Protecting your data, protecting your organisation
We take the time to understand how your organisation works and what data you handle. That insight means we can shape our advice around your needs, whether you’re responding to a request, reviewing a privacy notice or planning a new project involving personal data.
Policy and procedure drafting
We draft, review, and update data protection policies, internal procedures, and privacy notices for a wide range of audiences, including employees, job applicants, customers and pupils. Whether you need new documents or a review of what you already have, we’ll make sure everything is clear, compliant, and up to date.
Subject access requests
Responding to subject access requests can take time and and resource-intensive. We can handle the full process for you, from assessing complexity and refining search criteria to reviewing documents applying exemptions, and undertaking redactions.
Freedom of information requests
We are able to advise public authorities on complex Freedom of Information (FOI) and Environmental Information Regulations (EIR) requests. We can help you decide whether disclosure is required and support you in drafting clear, legally sound responses.
Data Protection impact assessments
We’ll help you decide when a data protection impact assessment (DPIA) is needed and guide you through the process from start to finish. We can also assess whether your data processing is likely to result in a high risk to individuals and whether you’ll need to consult the Information Commissioner’s Office (ICO).
Data protection agreements
We draft and review a wide range of agreements, including both data sharing agreements (controller to controller and joint controller) and data processing agreements (controller to data processer). We make sure your agreements are robust, readable, and reflect your legal responsibilities under UK data protection law.
Subject access requests
Practical support for managing data subject access requests, including advising on validity and scope, redacting and applying exemptions under the UK GDPR, and Data Protection Act 2018. Guidance also covers improving internal processes, handling complex requests, and managing correspondence with the ICO to reduce risk and maintain compliance.
Personal data breaches
Data breaches can happen in any organisation. We’ll help you determine whether a personal breach has occurred and, if needed, support you with the reporting process to the ICO (as well as other regulatory bodies) and the individuals affected. We act quickly and carefully to minimise risk and ensure compliance.
Marketing compliance
Marketing activity is heavily regulated under UK data protection law. We can help you shape marketing campaigns (both B2B and B2C) and strategies that are targeted and effective without crossing compliance lines. If you’re unsure what the rules are, we’ll talk you through your obligations and review your plans to keep you on track.
Website compliance
Support to help your business comply with UK GDPR and PECR, ensuring your website meets legal requirements from the day one. Advice covers cookie notices, website privacy notices, and supporting policies, giving you confidence that your digital presence meets regulatory standards and reduces risk.
Need an expert in
data privacy
?
For more information or a no obligation discussion, please call or email our team today.
-min.avif)


