Wider governance
A key part of the work was helping W&C move to a more consistent approach across the whole business. That meant developing a single, consolidated ROPA that reflects how the organisation actually operates today, and that clearly accounts for its different roles as controller, processor and joint controller depending on the relationship.
The Outcome
W&C now has a much more established privacy governance framework and strong internal compliance capability. Most of the original remediation work identified in the audit has been addressed, and core governance documentation is in place. The focus has moved from building the foundations to embedding, maintaining and continually improving them.
Day-to-day data protection work is now largely managed in-house at W&C, with DPP continuing to provide specialist advice, independent assurance and additional support when it’s needed, including ongoing work on the ROPA, LIAs (Legitimate Interest Assessments, used to justify processing personal data under legitimate interest rather than consent), DPIAs and the wider governance framework as the business continues to evolve.
“Everyone is so helpful and friendly and takes the time to understand the specific requirements and challenges of our business.”
Nia Roberts, Woodgate & Clark
Get in touch
If your organisation is working through a merger, acquisition or restructure and data protection compliance needs to catch up, DPP’s Data Protection Support Service can help.