EXPERTISE

Data & Privacy

Most businesses treat data protection as a paperwork exercise: template policy documents they are required to have on file. It holds up until someone tests it: a regulator enquiry, a breach, or a major customer's due diligence team asking how personal data actually moves through the business. That's when the gap between the policy and the practice becomes expensive.

We advise on the data protection issues that determine whether a business can use data the way it wants to. That means using personal data commercially without breaching GDPR, and structuring international data transfers correctly. It also means keeping AI systems that process personal data compliant, and making sure supplier and processor contracts put liability where it belongs.

Our consultant partners have advised media businesses, healthcare organisations and technology companies handling personal data internally and through data-heavy products, on exactly these issues, bringing in-house counsel backgrounds and direct experience of how regulators and major customers scrutinise this in practice.

THIS COVERS

  • GDPR compliance: practical compliance that stands up to scrutiny, not just a policy on file
  • International data transfers: structuring transfers so they hold up under UK and EU rules as the business operates across borders
  • AI and data: training data, automated decision-making and profiling handled compliantly as AI gets built into products
  • Data subject access requests: handling DSARs within the statutory timeframe, without exposing more than the request requires
  • Data breach response: a clear plan for what happens and who does what if something goes wrong
  • Vendor and processor agreements: contracts that put liability where it belongs when a third party handles your data

Whether you need to build a privacy programme, respond to an incident, or want ongoing strategic oversight, we’re happy to talk through how we can help.

START A CONVERSATION →
← BACK TO EXPERTISE OVERVIEW