Insights.

Plain-English coverage of UK data protection news, the Data (Use and Access) Act 2025, and what it means for your organisation.

DutySME

The 30-day complaints duty: no exemptions, no exceptions

Every UK organisation must have a way to take data protection complaints and must acknowledge them within 30 days. It applies whether you employ five people or five thousand. Here is what you actually need in place.

1 June 20263 min read
Insights

Goodbye ICO, hello Information Commission: what changes for you

The Information Commissioner's Office is being reshaped into the Information Commission, run by a board rather than a single commissioner. Here is what is changing, what is staying the same, and why it should not change anything you do today.

4 May 20263 min read
GuidesSME

Cookies just got easier: the consent exceptions explained

Some low-risk cookies no longer need a consent pop-up. The ICO finalised its guidance on 29 April 2026. Here is what is now exempt, what still needs consent, and how to update your banner without getting it wrong.

30 April 20263 min read
Insights

The Reddit fine: why children's data is everyone's problem now

The ICO fined Reddit £14.47m over children's data and weak age checks. Even if you are nowhere near social media, the case signals how the regulator now thinks. Here is what it means for any business that might collect data from under-18s.

30 March 20263 min read
Duty

A simpler reason to use data: recognised legitimate interests

There is an additional lawful reason to use personal data, and for a short list of purposes it skips the usual balancing test. Here is what 'recognised legitimate interests' covers and where the shortcut does and does not apply.

23 March 20263 min read
Duty

Letting software decide: automated decisions under UK GDPR

The old near-ban on fully automated decisions about people has been replaced by a system of safeguards. If you use software or AI to make decisions about customers or staff, here is what changed and what you must now put in place.

9 March 20263 min read
Guides

Subject access requests: you can now stop the clock

When someone asks for a copy of their data, you usually have one month to respond. You can pause that month while you confirm who they are or check what they want. Here is how the 'stop the clock' rule works in practice.

16 February 20263 min read
Investigations

Inside the regulator's new approach to fines

The regulator has been overhauling how it decides fines, including offering discounts for settling early. Here is what the new approach means, and why cooperating quickly is now worth real money.

12 February 20263 min read
Guides

Sending data abroad: the 'data protection test' explained

If your business uses cloud tools or suppliers based abroad, your data is travelling. New guidance from January 2026 introduces a clearer 'data protection test'. Here is what it means without the jargon.

19 January 20263 min read