Biometrics and Data Protection
As organisations increasingly adopt biometric technologies for identity verification, access control, and workplace monitoring, ensuring compliance with data protection law is critical. This practical course provides clear, real-world guidance on how to benefit from the advantages of biometric technologies while managing regulatory, operational, and reputational risk. Drawing on the latest requirements under the UK GDPR, […]
Special Category Data – Getting it Right
The rules of data protection provide prominent and significant restrictions on the collection, storage and use of certain special categories of personal data, over and above the protections for ordinary personal data. The failure by organisations to correctly use such “special category personal data” – which include information about people’s health, sexual orientation, sex life, […]
Children’s Data – Practical Compliance for Organisations
Many organisations process personal data on children, some inadvertently or peripherally. The legal requirements for processing children’s data are critically important for organisations to understand due to regulators’ current laser focus on this area for enforcement action. This course provides a comprehensive examination of the legal, practical, and operational responsibilities involved in handling children’s personal data, giving organisations the […]
Records Management 3: Operating & Sustaining the Programme
Records Management 3 looks at how to operate and sustain a records management programme. Topics covered include: information governance dealing with risk records management policy development embedding good records management practice records migration and dealing with legacy records digital continuity – managing electronic records over time Delegates who attend the Classroom sessions are encouraged to […]
Records Management 2: Designing & Implementing a Programme
This course examines how to implement good records management practice. Led by Claire Johnson, Records Management 2 studies the implementation of a records management programme, building on the concepts and principles covered in Records Management 1. The topics covered in Records Management 2 include: introduction – initiating a records management project records audit process mapping […]
Records Management 1: Essential Concepts & Principles
Organisations face increasing pressure to manage their records according to statutory and business requirements. As the use of electronic records and the deployment of electronic document and records management systems continue to increase, the core skills of the person responsible for records management become ever more important to the organisation. In many cases, appropriate data […]
FOI Practical Training – Level 2 (Applying the Exemptions)
Public sector bodies must make daily decisions on how to respond to requests for information under the Freedom of Information Act, and how to apply the exemptions in the Act. Those decisions are increasingly reviewed and, in many cases, overturned by the Information Commissioner, the Information Tribunal and the Courts. As case law develops, public […]
Understanding the Environmental Information Regulations
The Environmental Information Regulations 2004 (‘EIRs’) cover a wide range of information requests, many of which can wrongly be assumed to fall under the Freedom of Information Act. While the scope of the EIRs does include information about the most directly “green” environmental functions of the public sector, it is not restricted to them, and […]
FOI Practical Training – Level 1 (Essential Knowledge)
Since the Freedom of Information Act 2000 came fully into force in 2005 there has been a fundamental change in the relationship between government and its citizens as government information has become more publicly accessible. This has led to the publication of a wide range of public sector information and dramatic expansion of available information. […]
Training Staff in Data Protection
Having responsibility for training staff on data protection issues can be a daunting prospect. Yet it is essential that all staff who handle personal information understand the fundamental principles and the practical requirements for complying with data protection rules. It is also important that staff members are able to identify breaches or potential breaches of […]
Marketing & Data Protection
Marketing and promotion can be a vital tool in increasing sales, encouraging engagement with a product or brand, or the promotion of aims and ideals. Many tools used in this process are individualised, with the aim of reaching those people most likely to respond. Where these tools use or utilise identifiable information about people, there […]
International Data Transfers – Overcoming the Limitations
UK data protection law restricts the transfer of personal data to countries outside the UK. The restriction, together with fast-moving developments to the rules, can present a challenge for international commerce, global data processing and international outsourcing activities. This course provides a practical approach to the different mechanisms available to comply with the data protection […]
How to Conduct a Data Protection Audit
Data protection audits are invaluable for organisations in assessing their current state of data protection compliance. They can identify where the organisation is getting things right, as well as reveal where there are weaknesses or risks of non-compliance which require action or changes to internal procedures. Regular audits or compliance reviews can assist with risk […]
Handling Subject Access Requests
The right of access is a fundamental right of individuals under data protection law. Organisations can face challenges in dealing effectively with the exercise of the right (a subject access request or ‘SAR’), including in identifying requests, searching for personal data, and applying exemptions. This course looks at the requirements for SARs set out in […]
FOI and Data Protection – How They Work Together
The competing demands of Freedom of Information and Data Protection legislation in the UK present challenges for all public bodies involved in collecting, holding and disclosing personal information. Understanding the interface between Freedom of Information laws (including the Environmental Information Regulations 2004) and the General Data Protection Regulation is essential for all those involved with […]
Data Sharing in the Public Sector
The sharing of personal data in the public sector grows constantly, as new opportunities are identified to improve public services through the sharing of information about individuals. Given the implications for privacy, a thorough understanding of how the data protection regime applies to data sharing is increasingly important for public authorities, as they negotiate and […]
Data Security & Cyber Security
Data protection law requires that personal data must be kept secure, with severe financial penalties and adverse publicity as possible consequences for organisations that fail to do so. Organisations must consider the myriad ways in which personal data could become compromised, accessed, altered, used or deleted and take appropriate measures to prevent this. The threat […]
Data Protection in the Workplace
Meeting the requirements of data protection law whilst handling staff data effectively can be challenging. Holding and using staff information carries significant legal responsibilities and risks. This invaluable one-day session is designed to meet the needs of anyone who has responsibility for the use of employee and other worker data, including Human Resources Officers and […]
Data Protection Essential Knowledge – Level 2
This practical training session is designed for those that work in the field of data protection. The Level 1 and Level 2 courses taken together constitute a complete training package on the fundamentals of data protection. Following the latest guidance and requirements set out in the UK GDPR and Data Protection Act 2018, this session […]
Data Protection Essential Knowledge – Level 1
This course is an introductory-level course for all those that are new to data protection, or those that require a refresher on the fundamental concepts. It is designed for people who work with, or will work with, data protection issues on a regular basis. Following the latest guidance and requirements set out in the UK […]
Data Protection by Design & Default
Data protection by design requires organisations to take steps to ensure that personal data processing activities are designed to comply with data protection law and protect the rights of data subjects. Data protection by default requires that the default position for any data processing activity should be to carry out the minimum amount of processing. […]
Data Protection – Rights of Individuals
Individuals have a range of rights under data protection law, which aim to give them some control over use of their data, and to stop unlawful or unnecessary processing. Organisations must facilitate the exercise of rights and take action when receiving requests from data subjects. It is important for organisations to understand the parameters of […]
AI & Data Ethics
The advent and rise of the use of AI and the lack of primary legislation in the UK governing its deployment has left many scratching their heads when asked by their organisations how it and other novel processing activities should be rolled out in a compliant way. While technology and its possibilities continue to race […]
Cybersecurity for Data Protection Professionals
Breaches of information security are consistently one of the top reasons for regulator enforcement action, with fines for security breaches usually higher than for other types of data protection law breaches. The average global data breach cost now stands at over $4 million, and the threat landscape has evolved significantly, with criminal organisations forming complex […]
Controllers and Processors – Handling the Relationship
When a controller appoints a processor, both the controller and processor have obligations under data protection law. A controller may only use processors providing sufficient data protection guarantees, and remains responsible for compliance with the data protection principles in relation to a processor’s use of data. The processor must follow the controller’s instructions in relation […]
Conducting Data Protection Impact Assessments
Data Protection Impact Assessments (DPIAs) enable organisations to assess potential risks to individuals at the design stage of a new system or activity involving the use of personal data. Such risks can then be addressed within the development of the system or activity, rather than being a “bolt-on” after implementation (when it may be too […]
Breach Management – Preparing for the Worst
A personal data breach can have a significant impact on an organisation, including exposure to regulatory fines, claims for compensation and damage to reputation. For most organisations, it is now a question of when a breach will occur rather than if. Organisations are legally required to notify a personal data breach to the relevant data […]
Accountability – Achieving Compliance
All organisations must be “accountable” for their data protection compliance measures. In basic terms, accountability means that in addition to actually complying with the requirements of data protection law, organisations must also demonstrate that they comply. Demonstrating compliance consists of several elements, including preparing policies, monitoring compliance with internal policies and procedures, amending job roles […]
Data (Use & Access) Act – Implementing the Changes
The Data (Use and Access) Act 2025 updates the UK’s post-Brexit data protection framework. In addition to data protection law changes, the Act has implications that extend beyond data protection and privacy in that it aims to support growth, trust and engagement with the digital economy and improve delivery of public services, as well as […]
AI & Data Protection
The UK Government’s stated vision is to foster a pro-innovation approach to AI regulation while ensuring the concept of fairness is embedded into its deployment and use. The ICO has stated publicly that it supports this approach and will work with the other members of the Digital Regulatory Cooperation Forum to avoid regulatory overlap, gaps […]