Guidance Articles

Data Protection Officer Qualification GDPR Privacy

Is your Data Protection Officer (DPO) qualified? Are Data Protection Officer qualifications a GDPR legal obligation? What qualification should a DPO have? How do we know if the DPO is doing their job effectively?

UK Minister of State for Data Protection and Telecoms

What is the Minister of State for Data Protection and Telecoms? The Minister of State for Data Protection and Telecoms is a government role. Responsibilities of the role vary between different government agendas.

What is PECR? Meaning in UK Law with GDPR

What is PECR? PECR is part of UK law, focusing on direct marketing, website cookies, and telecommunications data protection legislation. Fines for failing to comply with PECR can be significant.

What is GDPR? Meaning in UK Law

What is GDPR? GDPR is part of UK law, providing part of our data protection legislation. What does GDPR stand for? GDPR is an acronym that stands for the General Data Protection Regulation.

What are the 7 GDPR Principles?

The 7 GDPR Principles for Data Protection. The GDPR, a UK data protection law, gives us 7 principles for processing personal data. Complying with these principles is a legal obligation.

GDPR Marketing Scheme Refer-a-friend

Are you sure that your marketing referral scheme is lawful under GDPR and PECR? Refer-a-Friend, Member-get-Member, and Customer-get-Customer schemes can be effective marketing strategies.

When is a GDPR DPIA Required?

There’s still confusion around when DPIAs (Data Protection Impact Assessments) are legally required under GDPR, affecting organizations in both the UK and EU.

How to Write a Privacy Policy?

What is GDPR Article 13 – Privacy Notice? The correct title describes the information that must be provided when personal data is collected from the data subject.

GDPR Lawful Bases (Article 6)

What is GDPR Article 6 Lawfulness of processing? Under GDPR, each purpose of processing must be assigned a lawful basis. Consent is one of several lawful bases.

GDPR Processor Contracts – Data Processing Agreements (Article 28)

Data Processing Agreements are necessary under GDPR for sharing information between Data Controllers and Data Processors, requiring adequate written agreements.

What is a ISO 27001 Statement of Applicability SoA?

What is a Statement of Applicability (SOA) for ISO 27001? The SOA outlines which controls are applicable in an information security management system.

11 Key Things a GDPR Website Privacy Notice Policy Must Have

What MUST be included in a GDPR Website Privacy Notice? Essential elements ensure compliance with GDPR and provide transparency to users.

GDPR Website Privacy Policy or Privacy Notice

Understanding the distinction between a Privacy Policy and Privacy Notice under GDPR and evaluating your website’s compliance requirements.

The Three Lines of Defence Risk Management Model

An overview of the Three Lines of Defence model which aids business leaders in effective risk management.

What Skills Do DPOs Need? GDPR Data Protection Officers

DPOs require a multi-disciplinary skill set based on professional qualities as specified by GDPR.

Tasks of the DPO – UK GDPR Data Protection Officer

An exploration of the mandated tasks for DPOs in the context of UK GDPR, which includes informing and advising on compliance.