Find practical guidance on UK GDPR, data protection, privacy, electronic marketing and information security. Browse by topic or use the complete chronological archive to reach every article published by Measured Collective.
Browse by topic
Explore practical guidance and regulatory analysis by subject.
Complete article archive
Every published Measured Collective article, organised by year. Select a year or browse the full list below.
2026 98 articles
- P&O Ferries data breach: lessons for customer communications
- AliExpress and silent audio fingerprinting: what the finding means for online tracking
- Data Protection Training Matrix: How UK Employers Can Map Training by Role
- Dutch AP fines Uber €825m: what meaningful human review looks like
- Data protection training for staff: a practical UK employer checklist
- ICO action against the Metropolitan Police: why training and assurance must be demonstrable
- Agentic AI and GDPR: a practical guide to compliant adoption
- ICO investigation leads to sentence for unlawful council-record access: what employers should do
- CNIL connected-vehicle location rules: what fleet managers and telematics providers should check
- ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers
- AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects
- Can you reuse customer data for a new purpose? ICO’s 2026 compatibility rules explained
- When exactly can UK marketers use the soft opt-in?
- GDPR & Slack: How to stay compliant with GDPR
- Can I Request a Copy of All My Employment Data from My Employer Under GDPR?
- Garante fines Emirates €180,000 over assisted-travel health data
- London Clinic ICO caution: what staff medical-record misuse teaches employers
- Irish DPC fines HSE €300,000 after Tullamore ransomware breach
- Is Employee Data Subject to GDPR? How must it be protected?
- When Do You Need to Conduct a GDPR Risk Assessment/DPIA?
- ICO fines South Staffordshire £963,900 after phishing-led breach exposed 633,887 people’s data
- NHS data breach disciplinary disparity: why staff rarely face dismissal
- California sues 23andMe: why genetic-data security failures become a board issue
- ICO secures over £118,000 in confiscation orders against former RAC employees — why employee access abuse still demands hard controls
- Nottingham dismissed 11 staff. Liverpool reportedly dismissed none. What NHS leaders should learn
- ICO AI code of practice: what UK organisations should do before the next strategy lands
- CNIL fines IQVIA €5m over health data warehouse breaches
- Disney CCPA settlement: why cross-device opt-outs must work account-wide
- ICO secures £355,880.10 confiscation order against Rizwan Manjra — why insider misuse controls still matter
- Why a templated privacy policy is only half the job — writing vs. operationalising it
- ICO fines Energy Prices Direct £160,000 for 700,000 unsolicited marketing calls
- General Motors CCPA settlement: why data minimization is now an enforcement risk
- Why some UK news websites can now ask readers to accept cookies or pay
- Irish DPC fines Permanent TSB €277,500 over phone-based account takeover and late breach reporting
- UK Data Protection Complaints Procedure: What Organisations Need in Place Before 19 June 2026
- Dutch AP fines Yango €100 million over Russia transfers — why boards should revisit GDPR transfer governance
- ICO fines South Staffordshire PLC & South Staffordshire Water £963,900 after phishing-led breach exposed 633,887 people’s data
- UK Government Advances Facial Recognition Rollout — What This Means for Privacy Compliance
- EDPB Issues New Guidelines on AI Systems and Personal Data — Key Changes for EU Organisations
- Reddit Fined £14.47m by ICO for Children’s Privacy Failures — 2026
- EDPB Launches 2026 Coordinated GDPR Enforcement on Transparency – What Teams Need to Prepare
- Minnesota MCDPA Is Already in Force — Is Your Organisation Compliant?
- Advanced Computer Software Group Fined £3m by ICO for NHS Ransomware Data Breach — 2025
- EU AI Act Prohibited Systems Ban Takes Effect — What HR and Compliance Teams Need to Know
- ICO Updates Cookie Consent Rules Under the Data (Use and Access) Act — What Organisations Need to Do Now
- Indiana Consumer Data Protection Act — What Managers Need to Know in 2026
- Reddit Fined £14.47m by ICO for Children’s Privacy Failures — 2026
- Copyright vs. GDPR: The Tension in AI Training and Data Protection
- Cross-Border Data Breach Lawsuits: Courts Are Coming for You
- Age Verification Is No Longer Optional: How Regulators Are Raising the Bar
- The UK Just Quietly Flipped the Switch on Automated Decisions
- UK Data Use and Access Act: What Changes on 5 February 2026 and How to Prepare
- AI Note Taking Tools and GDPR: Do You Need a New Lawful Basis?
- ICO Launches Investigation into X and xAI Over Grok Deepfake Concerns
- Indiana INCDPA Fines: What We Know So Far
- Rhode Island RIDTPPA Fines: What We Know So Far
- Kentucky KCDPA Fines: What We Know So Far
- Minnesota CDPA Fines: What We Know So Far
- MODPA Fines: What We Know So Far
- Austria Orders Microsoft to Stop Tracking School Children
- US Privacy Enforcement Isn’t Slowing Down
- NDPA Fines: What We Know So Far
- NHPA Fines: What We Know So Far
- NJDPA Fines: What We Know So Far
- DPDPA Fines: What We Know So Far
- TIPA Fines: What We Know So Far
- ICDPA Fines: What We Know So Far
- UCPA Fines: What We Know So Far
- MCDPA Fines: What We Know So Far
- OCPA Fines: What We Know So Far
- ICO Updates International Transfer Guidance: What It Means for Your Business
- Biggest CTDPA Fines: Connecticut Privacy Enforcement Actions
- CPA Fines: What We Know So Far
- VCDPA Fines: What We Know So Far
- Biggest TDPSA Fines: Texas Data Privacy Enforcement Actions
- Biggest CCPA/CPRA Fines: California Privacy Enforcement Actions
- Rhode Island Data Transparency and Privacy Protection Act: 101 – What You Need to Know
- Flock’s AI Surveillance Cameras Were Wide Open on the Internet—Here’s What That Means
- Wegmans Is Scanning Your Face at the Grocery Store—And You Can’t Opt Out
- Confer: Signal’s Founder Builds an AI Chatbot That Can’t Spy on You
- California’s DROP Tool: Delete Your Data From 500+ Brokers With One Request
- Minnesota Consumer Data Privacy Act: 101 – What You Need to Know
- Maryland Online Data Privacy Act: 101 – What You Need to Know
- Nebraska Data Privacy Act: 101 – What You Need to Know
- Kentucky Consumer Data Protection Act: 101 – What You Need to Know
- New Hampshire Privacy Act: 101 – What You Need to Know
- New Jersey Data Protection Act: 101 – What You Need to Know
- Delaware Personal Data Privacy Act: 101 – What You Need to Know
- Tennessee Information Protection Act: 101 – What You Need to Know
- Iowa Consumer Data Protection Act: 101 – What You Need to Know
- Utah Consumer Privacy Act: 101 – What You Need to Know
- Montana Consumer Data Privacy Act: 101 – What You Need to Know
- Oregon Consumer Privacy Act: 101 – What You Need to Know
- Vietnam’s New Data Protection Law: What You Need to Know Before January 2026
- Colorado Privacy Act: 101 – What You Need to Know
- Virginia Consumer Data Protection Act: 101 – What You Need to Know
- Texas Data Privacy and Security Act: 101 – What You Need to Know
- California CCPA/CPRA: 101 – What You Need to Know
2025 27 articles
- The UK Cyber Security and Resilience Bill: What Data Protection Officers Need to Know
- ICO’s Public Sector Approach: Why the Post Office Received a Reprimand Instead of a £1m Fine
- The EU’s First DSA Fine: What X’s €120m Penalty Means for Digital Platform Compliance
- ICO Enforcement in 2025: Record Fines and What They Mean
- EU Digital Omnibus Explained: Will Cookie Banners Finally Disappear?
- GDPR Subject Access Requests When AI Processes Your Data
- What is the UK Cyber Security and Resilience Bill?
- Is GDPR Really on the Chopping Block in the EU?
- Australia Privacy Act 1988: 101 – What You Need to Know
- Connecticut Data Privacy Act: 101 – What You Need to Know
- Rhode Island Data Transparency and Privacy Protection Act: 101 – What You Need to Know
- Indiana Consumer Data Protection Act: 101 – What You Need to Know
- Can a Company Process and Store Employee Fingerprint Data Under GDPR?
- EU Court Redefines ‘Personal Data’: 5 Documents to Update Now
- EU NIS-2 Management Liability: The SonicWall Breach Test Case
- Got Views on How the ICO Handles Complaints? Now Is the Time to Share
- Are EU-UK Cross-Border Data Transfers at Risk of Change?
- GDPR Recognised Legitimate Interests: Understanding the New ‘Recognised’ Category
- £300,000 ICO Penalty for Illegal Automated Marketing Calls: Home Improvement Marketing Ltd Case Analysis
- Bristol City Council ICO Enforcement Case: Falling Behind On Subject Access Request Compliance
- How to request your personal data under GDPR in the UK?
- What the ICO Says About Data Protection Refresher Training
- Does my business need to prepare for changes to Data Protection in the UK via the Data (Use and Access) Act 2025?
- Do I need to train my team about data protection – what does the ICO say in 2025?
- ICO fines Care Home Director for Deleting Data: The Warning Every Manager Should Read
- The UK Data (Use and Access) Act 2025: What You Actually Need to Know
- Understanding GDPR Data Subject Access Requests: A Practical Guide for Organisations
2024 3 articles
2023 1 articles
2022 10 articles
- GDPR Legitimate Interests Assessment: The Complete Guide
- What is considered “disproportionate effort” under GDPR?
- Do I need ongoing GDPR training?
- How to make any form GDPR compliant
- Does GDPR apply to b2b data?
- Mailchimp & GDPR: Complete Compliance Guide for UK Businesses
- GDPR Training Requirements: Who Needs Training and How Often?
- Can I get compensation for a GDPR Data Breach?
- How the Data Protection and Digital Information Bill could change marketing in the UK
- Royal Mail fined £20,000 under PECR for marketing automation gone wrong
2021 14 articles
- The Biggest GDPR Fines So Far (2026)
- What the marketing team at Virgin Media got wrong about PECR
- What does the biggest security exploit of the year mean for your GDPR compliance?
- Is Google Forms GDPR compliant?
- GDPR: what counts as personal data?
- GDPR & Google Workspace: How to stay compliant with GDPR
- Facebook to update cookie consent controls on Facebook & Instagram in Europe
- Europe data privacy decisions round-up August 2021
- Most ironic PECR fine yet as firm selling nuisance call blocker fined under TPS rules
- How much are GDPR fines?
- GDPR Fines for Individuals: Can an individual really get a GDPR fine?
- GDPR & Recaptcha: How to stay compliant with GDPR
- GDPR & Google Analytics 4: What you need to know
- ICO fines protein e-commerce company Muscle Foods Limited for sending millions of marketing messages without valid consent
2020 7 articles
- ICO fines “Digital Growth Experts Ltd” £60,000 for sending thousands of nuisance marketing texts during coronavirus pandemic
- Do you need a GDPR Representative in the EU?
- The most common cookie banner mistakes and how to fix them
- Security firm fined under GDPR after employee used WhatsApp to transfer personal information
- Hotel group fined approx 148,000 euros for failing to delete over 500,000 customer profiles
- Spanish Data Authority (AEPD) fines e-commerce website €3,000 for unlawful cookie practices
- ICO Fine Cathay Pacific £500,000 for failing to protect customers’ data
