Data protection insights, UK GDPR updates, NHS information governance news, and practical compliance guidance from our team of practitioners.
NHS England has updated the Data Security and Protection Toolkit for 2025/26. We break down the new mandatory assertions, changes to the cyber security area, and what evidence you need to gather before the June submission deadline.
Folelse Team
Folelse
Subject Access Requests are the most common data protection complaint to the ICO. We look at the five most frequent mistakes organisations make — from missing the one-month deadline to over-redacting — and how to build a compliant process.
Folelse Team
Folelse
The ICO issued significant fines in 2025, with marketing opt-outs and cyber security failures the leading causes. We analyse the enforcement trends and what your organisation should prioritise.
Folelse Team
Folelse
The eighth Caldicott Principle — that patients should be informed about how their data is used — is often the hardest to operationalise. We explore practical approaches to transparency notices, fair processing, and the National Data Opt-Out.
Folelse Team
Folelse
When a personal data breach occurs, you have 72 hours to notify the ICO if it is likely to result in a risk to individuals' rights and freedoms. But what counts as a notifiable breach, and what information do you need to provide?
Folelse Team
Folelse
UK GDPR Article 28 requires a written contract with every data processor. Yet many organisations still rely on out-of-date DPAs or haven't reviewed them since 2018. Here's how to audit and remediate your supplier register.
Folelse Team
Folelse
The Record of Processing Activities is the backbone of UK GDPR compliance. An ICO investigation will go straight to your ROPA. We share what inspectors look for and how to build a register that withstands scrutiny.
Folelse Team
Folelse
NHS England is migrating from the legacy Smartcard system to CIS2, the new Care Identity Service. We explain what the transition means for identity assurance, role-based access controls, and your organisation's access policies.
Folelse Team
Folelse
We've launched a new real-time compliance dashboard giving DPOs and SIROs an instant RAG status view across all compliance areas — plus one-click exportable board reports in PDF.
Folelse Team
Folelse
Subscribe to our monthly newsletter for UK GDPR updates, DSPT deadlines, ICO enforcement news, and product updates.
No spam. Unsubscribe at any time. See our Privacy Policy.