June 8, 2026

CNIL MR-001: What clinical trial sponsors need to know

Data Protection Impact Assessments (DPIAs) help sponsors identify and address risks to participant data before a clinical trial begins. Under the UK and EU General Data Protection Regulation (GDPR), they are a mandatory requirement for high-risk personal data processing, which includes health information used in clinical research. Getting data protection right is not just a regulatory requirement, but a critical part of running an effective and trustworthy trial.
January 5, 2026

Data Use and Access Act 2025: What UK Financial Services need to know

The Data Use and Access Act (DUAA) 2025 introduces targeted updates and reforms to the UK’s data laws, with clear implications for the Financial Services sector. Enacted in June 2025, it amends the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulation (PECR).
October 27, 2025

Pseudonymisation under the GDPR: What the latest EU ruling means for organisations

On 4 September, the Court of Justice of the European Union (CJEU) delivered an important judgement in European Data Protection Board (EDPS) vs Single Resolution Board (SRB), providing fresh clarification on the status of pseudonymised data under the EU General Data Protection Regulation (GDPR). 
July 21, 2025

GDPR compliance in white label banking

White label banking is a fast-growing area, but it also brings regulatory challenges. This blog explores the key GDPR considerations for organisations operating in the EU […]
July 8, 2025

How to share data legally for safeguarding

How can organisations share personal data about at-risk children in the UK responsibly and compliantly?  This blog explores that question in light of the independent report, […]
December 9, 2024

International data transfers: TIAs vs TRAs

As businesses expand globally, transferring personal data across borders has become a routine part of operations. However, these transfers carry inherent risks that require careful consideration […]
May 13, 2024

Quebec’s Law 25: A guide to support compliance

Organisations that collect, process and store the personal information of Quebec individuals must ensure their existing privacy programs are in line with the provisions of Quebec’s […]
March 18, 2024

What is a DPA and why do you need one?

A Data Processing Agreement (DPA), also called a Data Processor Agreement, is a legally binding contract between a data controller (usually your organisation) and a data processor […]
January 22, 2024

International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA

EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.  With […]
October 30, 2023

Vendor due diligence & GDPR compliance: 5 practical steps

From IT solutions to DPO services, accounting, and customer services, the global outsourcing sector is expanding to support the needs of organisations across all industry sectors. […]
Change your cookie consent