July 6, 2026

UK charity soft opt-in: What charities need to know

The introduction of the charity soft opt-in was widely welcomed across the sector. Brought in through the UK’s Data Use and Access Act 2025 (DUAA) and available to use from February 2026, the change allows charities to send certain electronic marketing communications without obtaining explicit consent, provided specific conditions are met. 
June 22, 2026

5 signs your organisation needs a Data Protection Officer

It’s easy to assume that a Data Protection Officer (DPO) is only necessary for large organisations or those operating in highly regulated sectors. As a result, many organisations rely on support from legal, compliance, or IT teams, rather than appointing a dedicated privacy professional.  That can work for a while, but as businesses grow, so do the data protection responsibilities. For example, introducing new technologies, launching new products and services, or using more third-party suppliers can all create privacy risks that ad hoc support cannot manage.  
May 25, 2026

GDPR compliance: Why low-risk data processing can still create risk

GDPR compliance gaps don’t always come from high-risk data processing and sometimes come from seemingly low-risk activities that no one thinks to question. Organisations can often prioritise their compliance reviews on obvious areas, such as special category data, large-scale profiling, and international data transfers. These activities carry a higher risk of harm to individuals and often trigger additional GDPR obligations. But it can also mean lower-profile processing is reviewed less often, or not at all.  
May 11, 2026

A practical guide to identity verification for DSARs

Identity verification for DSARs is essential to prevent unauthorised data disclosure and avoid unnecessary delays.  To respond to DSARs in a compliant and effective way, organisations must strike a careful balance between two risks: sharing personal data with the wrong person and delaying or obstructing valid DSAR requests by asking for excessive or unnecessary identification, which could lead to poor user experience and complaints.  
April 27, 2026

Clinical trials part 4: Practical approaches to DPIAs

Data Protection Impact Assessments (DPIAs) help sponsors identify and address risks to participant data before a clinical trial begins. Under the UK and EU General Data Protection Regulation (GDPR), they are a mandatory requirement for high-risk personal data processing, which includes health information used in clinical research. Getting data protection right is not just a regulatory requirement but a critical part of running an effective and trustworthy trial.  
April 13, 2026

Bring Your Own Device (BYOD) risk management guide

Clinical research organisations are increasingly asked to demonstrate privacy assurance through recognised frameworks and certifications. For teams already navigating multiple regulatory requirements, this can quickly feel overwhelming.  Whilst compliance with laws such as the EU and UK General Data Protection Regulation (GDPR) or the US Health Insurance Portability and Accountability Act (HIPAA) remains essential, sponsors, partners, and regulators are now also looking for evidence that privacy and security controls operate effectively in practice. 
March 30, 2026

Privacy compliance vs assurance in clinical trials: Why you need both

Clinical research organisations are increasingly asked to demonstrate privacy assurance through recognised frameworks and certifications. For teams already navigating multiple regulatory requirements, this can quickly feel overwhelming.  Whilst compliance with laws such as the EU and UK General Data Protection Regulation (GDPR) or the US Health Insurance Portability and Accountability Act (HIPAA) remains essential, sponsors, partners, and regulators are now also looking for evidence that privacy and security controls operate effectively in practice. 
March 2, 2026

Clinical trials and GDPR: 5 common misconceptions and how to overcome them

In fast-moving clinical trial set-ups, General Data Protection Regulation (GDPR) governance and compliance can often seem like another layer of operational complexity. However, the challenge is rarely the regulation itself but uncertainty around how to interpret and apply it in practice. When expectations are not fully aligned across sponsors, CROs, and trial teams, this can increase risk and delay study timelines.
February 16, 2026

IT equipment disposal: How to stay GDPR compliant

IT equipment disposal is often treated as a straightforward operational task. However, studies consistently show that discarded hardware frequently still contains recoverable information. Research by the University of Hertfordshire’s Cyber Security Centre found that 65% of second-hand memory cards held recoverable data. The General Data Protection Regulation (GDPR) sets clear legal requirements for how organisations handle personal data. Organisations are expected to take reasonable steps to delete data when it is no longer accurate or required, and to protect both the data and the equipment used to store it against unauthorised access throughout its lifecycle.
November 24, 2025

GDPR & AML: Why Financial Services must align KYC, CDD, and data protection

Financial services are under pressure. Digital onboarding, AI-powered due diligence, and growing data volumes are redefining customer verification — exposing firms to new regulatory risks. As Know Your Customer (KYC), Customer Due Diligence (CDD), and Anti-Money Laundering (AML) processes evolve, firms operating in the UK face mounting pressure to ensure data governance keeps pace. The Financial Conduct Authority (FCA) and Information Commissioner’s Office (ICO) are jointly calling for closer collaboration between financial and privacy teams, making it clear that Anti-Money Laundering (AML) and UK General Data Protection Regulation (UK GDPR) obligations can no longer be managed in isolation.
Change your cookie consent