Can a Data Processor Cause a Breach and are you Still Liable?
|

Can a Data Processor Cause a Breach and are you Still Liable?

You can outsource processing, but not responsibility. Here’s what to do if your vendor causes a breach. If your third-party processor causes a breach, you are still the controller — and responsible under UK GDPR. Key steps to protect yourself: Outsourcing doesn’t mean offloading accountability. Choose vendors who take GDPR seriously.

A hooded figure engaged in hacking using a laptop and smartphone in low light.
| |

Who Needs to Be Told? Notifying Data Subjects After a Breach

Should you notify individuals after a breach? UK GDPR requires it if their risk is high. Here’s how to assess that. If a data breach is likely to result in a high risk to the rights and freedoms of individuals, you must inform them without undue delay. High-risk examples: Your message should: Clear and timely…

Diverse professionals engaged in strategic discussion in a law office setting.
| | |

Who Owns Data Retention in Your Organisation?

Is it IT? Legal? HR? Retention needs ownership — or it becomes a shared blind spot. Here’s how to assign responsibility. Without a clear owner, data retention becomes everyone’s responsibility — and no one’s priority. Ownership models that work: Either model can work — but only if: Assigning ownership turns policy into practice. Without it,…

A collection of vintage floppy disks showcasing retro data storage technology.
|

Backups Aren’t Exempt From GDPR – Here’s Why That Matters

Think your backup server doesn’t count? Think again. GDPR applies to all personal data, including archives. Retention policies often focus on live systems, but forget one major risk: backups. Backups containing outdated or deleted personal data can still put you in breach of UK GDPR, especially if: What to do: GDPR applies whether data is…