Takeaways from the Data Protection Practitioners’ Conference

ico logo

On Monday 13th April, we saw the ICO’s 12th annual Data Protection Practitioners’ Conference. This took place at the Manchester Central Conference Centre.

The day had a variety of events, including a talk from President and Executive Director of Electronic Privacy Information Centre, Marc Rotenberg. We also enjoyed panel sessions covering important topics, including what Brexit means for Data Protection.

All of the speakers were raising interesting discussion points throughout the day. I would like to take the time to discuss the two that I found myself most fascinated by.

First, the ICO’s focus on the accountability principle of the GDPR. Second, the developing area on Ethical Data Protection and AI profiling.

One: “Accountability encapsulates everything the GDPR is about.”

The Commissioner made the message on prioritising accountability clear in her opening speech for the DPPC. Simple demonstration of compliance is not enough. The emphasis is instead on the ability to demonstrate you are compliant.

This strong message from Elizabeth Denham will likely be a welcome one to Data Protection Professionals across the country. They may be battling to convince organisations that the GDPR is not a one-time tick box, but a factor to consider continually.

The Commissioner’s reinforcement of this point should help cement Data Protection’s integration into business culture. The progress we have made in the year since GDPR came into force is a promising start. We must continue the trend in the right direction.

Two: Technology, ethics and compliance – leave no room for loopholes.

I would like to congratulate Mikko Nava for winning the second ICO Data Practitioner of the Year award. I thought his acceptance speech was genuine and gracious. His thoughts on the industry being “the intersection between technology, ethics and compliance,” are thought provoking in its own right.

Data privacy incorporates so many areas which are in the process of change and growth. The only way to ensure the protection of data subjects is by reaching an balance between technology, ethics, and the legislation which is already in place.

To reach this balance, forward-thinking ethical and legal discussion is required. We also need to improve the understanding of these technologies, such as the growing use of Artificial Intelligence (AI).

It was a welcome sight to see the ICO taking steps towards striking this balance. Their AI auditing framework blog is a useful starting point. I will be putting out a few thoughts on this topic myself, over the coming months.

related posts

Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »
Noah de Wild

How to Assess a Data Breach: A Practical Guide

This blog explains how to assess a data breach by identifying its cause, determining what information was exposed, and evaluating the potential impact on affected individuals and the organisation. It outlines common causes of breaches, the importance of understanding the type and scale of compromised data, and how assessing the timeline of an incident can help businesses respond effectively, meet legal obligations, and reduce long-term risks.

Read More »
Noah de Wild

Don’t Panic: A Pragmatic Guide to the June 2026 Enforcement of the Data (Use and Access) Act Changes

With the June 19, 2026 enforcement of the Data (Use and Access) Act approaching, ensuring your business is compliant doesn’t have to be complicated or expensive. In our latest guide, we break down exactly what the new data protection complaint rules mean for you. Cut through the noise and discover our simple, free six-step checklist to update your protocols, designate handlers, and keep your business confidently compliant.

Read More »

Get a Free Consultation