Looking back at 2024 for DPAS

What has happened this year?

As we reflect on another remarkable year, I want to take a moment to personally thank you for choosing DPAS. Your loyalty and trust drives us to continually deliver the highest-quality training and services for our clients.

This past year has been both challenging and exciting, filled with opportunities for growth that we could not have achieved without our amazing customers. Supporting a diverse customer base—from large multinationals to small charities—has given us invaluable insights into the unique challenges faced by organisations of all types and sizes. We’re proud to have continued offering pro bono work this year and are excited to expand those efforts even further in the coming year. Thank you for being a part of our journey!

Our work during 2024

Our team has been busy performing Data Protection and Information Security Audits, as well as providing remedial support to help our clients meet compliance standards. We’ve also been supporting organisations with redacting and converting their Subject Access Requests. We have helped multiple Councils with social care SAR backlogs, and businesses with complex employee SARs.

We’re also thrilled to have welcomed nearly 15 new DPO as a Service customers—an encouraging sign that organisations are prioritising data protection more than ever. More recently we’ve been supporting organisations with the implementation of AI, supporting them with policies, guidance, DPIAs and training.

We’re delighted to have received countless 5 star reviews and feedback on our services and training courses via our surveys. If you’ve worked with us and want to provide feedback, I’d be grateful to receive it. You can leave us a TrustPilot review here or get in touch with me directly. Alternatively, check out some of our recent case studies on our website

engage, educate, empower - data protection conference 2024

The DPAS Engage, Educate, Empower Conference, held in Birmingham earlier this year, was a resounding success. Events like these are invaluable for privacy and data protection professionals, offering a rare opportunity to connect, share, and learn in a supportive environment. This work is not only challenging but can often feel isolating, making such gatherings all the more meaningful.

Our day was packed with insightful discussions, shared experiences, expert commentary—and plenty of fun! If you haven’t already signed up for our free conference in February 2025, don’t wait—spaces are filling fast. You can view the event here. 

new training courses for 2024

We’re were excited to be added to the IAPPs list of approved training providers this year, and spent time developing some of our own CPD accredited training courses, these include:

  • CPD: Introduction to AI for Data Protection Practitioners (1 and 2 day options)
  • CPD: Introduction to AI for Health Care Professionals (1 day)
  • IAPP Certified Information Privacy Professional (2 day)
  • IAPP Certified Information Privacy Manager (2 day)
  • IAPP Artificial Intelligence Governance Professional (2 day)

our brilliant team at dpas

This year, we’ve had plenty to celebrate! We welcomed two talented new consultants to our team, celebrated two beautiful weddings and an engagement, and worked with countless happy customers. Along the way, we delivered over 100 training courses and achieved outstanding results.

We also recognised the hard work and dedication of our incredible staff with well-deserved promotions, introduced new perks, and enjoyed team celebrations, including a festive escape room adventure and a Christmas dinner. With such a fantastic team, we’re looking forward to everything 2025 has in store!

let's prepare for 2025 together

Keep an eye out for our upcoming annual data protection reminders blog and email where we’ll share our insights and challenges shaping data protection, information security and information governance in the year ahead. If you are not subscribed to our newsletter sign up below. 

our charities for 2025

We are extremely pleased to announce that we will be supporting two charities next year. They are two charities that are close to our hearts here at DPAS. The first being the 4Louis. 4Louis is a UK-based charity that supports families experiencing miscarriage, stillbirth, or child loss by providing memory boxes and emotional support.

The second is Hospicare, Hospiscare is a charity providing holistic palliative care services to patients with life-limiting illnesses in Exeter, Mid, and East Devon.  Keep an eye out for our 2025 fundraising staff and customer events. If you’d like to help us with fundraising, please do get in touch.  

final round up

At DPAS, our mission is to empower organisations to prioritise privacy in everything they do. We are passionate about helping our clients navigate the complexities of data protection and privacy, offering tailored solutions to meet their unique needs. Whether it’s through training, consultancy, or hands-on support, we’re here to make privacy compliance more accessible and effective for everyone.

If there’s anything more we can do to support you or your organisation, don’t hesitate to get in touch. 

As we reflect on the past year, we want to thank you for being an integral part of the DPAS community. Your trust and partnership inspire us to continue driving positive change in the field of privacy and data protection.

Wishing you and your loved ones a very Merry Christmas and a New Year filled with success, joy, and new opportunities!

related posts

Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »

Get a Free Consultation