Data Protection

private ai for uk businesses a cube vault single doorway

Private AI for UK Businesses: How to Use LLMs Without Exposing Company Data

The general, all-sector answer to the question every UK business is now asking: how do you get the benefit of large language models without feeding them things you are paid to protect? This guide defines what private AI actually means, maps the five deployment levels from business-tier chatbots to fully self-hosted open-weight models, sets the UK GDPR and confidentiality position, prices a 20-person worked example across all four buyable routes, covers RAG without exposure, the NCSC and OWASP security layer, vendor due diligence in eight questions, and finishes with a 90-day rollout plan.

Read more
sharepoint for accountancy firms secure client document management a document wallet raised tab

SharePoint for Accountancy Firms: Secure Client Document Management

How a UK accountancy practice should design and secure client documents in SharePoint Online — the seven-site architecture that replaces one site per client, the metadata columns that replace folder trees, a group-based permission model with restricted access control on anti-money laundering evidence, the four external sharing settings and why Anyone links break your device policies, sensitivity labels and data loss prevention for client data, retention to Regulation 40 of the Money Laundering Regulations 2017, version limits and the 93-day recycle bin, Copilot oversharing controls, Microsoft’s own hard limits, UK licence costs with a worked forty-one person example, and a thirty-day build calendar.

Read more
automated decision-making - automated decision making under the duaa a branching decision node

Automated Decision-Making: Essential DUAA Rules to Avoid Risk

Section 80 of the Data (Use and Access) Act 2025 deleted Article 22 of the UK GDPR and replaced it with Articles 22A to 22D, commenced on 5 February 2026. The prohibition became a permission with conditions: for ordinary personal data you may now make solely automated significant decisions, provided you notify the individual, accept representations, provide genuine human intervention and allow a contest. This guide sets out the two-part test, what the ICO now means by meaningful human involvement, the special category data rules that did not relax, where automated decisions hide inside ordinary business software, the EU divergence that catches exporters, the evidence pack a regulator will ask for, seven failure patterns and a 60-day plan.

Read more
duaa compliance checklist uk smes a upright grooved slab

DUAA Compliance: Essential SME Checklist to Avoid Costly Fines

The Data (Use and Access) Act 2025 is fully commenced and there is no small-business exemption from the parts that matter. This checklist is written for the firm with no data protection officer and one person watching the shared inbox: a three-question scoping test, the five-item baseline every UK controller must meet, the conditional duties that only fire for some businesses, the new universal complaints procedure and its 30-day clock, the cookie audit behind a PECR ceiling that rose from £500,000 to £17.5 million, automated decisions hiding inside off-the-shelf SaaS, an honest hour-and-cost budget, the nine-artefact evidence pack, seven small-business failure patterns, and a ninety-day plan with owners.

Read more
duaa uk gdpr changes what changed for businesses a three ascending rounded pillars

DUAA UK GDPR Changes: Essential Guide to Avoid Costly Risk

The Data (Use and Access) Act 2025 edits UK data protection law rather than replacing it, which is why a summary is less useful than a diff. This guide sets the pre-2026 position beside the current one across lawful basis and the new Annex 1 recognised legitimate interests, the repeal of Article 22 and the safeguards in Articles 22A to 22D, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day clock, and the three narrow cookie exemptions behind a PECR ceiling that rose from £500,000 to £17.5 million. It then translates every change into the document you edit, the team that owns it, a 90-hour effort register, a UK-versus-EU divergence table, and a ninety-day plan.

Read more
data use and access act 2025 a three ascending rounded pillars

Data Use and Access Act 2025: Essential UK Risk Checklist

The main data protection provisions commenced on 5 February 2026, the mandatory complaints procedure followed on 19 June 2026, and the maximum PECR penalty rose thirty-five-fold to £17.5 million. This guide sets out exactly what is in force, what is still pending, and what each change obliges a UK business to do differently: the commencement timetable tied to its statutory instruments, recognised legitimate interests and the direct-marketing trap underneath them, the repeal of Article 22 and the new Articles 22A to 22D on automated decision-making, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day acknowledgement clock, the three narrow cookie exemptions and why the analytics one is narrower than it looks, renewed EU adequacy to December 2031, what the Act pointedly did not change, and a sequenced six-step remediation plan for the rest of 2026.

Read more
ai procurement checklist a three interlocking rings

AI Procurement Checklist: Essential Guide for Safe Buying

Buying AI is not like buying a database. The product changes after you sign, your data may never come back, and legal, security and IT each see a different danger. This guide sets out a complete AI procurement checklist for all three teams, organised the way a purchase actually moves: intake and triage, three parallel reviews, evidence instead of assurances, scoring with three possible outcomes, and the contract clauses worth arguing over. It covers training rights, output ownership, retention limits, prompt injection, model provenance, cost ceilings and exit paths, plus how to keep the whole process fast enough that nobody bypasses it.

Read more
supplier contract security requirements a shield emblem on hexagonal plinth

Supplier Contract Security: Essential Clauses to Avoid Risk

Most contracts dispose of security in a single sentence promising “appropriate technical and organisational measures”, which gives you no notification deadline, no evidence rights and no route to terminate when the supplier is breached. This guide sets out the cybersecurity requirements worth writing into supplier agreements: the standards and certification scope to specify, the core control clauses, the UK GDPR processor terms that are statutory rather than optional, incident notification and cooperation, audit and evidence rights, subcontractor flow-down, exit and data return, liability and insurance, and the three-tier model that keeps the whole programme proportionate across a real supplier base.

Read more
cyber due diligence mergers acquisitions a magnifying glass on plinth

Cyber Due Diligence in M&A: Essential Guide to Avoid Risk

Financial diligence values the earnings and legal diligence values the contracts, but neither tells a buyer whether the target has been quietly compromised for eight months. This guide sets out proportionate cyber due diligence on a real transaction: what the exercise actually covers, the four ways weak review destroys deal value, the five phases from scoping to costed reporting, the data room evidence list and what its absence proves, the red flags that justify repricing, how deal size and sector change the scope, the mapping from findings to price adjustments, warranties, indemnities and conditions, the first hundred days after completion, who should run the exercise and what it costs, and the mistakes that keep repeating.

Read more
passkeys vs mfa replace business passwords a hexagonal shield fingerprint

Passkeys vs MFA: Proven Guide to Stop Password Risk

Adversary-in-the-middle phishing kits now defeat one-time codes and push approvals routinely, which is why the multi-factor authentication you deployed in 2020 is no longer doing the job you think it is. This guide compares passkeys and traditional MFA by the attacks each one actually stops, explains how origin binding makes a passkey unphishable, sets out the parts of a typical application estate that cannot accept a passkey yet, costs the migration in service desk time and hardware, and gives a staged rollout plan that ends with weak factors switched off rather than left as a fallback.

Read more
CHAT