STAFF PROFILE – ZACK

We put our amazing SARs manager Zack in the hotseat, to ask him all of life’s most pressing questions… 


Hi Zack, Can you tell us a bit about your role at DPAS? 

I am the Subject Access Requests Manager, I manage a team of SAR officers that assist external organisations with dealing with SAR backlogs, Ad-hoc SAR advice and everything in between.

 

What does your average day look like at DPAS?

An average day includes providing advice to the SAR team, as well as external organisations. This could include redaction guidance, applicable exemptions, and how to conduct a reasonable and proportionate search for the data requested.

The majority of the day is spent leading the quality assurance process on the SAR redaction work the team completes.

 

What attracted you to DPAS? 

I was attracted by the ambition and fast growth of the organisation. There is always opportunity to expand on knowledge and experience through the training courses DPAS provides and ongoing project work. 

 

What do you do in your personal life?

I’m a bit of a bore to be honest! I enjoy cooking, working on my allotment, and walks on the beach.

 

What’s one achievement you’d like to accomplish (work or personal) in the next 5 years?

I would like to help DPAS continue to grow and cement itself as a market leader in all things data protection, namely SARs.

 

What’s the best place you’ve ever been to?

New Zealand. I spent a while working over there, the country is beautiful with great people!

 

If you were stranded on a desert island, what three items would you bring?

Orange juice, Tequila, Grenadine

 

Do you have any predictions about the future of data protection?  (or) In your opinion, what are the main challenges currently facing the Data Protection sector? 

The main challenges currently facing the Data Protection sector are changes to legislation and the ever increasing use of AI. Each poses challenges to the sector but also opportunities.

related posts

Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »

Get a Free Consultation