ICO enforcement analysis, DUAA commentary, sector briefings, compliance how-tos — written for the people who actually need to make data protection work, not for the people who write about it.
The Data (Use and Access) Act 2025 takes effect on 19 June 2026. Most public commentary has overstated the scale of change. The detail matters: complaint handling is the genuine new obligation, transparency rules tighten, and the rest is incremental. A briefing for SME data owners on what to action and what to ignore.
Read the full piece →Pieces are published roughly monthly. Each one is something I would otherwise be saying in a client conversation — written down so the answer is consistent and the reasoning is preserved.
Analysis of ICO reprimands, monetary penalties, and enforcement notices. What the regulator actually does, calibrated against what the regulator says.
The Data (Use and Access) Act 2025 in detail. What has changed, what is coming, what to action now and what to wait on.
Step-by-step guidance on the practical compliance tasks — DSAR handling, breach response, DPIA construction, ROPA maintenance.
Sector-specific data protection challenges and how to handle them — healthcare, financial services, charities, recruitment, education.
One email per month — the regulatory developments that actually matter to UK SMEs, in five minutes of reading. No marketing, no upsell, no follow-up sequence. Cancel any time.
Subscribe via the intake form →