Data Protection
Follow Kristy for practical commentary and professional insight on data protection.

Partner at Spencer West
I'm Kristy Gouldsmith, a data protection expert. I’m a solicitor who helps organisations to sort their data protection so that they can keep the trust of their customers and staff, avoid the cost and time of dealing with data breaches and create good data protection practices to enhance their business. I take care of your data protection worries so that you can concentrate on your business.
I offer practical solutions to your data protection issues and help you to achieve a sensible, workable balance between the needs of your organisation and the demands of the GDPR. I can help you to achieve on-going compliance with the GDPR while also showing you how it can genuinely help your organisation.

Kristy Gouldsmith’s profile brings together professional experience, specialist subjects and published Chronicle Law contributions.
Follow Kristy for practical commentary and professional insight on data protection.
Follow Kristy for practical commentary and professional insight on gdpr compliance.
Follow Kristy for practical commentary and professional insight on information governance.

When a personal data breach occurs, controllers must assess the risk it creates for affected individuals. This article examines the factors to consider when deciding whether a breach must be reported to the ICO and whether affected individuals should also be informed.
Read the article →
AI is transforming legal practice, but it also introduces significant data protection, confidentiality and professional conduct risks. This guide explains how law firms can adopt AI responsibly while complying with UK GDPR and safeguarding client information.
Read the article →
The High Court’s decision in Raine v JD Wetherspoon clarifies when spoken disclosures can amount to data processing. This article compares Raine and Scott and explains why information retrieved from records is treated differently from memory-only disclosures.
Read the article →
Deepfakes are no longer theoretical for the legal sector. They pose real risks to evidence, fraud prevention, data protection and professional responsibility, requiring firms to rethink verification, governance and trust in an AI-driven environment.
Read the article →
A Chronicle Law webinar explores the legal and compliance considerations for law firms recording calls and meetings and communicating with clients via WhatsApp, including UK GDPR requirements, consent, and best practice for managing messaging communications.
Read the article →
This article explores how the NHS is adopting AI-powered ambient scribes to reduce clinical administration, while examining the data protection, UK GDPR, and patient transparency challenges associated with voice data, anonymisation, and vendor use of sensitive health information.
Read the article →
23 September 2026, Wednesday @ 12:00pm
View session →
15 July 2026, Wednesday @ 12:00pm
View session →
20 May 2026, Wednesday @ 12:00pm
View session →
26 February 2026, Thursday @ 12:00am
View session →Contributor profiles display approved professional information and published work. Saved content, CPD records, benefits and account activity remain private within My Chronicle.