Archives

Howard Freeman

ESA’s 2nd Batch Publication

The three European Supervisory Authorities (EBA, EIOPA, and ESMA – the ESAs) have published a second batch of policy products under the Digital Operational Resilience Act (DORA). This batch consists of four final draft regulatory technical standards (RTS), one set of...

Creating an AI Policy

If you are considering integrating AI into your business? Are you not sure where to start, or how to navigate the challenges? Fear not, you are not alone. That statement is not helpful I know, but don’t worry, we are very helpful indeed! Many organisations...

Data Processing Agreements and why you need them.

Whenever a controller uses a processor, there must be a written contract in place. The contract is important so that both parties understand their responsibilities and liabilities. The UK GDPR sets out what needs to be included in the contract. If a processor uses...

What is a data protection officer?
What is a data protection officer?

Find out what the data protection officer role involves and who or what you need to hire. The General Data Protection Regulations (GDPR) is something you've heard a lot about, whether you collect, store and use customer data, or you don't. It's the biggest...

The Data Protection Act 2018
The Data Protection Act 2018

On 25th May 2018 when the GDPR came into force, the European regulation attracted all the headlines. However, another price of regulation also came into law which acted differed from the EU GDPR. The Data Protection Act of 2018 is strewn with references to the GDPR...

GDPR Adoption…the reality
GDPR Adoption…the reality

It is almost four and a half years since the GDPR became enforced in May of 2018. Since that date, when the world went mad over consent, subscriptions and other connection requests that most of the requestors ignored, we have had Harry and Megan, Brexit, Covid-19 and...

What is the cost of PCI DSS Compliance?
What is the cost of PCI DSS Compliance?

The PCI DSS (Payment Card Industry Data Security Standard) compliance is not easy or inexpensive. In fact, depending on the size of your organisation and the complexity of your CDE (cardholder data environment), it could take months and cost tens of...

Yodel Hack – Parcel Delivery Delays
Yodel Hack – Parcel Delivery Delays

The delivery service company Yodel has suffered a “cyber incident” resulting in widespread disruption. Customers awaiting deliveries noted that Yodel’s systems were offline last weekend. Yodel said: “We are working to restore our operations as quickly as possible but...

Meta (Facebook) Fined £14 Million

Meta has been fined €17 million for twelve breaches of the EU GDPR. The company, formerly known as Facebook, violated several GDPR (General Data Protection Regulation) requirements. More than 30 million people have been affected. The Irish DPC (Data...

Special Categories of Data

What is special category data? Found out here. Special category data is personal data that needs more protection because it is sensitive.In order to lawfully process special category data, you must identify both a lawful basis under Article 6 of the UK GDPR. You also...

Six Data Privacy Mistakes every company makes

Does the following sentence sound familiar?  “I have read and accepted the privacy policy.”  This checkbox is found beneath various online forms. It’s completely superfluous. There is no need to accept a privacy policy because it merely serves an informational...