THINKING · ACCEPTABLE RISK

Data Privacy in Practice

Privacy as an operating discipline: evidence, accountability, rights, complaints and the organisational consequences of getting the reality wrong.

The useful questions are practical. What evidence exists? Who owns the response? Where does customer confidence depend on demonstrable governance rather than policy language?


  • Complaints Handling Becomes a Real Governance Control

    When the Freedom of Information Act came into force, I was brought in to build and manage an internal audit team for a large government agency. The FOI compliance picture wasn’t the reason I was there. It emerged during the audit. Requests that had been missed entirely. Others within days of breaching the statutory deadline.…

    Read

  • What GDPR Actually Ask For

    Most GDPR programmes spend too much time producing artefacts and not enough time proving judgement. Somewhere along the way, privacy compliance became a document factory. Another policy. Another register. Another DPIA filed in a folder nobody opens. But that is not what the law asks for. UK GDPR asks for something more practical and more…

    Read