– Intelligent-by-Design

Search blog Posts
-
Article 23 — Restrictions on Data Subject Rights and What They Mean for Your Business
Article 23 of the UK GDPR allows certain restrictions on data subject rights — but only in defined cases. Learn when this applies and how your company must respond.
-
When Can You Use Automated Decision-Making? Legal Bases and Safeguards Explained
UK GDPR Article 22 restricts automated decisions — but there are exceptions. Learn when you can use automation lawfully and what safeguards you must have in place. Article 22 of the UK GDPR generally prohibits companies from making decisions based solely on automated processing that have a significant or legal effect on individuals. However, there…
-
What Article 22 Says About Automated Decisions — and Why It Matters
Article 22 of the UK GDPR restricts fully automated decisions that impact individuals. Understand what this means for AI, recruitment tools, and data-driven profiling. As companies adopt automation in everything from hiring to credit scoring, it’s vital to understand the limits imposed by Article 22 of the UK GDPR. This provision protects individuals from being…
-
How to Handle Objections to Direct Marketing Under UK GDPR
Under Article 21 of UK GDPR, individuals can object to direct marketing at any time. Learn how your company must respond — and what compliance looks like in practice. Marketing teams rely on data to reach the right audience — but under Article 21 of the UK GDPR, individuals have an absolute right to object…
-
Understanding the Right to Object Under UK GDPR (Article 21)
The UK GDPR grants individuals the right to object to certain types of data processing. Learn what Article 21 means for your company and how to stay compliant. Companies today rely on data to drive decision-making, marketing, and operational efficiency. But under the UK General Data Protection Regulation (UK GDPR), individuals have the right to…
-
High-Risk Data Uses Under the DUAA — What Triggers Extra Oversight?
Not all data use is equal under the DUAA. Learn how high-risk uses—like AI, profiling, and sensitive data handling—trigger stricter obligations and oversight. The Data Use and Access Act 2025 (DUAA) introduces a risk-based approach to data governance. Certain types of data use are considered high-risk and require additional scrutiny, documentation, and oversight. Understanding what…
-
Obligations for Data Providers and Data Users under the DUAA
The DUAA introduces specific duties for data providers and data users. Learn what your obligations are and how to structure compliant access arrangements and audits. Under the Data Use and Access Act 2025 (DUAA), organisations must meet specific legal and governance obligations based on their role as either a data provider or a data user….
-
Audits, Enforcement, and Penalties Under the DUAA — What Companies Need to Know
Non-compliance with the DUAA can lead to fines, audits, and reputational damage. Learn how enforcement works, what to expect in an audit, and how to avoid penalties. The Data Use and Access Act 2025 (DUAA) introduces a new regulatory framework for how companies share and re-use data. But it doesn’t stop at rules — the…
-
Article 13 vs Article 14 of the UK GDPR: What’s the Difference and Why It Matters
Understand the key differences between Articles 13 and 14 of the UK GDPR, and why your company must tailor privacy notices depending on how personal data is collected. Companies often overlook the difference between Article 13 and Article 14 of the UK GDPR — yet getting this wrong can lead to non-compliance and ICO scrutiny….
-
What Is a DUAA Access Arrangement and When Do You Need One?
An Access Arrangement under the DUAA is a legal requirement for many data-sharing activities. Find out when your company needs one and what it must include. One of the cornerstones of the Data Use and Access Act 2025 (DUAA) is the concept of an Access Arrangement. This formal document governs how data is shared and…
-
Key Definitions and Scope of the Data Use and Access Act 2025 (DUAA)
Understanding the DUAA starts with the basics. Learn the key definitions—like data user, data provider, access agreement—and the scope of the Data Use and Access Act 2025. The Data Use and Access Act 2025 (DUAA) introduces new terminology and a legal framework that complements existing UK data protection law. To stay compliant, organisations must understand…
-
1 of 6: What Is the Data Use and Access Act 2025 (DUAA)?
The Data Use and Access Act 2025 (DUAA) is a landmark UK law that regulates access, sharing, and processing of data across sectors. Learn what DUAA is and how it complements GDPR. The Data Use and Access Act 2025 (DUAA) is a new UK legal framework designed to regulate how organisations access, share, and use…
-
When Can You Refuse a Data Subject Request?
Under GDPR, companies can refuse rights requests that are manifestly unfounded or excessive. Learn when and how to lawfully say no. You can refuse to act on a GDPR request if it’s manifestly unfounded or excessive. This includes: If you refuse, you must: 💡 Tip: Keep a clear record of all refused requests and your…
-
Verifying Identity Before Fulfilling a GDPR Request
You can ask for ID before fulfilling GDPR requests — but only when necessary. Here’s how to verify identity without breaching privacy. The UK GDPR allows companies to request ID if they have reasonable doubts about the identity of the requester. But be careful — asking for too much ID or failing to protect it…
-
Responding to Data Subject Requests: Timelines and Exceptions
Companies must respond to GDPR rights requests within strict timeframes. Here’s what counts as a valid request — and when deadlines can be extended. The default timeline to respond to data subject rights requests (access, erasure, objection, etc.) is one calendar month. You may extend this by two months if the request is: But —…
-
Article 13 vs Article 14 of the UK GDPR: What’s the Difference and Why It Matters
Understand the key differences between Articles 13 and 14 of the UK GDPR, and why your company must tailor privacy notices depending on how personal data is collected. Article 13 vs Article 14 of the UK GDPR: What’s the Difference and Why It Matters Companies often overlook the difference between Article 13 and Article 14…
-
Understanding Automated Decision-Making and Profiling
Under Article 22 of the UK GDPR, individuals have rights related to automated decision-making and profiling. Learn how companies should respond. Article 22 of the UK GDPR gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, if it produces legal or similarly significant effects. This affects: Where…
-
Children’s Data Rights Under the UK GDPR
Children have enhanced data protection rights under UK GDPR. Learn how companies working with under-18s should comply. The UK GDPR gives special protection to children’s personal data. If your company provides services to or collects data from individuals under 18, specific rules apply. Key principles include: These rights tie into the right to be informed,…
-
The Right to Be Informed: What Does Transparency Really Mean?
The right to be informed (Articles 13 and 14 of the UK GDPR) requires companies to explain how they use personal data. Learn how to comply with transparency obligations. Under Articles 13 and 14 of the UK GDPR, individuals have the right to be informed about how their personal data is collected and used. This…
-
The Right to Object: When Can a Company Say No?
Article 21 of the UK GDPR gives people the right to object to certain types of data processing. Learn how your company should handle objections. Under Article 21, individuals can object to processing based on: Once someone objects, you must stop processing unless you can demonstrate compelling legitimate grounds that override their interests. 💡 Tip:…
-
The Right to Data Portability: A Growing Challenge for Companies
Article 20 of the UK GDPR gives individuals the right to receive and reuse their data. Learn how companies should prepare. Article 20 of the UK GDPR allows individuals to receive a copy of their personal data in a structured, commonly used, machine-readable format. This typically applies when: Examples include payroll records, client CRM exports,…
-
The Right to Erasure (Right to Be Forgotten)
The GDPR gives individuals the right to be forgotten in certain cases. Understand what this means for your company. Article 17 of the UK GDPR gives individuals the right to request the erasure of personal data where: However, this isn’t absolute. You may retain data if you need it for legal claims, compliance, or public…
-
The Right to Restrict Processing: What It Means in Practice
Under Article 18 of the UK GDPR, individuals can limit how their data is used. Here’s when and how restriction applies Article 18 of the UK GDPR gives people the right to restrict how their data is used in specific scenarios, such as: During restriction, you may store data but not use it. You must…
-
The Right to Rectification: Keeping Employee and Client Data Accurate
Under GDPR Article 16, individuals have the right to correct inaccurate personal data. Learn how your company can stay compliant. Under Article 16 of the UK GDPR, individuals have the right to request the correction of inaccurate or incomplete personal data. Common requests include updates to: Companies must respond without undue delay, usually within one…
-
Understanding the Right of Access: What Your Company Needs to Know
The UK GDPR gives individuals the right to access their personal data. Here’s what companies need to know about handling Subject Access Requests (SARs) effectively. The UK GDPR gives individuals the right of access under Article 15. This allows people to ask what personal data your company holds about them and request a copy. SARs…
-
DPIAs in Mergers, Acquisitions and Restructures
Data protection risks spike during M&A. Here’s why DPIAs matter in corporate change. Change creates risk — especially where data is concerned. During M&A or restructuring, use DPIAs to: DPIAs ensure privacy is protected even when organisations shift. Privacy IQ supports teams navigating sensitive transitions.
-
Who Should Sign Off a DPIA?
DPIAs aren’t complete until they’re approved — but who’s responsible for sign-off? A DPIA is a formal risk document. It needs input and ownership from the right people: If high risks can’t be mitigated, you may need to consult the ICO before proceeding. Privacy IQ guides teams through sign-off and escalation smoothly.
-
How Long Should You Keep DPIA Records?
DPIAs must be documented — but for how long? Here’s what the UK GDPR says about retention. There’s no legal time limit for DPIA retention, but regulators expect documentation to be available for: Don’t forget: DPIAs should be reviewed if the risk landscape changes. Privacy IQ helps clients set smart DPIA retention and review policies.
-
Using DPIAs to Improve Decision-Making
Go beyond compliance. DPIAs can inform better, more transparent business decisions. DPIAs aren’t just regulatory paperwork — they’re decision-support tools. When used early, they help teams: By identifying blind spots, DPIAs make your business smarter. Privacy IQ helps clients embed DPIAs into every strategic step — not just the risk register.
-
When Is a DPIA Legally Required?
Not every project needs a DPIA — but some must have one. Here’s how to tell. Under the UK GDPR, DPIAs are mandatory in high-risk processing. But what qualifies? Don’t guess — document your justification. Privacy IQ helps clients confidently assess when DPIAs are required — and when they’re just good practice.
-
Your DPIA Template – What to Include
Need a DPIA template? Here are the key sections every template should have to pass scrutiny. A strong DPIA template does more than tick boxes — it supports real insight. At a minimum, yours should include: Privacy IQ supplies templates aligned with ICO guidance, customised for your sector and team maturity.
-
DPIAs and Procurement: Vetting Your Vendors
Discover how DPIAs help assess third-party data risks and strengthen procurement due diligence. Third-party risk is often your biggest blind spot. When onboarding vendors: Good vendors won’t resist — they’ll welcome the structure. Privacy IQ helps clients carry out fast, reliable vendor DPIAs across the supply chain.
-
Top 5 Mistakes Companies Make in DPIAs
Avoid these common pitfalls and improve the effectiveness of your DPIA process. Top 5 Mistakes Companies Make in DPIAs Even experienced teams stumble with DPIAs. Here are the most common issues we see: A weak DPIA leaves you exposed. Privacy IQ ensures your assessments are tailored, actionable, and regulator-ready.
-
Integrating DPIAs into Your Project Lifecycle
Don’t wait until it’s too late. Here’s how to embed DPIAs at the right stages of your projects. Many firms delay DPIAs until just before launch — often too late to change course. Instead, build DPIA’s into your project lifecycle: DPIAs should evolve with your project, not sit in a drawer. At Privacy IQ, we…
-
Can a Data Processor Cause a Breach and are you Still Liable?
You can outsource processing, but not responsibility. Here’s what to do if your vendor causes a breach. If your third-party processor causes a breach, you are still the controller — and responsible under UK GDPR. Key steps to protect yourself: Outsourcing doesn’t mean offloading accountability. Choose vendors who take GDPR seriously.
-
When Is a Data Protection Impact Assessment (DPIA) Required?
Not sure when you need to carry out a DPIA? Here’s how professional services firms can stay compliant and reduce risk. Data Protection Impact Assessments (DPIAs) are a legal requirement under the UK GDPR when processing is likely to result in a high risk to individuals’ rights and freedoms. Common DPIA Triggers in Professional Services…
-
Futureproofing Breach Defences in 2025 and Beyond
GDPR is evolving. Here’s how to keep your breach response fit for the future. The threat landscape is changing. So must your breach defences. For 2025 and beyond, focus on: Compliance is continuous. Regular reviews of your security and response policies are essential to staying protected.
-
Why Documentation Matters in a Breach
Failing to document a breach, even if not reportable, could still cost you. Here’s what you must log. UK GDPR Article 33(5) requires you to document all breaches — whether or not they are reported to the ICO. Each record should include: This record must be made available to the ICO if requested. Good documentation…
Let’s discuss how PrivacyiQ can help you reduce risk, strengthen compliance, and drive strategic value
