Legislation Articles

GDPR Chapter 5 – International Transfers

GDPR Chapter 5 – International Data Transfers GDPR recognises that personal data transferred outside the UK may not be subjected to the same legal standards. As such, GDPR Chapter 5 (GDPR Article 5) provides guidelines on these transfers.

GDPR Article 32 – Security

GDPR Article 32 on Information Security For most businesses, information security is the biggest risk associated with GDPR. However, GDPR provides very little guidance for organisations regarding the measures they must implement.

GDPR Article 28 Data Processing Agreements DPA

Controller-Processor Data Processing Agreements (DPA) If a company (a Data Controller) is outsourcing the processing of personal data to a third party (a Data Processor), GDPR states that there must be a contract in place outlining the relationship.

The Data (Use and Access) Act 2025

The following information is a full copy of the UK Data (Use and Access) Act 2025 (DUAA). The UK Data (Use and Access) Bill (DUAB) received Royal Assent on 19th June 2025. Data (Use and Access) Act aims to govern the use of data in a transparent manner.

Cyber Security and Resilience Bill – Kings Speech 2024

The Cyber Security and Resilience Bill was announced in the Kings Speech, on 17th July 2024. The recently voted Labour government has suggested that this will keep personal data safer and enhance security measures for digital infrastructures.

Digital Information and Smart Data Bill

The Digital Information and Smart Data Bill was announced in the Kings Speech, on 17th July 2024. The government has suggested that this will make better use of digital data but requires careful consideration of privacy concerns.

GDPR Lawful Bases (Article 6)

What is GDPR Article 6 Lawfulness of processing? Under GDPR, each purpose of processing must be assigned a lawful basis. Consent is only one type of lawful basis, so you can choose other lawful bases depending on the processing activity.

GDPR Principles of Processing (Article 5)

What is GDPR Article 5 – Principles of Processing? GDPR provides several core principles (considerations / requirements) for processing personal data. GDPR Article 5 defines those processes that must be adhered to.

GDPR Terms and definitions (Article 4)

What is GDPR Article 4 Definitions? GDPR Article 4 Definitions outline a number of key terms that apply in the regulation. Understanding these definitions is crucial for compliance.

GDPR Records of Processing (Article 30)

What is GDPR Article 30 Records of Processing Activities (RoPA)? Under GDPR, organisations must maintain a Records of Processing Activities if they employ 250 people or more and process personal data.