Any organisation that processes personal data is expected to remain accountable for how it uses and safeguards that data. Clear and proportionate data protection practices are increasingly required by customers, partners and regulators, particularly in data‑driven and technology‑enabled transactions.

I assist clients in establishing and maintaining GDPR‑compliant data protection frameworks, including:
My aim is to help organisations demonstrate accountability while keeping compliance manageable and aligned with their size and risk profile.
Clear and accurate documentation is a cornerstone of data protection compliance. I assist with:
This work is particularly relevant for businesses operating online or providing digital and technology‑enabled services.
Understanding how personal data flows through an organisation is critical for compliance and risk management. I advise on:
These exercises are often closely linked to broader technology, AI and process‑design decisions.
International transfers of personal data remain a complex and evolving area of GDPR compliance. I assist clients with:
This is particularly relevant for cloud‑based services, international groups and technology providers.
Where required or commercially desirable, I provide regulated support services, including:
External appointments can offer flexibility and expertise without the burden of internal resourcing.
Advised an international software and technology business on personal data protection compliance in connection with data‑driven digital services, with a particular focus on the protection of children’s personal data. The work involved analysing heightened GDPR obligations, designing appropriate safeguards and transparency measures, and addressing complex risk and accountability considerations arising from the processing of minors’ data within scalable technology platforms.
Advised a UK‑based data and advertising‑technology company on GDPR compliance in the context of complex data‑sharing and data‑supply arrangements, including structuring contractual safeguards, assessing data protection risk and aligning data‑processing practices with the commercial use of proprietary datasets.
Act as external data protection officer for a provider of an online platform offering tools to streamline client onboarding processes, regularly assisting with the preparation, review and maintenance of privacy documentation, internal policies and governance measures to ensure ongoing compliance with applicable data protection rules.
Participated in advising an international internet governance organisation on GDPR compliance and the anonymisation of publicly accessible records, including assessment of technical and organisational measures to mitigate privacy risks.
and make something big