Stewart Room is a barrister and solicitor, and is President of the National Association of Data Protection and Freedom of Information Officers (NADPO).
The past few years has seen transformative changes in privacy, particularly in the UK, where GDPR and Brexit have created a host of new and potentially divergent data protection laws. In this book, Stewart and his team distill several decades of accumulated privacy, data protection and information governance experience and know-how into a guide that's essential reading for data protection newcomers and experienced practitioners alike. -- Toby Hayes FBCS CITP FIP CIPP/E CIPM There are many misconceptions about what is and isn't Data Protection, alongside the misinformation and scaremongering that arose in the early days of the GDPR. This book distils the considerable knowledge of its author and fellow contributors to deliver the key facts with clarity, supported with reference to landmark cases and regulatory texts. The chapter on Operational Data Protection is a timely reminder that Data Protection is people, paper (processes) and technology, and that all three are required to be effective. -- David Francis CIPP/E, CIPT, CIPM, Group Data Protection Officer, Canopius One of the biggest challenges to data protection law is how to effectively operationalise compliance and manage risk effectively within an evolving business structure. This book shows appreciation for this challenge and provides clear methods and concepts to address it. Operational landscape of data protection is summed up concisely and the concept of 'Technology Reference Architecture' linked to Privacy by Design, is incredibly insightful and relevant for businesses. I recommend this book for all data privacy practitioners, including in-house lawyers. -- Nargis Hassani, Solicitor This is your 'one-stop shop' resource for data protection guidance! This book effortlessly and coherently brings together the legislative and relevant case law on data protection into a well structured and easy to follow book. This is a must have for any data protection professional looking to operationalise and embed data protection compliance within an organisation through a risk-based approach. -- Harrison Barrett, CIPM CIPP/E, Deputy Data Protection Officer, Canopius