Loading

List of mandatory documents required by the GDPR

The documentation of processing activities is a new legal requirement under the EU GDPR (General Data Protection Regulation). Documenting your processing activities can also support good data governance, and help you to demonstrate your compliance…

GDPR: Data transfers outside the EU – what…

This blog has been updated to reflect industry developments. Originally published Jan 04, 2018. The EU General Data Protection Regulation (GDPR) restricts transfers of personal data to countries outside the EEA. These restrictions apply to…

Hotel giant Marriott to be fined £99m for…

Marriott International is to be fined £99.2 million for a massive data breach that it disclosed last year. The penalty, levied by the ICO (Information Commissioner’s Office), relates to a cyber attack that occurred in…

What is data protection by design and default

If your organisation is subject to the GDPR (General Data Protection Regulation), you’re probably aware of your requirement to “implement appropriate technical and organisational measures” to protect the personal data you hold. An essential principle…

How Ireland became Europe’s data protection watchdog

When the GDPR (General Data Protection Regulation) took effect a year ago, it promised to overhaul the EU’s data protection landscape. Things have moved a little slower than expected for most member states, but that’s…

The GDPR: A year in review

A year ago this week, the GDPR (General Data Protection Regulation) took effect, promising to revolutionise information security. To mark the anniversary, we gathered a panel of data protection experts to discuss the effect of…

Loading

HMRC forced to delete 5 million voice records…

HMRC (HM Revenue and Customs) has been told to delete more than five million people’s voice records after it was discovered that the way the information was collected breached the GDPR (General Data Protection Regulation).…

How to write a GDPR data protection policy…

A version of this blog was originally published on 6 February 2018. The GDPR (General Data Protection Regulation) isn’t just about implementing technological and organisational measures to secure the information you store. You also need…