Records of processing
Maintaining the record of processing activities required by Article 30, kept accurate against operational practice.

McCulloch Regulatory Compliance (“MRC”) acts as outsourced Data Protection Officer for controllers and processors under the UK GDPR and EU GDPR, providing the independent monitoring, advice, and supervisory-authority liaison the role requires, from data protection impact assessments to breach notification and international transfers, with a dedicated specialism in clinical trials.
Under Article 37 of the UK GDPR and the EU GDPR, the appointment of a Data Protection Officer is mandatory where an organisation's core activities consist of the large-scale processing of special category data, including health data, or the regular and systematic monitoring of individuals on a large scale, and for all public authorities. The Regulation permits the role to be fulfilled by an external service provider, which enables an organisation to meet its statutory obligation without appointing a full-time member of staff. For organisations in life sciences and health technology, appointment is frequently required.
The full scope of the Data Protection Officer role, each element mapped to the provision it discharges.
Maintaining the record of processing activities required by Article 30, kept accurate against operational practice.
Advising whether an assessment is required under Article 35, and reviewing the assessment of high-risk processing.
Advising the organisation and its personnel on their obligations, and monitoring compliance with the UK and EU GDPR.
Reviewing processors and sub-processors, together with the data processing terms that bind them.
Governing transfers from the UK and EEA under Chapter V, using the Standard Contractual Clauses, the UK International Data Transfer Agreement, and transfer risk assessments.
Raising awareness and training the personnel who handle personal data.
Delivered in person, remotely, or asynchronously through the MRC Learning Portal.
Assessing personal data breaches, meeting the 72-hour notification requirement, and communicating with data subjects where required.
Acting as the published point of contact for the supervisory authority and for data subjects.
MRC is appointed as the organisation's external Data Protection Officer and named as its point of contact for supervisory authorities and data subjects. The role is performed by a named senior privacy lead who maintains current knowledge of the organisation's processing, operates independently of its business functions, and remains accessible to the organisation, its data subjects, and the relevant authority.
Engagements are scaled to the organisation's circumstances, from an initial appointment to a mature multi-jurisdiction programme, and adjusted as processing activities change. The appointment provides the independence, resources, and reporting lines required by Articles 38 and 39, without the expense of a permanent hire.
Credentials
The service is led by a practitioner holding the CIPP/E, the International Association of Privacy Professionals’ certification in European data protection. The CIPP/E examines the GDPR and the wider European framework in depth, and is a recognised credential for those advising on compliance across the United Kingdom and the European Union.
MRC provides that expertise independently, as the appointed Data Protection Officer under Articles 37 to 39. It is not a law firm and does not provide legal advice or legal services in any jurisdiction.
Artificial intelligence systems process personal data and produce decisions affecting individuals, which brings them within the scope of data protection law. The GDPR applies to the personal data used to train, refine, and operate a model, and applies in parallel with the EU Artificial Intelligence Act rather than being displaced by it. The Data Protection Officer has a central role in assessing and documenting compliance across both regimes.
Artificial Intelligence practiceEstablishing a lawful basis for the personal data used to train and refine models, and observing purpose limitation and data minimisation.
Article 22 applies where decisions concerning individuals are taken without meaningful human involvement, and imposes specific safeguards and a right to an explanation.
High-risk processing by an artificial intelligence system ordinarily requires a data protection impact assessment before deployment, documenting the risks and the controls applied.
Informing individuals, clearly and accessibly, when their personal data is processed by an automated system and to what effect.
Identifying the areas in which the two regimes overlap, in order that a system satisfies both rather than one at the expense of the other.
Managing access, rectification, and erasure where personal data is embedded in models, prompts, and processing pipelines.
The latest fines, breaches and claims in data protection, from the UK and EU authorities and the courts. Updated daily; each links to the original report.
ICO8 Oct 2026
Crown Office and Procurator Fiscal Service13 Aug 2026
BBC21 Sept 2026
Financial Times13 Aug 2026
Reuters13 Sept 2026
Euronext Markets: Real-time Stock Market Data | live7 Oct 2026
Powered by Google NewsHeadlines are aggregated and updated daily; each links to the original report. Inclusion is not endorsement, and figures are as reported.
Clinical trials involve the large-scale processing of health data, which renders the appointment of a Data Protection Officer mandatory in most cases. The role in this context is distinct, comprising data protection impact assessments for the trial data flows, review of informed consent and participant information, review of the trial website and privacy notice, and assessment of CRO and vendor compliance.
Clinical Trials DPOCommon questions on the Data Protection Officer role under the UK GDPR and the EU GDPR. A fully referenced version, with the citations set out under OSCOLA, is available to download.
Appointment is mandatory where an organisation's core activities consist of large-scale, regular and systematic monitoring of individuals, or the large-scale processing of special category data such as health data, and for all public authorities. The same test applies under the UK GDPR and the EU GDPR. Organisations in life sciences and health technology frequently meet it.
GDPR, art 37(1); UK GDPR, art 37(1).
Yes. The role may be filled by a staff member or performed by an external provider on the basis of a service contract, which allows an organisation to meet its statutory obligation without a permanent hire.
GDPR, art 37(6).
No. The Data Protection Officer must be easily accessible to the organisation, data subjects, and the supervisory authority, but there is no requirement that the Officer be established in the United Kingdom or the Union. That requirement applies to the separate Article 27 representative, not to the Data Protection Officer.
GDPR, arts 37 to 39; cf art 27.
They are distinct roles. The Data Protection Officer provides independent monitoring and advice on compliance within the organisation. The Article 27 representative is the point of contact in the Union for a controller or processor not established there. An organisation may require both.
GDPR, art 37 and art 27.
An employee may hold the role, provided it gives rise to no conflict of interest. A processor that acts on the organisation's instructions, such as a contract research organisation, cannot provide the independent oversight the role requires, because it would be overseeing its own processing.
GDPR, art 38(6); WP29 DPO Guidelines, s 3.5.
The Officer informs and advises the organisation and its staff of their obligations, monitors compliance with the applicable data protection law, advises on data protection impact assessments, and cooperates with and acts as the contact point for the supervisory authority.
GDPR, art 39; and see art 35 and arts 33 to 34.
Where processing falls under both regimes, the appointment test is applied under each. A single appointment can discharge the obligation under both where the Officer meets the requirements of each regime and remains accessible to each supervisory authority.
UK GDPR, art 37; GDPR, art 37.
No. Personal data processed to train or operate an artificial intelligence system remains within data protection law, which applies in parallel with the EU Artificial Intelligence Act. High-risk processing ordinarily requires a data protection impact assessment, and decisions taken solely by automated means attract specific safeguards.
GDPR, art 35 and art 22.
MRC provides regulatory compliance advisory services. It is not a law firm and does not practise law. Nothing on this website constitutes legal advice, and neither your use of it nor any communication with us through it creates a professional, advisory, or contractual relationship. Such a relationship is formed only under a signed engagement agreement. Read the full disclaimer.
