Kuulo
← Trust Centre
Data protection mark

Data protection

Data protection and the Data Protection Act 2018

The important questions are practical: what data moves, who decides why it is used, who can access it, how long it remains useful, and what evidence shows that the system behaves as described.

Applied through data-protection by designICO data protection guidance

The framework

What Data protection is for.

Data protection requirements, supplemented by the Data Protection Act 2018, govern how organisations use personal data. They cover lawful processing, transparency, security, individual rights, accountability and the relationship between controllers and processors.

How we work with it

Make the obligation usable.

  • Map data flows, roles, purposes, retention and access before choosing the implementation.
  • Use minimisation, clear ownership and privacy-by-design controls in the workflow.
  • Produce DPIA, processing-record and client-review material where the engagement requires it.

What we can leave behind

Evidence a reviewer can follow.

  • Data-flow map
  • Data Protection Impact Assessment
  • Records of Processing support
Request documentation →

Concrete delivery evidence

How this showed up in client work.

The health-platform delivery included a DPIA, client security questionnaires and data-protection work alongside the patient and clinician workflows. The CRM platform also lists GDPR requirements as part of the live product delivery, with customer workspaces and permissions keeping business data separated.

Keep the map connected

Need this mapped to your system?

Start with the evidence your review needs.

Talk to us →