Skip to content
Clarium

Blog

Insights on GDPR compliance, data protection, and Article 30 best practices.

sector guides

how-to

DPIAdata protection impact assessmentGDPR

Data Protection Impact Assessment (DPIA): The Framework

A Data Protection Impact Assessment is the GDPR's risk assessment for high-risk processing, required under Article 35 before processing begins. This is the framework page for the DPIA: when it is mandatory, what it contains, and how it sits alongside your RoPA.

18 Aug 2026Read more
DSARdata subject access requestGDPR

Data Subject Access Request (DSAR): The Framework

A Data Subject Access Request is an individual's right to access the personal data you hold about them, under Article 15 of the GDPR, with a one-month deadline. This is the framework page for the DSAR: how it works, what a response must contain, and how it depends on your RoPA.

18 Aug 2026Read more
JerseyDPJL 2018JOIC

The Data Protection (Jersey) Law 2018: The Framework

The Data Protection (Jersey) Law 2018 is Jersey's GDPR-equivalent regime, supervised by the Jersey Office of the Information Commissioner, with EU adequacy. This is the framework page for the DPJL: what it covers, how it mirrors the GDPR, and where it diverges.

18 Aug 2026Read more
DPIAdata protection impact assessmentGDPR

When Is a DPIA Required and How to Do One

Article 35 makes a DPIA mandatory before high-risk processing begins, and the threshold is lower than most teams assume. Here is when the obligation bites, what the assessment actually contains, and how to run one that survives ICO scrutiny.

5 Aug 2026Read more
DPJL 2018Jerseydata protection

Data Protection in Jersey: A Guide to the DPJL 2018

Jersey has run its own GDPR-equivalent regime since 25 May 2018 and has held EU adequacy since 2008. This guide covers the DPJL 2018, the JOIC, registration, DPIAs, breach notification, and where Jersey law genuinely diverges from the GDPR.

29 Jun 2026Read more
DPIAAIEU AI Act

AI DPIAs: A New Frontier

The EU AI Act's high-risk obligations are live. If your AI system processes personal data, your DPIA needs to account for model opacity, bias, and function creep. Here is what that looks like in practice.

3 Jun 2026Read more

resources

Article 28data processing agreementDPA

10 Questions to Ask Your Data Processor (Template)

Before you sign a data processing agreement, ask your processor these 10 questions. This Article 28 GDPR checklist covers sub-processors, transfers, security, and audit rights, with a template you can reuse.

24 Aug 2026Read more
Article 30GDPRRoPA

GDPR Article 30: The Record-Keeping Obligation Explained

Article 30 of the UK and EU GDPR is the provision that forces every controller and most processors to keep a written record of their processing activities. This is the framework page for the obligation: who it binds, what it demands, and how it feeds the rest of your compliance programme.

18 Aug 2026Read more
RoPArecord of processing activitiesGDPR

Record of Processing Activities (RoPA): The Framework

A Record of Processing Activities is the register of everything you do with personal data, built on Article 30. This is the framework page for the RoPA: what it is, what goes in it, who needs one, and how it feeds a DPIA, a DSAR and breach response.

18 Aug 2026Read more
AIGDPRcompliance

How AI Is Transforming GDPR Compliance for SMEs

AI extraction is changing how SMEs build GDPR Records of Processing Activities. From free-text input to structured Article 30 fields with confidence scores, here is where AI actually helps small compliance teams.

13 Jul 2026Read more
RoPArecord of processing activitiesGDPR

What is a Record of Processing Activities (RoPA)?

A Record of Processing Activities is the register GDPR builds everything else on: what personal data you hold, why you hold it, where it goes and when it leaves. Here is what goes in one, who actually needs one, and why it decays faster than you expect.

1 Jun 2026Read more
Article 30GDPRrecords of processing activities

GDPR Article 30: Complete Guide to Records of Processing Activities

Article 30 GDPR requires controllers and processors to keep records of processing activities. This guide works through the article paragraph by paragraph: the required fields, the written-form rule, the exemption almost nobody qualifies for, and what enforcement actually looks like.

15 Mar 2026Read more