Getting a notification through an app like ASOS seems like fairly standard practice, whether it’s informing you about new deals on that jacket you’re eyeing up or reminding you about its current offers and deals but I’d bet you wouldn’t expect that notification to announce that ASOS had been hacked. The issue with this news…
-
-
When a financial services firm suffers a cyber incident, the first question is usually technical: what has happened, and how do we contain it? Close behind comes a regulatory question that is getting harder to answer: who do we have to tell, and by when? For years the data protection answer has been familiar. Report…
-
Charities handling complex Subject Access Requests (SARs) need to identify the requester’s personal data while carefully considering third-party information, safeguarding concerns, confidentiality and any exemptions that apply. Complex charity SARs often involve third-party data and safeguarding information. Redaction should protect other people’s personal data without unnecessarily removing the individual’s information. Whistleblower, multi-agency and child SARs…
-
The ICO has approved a UK GDPR code of conduct for information sharing between public services in Wales. The Wales Accord on the Sharing of Personal Information (WASPI) code was approved on 24 September 2026 and announced on 28 September 2026. What happened? WASPI is an existing framework that helps organisations in Wales share personal…
-
The short answer: Since 1 October 2026, private registered providers of social housing in England must have a STAIRs publication scheme. It covers information they hold about governance, spending, homes, performance, services, registers and housing management. Providers do not have to create new records. Appropriate redaction is allowed. The separate requirements for tenant information requests…
-
External Attack Surface Management, usually shortened to EASM, is the continuous discovery and monitoring of everything your organisation exposes to the internet, domains, subdomains, cloud services, servers and applications, including the ones nobody currently has on a list. What “attack surface” actually means Your external attack surface is every point an attacker could potentially reach…
-
Generative AI tools like ChatGPT, Microsoft Copilot and Gemini can be used in schools under UK GDPR if used safely and effectively, with appropriate data protection policies in place. To remain GDPR-compliant, schools should avoid using free versions of generative AI tools, as they may lack the necessary safety features. Instead, schools should use enterprise…
-
Pentesting, short for penetration testing, is an authorised, simulated attack on your organisation’s systems, carried out by a security professional using the same techniques a real attacker would, to find exploitable vulnerabilities before someone with genuinely bad intentions does. How pentesting differs from a vulnerability scan These two are often confused but they’re not the…
-
Cyber security support is an ongoing, retained service that gives your organisation continued access to expert security guidance. Rather than a single project with a fixed end date, it’s a standing relationship, someone you can turn to as questions, decisions and issues come up, rather than starting from scratch every time. How support differs from…
-
What Is a Weaponised Subject Access Request? A “weaponised” Subject Access Request (SAR) is a SAR that is being used as part of a wider dispute or strategy, rather than simply because someone wants to understand what personal data an organisation holds about them. You often see this during a grievance, disciplinary process, redundancy consultation…
Join our community
Our mission is to make data protection easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.