November 24, 2025

GDPR & AML: Why Financial Services must align KYC, CDD, and data protection

Financial services are under pressure. Digital onboarding, AI-powered due diligence, and growing data volumes are redefining customer verification — exposing firms to new regulatory risks. As Know Your Customer (KYC), Customer Due Diligence (CDD), and Anti-Money Laundering (AML) processes evolve, firms operating in the UK face mounting pressure to ensure data governance keeps pace. The Financial Conduct Authority (FCA) and Information Commissioner’s Office (ICO) are jointly calling for closer collaboration between financial and privacy teams, making it clear that Anti-Money Laundering (AML) and UK General Data Protection Regulation (UK GDPR) obligations can no longer be managed in isolation.
November 10, 2025

AI Officer vs DPO: Defining roles in AI governance

According to McKinsey’s latest global survey on AI, over 75% of organisations now use AI in at least one business function. As adoption accelerates, questions around accountability and oversight are becoming more pressing.  Many organisations are beginning to formalise their AI governance structures by expanding their Data Protection Officer (DPO) responsibilities or appointing a dedicated AI Officer. But which approach is most effective? 
August 18, 2025

Privacy Management Platforms: A practical guide for strengthening privacy operations

As data protection obligations grow, many organisations are implementing Privacy Management Platforms (PMPs) to reduce admin, bring structure to complex privacy operations, and support compliance.   […]
February 3, 2025

GDPR DPO requirements: What qualifies as large-scale processing?

Under the GDPR, certain organisations must appoint a Data Protection Officer (DPO) to oversee compliance efforts and protect personal data. A key factor in this decision […]
September 30, 2024

Live Facial Recognition deployment and data protection compliance

On paper, using AI-based Live Facial Recognition (LFR) technology for security and law enforcement makes perfect sense. It improves accuracy, takes the guesswork out of identifying […]
May 27, 2024

Canadian Privacy Laws: PIPEDA and Data Protection

Q&A with Ray Pathak, MD The DPO Centre, Canada The Personal Information Protection and Electronics Act (PIPEDA) was enacted in April 2000. Since then, there have […]
April 29, 2024

Data protection checklist for mergers and acquisitions

A data protection checklist for mergers and acquisitions is a useful tool to help both parties understand what documents should be included to demonstrate compliance with […]
April 15, 2024

Data protection compliance: Law firm vs outsourced DPO services

When it comes to ensuring data protection compliance, organisations often face a choice between engaging a specialist law firm vs outsourced DPO (Data Protection Officer) services. […]
March 4, 2024

EDPB Report: Challenges faced by DPOs in Europe

On 17 January 2024, the European Data Protection Board (EDPB) published a report on a co-ordinated investigation into the role of Data Protection Officers (DPOs).  25 […]
February 19, 2024

GDPR advice for SaaS companies entering EU & UK markets

Europe and the UK offer many growth opportunities for SaaS companies looking to expand beyond their home territories. The EU’s and UK’s mass consumer markets have […]
Change your cookie consent