All
Adequacy
Age Appropriate Design Code
AI
Binding Corporate Rules
Clinical Trials
Consultancy
CRM data retention
Data Breach
Data Discovery
Data Privacy Officer
Data Protection Impact Assessment (DPIA)
Data Protection Officer
Data Retention
Data Security & Encryption
Data Sharing
DSARs
EU AI Act
EU Data Act
EU/UK Representation Services
featured post
GDPR compliance
Global data privacy laws
Global data protection news
International
International data transfers
Lawful Bases
Marketing
Official Guidance
Policies & Documentation
Principles of GDPR
Privacy by Design
Privacy Software
Record of Processing Activities (RoPA)
Special Category Data
Staff Training & Awareness
Uncategorized
July 20, 2026

Marketing compliance under DUAA and PECR

Marketing

The Data Use and Access Act 2025 (DUAA) has brought a notable change to UK electronic marketing law, shifting the risk profile for compliance. From 5 February 2026, organisations can face fines of up to £17.5 million, or 4% of annual...

January 25, 2021

What is Adequacy?

Adequacy

NB: This blog was updated on 29/6/21 to reflect the EU Commission’s decision to grant the UK Adequacy. Adequacy, the word that has been on everyone’s […]

CCPA
March 2, 2020

CCPA Overview

Global data privacy laws

The California Consumer Privacy Act Overview The California Consumer Privacy Act (“CCPA”) entered into force on January 2020, bringing with it increased data protection obligations on […]

March 18, 2021

UK GDPR

The UK General Data Protection Regulation. Before leaving the EU, the UK transposed the GDPR into UK law through the Data Protection Act 2018. This became […]
March 18, 2021

Safeguards

When transferring personal data to a third country, organisations must put in place appropriate safeguards to ensure the protection of personal data. Organisations should ensure that […]
March 18, 2021

European Commission

One of the core institutions of the European Union, responsible for lawmaking, policymaking and monitoring compliance with EU law.
March 18, 2021

3rd countries

Countries that are not part of the European Economic Area (EEA).
March 18, 2021

Third countries

Countries that are not part of the European Economic Area (EEA).
March 18, 2021

3rd country

A country that is not part of the European Economic Area (EEA).
March 18, 2021

Third country

A country that is not part of the European Economic Area (EEA).
March 18, 2021

Accountability

Perhaps the most important GDPR principle, which requires controllers to take responsibility for complying with the GDPR and, document their compliance.
March 18, 2021

Integrity and confidentiality

The sixth GDPR principle, also know as the security principle. This requires organisations to implement the appropriate security measures to protect personal data.
March 18, 2021

Storage limitation

The fifth GDPR principle which requires organisations to only store data for as long as it is needed.
Change your cookie consent