Alex Goodman writes every article here. He is a data protection consultant with over ten years of practice across financial services, SaaS, healthcare, and the charity sector.
The topics come from the questions UK businesses ask: how to respond to a subject access request, what to do in the first 72 hours of a data breach, whether you need a named DPO, and how to handle UK GDPR without a full-time compliance team.
The answers are in plain English.
An employee sends a subject access request in the middle of a grievance, disciplinary or tribunal claim. What you must search, what you can hold back, the 2026 DUAA changes, and the mistake that got a director convicted.
Yes, UK businesses can email existing customers without consent, but only under PECR's soft opt-in and only if 4 conditions are met on every send. Here is what the rules say, where businesses fail, and what the ICO now fines.
The EU AI Act reaches UK businesses whose AI output is used in the EU. The high-risk deadline moved to December 2027, but the transparency rules and fines went live on 2 August 2026. Here is what UK SMEs need to check now, under both the EU Act and UK GDPR.
Just received a subject access request? A practical guide from an outsourced DPO on what starts the one-month clock, what you must provide, what you can legally withhold, and what the ICO does when you miss the deadline.

Driven by expertise and personalised service, we’re here to guide you towards GDPR compliance every step of the way.
Business
Services
Socials
Documentation
© 2026 - GDPR Consultant - All Rights Reserved.

Alex Goodman is an experienced GDPR consultant and outsourced Data Protection Officer working with UK businesses to improve their DPO and GDPR compliance.
Business
Services
Socials
Documentation
© 2026 - GDPR Consultant - All Rights Reserved.