June 8, 2026

CNIL MR-001: What clinical trial sponsors need to know

CNIL MR-001 is the primary data protection framework interventional clinical trials in France where participants give informed consent. Organisations conducting these studies must either apply for direct authorisation from the French data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), or declare that they comply with an applicable Reference Methodology, such as MR-001. This framework has been in place since 2018, but the May 2026 update introduced further complexity to the methodology. 
January 5, 2026

Data Use and Access Act 2025: What UK Financial Services need to know

The Data Use and Access Act (DUAA) 2025 introduces targeted updates and reforms to the UK’s data laws, with clear implications for the Financial Services sector. Enacted in June 2025, it amends the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulation (PECR).
October 27, 2025

Pseudonymisation under the GDPR: What the latest EU ruling means for organisations

On 4 September, the Court of Justice of the European Union (CJEU) delivered an important judgement in European Data Protection Board (EDPS) vs Single Resolution Board (SRB), providing fresh clarification on the status of pseudonymised data under the EU General Data Protection Regulation (GDPR). 
July 21, 2025

GDPR compliance in white label banking

White label banking is a fast-growing area, but it also brings regulatory challenges. This blog explores the key GDPR considerations for organisations operating in the EU […]
July 8, 2025

How to share data legally for safeguarding

How can organisations share personal data about at-risk children in the UK responsibly and compliantly?  This blog explores that question in light of the independent report, […]
December 9, 2024

International data transfers: TIAs vs TRAs

As businesses expand globally, transferring personal data across borders has become a routine part of operations. However, these transfers carry inherent risks that require careful consideration […]
May 13, 2024

Quebec’s Law 25: A guide to support compliance

Organisations that collect, process and store the personal information of Quebec individuals must ensure their existing privacy programs are in line with the provisions of Quebec’s […]
March 18, 2024

What is a DPA and why do you need one?

A Data Processing Agreement (DPA), also called a Data Processor Agreement, is a legally binding contract between a data controller (usually your organisation) and a data processor […]
January 22, 2024

International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA

EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.  With […]
October 30, 2023

Vendor due diligence & GDPR compliance: 5 practical steps

From IT solutions to DPO services, accounting, and customer services, the global outsourcing sector is expanding to support the needs of organisations across all industry sectors. […]
Change your cookie consent