Get a good background to data protection law and view practical guidance focused on data protection matters for commercial transactions. See also our UK GDPR compliant pro-party clauses for use in commercial agreements.
Protect trade secrets and know-how using the law of confidentiality. Get information and a set of pro-party confidentiality agreements here.
View a range of trackers to enable horizon scanning and monitoring of key developments. The trackers are maintained - making them useful for keeping up-to-date and for business development.
It’s our online practical guidance product for contentious and non-contentious lawyers dealing with Data Protection, Confidential Information, Privacy, Cybersecurity and Freedom of Information issues.
The Information Commissioner's Office (ICO) has fined LastPass UK Ltd £1.2m following a 2022 data breach that compromised personal information of up...
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to...
The Information Commissioner's Office (ICO) has updated its main Subject Access Request (SAR) guidance following the Data (Use and Access) Act, 2025...
The Information Commissioner’s Office (ICO) has warned that people trying to access their care records are being systematically failed, citing...
The Information Commissioner's Office (ICO) has updated its guidance on the right of access under UK General Data Protection Regulation (GDPR) to...
Autonomous and connected vehicles—data protection and privacy issuesThis Practice Note considers the following data protection, privacy and security...
Data protection for pensions lawyersThis Practice Note provides an overview of the key provisions and requirements of the UK’s data protection regime...
DeedsUnder English law, legally binding agreements can be made orally, in writing or by deed.This Practice Notice considers the circumstances in which...
Personal data sharing between controllersFORTHCOMING CHANGE: On 19 June 2025, the Data (Use and Access) Bill received Royal Assent, becoming the Data...
Image rights—protection, exploitation and taxationFORTHCOMING CHANGE: it was announced at Budget 2025 that the government will legislate in Finance...
Rights in databases—training materialsThese training materials consist of template PowerPoint slides that can be used as the basis of one or more...
Template agreement—mutualThis Agreement is made on [date]Parties1[insert name of Party A][ of OR a company incorporated in [England and Wales] under...
Rights of data subjects—list of precedentsThe following Precedents relating to the rights of data subjects under the United Kingdom General Data...
Confidentiality agreement—mutualThis Agreement is made on [date]Parties1[insert name of party] [of [insert details ] OR a company incorporated in...
Confidentiality agreement—one-way—pro-recipientThis Agreement is made on [date].Parties1[Insert name of party] [of [insert address] OR a company...
The UK General Data Protection Regulation (UK GDPR)—NavigatorThis Practice Note serves as a reference guide to the Retained Regulation (EU) 2016/679...
Privacy law—misuse of private informationThe tort of misuse of private information is focused on ‘the protection of human autonomy and dignity—the...
Confidentiality agreement—mutualThis Agreement is made on [date]Parties1[insert name of party] [of [insert details ] OR a company incorporated in...
The Information Commissioner’s Office (ICO)The Information Commissioner’s Office (ICO) is the UK’s independent regulator designed to uphold...
The UK General Data Protection Regulation (UK GDPR)This Practice Note provides a summary of the UK GDPR regime. For a higher-level introduction to UK...
Letter of claim—breach of confidence[Insert name and address of recipient]Dear [insert organisation name],[Name of client] and confidential...
Trade secrets and confidential information—protection and enforcementThis Practice Note sets out the protection available for trade secrets and...
Introduction to the EU GDPR and UK GDPRThis Practice Note provides a high-level introduction to the EU’s General Data Protection Regulation,...
Data protection, privacy and confidential information case law trackerThis Practice Note tracks noteworthy High Court, Court of Appeal and Supreme...
Commercial use of photographs—data protection and privacy issuesThis Practice Note addresses issues affecting professional photographers taking...
Letter of claim—breach of data protection law[Insert name and address of recipient]Dear [insert organisation name],[Name of client] and breach of data...
What does IP completion day mean for Information Law? [Archived]ARCHIVED: This Practice Note has been archived and is not maintained.11 pm (GMT) on 31...
Confidential information, privacy and injunctionsThis Practice Note deals with the general principles of obtaining an injunction relating to...
The Data Protection Act 2018This Practice Note introduces the UK’s Data Protection Act 2018 (DPA 2018).For higher-level introductions to data...
There must be a clear and affirmative action by the user. Deeming that consent has been provided, for example by a user continuing to use a website (regardless of whether they been warned of the presence of cookies), is not sufficient. Pre-ticked boxes, sliders that are set to ‘on’, or any equivalent mechanism that is intended to provide consent by default is not adequate.
Defined under the EU GDPR and UK GDPR as one of two or more controllers that jointly determine the purposes and means of the processing of personal data.
Non-disclosure agreement: an agreement to keep certain information confidential.