Guides & Learning
Legitimate Interests vs Consent: Getting the Lawful Basis Right
Consent and legitimate interests are both valid lawful bases under UK GDPR, but work very differently. Here’s when each is …
How to Respond to a Subject Access Request Without Over- or Under-Disclosing
A subject access request entitles someone to a copy of their personal data. Here’s how to scope the response correctly, …
What Happens When an AI Tool Gets Something Wrong?
An AI incident response process sets out what happens when an AI tool gets something wrong. Here’s what counts as …
Who Should Sign Off a New AI Tool Before It Goes Live?
Deployment sign-off is the checkpoint before an AI tool moves into regular use. Here’s who should have sign-off authority, what …
What Does a UK GDPR-Compliant DPIA Actually Look Like?
A DPIA is a legal requirement for high-risk processing under UK GDPR. Here’s what a compliant one actually covers, who …
What Should an AI System Register Actually Record?
An AI system register records every AI tool an organisation uses, what it’s for, and who’s accountable. Here’s what fields …
How to Carry Out an AI Risk and Impact Assessment
An AI risk and impact assessment identifies what could go wrong with a tool before it goes live, and what …
Outsourced DPO vs In-House: What’s the Real Difference?
An outsourced DPO provides the independent oversight required under UK GDPR without the cost of a full-time hire. Here’s how …
Does My Organisation Need an AI Acceptable Use Policy?
An AI acceptable use policy sets out which AI tools staff may use, for what purposes, and with what data …