Where security controls meet legal obligation
Good security isn't automatically good data protection, and vice versa — but they need to be talking to each other. I advise on the overlap: where Article 32's "appropriate technical and organisational measures" actually lands for your systems, and how to evidence it.
Ask about security adviceAreas of focus
Security & privacy alignment
Making sure technical security controls actually satisfy the "appropriate technical and organisational measures" requirement under Article 32.
Data breach response
Incident response support and guidance on the 72-hour ICO notification requirement, including drafting notifications.
Security policy review
Reviewing access control, encryption, retention and third-party security policies for consistency with your data protection obligations.
Vendor & supply chain risk
Assessing the security posture of processors and sub-processors as part of due diligence and DPA review.
A note on scope
This isn't penetration testing or technical security auditing — for that, you want a specialist security firm, and I'm glad to help you interpret their findings against your data protection obligations once you have them. What I offer sits one layer up: making sure the security decisions your engineering and IT teams make are ones you can defend from a data protection standpoint, too.
Need security and data protection advice that actually agree with each other?
Tell me what's prompted the question — an incident, an audit, a new system — and I'll tell you honestly how I can help.