GDPR Workshop

13 November 2024

Hybrid - Online / Crewe

The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR).
Everyone responsible for using personal data has to follow strict rules
called ‘data protection principles’. They must make sure the
information is:

• Used fairly, lawfully and transparently
• Used for specified, explicit purposes
• Used in a way that is adequate, relevant and limited to only what is
• Accurate and, where necessary, kept up to date
kept for no longer than is necessary
• Handled in a way that ensures appropriate security, including
• Protection against unlawful or unauthorised processing, access, loss,
destruction or damage

There is stronger legal protection for more sensitive information, such as:

• Race
• Ethnic background
• Political opinions
• Religious beliefs
• Trade union membership
• Genetics
• Biometrics (where used for identification)
• Health
• Sex life or orientation

The workshop provides a basic insight into aspects of:

• What is personal data.
• An introduction / recap on the GDPR and data protection
• The key principles that organisations must comply with.
• An introduction to lawful bases (legal reasonings for processing
personal data): explore personal data processed by the
organisation and brainstorm how lawful bases will apply.
• The rights that individuals have with regards to their own personal
data and what organisations must do to meet those rights.
• An introduction to “Subject Access Requests” – perform a live
example of how an organisation would actively deal with an
information request compliantly from an initial correspondence to
• Data breach; an introduction, stats, and examples.
• How to respond to a data breech
• Data breech prevention.
• Impacts of non-compliance.

To book your place on this workshop, please fill in the booking form on the right and send it to

