Private and Cookie PolicyWe use cookies to enhance your experience while using our website. We will take your continued use of our website as consent to our use of cookies.





Data Protection & Regulation

Lupton Fawcett's team of data protection solicitors provide a full range of advice on data protection and regulation.  This is an area with significantly increased relevance to many businesses and other organisations, due to the implementation of the General Data Protection Regulation (GDPR) in May 2018.

This legislation contains some onerous obligations, many of which take considerable time and effort to prepare for.  Non-compliance has serious penalties in the form of fines. The new GDPR maximum fine is €20m, or 4% of an organisation’s global turnover (if higher).

What can Lupton Fawcett do to help? 

We can help you address the steps you will need to take to ensure your GDPR compliance including: 

If you are facing an ICO investigation or associated court hearings we are able to advise and represent you. 

GDPR (EU General Data Protection Regulation) – what it is and key points to consider


Who does the GDPR apply to:

The GDPR applies to “controllers and processors”. The controller is the person who determines the purpose, and the manner in which personal data is processed. The processor acts on the controller's behalf.


What information does the GDPR apply to: 

The GDPR applies to “personal data” but the definition is more expansive to reflect changes in technology and how information on people is collected. 

Personal data such as HR records, customer lists or contact details are all covered by the GDPR. The GDPR applies to both automated personal data and certain manual filing systems. 

Sensitive personal data needs to be treated with extreme caution, and includes raicial or ethnic origin, religious or philosophical beliefs, trade union membership, health data and information about a persons sex life or sexual orientation, genetic and biometric data.


Principles of GDPR 

Under the GDPR the data protection principles set out the main responsibilities for organisations, for example, that data is processed lawfully, is collected only for specified, explicit and legitimate purposes and is accurate and appropriately secure. 

The GDPR introduces an accountability requirement with a focus on the legal basis for processing personal data and transparency. 

You are expected to put into place comprehensive and proportionate governance measures to minimise the risk of breaches and to protect personal data. Practically this will mean policies and procedures for organisations.



The giving of consent is one of the gateways through which a controller can establish a legal basis for processing personal data. 

The definition of "consent" is strict under the GDPR. Consent should be freely given, specific, informed and unambiguous. Implied consent (e.g. not responding to a request) will not be sufficient. 

Consent must be explicit so if consent is to be given in a written document it must be made in a manner which is clearly distinguishable from other aspects of the document.


Data Subject rights 

The GDPR sets out the rights for individuals: 

  • The right to be informed on what data is being processed, typically through a privacy notice which must include detailed information;
  • The right to access their personal data - information must be provided within 1 month;
  • The right to rectification if data is inaccurate or incomplete;
  • The right to erasure: this is known as the “right to be forgotten”. Data subject has the right to require a controller to delete data files if there are no legitimate grounds for retaining them.
  • The right to restrict processing: i.e have the right to block the processing of data, for example when the accuracy of personal data is contested. 
  • The right to data portability: which allows individuals to move, copy or transfer personal data easily between one IT environment to another in a secure and safe manner;
  • The right to object: individuals have the right to object to processing on grounds relating to his or her particular situation unless there are compelling legitimate grounds for processing.
  • Rights relating to automated decision making and profiling: the GDPR provides safeguards for individuals against the risk of a decision being taken without human intervention.  


Data Processors 

The GDPR directly regulates data processors, extending the formal contractual requirements needed between data controllers and data processors. Data processors have a duty to comply and potential liability if they fail.



The GDPR increased responsibility and accountability on organisations to manage how they control and process personal data. This complements the transparency requirements. 

Organisations are expected to put in place comprehensive and proportionate governance measures. The measures include: 

  • Keeping a detailed record of processing operations;
  • Conducting a privacy impact assessment;
  • Designating a data protection officer (“DPO”) if required (this only applies if you are a public authority, carry out large-scale systematic monitoring of individuals, or carry out large scale processing of special categories of data). If appointing a DPO is not a requirement for your organisation you must still ensure someone has the skills to discharge the organisation's obligations under the GDPR;
  • Notifying the Regulator of data breaches. Mandatory notification promptly and at the latest, within 72 hours is a significant new measure imposed by the GDPR. A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data;
  • Implementing “privacy by design and default”. Under the GDPR organisations have an obligation to implement technical and organisational measures to demonstrate that you have considered and integrated data protection into your processing activities.



The regime under the GDPR provides for regulators to impose high financial sanctions, £20m or up to 4% of the annual worldwide turnover of an organisation if higher.

The GDPR is applied consistently across all EU member states thereby creating uniformity of approach in imposing sanctions for breach. 

The significant financial consequences for data security breach under the GDPR requires businesses toimplement clear policies and procedures to mitigate operational risk. 


How Lupton Fawcett can help with GDPR compliance 

  • Audit of your data protection practices 
    • We will visit your premises and interview the key personnel who manage data in your organisation.
    • We will view the physical and digital arrangements that you have for storage of documentation.
    • We will review your key data protection policies, consent forms and other documents.
    • We will review your key data protection statements on your website. 
  • We will provide you with a report of the steps you must take to become GDPR compliant and how you can achieve them
    • Following our audit visit, we will draft a full audit report.
    • We will highlight the areas where you are compliant with data protection legislation.
    • We will highlight any areas where your processes and arrangements fall short of the requirements of the data protection legislation.
    • We will recommend the steps that you should take to ensure that you are fully compliant with the data protection legislation.
  • We can prepare all policies, notices, consent forms etc you will require to ensure GDPR compliance
    • Data protection policies
    • Fair processing notices
    • Consent forms
    • Electronic consent forms/email consent forms/web consent forms
    • Subject access request documentation 
  • We will advise you about your obligations concerning the transfer of data to foreign locations and provide guidance on the steps and limits you must implement to ensure compliance
    • We will review your current contracts and advise on any amendments to be made.
    • Where necessary we will provide further contractual documentation. 

Further Reading

Contact us for help

To speak to a solicitor about our GDPR services or for advice, call us on 0333 323 5292, or download our team sheet. Alternatively, send us an email or complete the form below to let us know that you would like to hear from us.


  • A good summary of the key issues to review further within the organisation

    Lupton Fawcett Logo
    Lupton Fawcett Logo
    Guy Baragwanath Rural Arts North Yorkshire

    Louise was very clear and gave complex information in an easily understood way

    Lupton Fawcett Logo
    Lupton Fawcett Logo
    Collette Ibbotson Yorkshire Adoption Agency
  • This session was perfect as an introduction to what is required of charities to follow GDPR

    Lupton Fawcett Logo
    Lupton Fawcett Logo
    Anya Mathewson Wandesford House Trust

    I found the course to be enjoyable and very informative on what is considered to be quite a dry subject

    Lupton Fawcett Logo
    Lupton Fawcett Logo
    Neil Clarke Titan Interior Solutions
  • Good presentation, enjoyed the subject

    Lupton Fawcett Logo
    Lupton Fawcett Logo
    Susie Maguire St Annes Community Services
  • Guy Baragwanath

    A good summary of the key issues to review further within the organisation

    Rural Arts North Yorkshire
  • Collette Ibbotson

    Louise was very clear and gave complex information in an easily understood way

    Yorkshire Adoption Agency
  • Anya Mathewson

    This session was perfect as an introduction to what is required of charities to follow GDPR

    Wandesford House Trust
  • Neil Clarke

    I found the course to be enjoyable and very informative on what is considered to be quite a dry subject

    Titan Interior Solutions
  • Susie Maguire

    Good presentation, enjoyed the subject

    St Annes Community Services

Get in Touch

With Lupton Fawcett on your side, you're taking control. Contact us today.

Enquiry Form

Please complete this form to make an enquiry and we will get back to you as soon as we can.

Remember you can still call us on 0333 323 5292 or email us at

Get in Touch