Insights
Plain-language guides to the law we practise.
Written for the person who has to act on the obligation, not for other lawyers. These notes are general information and not advice on your particular matter.
Data protection · 12 August 2026
When does your organisation need a DPIA?
A data protection impact assessment is not a form to be filed. It is the record that shows you thought about the risk to people before you built the thing, and it is the first document a regulator asks for.
Read the guide →Data protection · 29 July 2026
Registering with the Data Commissioner
Registration is the most visible compliance obligation under the Data Protection Act 2019, and the one most often missed by organisations that assume it applies only to large companies.
Read the guide →Data protection · 15 July 2026
Seventy-two hours: handling a data breach
The clock in the Act is short, but the first task is not notification. It is a documented assessment of what happened and who is exposed, because that assessment decides everything that follows.
Read the guide →Climate · 30 June 2026
Climate clauses that survive a negotiation
Climate obligations reach most organisations through contracts long before they arrive through legislation. The drafting question is not whether to include them, but how to write one that is capable of being enforced.
Read the guide →Climate · 16 June 2026
Making a climate commitment you can defend
A climate target is a statement about the future made in public. The legal exposure it creates does not depend on a climate statute; it comes from consumer, contract and securities law, which already prohibit saying things that are not so.
Read the guide →Succession · 2 June 2026
Drafting a valid will in Kenya
Most wills that fail do not fail on their contents. They fail on the formalities, and almost always on the witnessing, which is the one part of the process the maker cannot correct afterwards.
Read the guide →