Insights

Briefings for regulated practices

Precise, senior analyses of what your regulator requires of the web and email estate behind your practice — and how to hold it to that standard. Written to be read by a partner, not skimmed by a marketer.

Cornerstone briefings

NTSELAT · Estate agents

Why your UK estate agency website probably fails the NTSELAT Material Information rules (2026)

UK estate agency listings carry NTSELAT Material Information duties most agency-built sites quietly fail, plus a data-residency gap on valuation forms. What a regulated-grade estate puts right.

23 Jun 2026

ICAEW · Accountancy practices

Why your UK accountancy website probably fails ICAEW confidentiality

ICAEW Section 114 confidentiality, AML duties, and UK GDPR: why agency-built UK accountancy websites silently breach the confidentiality duty on enquiry forms and client-document portals — and what a regulated-grade estate puts right.

1 Jun 2026

ICO / UK GDPR · Clinics

Why your UK clinic's website probably breaks GDPR

UK GDPR for clinics: most agency-built websites silently fail data-controller duties around special-category health data. Where a typical site breaks the rules — and what a regulated-grade estate puts right.

1 Jun 2026

SRA · Law firms

Why your UK law firm's website probably fails SRA confidentiality

SRA confidentiality and UK GDPR: why agency-built UK solicitor websites silently breach Rule 6 on enquiry forms and document uploads — and what a regulated-grade estate puts right.

1 Jun 2026

KCSIE · Schools

Why your UK school's website probably fails KCSIE

KCSIE safeguarding and child-data duties trip up most UK school websites built by agencies. Where a typical site breaks the rules — and what a regulated-grade estate puts right.

1 Jun 2026

Clinics

CQC / ICO · Clinics

A CQC-ready clinic website: what to publish and what to keep private

What a CQC-registered clinic must publish on its website, what it must never publish, and where the line sits: Regulation 20A display of ratings, the duty of candour, and the UK GDPR limits on testimonials, photos, and patient data.

3 Jul 2026

NHS DSPT · Clinics

Does your private clinic need the NHS Data Security and Protection Toolkit (DSPT)?

A clear decision guide to the NHS DSPT for private UK clinics: who must complete it, who does not, how NHS contracts and NHSmail pull you into scope, what changed in Version 8, and the 30 June deadline.

3 Jul 2026

ICO / UK GDPR · Clinics

Health data on your clinic website: UK GDPR special-category rules in plain English

Special-category health data under UK GDPR, in plain English for UK clinics: the two-part lawful-basis test, why consent is usually the wrong basis for care, what a website form should never collect, and where the rules actually bite.

3 Jul 2026

ICO / UK GDPR · Clinics

Online booking for clinics without breaking data rules

How a UK clinic can offer online booking without breaking UK GDPR: why a booking is special-category health data, why the US-cloud booking tools most clinics use are the weak point, and what EU and UK-sovereign booking looks like.

3 Jul 2026

NHS DSPT · Clinics

DSPT compliance for UK clinics — the website-side checklist 2026

DSPT compliance checklist for UK clinics: private GPs, dentists, and physios in the NHS supply chain inherit DSPT website obligations most agencies never read.

3 Jun 2026

Custody, not marketing.

Built to your regulator's standard.

Request a scoping call