-
Posted in:
How FCA and Data Protection Complaints Handling Intersect?
After nearly two decades in compliance, I have come to the conclusion that FCA complaints and data protection complaints have more in common than most people realise. Before anyone starts drafting an objection, I am not suggesting they are the same thing. They aren’t. They are covered by different laws. They involve different rights, create…
-
Posted in:
Social Media Data Collection: Protecting Customer Data
Social media is everywhere, in healthcare, finance, education, retail, and government. If your organisation uses platforms like Instagram, LinkedIn, TikTok, or Facebook, you are almost certainly handling personal data. That means you must follow data protection laws like the GDPR and the Privacy and Electronic Communications Regulations (PECR), along with, where relevant, the EU AI…
-
Posted in:
The UK Children’s Data Protection: What’s Law, In Power, and Still a Policy in 2026
Over the past year, UK policymakers have moved decisively to strengthen the legal framework protecting children’s personal data online. Rather than arriving as a single, sweeping reform, the changes have come through several parallel channels: primary legislation, secondary powers not yet exercised, statutory guidance, and government policy announcements that sit outside the legislative process altogether. …
-
Posted in:
The Rise of Operational Risks without AI Governance in 2026
Most organisations are still talking about artificial intelligence (AI) risks in day-today operations as though it is something coming in the future. The reality? It is blatantly here! For many businesses, AI is omnipresent, whether leadership teams fully realise it or not. That is why the recent direction coming out of the UAE is so…
-
Posted in:
The Data Use and Access Act (DUAA) Compliance Risks and Checklist
There is a lot of noise around the Data (Use and Access) Act (DUAA) at the moment. New requirements. More guidance. Plenty of “what’s changed” summaries. But the real shift is not what’s been added. It is what is now being expected. Because DUAA does not completely change the rules. It changes how closely those…
-
Posted in:
Data Privacy Day: Risks to Avoid in 2026
Most people have no idea that this day exists. There is no countdown, fireworks, or public holiday. There will be, however, cake in my office, which feels like a reasonable and proportionate response from a DPO. It falls on 28 January every year, and not because of GDPR, fines, or cookie banners (we are all…
-
Posted in:
GDPR History: 2016 – 2026 Evolution
When Did GDPR Come Into Effect? Key Dates in GDPR History GDPR is 10 years old this year, and I am 10 years older. We have both seen things (including botox and motherhood.) So, apparently GDPR is turning 10 this year. TEN. A full decade. Which is a tad scary, because I still remember explaining…
-

Posted in:
Egypt’s PDPL | 2026 Updates & Guide
Egypt’s Personal Data Protection Law (PDPL) is the country’s primary framework governing how organisations collect, use, store, transfer, and protect personal data relating to individuals in Egypt. It applies to organisations operating inside Egypt, as well as organisations outside Egypt that process the personal data of individuals located there. At its core, Egypt’s PDPL is…
-
Posted in:
UAE’s Child Digital Safety Law: 2026 Guide for Organisations
From 1 January 2026, it is essential organisations offering online services to users in the UAE, pay closer attention to how children may use those services. This follows the introduction of Federal Decree-Law No. 26 of 2025 on Child Digital Safety, which makes it clear that child digital safety is an organisational responsibility, not something…
-
Posted in:
Securing a VARA Licence in Dubai
For organisations seeking a VARA licence in Dubai, compliance is not limited to financial or technical readiness. It is now a critical requirement for any business operating in Dubai’s virtual assets ecosystem. Data protection, governance, and DPO independence are now core licensing requirements, particularly for firms operating across the UAE, Saudi Arabia, and the wider…
-
Posted in:
Digital Accessibility Compliance for Organisations
Thursday, 15 May, is Global Accessibility Awareness Day (GAAD) and serves as a timely reminder that if your website, app, or platform isn’t usable by everyone, you are not just falling short on inclusion. You might be falling short on data protection compliance, too. It is easy to think of digital accessibility requirements as a…
-
Posted in:
A DPO’s Guide to Password Protection
On World Password Day 2025, observed on May 1st, let’s reflect on one of our most basic yet crucial lines of defence…..the password protection. And let’s be honest, we’ve all been there… “Password123”, “pet’s name” or even default credentials such as “admin.” These practices significantly weaken your security posture and expose your organisation’s sensitive systems…
