Governance

Topic Archive

Browse articles in this topic, with practical GDPR guidance designed to help you understand the issues clearly and move forward with more confidence.

Data Protection Complaints Under UK GDPR: What Businesses Must Have in Place

Businesses need a clear process for handling data protection complaints, especially where individuals raise concerns about how their personal data has been used. This guide explains what organisations should have in place under UK GDPR, including complaint routes, response records, escalation steps, and links to wider accountability.

Data Retention Under UK GDPR: How Long Can Organisations Keep Personal Data?

Many organisations collect personal data but are less certain about when it should be deleted. Under UK GDPR, personal data must not be kept for longer than necessary. This guide explains the storage limitation principle, how retention periods are determined, and what businesses should include in a retention schedule.

GDPR Privacy Notices: What Businesses Need to Include

A practical guide to what GDPR privacy notices are, what businesses need to include, and how clear privacy information helps organisations meet UK GDPR transparency requirements.

Data Protection Impact Assessments (DPIAs): When They Are Required Under UK GDPR

A practical guide to DPIAs under UK GDPR, including when they are required, what high risk processing means, and how organisations should approach them in practice.

The Accountability Principle Under UK GDPR Explained

A practical explanation of the accountability principle under UK GDPR, including what it requires in day-to-day compliance and how organisations can demonstrate responsibility in practice.
Next step

Not sure where to go next?

Explore the glossary to build confidence in key privacy concepts, or download the GDPR readiness checklist for a practical overview of what organisations should review first.

Future Implementation Support Waitlist