12/07/2026

Just because you can doesn’t mean you should…

The biggest data protection risk? It’s certainty.


The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions.


They’re the ones convinced they’re already compliant.


Whether it’s a multinational or a start-up, the mistakes are remarkably similar:


Collecting data because they can, not because they need to. Data has become a commodity, and “just in case” is still one of the biggest GDPR failures.


Treating consent as a cure-all. Consent is only one lawful basis and, in many contexts, it’s the wrong one. Worse still, invalid consent gives a false sense of security.


Seeing compliance as paperwork. A privacy notice, a DPIA or a Record of Processing Activities is not compliance. They’re evidence of thinking. If the thinking isn’t there, the paperwork won’t save you.


Building products before asking legal or privacy questions. Privacy by design is not a slogan. Retrofitting compliance is invariably slower, more expensive and often impossible.


Assuming security equals privacy. You can have world-class cyber security and still process personal data unlawfully. Encryption cannot fix an unlawful purpose.


Forgetting that trust is an asset. Customers rarely see your internal governance. They judge you by how you treat their information when things go wrong.


The most mature organisations I’ve worked with don’t ask, “Can we use this data?”


They ask, “Should we?”


That single change in mindset is often the difference between organisations that merely comply with the law and those that earn lasting trust.

Leave a comment

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…