What is ISO 27001? – The Complete Guide

The security of your personal information cannot be overstated. This guide explains what ISO 270001 is, and how it benefits an organisation’s information security in order to comply with GDPR. What is ISO 27001? ISO/IEC 27001 (also known as ISO 27001) is the international standard for information security that was originally developed back in 2005. […]

DPIAs – What are they and when do you need to do one?

It is not unusual to occasionally come across the opinion that Data Protection regulation stops organisations from using or sharing personal data or even getting on with their work.   We are happy to say this is not the case, and a Data Protection Impact Assessment (DPIA) is a practical way to ensure that you can […]

Who needs a Data Protection Officer under the GDPR?

person questioning the need to appoint a Data Protection Officer

What is a Data Protection Officer? Data Protection Officers (DPOs) are independent experts. They will help your organisation monitor internal compliance, inform and advise you of your data protection obligations, provide advice on the application of Data Protection Impact Assessments (DPIAs) and act as a point of contact for data subjects and the supervisory authority. […]

Handling DSARs – Getting to Grips with Personal Data

Personal Data graphic - keyboard with network image overlay

Personal data oils the machinery of our modern online lives. But as time has passed, our relationships with online services, mobile devices, and other data hungry systems have matured. To reflect this, regulations are designed to enforce privacy-enhanced personal data control using data subject rights. These rights are reflected in regulations such as the EU’s General Data Protection Regulation (GDPR) and are increasingly included in other regulations across the world such as the California Consumer Privacy Act (CCPA).