Business

GDPR & Data Protection

Data protection that is proportionate to the business: the documentation regulators actually ask for, and a plan for the day something goes wrong.

What I handle

Clear advice for complex decisions.

Compliance, data subject rights, breach response and dealings with the Commissioner.

  1. 01

    GDPR compliance audits

  2. 02

    Privacy policies and notices

  3. 03

    Data processing agreements

  4. 04

    Data Protection Officer guidance

  5. 05

    CCTV and workplace monitoring

  6. 06

    Breach notification and response

  7. 07

    Data subject access requests

  8. 08

    Commissioner investigations

Why work with me

Experience where it matters. Direct access throughout.

30 years

Judgement formed through three decades of demanding legal work.

Personal attention

I remain responsible for your matter, its strategy and every communication.

Prompt and proportionate

Fast answers, focused work and clearly discussed fees.

Questions, answered

Before we begin.

Does my business need a Data Protection Officer?

It depends on the scale and nature of your processing. Many businesses do not, but must still document why not.

What must I do after a data breach?

Assess the risk immediately — notification to the Commissioner carries a 72-hour deadline where the threshold is met.

Can I use CCTV in my workplace?

Yes, within limits. Purpose, proportionality, signage and retention all have to be justified in advance.

Related insights

Recent thinking for this practice area.

View all insights
The Data Protection Impact Assessment (DPIA).

GDPR & Data Protection

The Data Protection Impact Assessment (DPIA).

Introduction. The GDPR under Article 35 introduces the concept of a Data Protection Impact Assessment (“DPIA”). DPIA is a process designed to describe the processing, assess its necessity and proportionality and help manage the risks to the rights and freedoms of natural persons resulting from the processing of personal data by assessing them and determining… Read More

You are being watched! The GDPR and the use of CCTV systems.

GDPR & Data Protection

You are being watched! The GDPR and the use of CCTV systems.

Introduction. At a time when technology, including smart cameras, allows companies to collect much more sensitive information about individuals, more stringent supervision of the protection of personal data is certainly needed. The General Data Protection Regulations (GDPR), which will apply throughout the European Union from May 2018, will therefore affect camera system operators. A video… Read M

What is the "controller"and what is the "processor" under the GDPR.

GDPR & Data Protection

What is the "controller"and what is the "processor" under the GDPR.

Introduction The GDPR imposes to the Controllers new data protection obligations. Further, in a change from previous legislation, processors have new statutory obligations in their own right under the new Regulation. But what is a “controller” or a “processor”? Controller According to Article 4 of the GDPR controller means: “the natural or legal person, public… Read More

Direct advice. Prompt response.

Your matter deserves senior attention from the start.

Book a consultation