Being a Female CEO

There exists an incorrect, yet common, assumption that being young and female are incompatible with leadership, especially for an evolving organisation like DPAS.

I often find us competing against companies led predominantly by men in their 50’s, whilst there’s nothing inherently wrong about being a man in business (your honour!). I am proud to be challenging the status quo and changing the landscape of leadership.

I will never forget pitching a project with another young colleague, in front of a senior leadership team of an FTE100. The parting words from the SIRO demonstrated just how pervasive the assumption is; ‘‘we didn’t think you’d have what it takes’. I led that meeting with confidence, I managed their expectations and every challenge was overcome. They signed off on over £100k of work that year and 3 years on we continue to support them.

It is my privilege to be the CEO of an organisation overwhelmingly female (77% of employees!), with an average age of 33. We are truly able to bring a different perspective to the table for our clients. Over my four years at DPAS we have changed direction a few times, adapting to industry requirements and of course Covid-19. One thing that we have never changed is our vision for success and our company motto;

We will deliver our clients organisational objectives within the framework of the legislation. We will help them protect their business from the risk of non-compliance but work with them to ensure that it does not impact their commercial goals.

In 2022 we want to make impactful contributions to our community. We have pledged to ensure that we support the South West, in particular by employing locally. We want to develop our team further to ensure their continued enthusiasm and ability within a career in data privacy. We also want to help our clients develop their teams with certification and help them to put their staff through the new data protection apprenticeships.

If you would like to find out more about what we do, you can view our page linked. Alternatively, get in touch.

Meet the Team Melanie Garnett

by Melanie Garnett, CEO

Melanie is currently responsible for day to day running of DPAS. She leads our financial planning, operational decision-making, and our business strategy. 

Having joined DPAS at the start of our journey, Melanie has continued to work closely with Nigel, growing the business to what it is now. She has a passion for all things business, and is continually striving to ensure DPAS is leading the field in data protection consultancy services. 

related posts

Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »

Get a Free Consultation