S3 Ep26: GDPR Radio- Data Protection News of the Week

Hosted by Myles Dacres

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Catarina Santos discuss the latest data protection news, including changes around the Information Commission, the TfL cyber attack, AI regulation, political marketing, anti-doping decisions and Meta’s app design.

GDPR Radio - Data Protection News of the Week

GDPR Radio: Data Protection News of the Week

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Catarina Santos discussed the latest stories shaping data protection, cyber security, AI regulation and online safety.

From changes at the Information Commission to cyber sentencing, political marketing, AI guidance and addictive app design, the episode explored what these developments mean for organisations and the people whose data they handle.

What Could Changes At The Information Commission Mean?

One of the first topics discussed was the appointment of seven non-executive directors to the Information Commission board and what this could mean for the future direction of the regulator.

“I really do hope whoever comes in and chairs this board is able to keep a rein on individuals’ rights and make sure that there’s not a really obvious imbalance here.”

Caine explained that any shift towards innovation still needs to be balanced with strong protection for individual rights.

Catarina also linked this to the wider direction of the regulator.

“The fact that we are appointing the new board chair probably will provide an opportunity to try to rebuild that trust and confidence in the regulator.”

This matters because the regulator plays a key role in how organisations understand and apply data protection law. If the Information Commission changes direction, organisations will need clear guidance on what that means in practice.

Why The TfL Cyber Attack Still Matters

Catarina then discussed the sentencing of two members of the Scattered Spider cybercrime group following the cyber attack on Transport for London.

“The impact goes way beyond the numbers of the customers involved.”

The attack involved personal data relating to around 10 million customers and affected around 27,000 employees. It was also estimated to have cost Transport for London £39 million.

Caine explained that cyber incidents like this are a reminder to review technical and organisational measures.

“All these stories about cyber attacks are just a little reminder to make sure that all your measures remain audited and remain strong.”

The discussion focused on access controls, which are rules that limit who can view, use or change information, and penetration testing, which is a controlled test used to find security weaknesses before attackers do.

Political Marketing And Purpose Limitation

The episode also covered a reported GDPR issue involving a Portsmouth councillor, a restaurant linked to his partner and messages promoting Reform UK.

Caine explained the concern clearly.

“Not only are they promoting something that is wholly outside of the scope of what they were doing in respect to the partner’s restaurant, but also in respect to a political party.”

Catarina highlighted purpose limitation, which means personal data should only be used for the reason it was collected unless there is a clear lawful reason to use it for something else.

“They are surely not expecting then the details to be used for any other campaign afterwards.”

This becomes especially important when political views may be involved. Political opinion can be special category data, which means it needs extra protection because it is sensitive.

The UK Government’s Call For Evidence On AI

A major story in the episode was the UK Government’s call for evidence on data regulation in the age of AI and other data-driven technologies.

Catarina explained that this does not change the law.

“This is not a consultation on new laws, anything around changing UK GDPR or any legal framework.”

Instead, the Government is asking businesses, regulators, academics and other organisations to share their experiences of using AI and explain where the current framework may be unclear or difficult to apply.

Catarina described it as a positive step.

“I think this is a very, very good step where you are actively asking the organisations and people that are actually working directly with these platforms and with AI in general.”

Caine agreed that clearer guidance is needed.

“Getting more stuff on the law and the guidance allows us to also be more helpful with you guys as well.”

For organisations using AI, this is important because many are already trying to apply existing data protection principles to tools that are developing quickly.

Anti-Doping Decisions And GDPR

The hosts also discussed a Court of Justice of the European Union ruling from 2024 about anti-doping rules and whether publishing athletes’ personal data online can be compatible with GDPR.

Catarina explained that publication can be compatible with GDPR, but only if the right checks are made first.

“The proportionality I think is key, the balance between the potential publication and the athletes’ rights and freedoms and interests on the other side.”

Proportionality means making sure an action does not go further than necessary to achieve its aim.

Caine considered the other side of the issue, including transparency in sport and the risk to clubs.

“Doping could carry a potential risk to the club itself.”

Catarina also raised the long-term impact of putting this information online.

“Once it’s published online, even if you delete it, it will never leave the internet.”

The discussion showed why organisations must think carefully before making personal data public, even where there is a strong reason to do so.

Meta, Addictive Design And Online Safety

The final story focused on Meta and the European Commission’s preliminary view that Meta may have breached the Digital Services Act.

The Digital Services Act is an EU law that places duties on online platforms to manage risks linked to their services.

Caine explained that the concerns related to features such as infinite scrolling, autoplay, push notifications and personalised content.

“The way that the social media app is designed bottom to top, it thinks it is doing too much to keep users engaged.”

He also questioned whether existing controls go far enough.

“What is it that they’re expecting Meta to do? What does Meta need to do now?”

Catarina raised concerns about children, vulnerable users, targeted content and connected technology such as smart glasses.

“There are so many concerns and the main one is definitely whether platforms are actually doing enough to protect children.”

The discussion ended with a wider privacy question about technology in the workplace.

“What’s the difference between wearing Meta glasses at work and everyone else that has a mobile phone that can record covertly anywhere?”

It is a useful reminder that privacy risks often appear before workplace expectations and regulation have fully caught up.

Looking Ahead

This episode showed how broad data protection has become.

It now connects to AI, cyber security, political campaigning, sport, social media design, workplace technology and public trust.

For organisations, the message is simple. Data protection is not just about policies. It is about how decisions are made, how risks are assessed and how people’s rights are protected in real situations.

Frequently Asked Questions

What was this episode of GDPR Radio about?

This episode covered key data protection news, including the Information Commission, the TfL cyber attack, political marketing, AI regulation, anti-doping decisions and Meta’s app design.

What is purpose limitation under GDPR?

Purpose limitation means personal data should only be used for the reason it was collected unless there is a clear lawful reason to use it for another purpose.

Why does the UK Government’s AI call for evidence matter?

It matters because organisations are already using AI and need clearer guidance on how existing data protection rules apply to new technology.

What is proportionality in data protection?

Proportionality means making sure an action is appropriate and does not go further than needed, especially where it affects someone’s rights.

Why are app design features a data protection issue?

App design features can influence how people behave online. If those features affect vulnerable users, children or personal data use, they can raise privacy and safety concerns.

Need Support With Data Protection, AI Or Cyber Security?

Data protection issues are becoming more connected.

AI, cyber security, marketing, employee access, online platforms and emerging technology all create new risks for organisations to manage.

Data Protection Made Easy helps organisations understand their responsibilities and take practical steps to improve compliance.

Whether you need support with UK GDPR, AI governance, cyber security or data protection training, our consultants can help make the process clearer and easier to manage.

Spotify logo

 

YouTube logo