Data (Use and Access) Act 2025: What Every UK Business Needs to Know

The UK's biggest update to data protection law since Brexit – and what your business should do next. Is your business affected? If your business: collects customer or employee information; sends marketing emails; uses cloud software such as Microsoft 365, Google Workspace or a CRM; uses AI tools; shares personal data with suppliers; or employs … Continue reading Data (Use and Access) Act 2025: What Every UK Business Needs to Know

Do you legally need to conduct a Data Protection Impact Assessment (DPIA)?

What is a DPIA? Where the DPIA rules come from (UK GDPR, DPA 2018, WP29/EDPB, ICO) When is a DPIA required? (Article 35) Examples of high-risk processing (WP29 & ICO) When a DPIA is not required Who is responsible? (Controller, DPO, Processor, Data subjects) What a DPIA must include (Article 35(7)) When to consult the … Continue reading Do you legally need to conduct a Data Protection Impact Assessment (DPIA)?

What should be in your privacy policy?

Every UK business that collects or uses personal data needs a privacy policy under the UK GDPR and the Data Protection Act 2018. Personal data doesn't include commercial information, but if your customers are companies, the individuals behind those companies may still be providing you with personal data. This guide explains, in plain English, what … Continue reading What should be in your privacy policy?

Sharing personal data with third parties? Here’s what you need to know

Last updated: 13 August 2025 On this page 1) What is data sharing? 2) The ICO’s 2021 Data Sharing Code of Practice 3) Professional guidance & voluntary industry codes 4) Key GDPR principles for sharing 5) Main risks for controllers in data sharing 6) Controller vs Processor (and why it matters) 7) Lawful bases for … Continue reading Sharing personal data with third parties? Here’s what you need to know