Category: Guides
Guides are our evergreen, practical references on AI governance and data protection – written to answer a specific question an organisation is actually facing, from “what should an AI system register record?” to “how do we respond to a subject access request without over-disclosing?”. Each guide opens with a direct answer, works through the practical detail in plain language, and reflects UK GDPR, the Data Protection Act 2018, and current regulatory guidance. They are written for the people who have to implement this – senior teams, compliance leads, and those who hold data protection or AI oversight alongside another role – and are kept under review as the law and guidance develop. For shorter commentary and opinion, see our articles.
Legitimate Interests vs Consent: Getting the Lawful Basis Right
Consent and legitimate interests are both valid lawful bases under UK GDPR, but work very differently. Here’s when each is the right fit, and what goes wrong when the wrong one is chosen.
How to Respond to a Subject Access Request Without Over- or Under-Disclosing
A subject access request entitles someone to a copy of their personal data. Here’s how to scope the response correctly, what the “provide a copy” standard actually means, and when data can be withheld.
What Happens When an AI Tool Gets Something Wrong?
An AI incident response process sets out what happens when an AI tool gets something wrong. Here’s what counts as an incident, who to report it to, and how it connects to data breach response.
Who Should Sign Off a New AI Tool Before It Goes Live?
Deployment sign-off is the checkpoint before an AI tool moves into regular use. Here’s who should have sign-off authority, what to check, and why it needs to be more than a one-off approval.
What Does a UK GDPR-Compliant DPIA Actually Look Like?
A DPIA is a legal requirement for high-risk processing under UK GDPR. Here’s what a compliant one actually covers, who needs to be involved, and the most common mistake organisations make.
What Should an AI System Register Actually Record?
An AI system register records every AI tool an organisation uses, what it’s for, and who’s accountable. Here’s what fields to include and how to find out what’s actually in use.
How to Carry Out an AI Risk and Impact Assessment
An AI risk and impact assessment identifies what could go wrong with a tool before it goes live, and what controls are needed. This walkthrough covers what to assess, who to involve, and what to do with the result.
Outsourced DPO vs In-House: What’s the Real Difference?
An outsourced DPO provides the independent oversight required under UK GDPR without the cost of a full-time hire. Here’s how outsourced and in-house DPO arrangements actually differ, and how to decide which fits your organisation.
Does My Organisation Need an AI Acceptable Use Policy?
An AI acceptable use policy sets out which AI tools staff may use, for what purposes, and with what data. Most organisations need one, because staff are already using AI tools whether or not there’s a policy in place.
Data Breach Response Plans: A Compliance-Driven Guide
A personal data breach is any security incident affecting personal data. This guide sets out a straightforward, UK GDPR-compliant approach to detecting, assessing, notifying, and documenting a breach.