LEGAL, REGULATORY & COMPLIANCE CONSULTANTS

Handley Gill Limited

Our expert consultants at Handley Gill share their knowledge and advice on emerging data protection, privacy, content regulation, reputation management, cyber security, and information access issues in our blog.

Let the cookie crumble…

As the Information Commissioner warns websites they have 30 days to achieve cookie compliance or face regulatory enforcement action, Handley Gill’s specialist data protection consultants advise on how to ensure that the Information Commissioner’s appetite for enforcing cookie compliance under PECR isn’t a recipe for disaster for your organisation. While amending your cookie banner is a bitter pill to swallow, your website won’t be toast and you can avoid having to eat humble pie.  

Read More
Practical mAgIc: a practical guide to deploying AI safely, responsibly & ethically

To coincide with the AI Safety Summit on 1-2 November 2023, Handley Gill hosted an official AI Fringe event ‘practical mAgIC: a practical guide to deploying AI safely’ addressing the measures organisations using – or considering using – AI should be taking to use AI responsibly, ethically and in alignment with their ESG goals. This post includes a recording of the webinar and access to resources and materials referenced therein, in particular Handley Gill’s AI CAN (AI Capability & Needs Analysis) tool to assess your organisational readiness to adopt AI responsibly and our checklist on using AI responsibly, safely & ethically.

Read More
It’s a fine life

Handley Gill’s specialist data protection consultants respond to the Information Commissioner’s consultation on its draft Data Protection Fining Guidance, which will replace relevant parts of its Regulatory Action Policy (2018) relating to when the issue of a monetary penalty notice is appropriate and the approach to calculating any fine.  

Read More
The Bill with the Holes?

Handley Gill’s consultants consider the new Artificial Intelligence (Regulation) Bill, which would establish the AI Authority, impose a requirement to make regulations on AI Responsible Officers (AIROs) and impose notification and compliance obligations in relation to training data.

Read More
Non-sequitur

Handley Gill’s specialist data protection consultants consider the conclusions and implications of the College of Policing’s review of Lancashire Constabulary’s handling of the investigation into the disappearance of Nicola Bulley for the processing of personal data for law enforcement purposes by police forces and other competent authorities under Part 3 Data Protection Act 2018.

Read More
King's Speech 2023

Handley Gill’s consultants highlight and consider the content of the King’s Speech at the State Opening of Parliament 2023, and the implications for those with an interest in data protection, privacy, freedom of expression, online safety, cyber security, broadcasting and VOD regulation, digital markets regulation and/or artificial intelligence.

Read More
PSNI Blues

Reflecting on the reprimand issued by the Information Commissioner against the Police Service of Northern Ireland (PSNI) for unlawfully transferring personal data processed for the law enforcement purposes under Part 3 Data Protection Act 2018 to the USA, Handley Gill’s consultants identify the elements of a compliance programme that would mitigate against such incidents and have produced a downloadable pdf illustrating each lawful basis for transferring personal data processed under Part 3 DPA 2018 overseas.

Read More
Feeling safer already?

The grant of Royal Assent to the Online Safety Act 2023 on 26 October 2023 starts the countdown to Ofcom’s Roadmap to Regulation for user-to-user services, search services, video sharing platforms and services with pornographic content. Handley Gill’s consultants have produced a visual timeline of Ofcom’s proposals for the implementation of the Online Safety Act 2023.

Read More
Barely recognisable?

Handley Gill Limited’s consultants respond to the Information Commissioner’s consultation on the draft Biometric Data Guidance Phase 1. We call for clarity on the circumstances in which the deployment of biometric recognition technologies will be considered to be lawful, particularly in the context of employment and the workplace, confirmation that a Data Protection Impact Assessment (DPIA) will always be required when deploying biometric recognition technologies and inclusion of the benefits and risks of biometric recognition. Finally, we argued for greater clarity about the requirements for further processing of special category biometric data.

Read More
Britain's Got Talent's Got Problems

Handley Gill Ltd’s specialist consultants provide initial comment and analysis on The Sun’s report of David Walliams’ data protection claim against one of the co-producers of ITV’s Britain’s Got Talent, Fremantle Media, including the nature of the claim, potential defences and the sums being claimed. The claim arises from the the leak of a transcript of comments made by Walliams on set to The Guardian in November 2022.

Read More
UK-US data bridge open for traffic

Handley Gill’s specialist data protection consultants consider the implications of The Data Protection (Adequacy) (United States of America) Regulations 2023 (SI 2023/1028) for data exporters subject to the UK GDPR conducting personal data transfers from the UK to the USA and what action should be taken.  

Read More
Sifting Out Data Protection Rights?

The Government has prepared a draft statutory instrument, The Data Protection (Fundamental Rights and Freedoms) (Amendment) Regulations 2023, to amend the UK GDPR and Data Protection Act 2018, and laid it before the Sifting Committees. The SI would re-define post-Brexit the definition of fundamental rights and freedoms in data protection legislation. Handley Gill’s specialist data protection consultants consider the implications of the SI for the enforcement of data protection rights across the UK.

Read More
AI Bootcamp Part I

In Part 1 of our 5 part Artificial Intelligence (AI) Bootcamp, we consider the terms and concepts needed to understand what AI is and how it works, including the difference between AI and machine learning, and what is meant by generative AI, LLMs, foundation models, neural networks and deep learning. In Parts 2-4 of our AI Bootcamp, we will consider the risks of developing, using and even not using AI, while in Part 5 of our AI Bootcamp, we will focus on AI regulation.

Read More
On Hand July 2023

July 2023 edition of Handley Gill’s monthly digital newsletter, with all the latest developments in data protection (UK, EU and global), cyber security, AI and machine learning, content regulation, open justice, access to information, reputation management and digital markets regulation. Presented in a readily digestible digital format, those who prefer the traditional newsletter format can export the newsletter to pdf.

Read More
So you’ve been debanked…

Handley Gill’s data protection consultants consider the implications of the data subject access request (DSAR) submitted by Nigel Farage in the context of his de-banking dispute with Coutts & Co and its parent company Natwest, and advise how individuals can make a data subject access request (DSAR).

Read More
Certify...certify me!

Handley Gill’s specialist data protection consultants consider the options and certification requirements for US entities importing personal data from the EEA following the adoption of the European Commission’s adequacy decision in respect of the Trans-Atlantic EU-US Data Privacy Framework, providing a lawful basis for transferring personal data to the US under the GDPR.

Read More
Freedom from the tyranny of supplementary measures

Handley Gill Limited’s specialist data protection consultants consider the impact of the European Commission’s adequacy decision in respect of the Trans-Atlantic EU-US Data Privacy Framework and the steps controllers and processors should take in relation to transfers of personal data from the EEA and UK to the USA.

Read More
Licence to hack?

Home Office Minister Lord Sharpe has confirmed that, following intensive lobbying by pockets of the cyber security industry, the government intends to pursue the introduction of a statutory public interest defence to the offences under the Computer Misuse Act 1990 (‘CMA’). Handley Gill Limited’s consultants consider the implications for cyber resilience, the protection of personal data and IP, and the ability of law enforcement to prosecute offences.

Read More