It has now been over five years since the GDPR (General Data Protection Regulation) came into force – and with it a major shift in what was expected of organisations when it comes to data protection compliance.

Although the GDPR was originally a European regulation, the standards and principles it set out have been transposed into UK law through the Data Protection Act 2018, which introduced a new UK GDPR.

Since then in the intervening period, employers have navigated the COVID pandemic and massive changes to the way we work with the increase in hybrid working, which has inevitably led to changes in the way they hold and utilise data. From our experience advising clients on their data protection compliance obligations over these last five years, here are our top tips when it comes to managing data protection issues in the workplace:

We often say that compliance is a journey, not a destination. It requires an ongoing commitment and if the team at Burness Paull can help you along the way please do not hesitate to get in touch. In particular, now might be a good time to consider carrying out an organisation-wide privacy audit / compliance “health check” through our newly established Data Protection Consultancy practice. If that sounds of interest, you can contact us here to arrange a time to discuss further.

For further information on how we can assist with any subject access request queries, please see here.

Written by

Related News, Insights & Events

Error.

No results.

The Progression Of The Employment Rights Bill

The progression of the Employment Rights Bill

17/12/2025

In this blog, we focus on the progression of the Employment Rights Bill, including the changes to unfair dismissal, parental and paternity leave, statutory sick pay, and harassment reforms.

Read more
Indefinite Leave To Change The Ongoing Saga Over Earned Settlement

Indefinite leave to change: the ongoing saga over “earned” settlement

17/12/2025

This article unpacks Reform UK's announcement about its plans to scrap indefinite leave to remain entirely.

Read more
Pension Scheme Trustees (002)

A good data be a trustee?: what does the Data (Use and Access) Act 2025 mean for pension schemes?

16/12/2025

The new Data (Use and Access) Act 2025 (DUAA) introduces some significant changes to UK data protection law since the GDPR. Its reforms have a direct impact on scheme governance and member experience.

Read more

Want to hear more from us?

Subscribe here Subscribe here