Blog & Commentary

Practical GDPR and Privacy Guidance

Clear explanations of key data protection concepts, regulatory obligations, and practical compliance strategies. These articles break down complex GDPR topics into straightforward insights for founders, marketers, and growing organisations.

Data Breaches Under UK GDPR: What Organisations Must Do

A practical guide to personal data breaches under UK GDPR, including what counts as a breach, when the ICO must be notified, when affected individuals need to be informed, and the steps organisations should take after an incident.

Data Protection Complaints Under UK GDPR: What Businesses Must Have in Place

Businesses need a clear process for handling data protection complaints, especially where individuals raise concerns about how their personal data has been used. This guide explains what organisations should have in place under UK GDPR, including complaint routes, response records, escalation steps, and links to wider accountability.

Data Retention Under UK GDPR: How Long Can Organisations Keep Personal Data?

Many organisations collect personal data but are less certain about when it should be deleted. Under UK GDPR, personal data must not be kept for longer than necessary. This guide explains the storage limitation principle, how retention periods are determined, and what businesses should include in a retention schedule.

GDPR Privacy Notices: What Businesses Need to Include

A practical guide to what GDPR privacy notices are, what businesses need to include, and how clear privacy information helps organisations meet UK GDPR transparency requirements.

Consent Under UK GDPR: When It Is Required and How to Get It Right

Consent under UK GDPR is not always required, but when organisations rely on it, the standard is high. Learn when consent is needed, what valid consent looks like, and the common mistakes organisations make.

Legitimate Interests Under UK GDPR: When Organisations Can Rely on It

Legitimate interests is one of the six lawful bases under the UK GDPR, but it is often misunderstood. This guide explains when organisations can rely on legitimate interests, how the balancing test works, and where businesses commonly get it wrong.
Next step

Not sure where to start with GDPR?

Explore the glossary to understand key privacy concepts, or download the GDPR readiness checklist for a practical overview of what organisations should review first.

Future Implementation Support Waitlist