treborjnametab1
The Privacy Partnership Podcast with Robert Bateman
Robert Bateman provides the latest on data protection and privacy, with regular solo news updates and short-form interviews. Brought to you by Privacy Partnership: www.privacypartnership.com
Author
treborjnametab1
Category
Podcast website
Latest episode
Jul 9, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Christmas Special: The top 5 data protection CJEU cases of 2025 17.12.2025 7:01
Time for the Privacy Partnership Podcast Christmas Special, where Rob looks at his top 5 data protection CJEU judgments for 2025. Here's the list of cases I summarise in this podcast, which span data transfers, non-material damages, data minimisation, and more: 1. Bindl v European Commission 8 January 2025 Case T‑354/22 2. Mousse v CNIL (Mousse v Commission nationale de l'informatique e...
The Accidental Americans v FATCA: Like the Schrems cases, but for tax 10.12.2025 5:22
The CJEU will soon hear the Belgian DPA's case against FATCA, the tax treaty that results in the systematic bulk transfer of data about thousands of "Accidental Americans" to the IRS. FATCA is a US law intended to prevent US citizens from hiding assets in foreign banks. But it also hits "Accidental Americans"—people who might have been born in the US and acquired a US pass...
Did the CJEU just junk the EU's intermediary liability AND general monitoring rules? X v Russmedia 03.12.2025 5:36
Did the CJEU just use the GDPR to junk the intermediary liability exemption and impose a general monitoring obligation? Here's a look at yesterday's Russmedia judgment. The facts are pretty grim: "X" saw an ad on an Russmedia's online marketplace falsely promoting her as a sex worker. She reported it, Russmedia took it down, but the ad had already been scraped and copied o...
The 'final straw': Open letter calls for inquiry into the ICO 26.11.2025 5:18
A coalition of organisations and experts sent an open letter calling for a Parliamentary inquiry into the performance of the UK ICO. What's the problem, and will this work? Full disclosure: I was asked to sign this letter, but I decided against it. Many people I know and respect are on the list of signatories, and while there's some stuff in here I'm not 100% behind, I think it make...
It's here! Major proposed GDPR changes under the Digital Omnibus Regulation 20.11.2025 5:44
In this episode of the Privacy Partnership Podcast, Rob walks you through the most important aspects of the proposed Digital Omnibus Regulation. • A new Article 88c states that processing of personal data for the development and operation of AI systems may be pursued for legitimate interests (p85). • A new condition under Article 9 allows the processing of special category data for AI training if...
GDPR's "death by 1000 cuts"? A look at the leaked Digital Omnibus draft 11.11.2025 4:24
"Death by a thousand cuts?" That's what the leaked Digital Omnibus proposals represent to the GDPR, according to noyb.eu. Here's a look at some of the most significant ideas, from the new definition of "personal data" to the narrowing of Article 9. -- Note: This is an unconfirmed internal draft from the Commission’s DG CONNECT and not an official proposal. It may cha...
Up to 40% off UK GDPR fines! The ICO's draft enforcement guidance 04.11.2025 4:28
The ICO is offering up to 40% off UK GDPR fines under its new draft Data Protection Enforcement Procedural Guidance. Here's how to take advantage of this special deal! The draft guidance updates the ICO's Regulatory Action Plan, which has been in place since 2018. There are two particularly interesting bits: - New teeth available to the ICO under the Data (Use and Access) Act (DUAA), sho...
The TikTok China decision: A de facto ban on international data transfers? 29.10.2025 4:42
The DPC's TikTok decision is not that surprising if you understand the law, but it's actually a pretty huge deal to see this play out in reality. Are most international data transfers de facto illegal? TikTok enabled remote access to EEA users' personal data in China, purportedly for purposes like maintenance and user support. The DPC said: Remote access is a transfer. Not really su...
The EDPB's long list of problems with UK data protection standards 21.10.2025 3:48
The EDPB just published its opinion on the UK's adequacy decision and it's pretty critical of the country's post-Brexit direction on data protection. But does the EDPB's opinion matter? Probably not—directly, at least. The Commission's draft adequacy decision now goes to a vote at the Comitology Committee and is very unlikely to be voted down, despite the EDPB's reser...
What is going on between the ICO and Clearview AI? The UK GDPR's scope and the meaning of "monitoring behaviour". 15.10.2025 4:53
What is going on between Clearview AI and the ICO? Actions against Clearview have been a test of how far digital regulation actually has extraterritorial effect. This month, we got an answer on this from the UK’s Upper Tribunal, and it’s an important judgment about the territorial reach of the UK GDPR—at least on paper. In May 2022, the ICO fined Clearview AI £7.5 million and ordered it to delete...
Discord's photo ID breach: Are the UK GDPR and Online Safety Act to blame? 07.10.2025 3:24
Discord's recent data breach exposed photo IDs used to verify users' ages. Should we blame the Online Safety Act, the Children's Code, or the UK GDPR? It's complicated. (Please excuse the unsightly cut on my forehead in this one). While this breach probably just boils down to vendor security, I wanted to consider whether Discord was obliged to collect users' ID documents,...
Tractor Supply: The first CCPA case involving HR data 02.10.2025 4:47
Tractor Supply: The first CCPA case about job applicants' privacy (and the largest CPPA settlement yet). Don't forget: Unlike other states, California's privacy law applies to data about employees and job applicants. Tractor Supply settled for $1.35 million for failing to tell job applicants about their rights (among other, more commonplace violations—GPC, Do Not Sell, the usual stu...
LinkedIn's AI training plans are back, but not all users are treated equally 24.09.2025 4:40
LinkedIn's AI training settings don't affect all users equally. Did you notice that LinkedIn will share UK users' data with Microsoft, but not EEA users? In this video, Rob looks at the background, the broader context, and the details. LinkedIn first floated the idea of training its AI models on users' personal data last summer and has since encountered several bumps in the ro...
The ICO is consulting on guidance on the new cookie rules—and whether to enforce them. 18.09.2025 4:51
The ICO has yet MORE draft guidance, this time on the UK's upcoming changes to the law on cookies (etc). At the same time, it's running a "call for views" about whether it should enforce that law in certain contexts. The updated cookies guidance includes a new chapter on the consent exceptions provided by the Data Use and Access Act (DUAA). We also get new material reflecting t...
The first criminal prosecution for 'ignoring' a DSAR: More common than we think? 10.09.2025 3:48
An individual has been criminally prosecuted for "ignoring" or having "blocked, erased, or concealed" a subject access request. A rare (perhaps unprecedented) case, but Rob wonders if this behaviour is more common than we might think. This care home director was prosecuted under Section 173 of the Data Protection Act 2018, which makes it a criminal offence to "alter, defac...
What does 'without undue delay' ACTUALLY MEAN? IL v Veracash 03.09.2025 3:42
All over EU and UK law, we see a requirement to report certain stuff "without undue delay", often coupled with a hard deadline period (e.g., within 72 hours). A CJEU case from last month explored what these dual obligations mean in practice. IL v Veracash (Case C‑665/23, 1 August 2025) concerned the old Payment Services Directive (PSD). The PSD requires cardholders (consumers) to notify...
More ICO guidance! Recognised legitimate interests 27.08.2025 4:56
More draft ICO guidance! This time, about one of the Data (Use and Access) Act's most important concepts: "Recognised legitimate interests". The "recognised legitimate interests" are data processing activities that, frankly, the government would like you to do more of. Unlike regular old legitimate interests, you won't need to conduct a "balancing test" bef...
How to handle data subject complaints: New draft ICO guidance 22.08.2025 3:45
In advance of new obligations under the Data (Use and Access) Act, the ICO has published some draft guidance on handling data subject complaints. This episode breaks down some of the ICO's expectations in this area. As always, the ICO sets out three tiers: • "Must": Legal duties, for example, under UK GDPR or DPA 2018. • "Should": Good practice stuff that you should do u...
UK Data (Use and Access) Act: The first provisions take effect 20.08.2025 6:04
Some parts of the Data (Use and Access) Act (DUAA) take effect today! This is our first chance to see how the Act is actually going to operate in practice. In this video, I'll talk you through the relevant provisions. Many of these provisions are quite technical. So to make sense of them, Rob breaks them down into three categories: • New powers for government and regulators • Institutional...
The Online Safety Act's tensions with the UK GDPR 07.08.2025 5:38
The Online Safety Act is why you might have been asked for your driver's licence on Reddit, X, and some... other websites. In this video, I explain how the OSA works and how it raises tensions with the UK GDPR. The OSA applies to "user-to-user" and search services with "links to the UK". This covers websites from social media giants to tiny online message boards. Through a...
AI Act: Should you be watermarking your AI-generated content? 04.08.2025 5:49
Are you using an in-house tool powered by an AI model from OpenAI, Google, or Meta to produce marketing copy? You might soon be responsible for watermarking your AI-generated content. In this episode of the Privacy Partnership Podcast, Rob explores a common scenario, where a company fine-tunes a general-purpose AI model and builds a simple internal tool for staff to generate copy in its own brand...
The ICO's Birthlink Fine: Accountability, Integrity, and the 'Public Sector Approach' (?) 30.07.2025 5:28
Last week, the ICO fined Scottish charity Birthlink £18,000 for destroying around 4,800 adoption records. In this video, Rob explains why this is such an interesting case. Birthlink is an Edinburgh-based charity that maintains the Adoption Contact Register for Scotland. It provides specialised support for people involved in adoptions. At the heart of this case are the "linked records": M...
Access to Customer and Business Data Under the DUAA with Boris Wojtan 28.07.2025 14:55
I spoke to Boris Wojtan, Senior Privacy Counsel at Privacy Partnership Law, about "Access to Customer and Business Data" under Part 1 of the UK's Data (Use and Access) Act. This has been on my "get to grips with this" list for absolutely ages. Like me, you're probably familiar with the DUAA's amendments to the UK GDPR, the DPA 2018, and PECR. But that's just...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.