All Articles

GDPR Chapter 5 – International Transfers

GDPR Chapter 5 – International Data Transfers GDPR recognises that personal data transferred outside the UK may not be subjected to the same legal standards. As such, GDPR Chapter 5 (GDPR Article 5) outlines the rights and responsibilities of organizations when transferring data internationally.

GDPR Article 32 – Security

GDPR Article 32 on Information Security For most businesses, information security is the biggest risk associated with GDPR. However, GDPR provides very little guidance for organisations regarding specific security measures.

GDPR Article 28 Data Processing Agreements DPA

Controller-Processor Data Processing Agreements (DPA) If a company (a Data Controller) is outsourcing the processing of personal data to a third party (a Data Processor), GDPR states that there must be a formal Data Processing Agreement in place.

The Data (Use and Access) Act 2025

The following information is a full copy of the UK Data (Use and Access) Act 2025 (DUAA). The UK Data (Use and Access) Bill (DUAB) received Royal Assent on 19th June 2025.

QR Code Scams – UK Fraud Alert

QR Code Scam – UK Fraud Alert Beware of fake QR Codes. QR Codes Scams are rapidly on the rise in the UK, expected to cause significant fraud losses in the coming years.

Data Protection Officer Qualification GDPR Privacy

Is your Data Protection Officer (DPO) qualified? This article explores the legal obligations regarding DPO qualifications under GDPR.

UK Minister of State for Data Protection and Telecoms

This section discusses the responsibilities of the Minister of State for Data Protection and Telecoms within the UK government framework.

What is PECR? Meaning in UK Law with GDPR

What is PECR? The Privacy and Electronic Communications Regulations (PECR) are part of UK law focusing on direct marketing related to cookies and telecommunications data.

What is GDPR? Meaning in UK Law

What is GDPR? GDPR is part of UK law that governs data protection and privacy for individuals within the EU and the European Economic Area.

Cyber Security and Resilience Bill – Kings Speech 2024

The Cyber Security and Resilience Bill was introduced in the Kings Speech, signifying government efforts to enhance personal data safety.

CrowdStrike Outage Falcon IT Issue

CrowdStrike, a US cybersecurity company, faced a significant outage due to an update, affecting computer systems worldwide.

Digital Information and Smart Data Bill

This bill encourages better utilization of digital data in governmental and business operations.

What are the 7 GDPR Principles?

The 7 GDPR Principles outline the necessary guidelines for the lawful processing of personal data.

Grindr fined EUR 5.7m for GDPR breach

Grindr faced a substantial fine due to non-compliance with GDPR regulations as established by the Oslo District Court in Norway.

GDPR Marketing Scheme Refer-a-friend

This article discusses the legality of referral marketing schemes under GDPR and PECR.

When is a GDPR DPIA Required?

DPIAs (Data Protection Impact Assessments) clarify when assessments are necessary to comply with GDPR.

10 Recent GDPR PECR Data Protection ICO Fines

Overview of recent fines issued by the ICO for non-compliance with GDPR and PECR regulations.

What are the Biggest GDPR Fines?

A compilation of the largest fines issued under GDPR as of October 2023.

How to Write a Privacy Policy?

Guidelines on drafting a compliant privacy policy under GDPR Article 13.

GDPR Lawful Bases (Article 6)

Outlines the lawful bases for data processing as defined in Article 6 of GDPR.

GDPR Principles of Processing (Article 5)

Describes the core principles for processing personal data under GDPR Article 5.

GDPR Terms and definitions (Article 4)

Defines key terms used within the GDPR regulation as per Article 4.

GDPR Records of Processing (Article 30 )

Requirements for maintaining records of processing activities as per Article 30 of GDPR.

GDPR Data Protection by Design and by Default (Article 25)

What is required for data protection by design as outlined in GDPR Article 25.

GDPR Processor Contracts – Data Processing Agreements (Article 28)

Criteria for data processing agreements between controllers and processors under GDPR.

ICO fine Halfords £30k for 500k Fix Your Bike emails. Are Halfords still quids in?

Halfords was fined by the ICO for unlawful marketing practices related to the “Fix Your Bike” scheme emails.

Grand Theft Auto GTA Security Breach – Rockstar Breach

Security breach details involving Rockstar Games related to Grand Theft Auto.

Morgan Stanley Pays USD 35m SEC Fine – Data Security Asset Disposal

Morgan Stanley faced penalties for failing to secure customer data during asset disposal.

Uber Cyber Security Breach 15/9/22

An alleged cyber security breach at Uber reported by an 18-year-old hacker.

What is a ISO 27001 Statement of Applicability SoA?

This article explains the Statement of Applicability for ISO 27001 standards.

11 Key Things a GDPR Website Privacy Notice Policy Must Have

Overview of essential components required for a GDPR-compliant website privacy policy.

GDPR Website Privacy Policy or Privacy Notice

Discussion on the distinctions between a privacy policy and privacy notice in the context of GDPR.

The Three Lines of Defence Risk Management Model

An explanation of the Three Lines of Defence model aimed at effective risk management.

What Skills Do DPOs Need? GDPR Data Protection Officers

Necessary skills and qualifications for Data Protection Officers under GDPR.

Tasks of the DPO – UK GDPR Data Protection Officer

Details of the tasks DPOs must perform according to UK GDPR requirements.

Do we need a DPO? GDPR Data Protection Officers

Answering whether a Data Protection Officer is required for businesses under GDPR.

Cathay Pacific airway fined £0.5m by ICO for cyber-attack

Cathay Pacific faced financial penalties due to a cyber-attack as mandated by the ICO.

Morrisons found not vicariously liable for data breach

The UK’s top court ruling that Morrisons is not liable for a data breach incident.

Beligian DPA GDPR EUR 50k fine for DPO lacking independence

A fine imposed by the Belgian Data Protection Authority for issues related to DPO independence.

200526 GBP18bn lawsuit filed against EasyJet after cyber-attack

A significant lawsuit filed against EasyJet following a major cyber-attack incident.

200716 GDPR US EU Privacy Shield Invalidated

The European Court of Justice invalidating the US-EU Privacy Shield agreement.

ISO 27002 Information Security Standard

Details about the ISO 27002:2013 Standard that supplements ISO 27001 on information security management.

Read The Full UK DPA Legislation

Direct link to a full transcription of the UK Data Protection Act legislation.

Read the full PECR Legislation

Access to the full transcription of the Privacy and Electronic Communications Regulation (PECR).

What Does GDPR Law Actually Say?

Provides a comprehensive look into the GDPR legislation and its implications for data protection.