The Privacy Desk

One Desk for Data Protection and Cyber Security.

Not every organisation needs a full-time Data Protection Officer or an internal cyber team. But every organisation does need to manage data securely, meet its legal obligations, and respond calmly when issues arise.

That’s where The Privacy Desk comes in.

We provide support when you need it — expert guidance, practical solutions, and steady, responsive help you can rely on.

Data Protection · Cyber Security Governance · Data Security Risk Management

DPO DSPT SARs breach response Cyber Essentials CAF policy suite training
  • Outsourced DPO / UK GDPR representation
  • Data Security Risk Management
  • Vulnerability assessments
  • Business continuity
  • ICO registration & liaison
  • Data breach response & incident management
  • SAR handling & templates
  • Policies, RoPA, LIAs, DPIAs
  • Supplier assurance & due diligence
  • Staff training (short & engaging)
  • NHS DSPT & CAF support

Your Data. Your Risks. One Desk.

services & support

Data Governance: privacy and cyber handled together

Data governance & the modern world

There was a time when data protection and cyber security were treated as two separate roles; one focused on policies and privacy, the other on systems and threats. Different teams, different language, different priorities. Organisations don’t work like that anymore and neither does risk.

Data protection and cyber security are no longer separate issues. A decision around how personal data is stored, shared, or accessed will change the organisation’s level of cyber risk. Likewise, a change to technical controls, like passwords, access rules, or system security, will directly affect how well personal data is protected and how you meet legal obligations.

And it isn’t only about security or compliance because service design plays a part too. How teams work, where information is saved, who needs access, and how new tools are introduced all influence both privacy and cyber resilience.

When these areas are handled separately, small gaps appear: a missing approval, unclear ownership, different interpretations of risk. Over time, those gaps become vulnerabilities and vulnerabilities affect everyone.

When privacy and cyber are aligned, the organisation becomes safer, clearer, and easier to run. Data governance today is not about box ticking or policy documents; it’s about alignment.

one partner. clear responsibilities. practical delivery.
One desk, one relationship, one clear path forward

data protection

  • outsourced DPO (named) & UK GDPR representation
  • ICO registration & regulator liaison
  • SARs toolkit & handling support
  • DPIAs, LIAs, RoPA & accountability evidence
  • policy suite, templates & training
  • DSPT alignment & submissions

cyber security governance

  • Cyber Essentials / Plus readiness (evidence-led)
  • CAF gap reviews for NHS partners
  • supplier assurance & risk registers
  • incident response playbooks & drills
  • board reporting & clear action plans
  • staff awareness (short, human sessions)
services & support

Our Services

data protection and cyber security are stronger together. we keep it practical and human.

  • ICO registration
  • data breach support & response (including liaison with the ICO)
  • SAR support
  • policy and procedure support & advice
  • UK GDPR representation
  • data mapping support & advice
  • DPIAs
  • customer questionnaires & due diligence
  • general GDPR support
  • arranging GDPR staff training
  • NHS Data Security & Protection Toolkit (DSPT)
  • CAF-aligned reviews for NHS partners
  • Cyber Essentials & Cyber Essentials Plus readiness
  • ISO/IEC 27001 implementation support
nhs & public sector

nhs, dspt & caf support

experienced support for nhs partners and health providers, aligning data protection with clinical safety and real operations.

readiness review

rapid discovery, risk register, 90-day action plan.

delivery & evidence

policies, controls, supplier assurance, training & audits.

board & culture

clear reporting, incident playbooks, continuous improvement.

About

about emma

i’ve spent years delivering digital systems and data protection in healthcare - leading dspt submissions, supplier assurance, and governance frameworks across nhs and care settings. i combine practical privacy with real operational experience: helping organisations move from intent to evidence, from policy to practice.

  • extensive nhs and care provider experience
  • dspt planning, evidence gathering, and submission
  • supplier assurance, contract reviews, and dpiAs
  • sars, incident response, and training delivery
  • cyber essentials/cyber essentials plus and iso 27001 guidance

side note: when i’m not demystifying privacy, i write songs - and i’ve had three songs in eurovision national finals. it keeps my communication sharp and my empathy high.

why clients choose me

  • calm, clear, human approach
  • practical templates & playbooks
  • fixed-fee transparency
  • remote-first, responsive support
start here

let’s make privacy · cyber feel simple

email me with a line about what you need. i’ll reply within 24 hours.