News

Credit

Category name

9 September 2026

The European Union Artificial Intelligence (EU AI) Act, the General Data Protection Regulation (GDPR) and data protection rights: what UK organisations need to know

By Clare Chatfield, Information Governance Manager A practical guide to when the EU AI Act may affect UK organisations. This post explains when the European Union Artificial Intelligence Act[1] (EU AI Act) may matter for UK organisations, especially where artificial intelligence (AI) involves personal data, EU users, EU customers or EU-facing services.  It focuses on […]

Read more

Suryadhityas via Unsplash
25 August 2026

DfE Data Breach Raises Phishing Risk for Further Education Colleges

By Clare Chatfield, Information Governance Manager Further education colleges are being urged to remain vigilant following reports of a cyber incident affecting the Department for Education’s (DfE) online customer help desk and Turing Scheme portal. According to reports, around 607,000 records were exposed during the incident. The affected data is understood to include professional contact information […]

The Night Picket, George Newnes Ltd (active since 1891) and Muirhead Bone (1876–1953) and Country Life Ltd (active since 1897), Royal Albert Memorial Museum & Art Gallery via ArtUK
20 August 2026

Who’s watching me?

Neighbour Disputes, CCTV, Privacy and Domestic Surveillance By Sue White, Head of Information Law Services Recent headlines about a dispute involving the chairman of WH Smith and a neighbour over CCTV cameras highlight an issue that is becoming increasingly common across the UK. As smart doorbells, home security cameras and rural surveillance systems become more sophisticated, […]

Wilhelm Gunkel via Unsplash
13 August 2026

Why Transparency continues to matter: Following the money in our public services

By Jess Pembroke, Director of Information Law Services As our new Prime minister talks about social care funding in recent weeks,[1] it’s incumbent upon him to look to end the scandal that is companies taking excessive profits from any of our public services. “Care is costly in the UK, with 70 per cent of local authority […]

11 August 2026

Data Protection Essentials

By Cleo Everett, Information Services Coordinator Data Protection is a topic which is ever evolving. You can feel confident with applying the main principles one day, yet the next, you may be asked a question about the UK GDPR, or receive a complex DSAR to review, and suddenly it all seems daunting once again. In my […]

Read more

A storm of thunder and lightning, rain, wind and floods threaten an ancient town on the sea-coast; representing conflict. Engraving by S. à Bolswert after Sir P.P. Rubens. Wellcome Collection.
6 August 2026

Your CRM Provider Has Had a Data Breach. What Should Museums Do Next?

By Jess Pembroke, Director of Information Law Services Many people working in the museum and heritage sector will have seen the recent cyber security incident affecting Client Relationship Manager (CRM) provider Beacon[1]. When a supplier experiences a security incident, the immediate reaction is often uncertainty. Museums and other cultural heritage institutions will want to know whether […]

5 August 2026

Most Data Protection Challenges Are Not Legal Challenges. They’re People Challenges.

By Jess Pembroke, Director of Information Law Services A hot topic now is  whether AI will replace jobs and in particular, can an “AI agent” do the same as my role? Will people come to me with questions or just ask a chatbot? If you are seeking information about data protection, there have always been plenty […]

First World War: The Surgeon Rear Admiral Visiting a Ward at the Royal Naval Hospital, Haslar by Jan (Godfrey Jervis) Gordon, presented by the Imperial War Museum, via ArtUK
30 July 2026

Access is not Permission

By Clare Chatfield, Information Governance Manager Introduction Recent data protection incidents are a timely reminder that not every data breach begins with a cyberattack.  Sometimes the risk comes from inside the organisation, where staff have legitimate access to systems but use that access for reasons unrelated to their role. This post looks at why “access” […]

23 July 2026

Introducing NKA Professional Support: A New Annual Subscription for Copyright and Data Protection Expertise

By Adrian Gibbs, Business Development Director Understanding Copyright and staying compliant with Data Protection legislation can be a challenge for any organisation. Whether you are digitising collections, publishing content, or managing personal data, having access to trusted expert advice is more important than ever. That is why Naomi Korn Associates is delighted to launch NKA Professional […]

Read more

Aideal Hwa via Unsplash
20 May 2026

AI adoption is accelerating – but are we keeping sight of the risks?

By Jess Pembroke, Director of Information Law Services I’ve written before about how the responsibility for AI governance is increasingly falling to information governance and data protection professionals often by default rather than design. As organisations move quickly to adopt AI tools, it is frequently Information Governance/Data Protection teams who are asked to interpret legal obligations, […]

Mediamodifier via Unsplash
22 April 2026

Small Fine, Big Message: Is the ICO fining the public sector again?

By Jess Pembroke, Director of Information Law Services When the ICO fined Police Scotland £66,000 in December 2025, it was easy to focus on the public sector penalty. However, the notice reveals organisations often overlook the real-world effects of poor data handling these decisions affect actual people in deeply personal ways. The victim chose to speak […]

Two merchants and a woman at a table; representing arithmetic. Etching by C. Schut after himself. Wellcome Collection.
9 April 2026

Reddit’s £14.47m Lesson: Complete a Data Protection Impact Assessment (DPIA)!

By Jess Pembroke, Director of Information Law Services In February 2026, the Information Commissioners Office (ICO) issued a £14.47 million monetary penalty to Reddit for serious UK GDPR failings relating to children’s personal data. There are lots of issues highlighted in the Monetary Penalty Notice (now the ICO have published it!) these include that Reddit: But […]

Page 1 of 13

Older »