Skip to content
Subject Access Requests in 2026: What the Updated ICO Guidance Means

INSIGHTS & NEWS

Subject Access Requests in 2026: What the Updated ICO Guidance Means

The Data (Use and Access) Act 2025 codified the reasonable and proportionate search standard. Deadlines, identity checks, exemptions, redaction and a 30-day workflow.

Operations9 min read
AI Web Scraping Under GDPR: What the EDPB's 2026 Guidance Means
Regulatory8 min read

Latest articles

AI Web Scraping Under GDPR: What the EDPB's 2026 Guidance Means

Publicly available does not mean freely usable. What the EDPB's draft Guidelines 03/2026 require before scraping personal data to train generative AI.

Read more →
Anonymised or Still Personal Data? The EDPB's New Three-Part Test
Regulatory8 min read

Latest articles

Anonymised or Still Personal Data? The EDPB's New Three-Part Test

Removing names does not make data anonymous. How to apply the three-part test in draft Guidelines 02/2026: no record isolation, no linkage, no inference.

Read more →
EU AI Act: Where Data Controllers Stand After the 2026 Omnibus
AI Act6 min read

Latest articles

EU AI Act: Where Data Controllers Stand After the 2026 Omnibus

The EU has finalised the AI Act simplification package, moving high-risk deadlines to Dec 2027. What deployers and controllers should do now.

Read more →
Cookie Compliance: 5 Evidence Gaps Auditors Keep Finding
Web Compliance5 min read

Latest articles

Cookie Compliance: 5 Evidence Gaps Auditors Keep Finding

CMP logs, consent scope, dark patterns, and what “proof” looks like in practice across EU/UK guidance.

Read more →
Vendor Risk in SaaS: SCCs, TIAs & Practical Controls
Vendor Risk7 min read

Latest articles

Vendor Risk in SaaS: SCCs, TIAs & Practical Controls

How to operationalise vendor reviews without slowing teams down — a tiered approach that works.

Read more →
DPIA Done Right: Risk Triggers Your Teams Will Actually Use
Operations6 min read

Latest articles

DPIA Done Right: Risk Triggers Your Teams Will Actually Use

Turn DPIAs into a lightweight guardrail — where they sit in tickets, PRs, and launch checklists.

Read more →
Security Baselines Every Privacy Programme Should Adopt
Security6 min read

Latest articles

Security Baselines Every Privacy Programme Should Adopt

From hardening and identity to logging and encryption — privacy-by-design in action.

Read more →
Outsourced DPO: What “Good” Looks Like
DPO5 min read

Latest articles

Outsourced DPO: What “Good” Looks Like

Scope, independence, reporting lines and cadence — what to expect from an effective DPO engagement.

Read more →
Company Formation: KYC Evidence Clients Forget
Company4 min read

Latest articles

Company Formation: KYC Evidence Clients Forget

A short checklist to avoid back-and-forth with banks and corporate service providers.

Read more →

Turn insights into action.

If one of these topics is live on your roadmap, we can turn it into a concrete plan — with regulator-ready evidence from day one.