Curriculum Vitae
Daniel Richard Lowther
Senior governance, compliance, information security and data protection professional with 9+ years in a regulated, publicly funded, third-sector environment, the last five of them working to Senior Management Team and Board level. Leads ISO 27001 and ISO 9001 certification through every surveillance and re-certification audit, and has held Cyber Essentials Plus continuously since it was first achieved.
Overview
Proven track record in corporate governance, enterprise risk management, UK GDPR compliance, ISO 27001, Cyber Essentials Plus, business continuity, audit readiness and organisational assurance. Experienced Data Protection Officer with strong hands-on capability across Microsoft 365 administration, information security controls, DSAR management, breach response and policy development.
Trusted to provide clear, evidence-based advice to senior leaders, directors and operational teams, translating regulatory and assurance requirements into practical, sustainable organisational controls.
Core specialisms
- Corporate governance & Board assurance
- Data Protection Officer duties, DPIAs & DSARs
- ISO 27001 & ISO 9001 certification and audit readiness
- Cyber Essentials & Cyber Essentials Plus
- Enterprise risk management & internal audit
- Incident, breach & business continuity
- Complaints handling, records management & document control
- Microsoft 365 administration & adoption reporting
- Budget management
Key achievements
Appointed organisational Data Protection Officer.
Led multiple ISO 27001 and ISO 9001 certification and surveillance audits.
Led the achievement and ongoing maintenance of Cyber Essentials and Cyber Essentials Plus.
Designed and implemented the Business Continuity Plan — put to real use during COVID-19.
Lead administrator for IT, information security and Microsoft 365 during an earlier period in a separate operational role.
Authored and maintained the corporate, governance and data protection policy suite.
Delivered DSAR processes and incident / breach management procedures.
Selected projects
A summary of the kind of governance and data protection work I do. Deliberately generic: no organisation, contract, supplier or individual is described here.
Policy library & document control
Reviewing a corporate policy, procedure and plan library at scale, and building the document-control regime that keeps it current — approval routing, named ownership, version integrity and scheduled review, aligned to the documented-information requirements of ISO 9001 and ISO 27001, with a phased implementation plan carrying owners and effort estimates.
Business management system
Designing an integrated management system that brings quality, information security, cyber assurance and data protection evidence into a single controlled structure, with defined review cadence, delegated ownership, and information classification and retention labelling tied to the retention schedule.
Role-based access model
Designing role-based access control models on a deny-by-default basis, with permissions granted to groups rather than individuals, approval of the most sensitive memberships held outside the data protection function to avoid a conflict of interest, and a periodic access-review cycle mapped to the relevant ISO 27001 control.
Layered privacy notice framework
Designing layered privacy notice frameworks against the UK GDPR information articles — a public notice, service-level notices and a staff and recruitment notice — with the controller or processor role defined for each, and the whole set built from the record of processing activities (ROPA) as its source.
Pre-employment screening framework
Building pre-employment screening frameworks on the statutory regulated-activity test at the heart of DBS eligibility, distinguishing baseline personnel security screening from criminal-record checking, and setting the handling position for check outcomes as Article 10 criminal offence data.
End-of-contract data return
Specifying secure data return and destruction processes for the end of a contractual relationship — batched transfer within platform limits, with per-batch cryptographic hash manifests carrying file counts, sizes and timestamps as chain-of-custody and reconciliation evidence.
Direct marketing & PECR guidance
Writing practical guidance on where PECR and UK GDPR meet — channel-by-channel consent requirements, the soft opt-in and its limits, and the difference between a marketing message and a service one. Written for people who have to apply it rather than for specialists.
Impact assessments & supplier assurance
Carrying out data protection impact assessments (DPIA) on third-party platforms before adoption — hosting and data residency, encryption, testing and vulnerability management, retention, and where automated processing gives way to human review. Reviewing supplier agreements and variations for data-processing provisions, and maintaining a supplier and licensing schedule covering renewal and notice windows.
Professional experience
Jan 2017 – Jul 2019
Trainee → Apprentice → Office Manager
Case-UK Limited
- Joined straight from school as a trainee, when the organisation was three people in a single room; progressed to apprentice, then to Office Manager.
- Writing policies, managing bids and running community consultations from the first weeks.
- Learned ISO 27001 from scratch and worked on the organisation’s initial certification in 2018.
- Built the compliance and screening infrastructure around a major new commissioned programme, and was appointed Data Protection Officer; oversight of DBS, BPSS, quality and compliance.
Jul 2019 – Jul 2021
Compliance Manager
Case-UK Limited
- Managed compliance operations, audits, contractual compliance and records management.
- Maintained ISMS documentation in line with ISO 27001 requirements.
- Delivered monthly audit reporting to SMT and monitored organisational KPIs.
- Managed and developed a team, ensuring quality and regulatory adherence.
- Supported development of secure systems, consultation processes and information governance controls.
- Led audit preparation and evidence collation for ISO 27001 surveillance.
- Developed physical and SharePoint-based records systems and audit trails.
- Supported evidence collation for business planning and assurance.
- Researched and wrote a business plan for a charity.
Aug 2021 – Dec 2025
Strategic Lead for Compliance, Governance & Data Protection
Case-UK Limited
- Accountable at organisational level for Data Protection Officer duties alongside compliance and governance leadership.
- Led ISO 27001 and ISO 9001 certification and the surveillance and re-certification audits that followed, including audit readiness and external assessor engagement.
- Delivered and maintained Cyber Essentials and Cyber Essentials Plus.
- Designed and embedded risk management frameworks, corporate risk registers, and reporting to senior leadership and the Board.
- Owned DSAR handling and breach response, and was the organisation’s designated contact point for the supervisory authority.
Jan 2026 – Present
Governance Lead & Data Protection Officer
Case-UK C.I.C.
- Lead responsibility for corporate governance, Board assurance, compliance and enterprise risk management.
- Appointed Data Protection Officer, advising the Board and executives on UK GDPR, data protection risk and regulatory compliance.
- Oversight of organisational assurance, policy governance and information security strategy.
- Owns the policy control register and the approval and review cycle for organisational policies.
- Maintains the corporate risk register and coordinates periodic risk reviews with senior leadership.
- Manages the complaints process end to end, including speaking directly with the people who have raised a complaint.
- Assisted in developing the budgets for the organisation’s active contracts.
- Co-produces the annual governance and assurance report for the Board, and advises on the organisation’s obligations as a Community Interest Company (CIC) under its Articles of Association.
- Provides objective governance and data protection assurance to the Board, with line management responsibility within the governance function.
What colleagues say
From colleagues.
“From day one of me arriving at Case-UK, Dan was the person everyone clearly went to. You have done so much for so many, and so often it is done quietly, in the background.”
Tim P.
“Great to see you develop from an apprentice to a vital part of the organisation’s delivery.”
Jeff E.
“Thank you for all the work you have done to see Case-UK grow into an amazing and successful organisation.”
Ian B.
“Every company needs a Daniel Lowther — such a well respected part of the structure that built Case-UK.”
Pam S.
“What an amazing growth story. Congratulations on all you have achieved — we are lucky to have you.”
Leanne M.
“My go-to IT and systems guru. Thank you for all that you do.”
Emma H.
“You always need a Dan. So proud of you and your story.”
Diane B.
Technical
Alongside the governance work I build small tools that remove manual effort — document processing, backups and file handling. I’m not a programmer by training; these are worked out through research and trial and error, and they exist because a problem in front of me needed solving. A fuller list is on the Software page.
References
Available on request.
Software
Software I use
Utilities I rely on day to day, and a few small tools I have built for my own use. Included for interest rather than as a portfolio.
Everyday utilities
Tools that each do one job well. Free unless the badge says otherwise.
The archiver worth having instead of whatever the operating system came with. Packs 7z, zip, tar, gzip and xz, and opens almost everything else including rar, iso and dmg. The detail that matters if you are sending something sensitive: AES-256 in the .7z format can encrypt the file names as well as the contents, whereas an encrypted zip still leaves the list of what is inside readable to anyone who opens it.
Everything 1.5
BetaInstant filename search for Windows. Indexes the NTFS master file table directly, so results appear as you type across an entire drive. The 1.5 line adds full content search, file-property indexing and a much better filter system. It spent years in alpha and voidtools now publish it as a beta alongside the 1.4 stable build — I run the beta as my daily driver, currently 1.5.0.1423b.
The universal media converter. Re-encoding, remuxing, trimming and format conversion for video and audio, scripted rather than clicked.
Fixes the metadata on a music library and then files it properly. The part that earns its place is AcoustID fingerprinting: it identifies a track from the sound itself, so a folder of files called track01.mp3 with no tags at all still comes back correctly named. Tagging rules are scriptable, so the folder structure comes out the way you want it rather than the way the tool prefers.
An audio editor that opens instantly and stays usable, which sounds like faint praise until you have waited on something heavier to load a single file you wanted to trim. Waveform and spectral views, and it keeps responding while long operations run in the background rather than freezing on you. Windows, macOS and Linux, free to use.
Python
DailyWhat the tools further down this page are built with. Free, cross-platform, and well enough documented that a problem can usually be worked out from the manual and a lot of trial and error.
Command-line PDF surgery — merging, splitting, linearising and repairing. Does the final merge step in my Apple Books PDF pipeline where higher-level libraries fall over on large page counts.
Recuva
Free / ProFile recovery for Windows. Scans a drive, memory card or USB stick for deleted entries and restores what is still intact. The deep-scan mode is the one worth waiting for. First thing I reach for when someone empties a recycle bin they shouldn’t have — the golden rule being to stop writing to the drive immediately.
A desktop front end for yt-dlp, which is the general-purpose media extractor a great many other tools quietly sit on top of, mine included. Stacher fetches and updates yt-dlp itself, so the version underneath stays current without any of the command-line housekeeping. Windows, macOS and Linux, free.
Open-source optical character recognition. The engine inside my OCR PDF Converter, turning scanned documents into searchable, editable text.
Full-disk and container encryption. It makes an encrypted file that mounts as a drive, or encrypts a whole partition or removable disk with pre-boot authentication. The container is the useful part for moving sensitive files about: it travels as one file and opens with a passphrase, rather than depending on keys held by the machine it lands on. Worth knowing it is the maintained fork of TrueCrypt, which was abandoned in 2014, and that it carries both the Apache 2.0 licence and the original TrueCrypt terms.
Where the scripts on this page get written, and where this site was edited. Free, cross-platform, and with the Live Preview extension it renders an HTML file in a pane beside the source as you type. Worth knowing the licensing has two layers: the source is MIT-licensed as Code – OSS, while Microsoft’s own build adds branding and telemetry under its own terms.
Answers “what is actually eating the drive” in one pass. Every file becomes a rectangle sized by how much space it takes and coloured by type, so a forgotten cache or a stack of old disk images shows up as an obvious slab rather than something you would ever find by opening folders. Worth knowing the 2.x line is a genuine rewrite: the old 1.1.2 build sat untouched for well over a decade.
Tools I’ve built
Made for my own use, worked out through research and trial and error rather than any formal training. They do useful jobs and I understand what they do — but I’d describe myself as someone who solves problems with software, not a developer. Source is on GitHub, AI collaboration and all; happy to talk through any of it.
Apple Books PDF pipeline
Mac & WindowsConverts folders of images into PDFs that read properly in Apple Books, splitting long pages and merging in chunks so large volumes complete reliably.
Cryptex
Mac & WindowsAn encoder, decoder and cryptography toolbox in one window — representation changes, historical ciphers with the solvers that break them, an Enigma machine, authenticated file encryption, hashing, keys and certificates, and steganography. It also handles radio: slow-scan television, RTTY, PSK31 and packet, decoded from a file, from a video, or live off the air. There is an auto-solve mode that works out what it is looking at and layers decoders until the text reads as English. Everything runs on the local machine and nothing is uploaded.
eBay Deal Hunter
Mac & WindowsSearches eBay UK for working items priced below the going rate, scoring each result against the median price of comparable live listings and filtering out broken and parts-only listings. UK-only, and runs entirely on the local machine.
findex
Mac & WindowsDesktop file search with content indexing. Every file is catalogued by name, and text is read out of documents, spreadsheets, presentations, PDFs, ebooks and email — with scanned PDFs handled by the operating system’s own OCR engine rather than a bundled one. The index is SQLite full-text search held on disk rather than in RAM, results narrow live as you type, and files can be copied, moved or sent to the bin straight from the results. Runs from its own folder, on Windows or a Mac.
Game Asset Harvester
WindowsOne front end over the game asset extraction tools, instead of juggling five of them. Point it at a game folder and it works out which engine the game uses, picks the right backend — CUE4Parse and umodel for Unreal, AssetStudio for Unity, Godot RE Tools, QuickBMS for the long tail — and drops meshes and textures into one predictable output tree with a manifest, ready for Blender. Windows only, which breaks my own two-platform rule: four of the five backends have no macOS build, so a Mac version would be a window of greyed-out buttons.
Game modifications
HobbySingle-player game mods built for my own use, and by now a reasonable pile of them. The interest is in the route in rather than the result: Lua scripting against an injected runtime, a small C injector paired with a metadata dumper to find the functions worth calling, disassembling and patching .NET assemblies, and script mods for Godot titles. Mostly a way of learning by taking things apart to see how they work.
OCR PDF Converter
Mac & WindowsBatch-converts scanned PDFs into searchable Word documents or plain text using OCR, with some image preprocessing to improve accuracy on poor-quality scans.
Sherlock GUI
Mac & WindowsA desktop front end for the Sherlock and Maigret username searches, running both at once and merging their results into a single table with a description and category for every site. The useful part is the false-positive filter — each claimed hit gets a confidence from the HTTP status, bot-wall and soft-404 detection, whether both engines agree, and whether the username actually appears on the page — and any claimed URL can be re-checked with a second, independent request.
Site Harvester
Mac & WindowsCrawls a site to a chosen depth and saves the images, documents and other files it finds into sorted folders, or the pages visited as a single PDF with a clickable contents page. Built for archiving sites I run or have permission to copy. It reads no robots file and does not throttle itself, which is exactly why it is a tool for your own sites rather than one to point at somebody else’s — a crawler is not a licence, and the terms are part of the job.
Scripts & automation
Windows batch and Robocopy utilities I use for backup and file handling. Each is commented with the reasoning behind it, so someone else can pick it up and adjust it.
Backup Users to External
BatchCopies the whole user profile tree to whichever external drive the script is run from, stamped with the machine name and run time so repeat backups never overwrite each other. Excludes cache and temporary folders, and reports genuine failures rather than Robocopy’s routine exit codes.
Drag and Drop Copy
BatchDrop any number of files or folders onto the script and it copies each one into a timestamped folder, filtered through an exclusion list for caches, build folders and other clutter. Handles large multi-item drops and awkward filenames that trip up a simpler script.
File Backup
BatchScheduled incremental backup to an external drive. It never deletes — new, newer and changed files are copied and identical ones skipped. Tolerant of exFAT and NAS timestamps.
Wipe Free Space — All Drives
BatchRuns the built-in Windows cipher /w free-space wipe across every connected drive, so previously deleted files can’t be recovered. Current files are untouched. Skips SSDs by default, where the pass causes unnecessary wear without a guaranteed result.
About this site
One HTML file. No framework, no build step, no analytics, no fonts pulled in from anywhere else. Built in collaboration with AI — Anthropic’s Claude wrote much of the code and the two of us argued about the rest; the decisions, the direction and the final say were mine, and everything on the page was tested against an independent implementation before it shipped. Checked in a browser, uploaded to Cloudflare Pages. The size in the footer is measured by your own browser as it loads the page, not typed in by me.
Most of the work went into things nobody sees. Getting date arithmetic right at month ends. Making every page readable with JavaScript switched off. Rewriting the print rules enough times that a printed page breaks where it should rather than trailing a blank one.
There is no contact form, no cookie banner, no newsletter and no chat widget, so there is nothing here that tells me who you are — beyond the request log any host keeps, which is covered under “How this site handles data”, linked in the footer. The Contact page is a published address and nothing more, for the same reason: a form would post your message through somebody else’s server, and that one convenience would undo most of what this page claims. That is deliberate, and it is most of the reason the whole thing still fits in one file.
Built in South Wales, mostly in the evenings. There is no repository to link you to, and there does not need to be: nothing sits in one that is not already in front of you. View Source is the whole site.
Accessibility
Accessibility software worth knowing about
Tools that make a screen usable. Most of these are free, and several are the difference between someone being able to do their job and not. This is a list of software, not advice on what any particular person needs — adjustments are an individual assessment, and on a work device they should go through your employer’s own process.
Try the adjustments
Rather than only listing the tools, the same adjustments are built into this site and can be applied to any page from Display options in the header — a colour overlay, wider reading spacing, stronger contrast and larger text. Nothing is saved: the settings last until you reload, and no preference is stored on your device.
Visual comfort & colour
ColorVeil
FreeLays a customisable colour filter over the entire Windows screen and every application on it — the software equivalent of a coloured overlay sheet. Widely used for visual stress / Scotopic Sensitivity Syndrome and by dyslexic readers, and it takes about a minute to try. Colour and opacity are both adjustable, and there is a portable build as well as an installer — though on a managed work device, put anything new through your own IT and procurement route first. Download.
macOS Zoom, Hover Text & Colour Filters
Built inThe Apple equivalents, under System Settings → Accessibility: screen zoom, enlarged hover text, display tinting, reduced transparency and reduced motion.
OpenDyslexic
FreeOpen-source typeface with weighted bottoms designed to reduce letter-swapping. Installs as a system font and has browser extensions to restyle any page. Evidence is mixed and it doesn’t suit everyone — but it costs nothing to test.
Windows Magnifier & Colour filters
Built inWindows ships with a screen magnifier (Win + +), high-contrast themes, and system-wide colour filters including greyscale and colour-blindness modes. Settings → Accessibility. Already on the machine, so no new software is involved.
Screen readers & text to speech
Balabolka
FreeText-to-speech reader that will take a document, web page or clipboard contents and read it aloud or export it as an audio file. Useful for proofreading long documents by ear as much as for access.
Microsoft Immersive Reader
IncludedBuilt into Word, OneNote, Edge and Teams. Read-aloud with word highlighting, line focus, syllable splitting, adjustable spacing and a picture dictionary. Already licensed anywhere Microsoft 365 is in use, which makes it one of the easiest to try.
Narrator & VoiceOver
Built inThe screen readers already on the machine — Narrator on Windows (Win + Ctrl + Enter) and VoiceOver on macOS (Cmd + F5; on an iPhone, triple-click the side button). Worth knowing even if you don’t use them daily.
NVDA
FreeNonVisual Desktop Access — the leading free, open-source Windows screen reader, developed by NV Access. Full braille display support, a portable build, and the tool most commonly used for real-world accessibility testing alongside JAWS. If you are checking whether a site or document actually works for a blind user, this is what you test with.
Testing & compliance
For checking that what you publish actually meets WCAG 2.2 AA — the standard behind the UK public sector accessibility regulations.
| Tool | What it does | Cost |
|---|---|---|
| WAVE | In-browser page evaluation from WebAIM — flags contrast failures, missing alt text and structural problems visually. | Free |
| axe DevTools | Developer-focused automated auditing built into browser dev tools; the engine behind many CI accessibility checks. | Free tier |
| Lighthouse | Accessibility scoring built into Chrome DevTools — quick baseline, not a substitute for manual testing. | Free |
| Colour Contrast Analyser | Desktop eyedropper that checks any two colours against WCAG AA and AAA ratios. | Free |
| WCAG 2.2 | The guidelines themselves — the reference everything above is measuring against. | Free |
Reference
References, links and guides
The pages I actually open when something needs doing, with a note on what each is for — plus two data protection guides written to be read by non-specialists, and a Windows command reference. The interactive tools have moved to the Toolkit.
Breach and incident
The page to open first when something has gone wrong. Explains what counts as a personal data breach, the 72-hour clock, when the ICO must be told, and when the people affected must be told — the two thresholds being different, which is the point most often missed.
The ICO’s own decision tool. Answer the questions and it tells you whether the breach is reportable, and takes you into the report if it is. Worth working through even when the answer looks obvious, because it produces a record of the reasoning.
How to judge severity: the factors that make a breach high risk to individuals rather than merely embarrassing to the organisation. This is the judgement the whole notification decision turns on.
ICO — Understanding and assessing risk in personal data breaches
Where the report itself is made, plus what the ICO expects to receive and what happens after you submit.
Assessments and accountability
The three statutory cases in Article 35(3), the ICO’s own list of processing that requires a DPIA, and the risk indicators. Note that several entries on the ICO list only require a DPIA when combined with another criterion — easy to read past, and it changes the answer.
The wider DPIA guidance, including how to run one, who to consult and what to do when a high risk remains after mitigation.
Nine toolkits setting out what the ICO actually looks for in an audit, with control measures and examples of good practice. The Accountability toolkit is the one to start with. Useful as a gap analysis against your own framework, whether or not an audit is coming.
Individual rights
Subject access in full: the one-month deadline and when it can be extended, what can be withheld, third-party data, exemptions, and when a request is manifestly unfounded or excessive. The area where organisations most often get the timing wrong.
Marketing and electronic communications
PECR sits alongside UK GDPR rather than inside it, and applies its own consent rules to email, text, phone and cookies. If you are deciding whether an appointment reminder counts as marketing, the answer starts here.
ICO — Direct marketing and privacy and electronic communications
Information security
What Cyber Essentials covers, the difference between the self-assessed certification and the audited Plus, and why a great many contracts now require one of them.
IASME is the NCSC’s official Cyber Essentials delivery partner, licensing the certification bodies that carry out the assessments. This is where the current question set, pricing and certification bodies live.
The NCSC’s structured breakdown of an organisational security programme — risk management, asset management, identity, logging, incident response. A good spine for an ISMS that has grown organically.
Written for Boards rather than practitioners, which makes it genuinely useful when you need non-technical trustees to ask the right questions. Includes the questions they should be putting to you.
Pre-employment screening
Which level of check a role is actually eligible for, including the eligibility tool. Eligibility turns on the statutory definition of regulated activity, not on how senior the post is or how vulnerable the people it serves are — a distinction that catches out a lot of recruitment policies.
Accessibility
The standard itself. AA is the level referenced by the UK public sector accessibility regulations and by most contracts that mention accessibility at all.
Free in-browser checking. Flags contrast failures, missing alternative text and structural problems visually, on any page. Faster than reading the guidelines when you just need to know whether something passes.
Guides
Three longer references, written to be read by people who have to comply with something without being specialists in it. Generic throughout — no organisation, supplier or case is named in any of them.
UK GDPR — a plain-English reference
what the law actually says, and what it means in practice
Written for people who have to comply with data protection law without being specialists in it. Each section quotes the provision itself — so you can see the wording rather than someone's summary of it — and then says what it means when you are actually doing the job. It is a reference, not legal advice, and it does not replace your own organisation's policies.
1 · The words that matter
Four definitions from Article 4. Get these right and most of the rest follows.
Personal data — Article 4(1)
“‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.
In plain terms: if you can work out who someone is from it, it is personal data. A name, a case reference that ties back to a person, an email address, a call recording, notes of a meeting about someone — all personal data. “Indirectly” is the word people miss: data that identifies nobody on its own still counts if it identifies someone when combined with something else you hold.
Processing — Article 4(2)
“‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction”.
Doing almost anything with data is processing — including simply storing it, or opening a file to read it. There is no “we only looked at it” exemption.
Controller and processor — Article 4(7) and 4(8)
A controller is the person or body which, “alone or jointly with others, determines the purposes and means of the processing of personal data”. A processor is a body “which processes personal data on behalf of the controller”. Two organisations can be joint controllers of the same processing.
This is the single most consequential thing to get right on a contract, because it decides who carries the obligations. Where you deliver a service as a subcontractor, the roles are set by the contract — read it rather than assuming. The label in the agreement is not decisive either: what matters is who actually decides why and how the data is processed.
2 · The seven principles
Everything else is built on these. Six sit in Article 5(1), with accountability in Article 5(2).
“Personal data shall be:
(a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
(b) collected (whether from the data subject or otherwise) for specified, explicit and legitimate purposes and not further processed by or on behalf of a controller in a manner that is incompatible with the purposes for which the controller collected the data (‘purpose limitation’);
(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 84B (‘storage limitation’);
(f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).”
Article 5(2): “The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).”
| Principle | Where it usually goes wrong |
|---|---|
| Lawfulness, fairness, transparency | A lawful basis was never actually chosen, or the privacy information does not match what is really being done. |
| Purpose limitation | Data gathered to deliver a service quietly gets reused for something else. Using someone's case for publicity is a new purpose and needs its own basis. |
| Data minimisation | Collecting identity documents or health detail “just in case”. If you cannot say what a field is for, do not collect it. |
| Accuracy | Records left stale after someone's circumstances change. |
| Storage limitation | Nothing is ever deleted, because no one set a retention period or nobody owns the deletion. |
| Integrity and confidentiality | Access granted to a whole team when three people needed it; sensitive files emailed rather than shared through a controlled route. |
| Accountability | The organisation complies but cannot prove it — no record of processing, no evidence of the decisions taken. |
3 · Lawful basis — you always need a reason
You cannot process personal data without a lawful basis. Pick it before you start, write it down, and be able to say which one it is. There were six; the Data (Use and Access) Act 2025 inserted a seventh, so a policy that still says “one of six” is out of date.
Article 6(1): “Processing shall be lawful only if and to the extent that at least one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to which the controller is subject;
(d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
(e) processing is necessary for the performance of a task of the controller carried out in the public interest or a task carried out in the exercise of official authority vested in the controller;
(ea) processing is necessary for the purposes of a recognised legitimate interest;
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”
“Points (ea) and (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.”
Point (ea) and the Annex 1 list it refers to were inserted by the Data (Use and Access) Act 2025 s.70, in force 5 February 2026. The recognised legitimate interests are a closed list — disclosure for another body's public-interest task, national security, public security and defence, emergencies, crime, and safeguarding vulnerable individuals — and unlike point (f) they need no balancing test. Each carries its own conditions: the first and broadest only operates where that other body has actually requested the disclosure and it is necessary for their task, so it is not a general licence to share. Outside the list, nothing has changed.
- The most common mistake is defaulting to consent for everything. Consent must be freely given and can be withdrawn at any moment. If someone cannot realistically say no — because the processing is what delivers the service they signed up for — consent is the wrong basis and one of the others fits better.
- The basis for core delivery is rarely the basis for optional extras. Delivering the service might run on contract or public task; publishing someone's story in a newsletter is optional and runs on consent.
- Legitimate interests needs a documented legitimate interests assessment, and “do the balancing test” is not the same instruction. The ICO's LIA has three named parts: the purpose test (is there a legitimate interest?), the necessity test (is this use necessary for it?) and the balancing test (do the person's interests override it?). Someone asked only for the balancing test will produce a third of the assessment. Without the record you cannot demonstrate the basis under Article 5(2).
4 · Special category data — the extra rules
Article 9(1): “Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.”
That prohibition lifts only if a condition in Article 9(2) applies. The two met most often outside a clinical setting:
Article 9(2)(a): processing is permitted where “the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where domestic law provides that the prohibition referred to in paragraph 1 may not be lifted by the data subject”.
Article 9(2)(h): processing is permitted where it “is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services” on the basis of domestic law “or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3” — the requirement that whoever processes it is under professional secrecy.
The UK add-on, and who it actually applies to
This is where the shorthand “you always need two conditions” goes wrong. Only five of the ten Article 9(2) conditions need a second condition from Schedule 1 to the DPA 2018: (b) employment and social security, (g) substantial public interest, (h) health or social care, (i) public health, and (j) archiving and research. Explicit consent under 9(2)(a) needs neither a Schedule 1 condition nor an appropriate policy document — so the condition most people reach for first is the one the shorthand does not describe.
The appropriate policy document requirement is narrower still. It attaches to Schedule 1 condition 1 (employment, social security and social protection) and to almost all of the roughly twenty-three substantial-public-interest conditions in Part 2 — but not to health or social care, public health, or archiving and research. A missing appropriate policy document is a common audit finding, but check which condition you are actually relying on before concluding you need one.
DPA 2018, s.10(2): “The processing meets the requirement in point (b), (h), (i) or (j) of Article 9(2) of the UK GDPR for authorisation by, or a basis in, the law of the United Kingdom or a part of the United Kingdom only if it meets a condition in Part 1 of Schedule 1.”
Criminal offence data is a separate regime, not a subset
Article 10 data — including the result of a criminal record check — is not special category data, and needs no Article 9 condition at all. What it needs is an Article 6 lawful basis plus either official authority or a condition in Schedule 1. Going looking for an Article 9 condition for a DBS result is a wasted search, and forgetting the official-authority route means organisations that have it reach for a Schedule 1 condition they do not need. Some, but not all, of the relevant conditions carry the appropriate policy document and record-keeping requirements.
5 · Being transparent
Article 12(1): “The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication made under or by virtue of Articles 15 to 22D and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child”.
In practice this is the privacy notice, given at the point of collection: who you are, what you collect, why, the lawful basis, who you share it with, how long you keep it, and their rights. Article 12(1) sets five separate qualities, and they are not synonyms — the information must be concise, transparent, intelligible, easily accessible, and in clear and plain language. A notice can be perfectly readable and still fail on accessibility because nobody can find it. Two things worth saying plainly:
- An internal data protection policy is not a privacy notice. A policy tells staff what to do; a notice tells the individual what is happening to their data. Having one does not discharge the duty to provide the other. (Note the ICO treats “privacy notice”, “privacy policy” and “privacy information” as the same thing — the distinction that matters is internal versus individual-facing, not the word on the front.)
- “Concise, transparent, intelligible and easily accessible” and “clear and plain language” are five separate legal requirements, not a style preference. The ICO’s advice on testing whether a notice meets them is to put it in front of the people it is written for — user testing and consultation — rather than to score it.
6 · Individual rights, and subject access requests
People have rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights around automated decision-making (Articles 15 to 22D). The one you will meet most is the right of access.
Article 15(1): “The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed …; (d) where possible, the envisaged period for which the personal data will be stored …; (e) the existence of the right to request … rectification or erasure …; (ea) the right to make a complaint to the controller under section 164A of the 2018 Act; (f) the right to make a complaint to the Commissioner under section 165 of the 2018 Act; (g) where the personal data are not collected from the data subject, any available information as to their source; (h) the existence of automated decision-making, including profiling, which is subject to the requirement to provide safeguards under Article 22C and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject”.
The clock — and where it now lives
This is the provision most often quoted from memory, and the wording changed. The one-month deadline used to sit in Article 12(3) itself. The Data (Use and Access) Act 2025 moved it into a new Article 12A, and Article 12(3) now simply points there. Anything still citing “one month under Article 12(3)” is quoting a superseded text.
Article 12(3): “The controller shall provide information on action taken on a request made under or by virtue of Articles 15 to 22D to the data subject without undue delay and in any event before the end of the applicable time period (see Article 12A).”
Article 12A(1): “the applicable time period” means the period of one month beginning with “the relevant time”.
Article 12A(3): “The controller may, by giving notice to the data subject, extend the applicable time period by two further months where that is necessary by reason of— (a) the complexity of requests made by the data subject, or (b) the number of such requests.”
The month itself is unchanged, and so is the two-month extension. Two things are worth knowing about the new drafting: the extension requires notice to the data subject, and the clock is kinder about missing information — where you reasonably need proof of identity, the month does not start until you receive it (Article 12A(2)), and where you need the request clarified, it pauses while you wait (Article 12A(5)). A genuine improvement on the old position, but only if you actually ask, promptly, and record when you did.
Article 12(5): the information “shall be provided free of charge”, though a “reasonable fee” or refusal is allowed for “manifestly unfounded or excessive” requests.
- A request can be made verbally or in writing, including by social media, to any part of the organisation, without using the words “subject access request” or any form. You can offer a standard form, but you must make clear it is not compulsory. If someone asks any member of staff for what you hold on them, the clock has started — and days lost before it reaches the right person are days off the month.
- Check which text your own procedure quotes. A DSAR procedure citing the one-month deadline as “Article 12(3)” has not been reviewed since the Data (Use and Access) Act 2025 moved it to Article 12A.
- Health and clinical records in a request need care: the DPA 2018 allows some health information to be withheld where disclosure would cause serious harm, and third-party information has to be considered before release. These are not decisions to take alone.
- Never start deleting anything once a request has arrived. Section 173(3) of the DPA 2018 makes it an offence to “alter, deface, block, erase, destroy or conceal information with the intention of preventing disclosure” of what the requester would have been entitled to receive. It bites on the controller, its officers, and people employed by or acting under its direction.
7 · Erasure, and the other rights
Article 17(1): “The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay … where one of the following grounds applies: (a) the personal data are no longer necessary in relation to the purposes for which they were collected …; (b) the data subject withdraws consent on which the processing is based … and where there is no other legal ground for the processing; (c) the data subject objects … and there are no overriding legitimate grounds …; (d) the personal data have been unlawfully processed; (e) the personal data have to be erased for compliance with a legal obligation …; (f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).”
The catch is Article 17(3): erasure does not apply where the data is still needed to comply with a legal obligation, or to establish or defend legal claims. So “the right to be forgotten” does not let someone wipe a record you are contractually or legally required to keep — but you do have to explain why, within the same one month.
The others in brief: rectification (fix inaccurate data, Article 16), restriction (pause processing while a dispute is resolved, Article 18), portability (a reusable copy, Article 20) and objection (Article 21). All carry the same one-month clock under Article 12A. Article 21(2) and (3) are worth knowing separately: an objection to direct marketing is absolute — there is no balancing test, and once made the data “shall no longer be processed for such purposes”.
8 · Keeping data secure
Article 32(1): “Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.”
Note (c) and (d). Backups you have never restored from, and controls you have never tested, do not meet Article 32 — the ability to restore and the process for testing are in the text. This is also where a certification such as Cyber Essentials or ISO 27001 earns its keep: not because either is legally required, but because they are evidence that the measures exist and are checked.
Sending data outside the UK
Chapter V adds a separate requirement on top of everything above: a restricted transfer needs a transfer mechanism. Either the destination is covered by UK adequacy regulations, or you put an appropriate safeguard in place — most often the IDTA, or the UK Addendum to the EU standard contractual clauses — and carry out a transfer risk assessment on whether the protection survives in that country in practice. This bites more often than people expect, because it is triggered by a supplier's hosting or support arrangements rather than by any deliberate decision to send data abroad. Ask the question at the same time as the impact assessment, not afterwards.
9 · Personal data breaches — the 72 hours
A breach is not only a hacker. A lost laptop, an email to the wrong person, a file left on a train, ransomware, and accidental deletion with no backup are all personal data breaches.
Article 33(1): “In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification under this paragraph is not made within 72 hours, it shall be accompanied by reasons for the delay.”
Article 34(1): “When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.”
- The 72 hours runs from when the organisation becomes aware, which the guidance the ICO works from reads as the point of reasonable certainty that a breach has happened — enough room for a short check, not for a week of deliberation. Report it internally the moment you spot it even if you are not sure it counts, because the clock is not yours to start.
- Two different thresholds, and this is the point most often missed: telling the regulator is triggered by a risk to individuals; telling the individuals is triggered by a high risk. One does not imply the other.
- 72 hours is a backstop, not an allowance — the duty is “without undue delay”. It is a continuous 72 hours rather than three working days, so a Friday discovery does not buy until Monday.
- Article 33(5) requires you to record every breach, including the ones you decide not to report, with the facts, the effects and the action taken. An organisation that reports the serious ones and keeps no log of the rest has a gap an audit will find, and no evidence for the judgement it made.
- Article 33(2): a processor who becomes aware of a breach must notify the controller without undue delay. There is no separate 72 hours for them — and the controller’s own clock generally starts when the processor tells them, which is why “without undue delay” is the phrase doing the work.
10 · Data protection impact assessments
Article 35(1): “Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.”
Note “prior to”. A DPIA done before a system is chosen is a short piece of work; the same assessment after go-live is an argument about a decision already taken. The practical rule for everyone else in the organisation is to raise a new app, tool or supplier that will touch personal data before it is signed, not after.
Three statutory triggers sit in Article 35(3): systematic and extensive automated evaluation producing legal or similarly significant effects; large-scale processing of special category or criminal offence data; and systematic monitoring of a publicly accessible area on a large scale.
The ICO adds ten of its own, and the distinction between them decides the answer. Five stand alone — denial of service, large-scale profiling, data matching, targeting children or other vulnerable people, and processing risking physical harm. Five require a DPIA only in combination with another criterion — innovative technology, biometrics, genetic data, invisible processing, and tracking. Reading past that rider produces a DPIA that was never required; missing one of the standalone five produces the opposite and worse error. The European criteria the ICO also adopts work on a rule of thumb that two factors together usually indicate a DPIA, though the ICO is explicit that this is not a strict rule.
Who has to be asked, and what happens if the risk remains
Article 35(2) puts a duty on the controller to seek the DPO's advice where one is appointed — the ICO states this as a must, and it is a stronger obligation than the DPO's own task list in Article 39(1) implies. On sign-off, the ICO leaves it to each organisation to decide who carries out a DPIA and who signs it; there is no rule that the author cannot. What there is a rule about is the residual risk: under Article 36, if a high risk remains after mitigation, you must consult the ICO before the processing starts. High residual risk cannot simply be accepted internally, however senior the person accepting it.
11 · The data protection officer
Article 38(1): “The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.”
Article 39(1): the DPO's tasks include “to inform and advise the controller … and the employees who carry out processing of their obligations”, “to monitor compliance”, “to provide advice where requested as regards the data protection impact assessment”, and “to act as the contact point for the Commissioner on issues relating to processing”.
Article 38(3): “The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks.” … “The data protection officer shall directly report to the highest management level of the controller or the processor.”
Those last two clauses are the ones that matter, and the ones most often overlooked. A DPO who reports to the person whose decisions they are meant to scrutinise is not independent in the sense Article 38 means. Article 38(6) is often described as barring the DPO from holding other roles. It does not: it says the DPO “may fulfil other tasks and duties”, and puts the duty on the controller or processor to “ensure that any such tasks and duties do not result in a conflict of interests”. The distinction matters, because it is the organisation's job to prevent the conflict, not the DPO's job to avoid the role. In practice the conflict is hard to avoid where the post-holder also decides how personal data is processed — which is why the head of IT, HR or operations is usually the wrong person to hold it.
One more that gets forgotten: Article 37(7) requires the controller or processor to “publish the contact details of the data protection officer and communicate them to the Commissioner”. If the appointment is not recorded in the documents that name role holders, that duty has not been met however real the appointment is.
12 · Accountability — proving it
Article 30(1): “Each controller … shall maintain a record of processing activities under its responsibility.”
The record of processing activities is the document everything else hangs off — privacy notices are built from it, retention schedules are built from it, and a regulator will ask for it first. It is only accurate if teams say when their processing changes, which makes it everyone's job rather than one person's.
Article 30(5) limits the duty for organisations with fewer than 250 staff, but the exemption is narrower than it sounds: it falls away where the processing is likely to result in a risk to individuals, is not occasional, or involves special category or criminal offence data — which covers most of what a small organisation handling case records actually does. In practice the sensible position for anyone in that position is to keep the record anyway.
The clause people forget to put in the contract
Where you engage a processor, Article 28(3) requires a written contract containing specified terms — subject matter and duration, nature and purpose, type of data and categories of individual, and the processor's obligations on instructions, confidentiality, security, sub-processors, assisting with rights requests and breaches, deletion or return at the end, and audit. A general services agreement that never mentions these does not satisfy Article 28, however commercially thorough it is.
The criminal offence worth knowing about
DPA 2018, s.170(1): “It is an offence for a person knowingly or recklessly— (a) to obtain or disclose personal data without the consent of the controller, (b) to procure the disclosure of personal data to another person without the consent of the controller, or (c) after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained”.
In plain terms: looking through records you have no business in, or taking data with you when you leave, can be a personal criminal offence — prosecuted against the individual, not the employer, and not merely a disciplinary matter.
13 · What the Data (Use and Access) Act 2025 changed
UK data protection law was amended by the Data (Use and Access) Act 2025, commenced in stages. The principles, lawful bases and rights above all still stand. The substantive changes for controllers are all in force — the data protection provisions commenced by 5 February 2026 and the new complaints duty on 19 June 2026; the changes worth knowing:
| Change | In force | What it means |
|---|---|---|
| Duty to handle complaints — DPA 2018 s.164A | 19 June 2026 | Controllers must have a route to receive and handle data protection complaints, acknowledge within 30 days and investigate without undue delay. A complaints process that exists only for service complaints does not satisfy this. |
| Solely automated decision-making relaxed | 5 February 2026 | A wider set of lawful bases can support it, with safeguards: tell people it is happening, let them contest it and obtain human review. Special category data keeps the stricter treatment. |
| “Recognised legitimate interests” — Article 6(1)(ea) and Annex 1 | 5 February 2026 | A seventh lawful basis, for a closed list of public-interest purposes — disclosure for a public task, national security, public security and defence, emergencies, crime, and safeguarding vulnerable individuals — with no balancing test required. Closed list, and not a general-purpose shortcut. It does not apply to public authorities performing their tasks. |
| PECR fines raised | 5 February 2026 | Brought in line with UK GDPR: up to £17.5 million or 4% of global turnover, whichever is higher, replacing the old £500,000 cap. This is the change that most alters the risk of getting marketing consent wrong. |
14 · Quotes to paste into an email
Short and self-contained, for when someone needs the actual wording rather than a paraphrase.
Accountability — Article 5(2). “The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).”
Data minimisation — Article 5(1)(c). Personal data shall be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”.
Security — Article 5(1)(f). Personal data shall be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage”.
Subject access timing — Articles 12(3) and 12A. The controller shall respond “without undue delay and in any event before the end of the applicable time period (see Article 12A)”, and Article 12A(1) sets that period at one month.
Breach notification — Article 33(1). The controller shall notify a breach to the Commissioner “without undue delay and, where feasible, not later than 72 hours after having become aware of it”.
Special category data — Article 9(1). Processing of data revealing health, and the other special categories, “shall be prohibited” unless a specific condition is met.
The criminal offence — DPA 2018 s.170(1). “It is an offence for a person knowingly or recklessly … obtain or disclose personal data without the consent of the controller”.
The five that matter most
- Only use data you need, for the reason you were given it.
- If someone asks for their data, log it the same day. The month runs from receipt of the request — or, where you reasonably need proof of identity, from the day it arrives; and it pauses while you wait for a clarification you asked for promptly. A complaint is a different regime with a different clock: acknowledge within 30 days and investigate without undue delay.
- Report a suspected breach internally the moment you spot it, so the organisation can decide. The legal 72 hours runs from the point of reasonable certainty that a breach has occurred, which allows a short investigation — but not one conducted alone, by the person who found it, over a weekend. Not every breach is reportable; every breach is recordable.
- Never release health or clinical records on your own judgement.
- Raise a new tool or supplier that touches personal data before it goes live, not after.
Last reviewed 24 August 2026. Quotations are from the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025. Law moves and this page does not update itself, so check the current position before relying on it. A working reference, not legal advice — for a decision that matters, read the provision itself and take proper advice.
Direct marketing and PECR
the rules that are stricter than UK GDPR, and catch people out
Direct marketing in the UK sits at the junction of two regimes. PECR — the Privacy and Electronic Communications Regulations 2003 — governs the communication; UK GDPR governs the data. PECR is the stricter of the two, and the mistake that costs organisations money is assuming a UK GDPR argument will carry the day when PECR applies.
The core rule: electronic direct marketing to an individual — email, SMS, automated call, fax — needs prior consent. Pre-ticked boxes do not give it, bundled consent does not give it, and “we have a legitimate interest” is not an answer to a PECR question.
The exception that changes everything for B2B: the PECR rule on marketing by electronic mail does not apply to corporate subscribers. You can send marketing email or SMS to a company, a limited liability partnership, a Scottish partnership or some government bodies without PECR consent. UK GDPR still applies to any individual named in the message, the sender must still be identified, and an opt-out must still work — but the consent requirement itself does not bite. Sole traders and ordinary partnerships are individual subscribers, so they do get the full protection.
1 · The words that matter
| Term | What it means |
|---|---|
| Direct marketing | Any communication of advertising or marketing material directed to particular individuals. Note “aims and ideals” count as well as goods and services — a campaign, a cause or a survey promoting a position can be marketing. |
| Electronic mail | Wider than most people assume. The ICO reads it as any text, voice, sound or image message stored in the network or on the recipient's device — so email and SMS, but also voicemail, in-app messages and social media direct messages. A campaign run through DMs is squarely inside regulation 22. |
| Electronic direct marketing | Marketing by electronic mail, automated call or fax. To an individual subscriber these need prior consent, with the soft opt-in exceptions below. To a corporate subscriber, the electronic mail consent rule does not apply at all. |
| Soft opt-in | PECR reg. 22(3). Where you obtained the contact details in the course of the sale, or negotiations for the sale, of a product or service to that person, you may market your own similar products and services by electronic mail without prior consent — provided a clear opt-out was offered at the point of collection and is offered in every message since. |
| Non-electronic marketing | Post, leaflets, face-to-face. PECR does not apply, but you still need a UK GDPR lawful basis and the individual can still object under Article 21. |
| Consent (in a PECR context) | The UK GDPR standard: freely given, specific, informed and unambiguous, by a clear affirmative action. Obtained before the first message. Separate from any other consent. Withdrawable at any time, as easily as it was given. |
| Transactional message | A message about performing the contract — appointment reminders, delivery updates, password resets, “your session is on Tuesday”. Not marketing, so no PECR consent needed. A UK GDPR lawful basis is still required. |
2 · Is it marketing? The quick test
Marketing — needs PECR consent
- Email about a new service, even one related to what they already receive
- SMS promoting a course, resource or product
- Any unsolicited outbound message about what you offer
- A newsletter that carries offers, even an educational one
- “Join our mailing list” invitations
- A satisfaction survey used to promote further services
Not marketing — lawful basis still needed
A reply the person asked for is not on this list. That is solicited marketing — outside regulation 22, but still marketing.
- Appointment reminders and confirmations
- Progress updates on the service they are currently receiving
- Case or account review summaries
- Correspondence you are contractually required to send
- Service messages: outages, changes to terms, security notices
The awkward middle: a message that is mostly transactional with a promotional paragraph bolted on is a marketing message. Splitting them is safer than hoping the balance of the text saves you.
3 · Soft opt-in is narrower than people think
Five conditions must all hold, and the whole exception falls away if any one fails:
- You obtained the details yourself, directly from the person. This is the one most often missed. If another organisation collected them for you — including another company in your own group — the soft opt-in does not apply.
- You obtained them in the course of a sale or negotiations for a sale. Nothing has to have been bought: the ICO's test is that the person actively expressed an interest in buying. An enquiry can qualify; a name captured at an event or from a referral does not.
- You are marketing your own similar products or services — not a partner's, not a sister organisation's.
- The individual was given a simple opt-out at the point of collection.
- An opt-out is offered in every subsequent message.
- “Similar” means similar. A genuinely different offering, a new line, or a service with a different purpose and eligibility is not similar just because you provide both.
- It has never applied to cold contacts who never expressed an interest in buying, and never to a bought-in list — for email exactly as much as for SMS.
- It covers electronic mail. It does not cover live calls, which have their own regime built around the Telephone Preference Service.
- There is no expiry written into it. Whether an old relationship still supports a message is judged on what the person would reasonably expect, not on a fixed cut-off — but the further back the sale, the harder that is to argue.
The charitable purpose soft opt-in — new, and easy to get wrong
The Data (Use and Access) Act 2025 inserted a second soft opt-in at regulation 22(3A), in force 5 February 2026, letting charities send electronic mail whose sole purpose is to further one or more of the charity’s charitable purposes, to people who previously expressed an interest in or offered support to those purposes, subject to conditions mirroring the ones above. Two traps sit around it:
- It is not retrospective. It can only be used where the contact details were obtained on or after 5 February 2026. An existing supporter list collected before that date is outside it.
- The ordinary products-and-services soft opt-in must not be used for campaigning or fundraising, even to existing supporters. Charities that assumed otherwise were non-compliant before this change and still are, outside the new route.
4 · Consent does not transfer
This is the principle that causes the most trouble in organisations that run more than one service. The ICO's test is that consent must be specific to the purposes it was given for, and that you must name any other controller who will rely on it. In practice that means consent given for one service will not usually stretch to marketing a different one — though the unit that matters is the purpose, not the org chart, and the ICO does not demand separate consent for activities that are clearly interdependent. Read the wording you actually used before deciding.
That holds even where the services are run by the same organisation and share a system, and it holds across a corporate group: a separate company is a separate controller, and “we are all part of the same group” is not a consent.
| Situation | New consent? | Why |
|---|---|---|
| A deeper tier of the same service, under the same agreement | Usually not | Same service, same relationship — if the original consent wording covered the full scope of what that service includes. Check the wording rather than assuming. |
| A different service, different funder or contract | Yes | Separate relationship. Soft opt-in will not rescue it, because the services are not “similar”. |
| A service run by another company in the group | Yes | Different controller. Consent must name them. |
| Follow-up after the relationship has ended | Yes, if it is marketing | Assume consent ends when the service does. |
| A follow-up survey you are contractually required to run | No | Evaluation required by the contract is not marketing — but an optional outreach dressed as a survey is. |
| They asked you what else is available | No | A solicited reply. Answer it, and still offer an opt-out for anything ongoing. |
Signposting is not marketing — but the line is real
Mentioning another service in a review meeting, because it is relevant to the person in front of you and your service includes onward referral, is a conversation — and PECR's electronic mail rules do not reach a conversation at all. Emailing everyone who finished last month about that service is marketing.
Two corrections to the way this is usually explained, because the intuitive version is wrong on both counts. Content is decisive. The ICO's position is that if a routine service communication has marketing elements in it, then it is direct marketing — you cannot immunise a promotional paragraph by attaching it to a billing message. And solicited does not mean “not marketing”. A reply someone asked for is solicited marketing: still direct marketing, so it still needs a lawful basis and still engages the absolute right to object under Article 21(2). What being solicited does is take it outside regulation 22, which bites only on unsolicited communications. Those are different things, and treating them as the same is how the objection right gets missed.
What a defensible audit trail looks like
- The original consent: what was agreed, the exact wording shown, the timestamp, and the method.
- Any cross-service consent recorded separately, with its own affirmative action and timestamp.
- A note of the reason a recommendation was made, in the record for that individual.
- Withdrawals recorded with the same care, and acted on immediately.
5 · Channel by channel
| What you are sending | PECR consent? | UK GDPR basis | Notes |
|---|---|---|---|
| Transactional email — confirmations, reminders, resets | No | Contract, or public task | Not marketing. Keep it genuinely transactional. |
| Service updates within the existing scope | Depends what is in it | Contract, or consent if it is marketing | There is no middle category. Either the message is genuinely a service message, and no PECR consent is needed at all, or it contains marketing, and it needs consent or the soft opt-in. Deciding it is “mostly” a service message is how organisations end up sending marketing under a service label. |
| Marketing a new or external offering by email, to an individual | Yes, prior consent | Consent | Affirmative tick, not pre-ticked, not bundled. |
| The same email to a corporate subscriber | No | Legitimate interests, usually | Regulation 22 does not apply to corporate subscribers. Identify yourself and provide a working opt-out regardless — that duty applies to both. |
| SMS reminders about a booking | No | Contract | Transactional. |
| SMS marketing campaign | Yes, prior consent | Consent | Same rule as email; soft opt-in only in the narrow case above. |
| Live telephone call to a business | No | Legitimate interests, usually | Screen against both the CTPS and the TPS, plus your own do-not-call list — sole traders and ordinary partnerships are individual subscribers and register with the TPS. An employee's work number counts as a corporate subscriber, because the subscriber is their employer. A caller is not in breach for the first 28 days after a number is listed, so treat a registration as live from day one. |
| Live telephone call to an individual | No, but screen against the TPS | Legitimate interests or consent | Calling a TPS-registered number without consent is a breach in itself. Claims management calls need consent outright; pension scheme calls are tighter still — only trustees, managers or FCA-authorised firms may make them, and then only with consent or an existing relationship that meets strict conditions. |
| Automated recorded call | Yes, specific consent | Consent | The strictest of the lot — general marketing consent is not enough. |
| Post and leaflets | Not applicable | Legitimate interests, usually | PECR is silent; the right to object still applies. |
| In-person, collecting details as you go | No | Depends on purpose | Privacy information has to be given at the point of collection. |
6 · The traps
- Soft opt-in is narrower than you think. Existing customers, similar products, opt-out every time. Miss any element and it does not apply.
- Interest in one thing is not consent for another. Consent to receive a service is not consent to be marketed about anything else.
- PECR beats UK GDPR on consent. Even where legitimate interests would support marketing under UK GDPR, PECR's rules for electronic channels are stricter and they govern.
- Pre-ticked boxes are invalid. Consent needs a clear affirmative action, and a separate one — not bundled into accepting terms.
- Withdrawal must be acted on without undue delay. The ICO sets no number, but a batch job that runs monthly is not a defence, and a message sent after someone opted out is a breach whatever the internal process says. Do not confuse this with the 28-day grace regulation 21(3) gives a caller after a number joins the TPS or CTPS — a different clock entirely.
- Liability follows the instigator, not only the sender. If you commission an agency to run a campaign, you instigated it, and the ICO has fined organisations on that basis.
- Consent does not cascade across services or group companies.
- Do not treat a closed file as a mailing list. Consent has no fixed expiry, but it should be refreshed at sensible intervals, and the further back the relationship the harder it is to argue the person still expects to hear from you.
- Buying or renting a list rarely works. The consent must have named you specifically; generic “trusted third parties” consent will not do.
- Every message must identify you and give a working opt-out. Sending from an unmonitored address with no unsubscribe route is a breach on its own.
Since 5 February 2026 the maximum PECR penalty has matched UK GDPR levels — up to £17.5 million or 4% of global turnover, whichever is higher, replacing the previous £500,000 cap. Getting marketing consent wrong stopped being a cheap mistake.
7 · A consent wording that works
The shape matters more than the words. Separate boxes, none pre-ticked, each naming what it covers and who will be contacting them.
Why this shape works
- Separate consent per service, so the audit trail is per service too.
- Someone can opt into one and not another — which is what “specific” means.
- Nothing is pre-ticked and nothing is bundled with accepting the service itself.
- It names any third party rather than saying “selected partners”.
- It makes clear that refusing has no consequence, which is what makes the consent freely given.
The other half of PECR
PECR is not only about marketing messages. Regulation 6 governs storing information on, or reading it from, someone's device — cookies, but also local storage, device fingerprinting and the tracking pixels embedded in marketing email. The Data (Use and Access) Act 2025 restructured it from 5 February 2026: storing or accessing information is prohibited unless one of the cases in a new Schedule A1 to PECR applies — consent, the long-standing transmission and strictly-necessary exemptions now moved into the Schedule, and a handful of new low-risk exceptions. Analytics is the case most often got wrong. It has never been strictly necessary; the new statistical-purposes exception does let first-party analytics run without consent, but only for improving the service, only if the data is not shared with anyone except someone helping you make those improvements, only with clear information, and only with a free and simple way to object — conditions, not a free-for-all. A guide that stops at email is only half a PECR guide.
8 · Where the rules live
- PECR 2003 — regulation 6 covers cookies and device access; regulations 19 to 24 cover automated calls, live calls, fax and electronic mail. Regulation 22 is the electronic mail rule; 22(3) is the products-and-services soft opt-in and 22(3A) the charitable purpose one.
- UK GDPR Articles 6 and 7 — lawful basis, and the conditions for valid consent.
- UK GDPR Article 21(2) — the absolute right to object to direct marketing. There is no balancing test: once they object, you stop.
- Data Protection Act 2018 — including the enforcement machinery PECR borrows.
- Data (Use and Access) Act 2025 — raised the PECR penalty ceiling, added the charitable purpose soft opt-in and restructured the cookie rules, all from 5 February 2026.
- ICO direct marketing guidance — linked in the Marketing and electronic communications section above.
Last reviewed 24 August 2026, against PECR as amended from 5 February 2026. Law moves and this page does not update itself, so check the current position before relying on it. A working reference, not legal advice: where a decision carries real consequence, read the regulation and take proper advice.
Windows command reference
the ones worth keeping, with what each switch does
Commands for backup, repair, disk checks, network tests and file listing — each with an explanation of what it does and, where it matters, what it will destroy if you get it wrong. Paths are shown as placeholders: replace anything in angle brackets before running. Type below to filter.
Run an elevated prompt where noted. Treat /MIR, /MOVE, /PURGE, cipher /w, chkdsk /f and anything with -Force as capable of losing data. Check the source and destination before you press enter, and quote any path containing a space.
The commands
Switches worth memorising
Robocopy
/E all subdirectories, including empty ones · /S subdirectories, excluding empty · /MIR mirror, equivalent to /E plus /PURGE — deletes from the destination · /MOVE move files and directories, deleting them from the source · /MOV the same for files only · /PURGE delete destination files no longer in source · /XO skip older files · /XN skip newer · /XC skip changed files — same timestamp, different size (unchanged files are skipped by default anyway) · /XF exclude files · /XD exclude directories · /FFT assume FAT file times, 2-second precision — needed for exFAT and NAS · /Z restartable mode for large files — ignored when /MT is used · /MT:n n threads · /R:n retries · /W:n wait between retries · /SEC copy with data, attributes, timestamps and ACLs — not owner or auditing; use /COPYALL for those · /L list only, change nothing · /LOG:file write a log · /NFL /NDL quieten the output
Chkdsk
/scan online scan, no restart, NTFS only · /f fix errors — may need a restart on the system drive · /r find bad sectors and recover what is readable; includes /f and takes hours · /x force dismount first, invalidating open handles · /spotfix targeted repair of known issues · /offlinescanandfix offline scan and fix · /b clear the bad cluster list and rescan · /perf faster scan, more resources · /i /c less thorough, faster, NTFS only
SFC
/scannow scan and repair everything · /verifyonly report without repairing · /scanfile= a single file · /verifyfile= check a single file · /offbootdir /offwindir point at an offline installation
Cipher
/w:path overwrite free space on that volume · /e /d encrypt or decrypt with EFS · /c show encryption status · /s:dir apply through subdirectories · /x back up the EFS certificate and key · /k new certificate and key · /u find encrypted files · /rekey update files to the current key
Removing worksheet protection from a spreadsheet by editing the underlying XML is sometimes described as a fix. It is left out here deliberately: it is a technique for defeating a control, it only works on sheet protection rather than real encryption, and on a file you did not create it is the wrong thing to be doing. If you own the file and have lost the password, the honest route is your own backup or whoever set it.
How this site handles data
It would be poor form to publish a site like this without saying what it does. This is the whole of it.
What this site does not do
No analytics, no tracking pixels, and nothing of mine stored on your device — no cookie I set, no local storage, no session storage, no service worker. No third-party fonts or scripts in anything I wrote: every line of code and style is in the page itself. No forms, and no server of mine for anything to be sent to. The display options and every tool on this page keep their state in memory only, and forget it when you close the tab.
That covers my half of it. The host adds something of its own, and it is set out beside this.
What does happen
The site is hosted on Cloudflare Pages, so Cloudflare serves it and — like any web host — records the requests it receives, which will include your IP address. That processing is Cloudflare’s, under their terms, and I have no access to it.
Their bot protection is also switched on. On a first visit it loads a small script from this domain and posts a set of browser characteristics back to Cloudflare, which is how it decides whether you are a person. That is fingerprinting, by any honest definition of the word. It is theirs rather than mine, it is the price of hosting a site somewhere that will not fall over, and you will see those requests in the network tab next to this page. I have not turned on their analytics. Saying a site processes nothing at all would be untrue of any hosted page, so I am not going to say it.
Files you open in the tools are read by your own browser and never transmitted. Links out to the ICO, NCSC and others take you to sites with their own terms.
Toolkit
Everyday tools
Small utilities for the things that otherwise get done by hand: spreadsheet formulas, percentages, VAT and dates, converting units, reading a regular expression back in plain English, pulling stills out of a video, comparing two versions of a document, reading the headers of a suspicious email, and hashing and verifying files. All of it runs in your browser — nothing is uploaded and nothing is stored.
Spreadsheets the things that go wrong quietly in a workbook
CSV inspector
what is actually in that file before you import itReads a file in your browser and reports what is actually in each column: the types it detects, blanks, mixed date formats, numbers stored as text, mangled characters from an encoding mismatch, ragged rows and invisible whitespace that breaks lookups.
Drop a CSV and get the shape of it: columns, detected types, blanks, duplicate rows, mixed date formats, stray whitespace and the encoding problems that turn an apostrophe into three characters. Read locally; nothing is uploaded.
Drop a CSV here, or
Excel formula explainer
break a formula apart and check it for trapsTakes the formula apart into a labelled tree, explains every function and numbers every argument, then reviews it for the things that go wrong quietly — unbalanced brackets, approximate lookups that need a sorted column, volatile functions, deeply nested IFs and hardcoded numbers.
Paste a formula and it is taken apart into its structure, with each function explained and each argument numbered — then reviewed for the things that quietly go wrong: unbalanced brackets, approximate lookups, volatile functions, nested IFs, hardcoded numbers.
Try one: · ·
Formula syntax converter
Excel ⇄ Google Sheets ⇄ LibreOfficeSwaps argument separators between comma and semicolon locales and flags the functions that will not survive the move — XLOOKUP and the TEXT family in LibreOffice, spilling versus ARRAYFORMULA in Sheets.
Mostly this is about argument separators and a handful of renamed functions. Paste a formula, pick where it is going, and get the version that will paste in cleanly.
Lookup builder
get a correct XLOOKUP, and the INDEX/MATCH fallbackAnswer four questions about what you are looking up and where, and it writes both the XLOOKUP and the INDEX/MATCH that does the same job — with the not-found value handled, and a note on why either beats VLOOKUP.
Answer what you are looking for and where, and take away a formula that works — plus the older equivalent for anyone on a version without XLOOKUP.
Numbers and dates arithmetic that is easy to get subtly wrong
Date difference & deadlines
months added correctly at month endsThe gap between two dates in years, months and days as well as a plain day count — and adding a period to a date with the month-end clamp applied, so one month after 31 January is the end of February rather than 3 March.
The gap between two dates in years, months and days — and adding a period to a date, which is fiddlier than it looks: one month after 31 January is 28 or 29 February, not 3 March.
Percentages
including the reverse one everybody gets wrongFour calculations in one place — a percentage of a number, the change between two numbers, adding or removing a percentage, and working back to the original. Precision adapts, so a movement of a hundredth of a percent still shows as a movement rather than 0.00%.
Four calculations that come up constantly. The last is the one worth knowing: taking 20% off a gross figure does not give you the net, because the 20% was added to a smaller number.
Percentage of a number
Change between two numbers
Add or remove a percentage
Reverse — find the original
Units and file sizes
including why a 1 TB drive shows as 931 GBLength, mass, temperature, area, volume, speed, time and data. The data one explains the drive-size discrepancy properly, and warns about the traps: bits against bytes for broadband speed, and UK against US pints and gallons.
Everyday conversions, plus the data one that trips everybody up: manufacturers sell drives in powers of ten and Windows reports them in powers of two, while still calling both “GB”. Nothing is missing from the drive — the two are counting differently.
VAT
add it, remove it, or check a gross figureShows both readings of the same figure at once — treating it as net and adding VAT, and treating it as gross and extracting it — at 20%, 5% or zero, and spells out how much you would be short if you took the shortcut of subtracting 20% from a gross figure.
To remove VAT at 20% you divide by 1.2, or equivalently take one sixth off the gross. Subtracting 20% is the common mistake and leaves you short.
Working days
England & Wales bank holidays built inCounts working days between two dates, or finds the date a number of working days away, excluding weekends and England and Wales bank holidays from the official GOV.UK list. It names each bank holiday it excluded so you can check the answer.
Counts working days between two dates, or finds the date a number of working days away. Weekends and England and Wales bank holidays are excluded, using the official list published by GOV.UK.
Converting and explaining turning one shape of data into another, and reading it back
JSON and CSV
convert either way, and see what breaksConverts either way. Columns are taken from every record rather than just the first, nested objects are flattened with a dot, and quoting follows RFC 4180 so commas, quotes and line breaks survive the trip into Excel.
Turns an array of JSON objects into a spreadsheet-ready CSV, or a CSV back into JSON. Columns are taken from every key seen across all records, not just the first — the usual cause of silently dropped fields. Quoting follows RFC 4180, so values containing commas, quotes or line breaks survive the trip into Excel.
Keyboard shortcuts
Excel and Windows, the ones that actually save timeSixty-three shortcuts across Excel, Windows and File Explorer, with the Mac equivalent where Excel differs. Filter by what you are trying to do rather than by the keys, since nobody remembers which combination does the thing they want.
Not the whole list — the ones worth committing to memory, with the Mac equivalent where Excel differs. Type to filter by what you are trying to do rather than by the keys.
| Does what | Windows | Mac |
|---|
Regular expression explainer
what the pattern actually says, in wordsReads a pattern back one piece at a time in plain English, indented by group depth, then runs it against your test text with the matches highlighted and any named capture groups laid out. It flags greedy matching, quantifiers that apply to one letter rather than the whole word, and the nesting that makes a pattern hang.
Paste a regular expression and it is read back to you a piece at a time in plain English, then run against your test text so you can see what it catches and what it misses. Regex is the sort of thing that is written once, pasted into a filter or a validation rule, and never looked at again — this is for the moment you have to work out what an inherited one does.
Try one: · · ·
Files and media what a file is carrying, and getting things out of it
Document diff
what changed between two versions of a fileCompares two versions of a document and shows exactly what was added, removed or reworded — paragraph by paragraph for Word, PDF, PowerPoint and text, cell by cell for Excel. Both files are read in your browser and never leave this device.
Two versions of a policy, a contract or a spreadsheet, and the question is always the same: what actually changed? Drop the original on the left and the revision on the right. Word, PowerPoint and PDF are compared paragraph by paragraph, with the changed words picked out inside each one; Excel is compared cell by cell, sheet by sheet, so a single altered number does not hide in a wall of text.
Supports .docx, .xlsx, .pptx, .pdf, .txt, .csv, .md, .json, .html and .xml — or paste text straight in. Formatting, images and comments are not compared: this is about the words and the values.
Original
Drop the original here, or
No file yet
Revised
Drop the revision here, or
No file yet
PDF text is extracted from the file's own content streams, which works for PDFs made from Word, Google Docs, LibreOffice and most report generators. A scanned PDF has no text to read, and a few unusually built PDFs will not decode cleanly — if the result looks wrong, export both versions to Word or plain text and compare those instead. Word tables and PowerPoint slides come through as paragraphs; headers, footers and speaker notes are not compared. Nothing is uploaded and nothing is stored.
Video frame extractor
pull stills out of a video, and the FFmpeg line for the ones it cannot openOpens a video in your browser, steps through it a frame at a time and saves any frame as a PNG or JPEG at the video’s own resolution. It will also take a still every few seconds across a whole clip, lay the set out as a single contact sheet, and pack the lot into one zip — and it writes the equivalent FFmpeg command as it goes, for long files, awkward codecs, or anything you would rather run properly.
Getting one clean still out of a video usually means a screenshot of a paused player: whatever scaling the window happened to be at, the play controls fading in over the shot, and no way to say exactly which frame you meant. This decodes the video and draws the frame itself, so the result is the video’s own resolution with nothing on top of it, and the timecode is recorded to the millisecond.
The video is opened by your own browser and never leaves this device. It is not uploaded, and nothing is stored — close the tab and it is gone. A frame saved here also carries none of the source file’s metadata, since it is drawn fresh rather than extracted.
Drop a video here, or
Whatever your browser can play: usually MP4 and MOV with H.264, and WebM. MKV, ProRes and most broadcast formats will not open — the FFmpeg command below covers those.
Take a still every few seconds
Every frame taken is kept in the browser until you clear it or close the video, so the limit below is really a memory budget. A full-resolution PNG of a 1080p frame is somewhere around 2 to 3 MB, so a hundred of them is a couple of hundred megabytes and a thousand is a few gigabytes, which is more than most machines will take kindly to. JPEG is roughly a tenth of that if you are taking a lot. The running total is shown as it goes, and nothing is written to disk until you save.
The same job in FFmpeg
For anything long, anything the browser will not decode, or anything you want to repeat: these are the commands for what is set above. Replace the input filename with the real path.
Two details worth keeping. Putting -ss before -i makes FFmpeg seek rather than decode its way there, which is the difference between instant and several minutes on a long file. And round=up is not decoration: the default rounding hands back the frame roughly one output period late, so fps=1/10 quietly gives you 9.96 seconds instead of 10.00, and nothing tells you.
Frames are held in memory while the page is open, so the number taken in one pass is capped. A video you did not make is still someone else’s work — this is for stills from your own footage, or for the ordinary uses that copyright law already allows.
What your documents give away
the metadata riding along inside a document or photoReads the metadata hidden inside Office files, PDFs and photographs: author, whoever last saved it, the software and version, timestamps to the second, and for photographs often the exact location the picture was taken. All of it survives being renamed, copied and emailed.
Every Office document, PDF and photograph carries metadata that travels with the file — author names, the name of whoever last saved it, the software and version, timestamps to the second, and in the case of photographs, often the exact location the picture was taken. None of it appears when you open the file, and all of it survives being renamed, copied and emailed.
Drop a file below and see what it is carrying. It is read by your browser and never leaves this device. Supports .docx, .xlsx, .pptx, .pdf and .jpg.
Drop a document or photo here, or
Try one you were about to send to someone.
Integrity and evidence proving a file is the one that was sent
Compare two hashes
check a hash somebody sent you against your ownFor when someone sends you a hash to check against your own. The comparison accumulates a difference across every character rather than stopping at the first mismatch, so it takes the same time whatever differs.
For when someone sends you a hash to check against your own. Both are compared in your browser and neither is uploaded.
Email header reader
who really sent it, which way it came, and whether the checks passedPaste the full headers of an email and get a plain-English account of where it came from: whether the sending server was allowed to send for that domain, whether the message was signed, whether replies would quietly go somewhere else, and every server it passed through on the way. Nothing is sent anywhere.
Every email carries a record of its journey in the headers — dozens of lines that mail programs hide because they look like noise. They are the best evidence you have when a message feels wrong. This reads them and tells you, without jargon, what they say: who the message claims to be from, whether the receiving server's checks backed that up, where replies would actually go, and the servers it passed through.
To get the headers: in Outlook open the message, then File → Properties and copy the "Internet headers" box; in Gmail open the message, use the three-dot menu → "Show original" and copy everything; in Apple Mail, View → Message → All Headers. Paste the lot below — the tool finds the headers on its own.
The pass/fail results come from the server that received the message, recorded in its Authentication-Results header — this tool reads them, it cannot re-run them, because verifying a signature means looking up keys in DNS and nothing here goes online. A message can pass every check and still be dangerous: the checks prove which domain sent it, not that the domain is honest or that the account was not compromised. Nothing you paste leaves this device.
File hash & transfer manifest
prove a file is byte-for-byte the one that was sentFingerprints files with SHA-256 in your own browser and produces a manifest — name, size, hash and timestamp for every file — as chain-of-custody evidence for a transfer. Nothing is uploaded, because there is no server to upload it to.
A SHA-256 hash is a fingerprint of a file’s exact bytes. Change one byte and the fingerprint changes completely, so comparing hashes proves whether a file is identical to the one that was sent — useful whenever a set of files is handed over and its integrity has to be evidenced afterwards, or when you need to show later that what you destroyed was what you meant to destroy. A manifest records the file name, size, hash and time for every file in a transfer, as chain-of-custody evidence.
Your files are read by your own browser and never leave this device. There is no server here to send them to.
Drop files here, or
Hashing happens on your device. Large files take a moment.
| File | Size | SHA-256 |
|---|
Verify a manifest
the receiving end of a transfer, which usually gets skippedThe receiving end of a transfer. Load a manifest you were sent, add the files that arrived, and every one is checked against its recorded hash — matched, altered, missing, or not on the manifest at all — with a report you can keep.
The other half of the job, and the half that usually gets skipped. Load a manifest you were sent, add the files you received, and every file is checked against its recorded hash — matched, altered, missing, or not on the manifest at all. This is the receiving end of a data transfer: the point at which you can say the records that arrived are the records that were sent.
1 · The manifest
No manifest loaded. JSON or CSV, as produced above.
2 · The files received
Hashed on your device and compared locally.
| File | Result | Detail |
|---|
Cryptography done in your browser, with nothing uploaded
Encrypt a file
AES-256 in the browser, with nothing uploadedAES-256-GCM with a key derived from your passphrase by PBKDF2 at 600,000 iterations. Encryption and decryption both happen on your device, so the passphrase never leaves it — and neither does the file.
AES-256-GCM, with the key derived from your passphrase using PBKDF2 at 600,000 iterations and a random salt. Encryption and decryption both happen in your browser. The output is a single file containing the salt, the initialisation vector and the ciphertext; feed it back in with the same passphrase to recover the original.
The honest caveat: this protects the file, not the passphrase. Getting the passphrase to the recipient safely is the hard part, and no browser tool solves it — send it by a different channel from the file, never in the same email.
Passphrase & password generator
and an honest estimate of how long it would holdBuilds either from the browser's cryptographic random source, with the character sets and length under your control, and reports the actual entropy in bits alongside an honest estimate of how long it would take to crack — assuming the attacker knows exactly how it was made.
Both modes draw from the browser’s cryptographic random source, using rejection sampling so no character or word is more likely than another. The strength figure is arithmetic — length multiplied by the bits each element contributes — not a guess, and the crack estimate assumes the attacker knows exactly how the secret was generated and can try a trillion candidates a second.
Drawn from a 256-word list embedded in this page, so each word is worth exactly 8 bits. A larger wordlist would need fewer words.
Look-alikes are Il1O0 — worth excluding for anything that will be read aloud or typed from paper, at a small cost in strength.
Sign and verify a file
prove who produced a file, not just that it is intactGenerates an ECDSA P-256 key pair, signs a file with the private key, and verifies a signature with the public one. A hash proves a file has not changed; a signature also proves who produced it.
ECDSA over P-256. Generate a key pair, sign a file, and anyone holding your public key can confirm the file has not changed since you signed it and that the signature came from the holder of the private key.
What it does not do: prove who you are. A signature proves possession of a key, not identity — that requires a certificate authority or some other trust infrastructure. Treat this as a demonstration of the mechanism rather than a document-signing service. The private key exists only in this tab and is gone when you close it.
Contact
Getting in touch
No form, just an address. A form would post your message through somebody else’s server, and there is no need for that.
ContactMe at daniellowther dot co dot uk
A role address on my own domain, so it can be retired and replaced if it ever ends up on a list. I read it in the evenings rather than during the working day, so a reply usually takes a few days.
Please don’t send attachments
Send a link, or paste the text into the message. Anything arriving with a file on it goes to a holding folder rather than the inbox, and is deleted unread if there is no obvious reason for the file to be there.