It has now been over five years since the GDPR (General Data Protection Regulation) came into force – and with it a major shift in what was expected of organisations when it comes to data protection compliance.

Although the GDPR was originally a European regulation, the standards and principles it set out have been transposed into UK law through the Data Protection Act 2018, which introduced a new UK GDPR.

Since then in the intervening period, employers have navigated the COVID pandemic and massive changes to the way we work with the increase in hybrid working, which has inevitably led to changes in the way they hold and utilise data. From our experience advising clients on their data protection compliance obligations over these last five years, here are our top tips when it comes to managing data protection issues in the workplace:

We often say that compliance is a journey, not a destination. It requires an ongoing commitment and if the team at Burness Paull can help you along the way please do not hesitate to get in touch. In particular, now might be a good time to consider carrying out an organisation-wide privacy audit / compliance “health check” through our newly established Data Protection Consultancy practice. If that sounds of interest, you can contact us here to arrange a time to discuss further.

For further information on how we can assist with any subject access request queries, please see here.

Written by

Related News, Insights & Events

Error.

No results.

Neurodiversity At Work – Building Inclusive Workplaces

Neurodiversity at Work – Building Inclusive Workplaces

29/04/2026


We invite you to join us for a practical and engaging session on neurodiversity in the workplace.

Read more
A Business’S People Are Its Greatest Asset – And One Of Its Biggest Risks

A business’s people are its greatest asset – and one of its biggest risks

23/03/2026

Employees are a business’s greatest asset but can become a major risk if talent is lost, disengaged, or hard to replace.

Read more
Is The Definition Of “Personal Data” Having An Identity Crisis

Is the definition of “personal data” having an identity crisis?

26/02/2026

The definition of “personal data” has been subject to recent scrutiny in both the EU and the UK.  In this article, we explore some of the recent case law and commentary in both the UK and the EU.

Read more

Want to hear more from us?

Subscribe here Subscribe here