The GDPR Studio Blog

Practical GDPR and PECR guidance for UK businesses

Clear, practical articles to help small and growing businesses understand data protection requirements and apply them to real decisions about customer data, marketing, websites, security, suppliers and individual rights. Need help with a term? Use our GDPR Glossary.

Legitimate Interests Under UK GDPR: When Organisations Can Rely on It

Legitimate interests is one of the six lawful bases under the UK GDPR, but it is often misunderstood. This guide explains when organisations can rely on legitimate interests, how the balancing test works, and where businesses commonly get it wrong.

Lawful Basis Under UK GDPR: The Seven Legal Grounds for Processing Personal Data

A practical guide to the seven lawful bases under UK GDPR, including recognised legitimate interest, consent, contract, legal obligation, vital interests, public task and legitimate interests

What Counts as Personal Data Under UK GDPR?

Personal data under UK GDPR includes any information that can identify a person directly or indirectly, from names and email addresses to IP addresses, customer records, and online identifiers. This guide explains what counts as personal data, what does not, and why the distinction matters for compliance.

Special Category Data Explained Under UK GDPR

Special category data under UK GDPR includes highly sensitive personal information such as health data, racial or ethnic origin, political opinions, religious beliefs, biometric data, and information about a person’s sex life or sexual orientation. This guide explains what counts as special category data, why stronger protections apply, and the additional conditions organisations usually need before processing it lawfully.

Data Controllers and Data Processors Under UK GDPR: Understanding the Difference

Understand the difference between data controllers and data processors under UK GDPR, including who decides the purpose of processing, who acts on instructions, and why the distinction matters in practice.

Data Protection Impact Assessments (DPIAs): When They Are Required Under UK GDPR

A practical guide to DPIAs under UK GDPR, including when they are required, what high risk processing means, and how organisations should approach them in practice.
Next step

Not sure where to start with GDPR?

Explore the glossary to understand key privacy concepts, or download the GDPR readiness checklist for a practical overview of what organisations should review first.

Future Implementation Support Waitlist