Skip to main content

Services

Data Protection & Privacy

We help organisations meet their obligations under UK GDPR and the Data Protection Act 2018, and build privacy practices that people can follow in their daily work.

Two colleagues reviewing a document at an office desk

What this covers

  • Data mapping and records of processing
  • Lawful basis and privacy notice review
  • Data protection impact assessments
  • Procedures for individual rights requests
  • Data sharing and processor arrangements
  • Personal data breach response and notification
  • Assessment of international data transfers
  • Awareness material for staff

How we work on this

The same five steps apply to every service, applied here to this work.

  1. Assess

    Establish what personal data you hold, where it flows and why.

  2. Identify

    Identify where practice differs from the law and from your own notices.

  3. Design

    Design records, notices, procedures and assessments that fit your operations.

  4. Implement

    Support rollout to the teams that handle the data.

  5. Monitor & Improve

    Review changes in processing and keep records and notices current.

Who it's for

Discuss your data protection requirements

Tell us what you are working towards and we will advise on where to start.