Data Protection and Process Advice
Most questions about data protection aren’t dramatic. They’re the day-to-day ones: what information can we collect, how long can we keep it, is this contract clause actually protecting us, what do we do when someone asks for their data. We help businesses answer them.
![]()
Whether you’re a start-up getting your terms right first time or an established business checking that a supplier’s contract actually protects you, the same thing matters: the advice has to fit how you work, not how a template assumes you do. We do a lot of this for technology businesses in particular, where data protection needs to be built in rather than bolted on.
We help you understand what personal data you collect, why you hold it and what the law expects you to do with it. That shows up everywhere: in your privacy notices, your customer and supplier terms, your internal policies, and in how you handle access requests, retention and breach response when they come up.
We regularly review and draft:
- data processing agreements
- data sharing agreements
- data protection policies
- subject access request procedures
- data breach procedures
- the key data protection clauses in your contracts
- acceptable use policies
- technology contracts
- the data protection side of employment issues
If you share data outside the UK, whether that’s within the EEA or further afield, there are extra requirements to meet. We can advise on those arrangements and put the right paperwork in place, including EU standard contractual clauses, the UK addendum and international data transfer agreements.
Data protection doesn’t stand still. The technology changes, the rules change and the business changes with them. A review will often turn up policies that have drifted out of date or contradict each other, and we can help you keep everything current as you go.
A data protection clause is only worth having if it does something when you need it to. We check that it does.
We work with businesses on the routine questions and the tricky ones: a founder writing terms and conditions for the first time, or a company sending customer data to a supplier overseas. Whichever is closer to yours, here’s where our data protection work applies.
If you’re not sure which of these fits your situation, call us, and we’ll point you in the right direction.
