November 24, 2025

GDPR & AML: Why Financial Services must align KYC, CDD, and data protection

Financial services are under pressure. Digital onboarding, AI-powered due diligence, and growing data volumes are redefining customer verification — exposing firms to new regulatory risks. As Know Your Customer (KYC), Customer Due Diligence (CDD), and Anti-Money Laundering (AML) processes evolve, firms operating in the UK face mounting pressure to ensure data governance keeps pace. The Financial Conduct Authority (FCA) and Information Commissioner’s Office (ICO) are jointly calling for closer collaboration between financial and privacy teams, making it clear that Anti-Money Laundering (AML) and UK General Data Protection Regulation (UK GDPR) obligations can no longer be managed in isolation.
September 1, 2025

AI Impact Assessments: What are they and why do you need one?

In this blog, we explore what an AI Impact Assessment (AIIA) is, why it’s becoming an essential part of responsible AI adoption, and how to carry one out effectively.  From hiring tools to chatbots, fraud detection, and medical diagnostics, every AI system your business deploys has the potential to create value and drive efficiency across departments. But these systems can also expose you to a range of risks, particularly when they process personal data, make decisions about individuals, or influence behaviour. 
July 21, 2025

GDPR compliance in white label banking

White label banking is a fast-growing area, but it also brings regulatory challenges. This blog explores the key GDPR considerations for organisations operating in the EU […]
May 23, 2025

CCTV and GDPR: What organisations get wrong

This blog explores some of the most common compliance mistakes organisation can make when using CCTV in the workplace and explains how to avoid them.  Under […]
January 20, 2025

Bank due diligence: Data protection checklist for providers

Before entering outsourcing contracts, banks conduct thorough data protection due diligence on third parties such as payment, insurance and credit service providers. Banks must safeguard sensitive […]
January 6, 2025

Microsoft Copilot: Privacy concerns and compliance tips for 2025

Microsoft Copilot privacy concerns have been in the spotlight recently. The technology has quickly become a powerful example of how AI-enhanced tools are transforming the capabilities […]
April 29, 2024

Data protection checklist for mergers and acquisitions

A data protection checklist for mergers and acquisitions is a useful tool to help both parties understand what documents should be included to demonstrate compliance with […]
October 2, 2023

What is a DPIA?

Since the implementation of the GDPR, consumers have become increasingly data protection savvy. People want to know that businesses have the right safeguards in place. Data […]
September 4, 2023

Data breach management: 5 tips for an effective response

This blog was edited and updated on 4 March 2024 Data breaches can have devasting impacts for both organisations and their data subjects, no matter the […]
February 20, 2023

CJEU Decision: Data subjects have the right to know who has received their personal data

In January 2023, the Court of Justice of the European Union (CJEU) in Case C-154/21, reached the decision that “every person has the right to know […]
Change your cookie consent