Skip to content
McCullochRegulatory Compliance
All practices

Data Privacy and Cyber Security

Data protection and information security for organisations handling personal, health, and AI data. GDPR and privacy by design, DPIAs and international transfers, breach response, and cyber security governance, including risk assessment, controls, and incident readiness.

Life-sciences organisations handle some of the most sensitive personal data there is, clinical, health, and increasingly AI-derived. We help you process it lawfully and defensibly under the EU and UK GDPR.

How we help

  • Privacy governance: records of processing (RoPA), policies, and accountability frameworks.
  • Data protection by design and by default across products, trials, and digital health.
  • Data Protection Impact Assessments (DPIAs) for high-risk and AI-driven processing.
  • International data transfers: SCCs, the UK IDTA / Addendum, and transfer risk assessments.
  • Data-subject rights, transparency, and lawful bases in a clinical and research context.
  • Personal data breach assessment, response, and regulator engagement.

Why it matters

Regulatory and data protection obligations increasingly intersect, in clinical trials, pharmacovigilance, connected devices, and AI. Getting privacy right protects participants and patients, and keeps products and programmes moving.

Specialists in this area

Discuss data privacy and cyber security

Tell us about your product or programme and we will come back to you promptly.