S2 Ep28 GDPR Radio – Data Protection News of the Week

Hosted by Amber Sivill and Mark Farrell

Amber Sivill and Mark Farrell discuss recent developments involving AI transparency, publicly shared AI conversations and privacy in television production.

GDPR Radio - News Of The Week (1)

S2 Ep28: GDPR Radio – Data Protection News of the Week

Amber Sivill and Mark Farrell discuss recent data breaches, AI risks and privacy enforcement.

From preventable spreadsheet errors to AI-generated decisions, this episode explores the changing risks facing organisations and data protection professionals.

Amber and Mark examine recent incidents involving government departments, exposed AI conversations, employee access to personal data and the growing use of facial recognition technology.

What This Episode Covers

In this episode, Amber and Mark discuss:

  • The Ministry of Defence data breach and the importance of basic software training
  • The cyber attack affecting the Department for Education
  • How AI can support both cyber attacks and defensive security measures
  • Claude conversations appearing in Google search results
  • AI-generated information being used in public-sector decisions
  • New transparency requirements under the EU AI Act
  • The risks created by unsecured paper records
  • Unauthorised employee access to personal data
  • AI-generated inferences and the future of anonymised data
  • Facial recognition, smart surveillance technology and privacy
  • Recent ICO action relating to nuisance marketing messages

When Basic Training Is Overlooked

The episode begins with the Ministry of Defence data breach involving information about Afghan relocation applicants.

Amber and Mark discuss reports that the breach could have been prevented through basic spreadsheet training. They also consider what this tells organisations about accountability and the importance of practical training.

Mark explains:

“AI is going to be leveraged to launch cyber attacks, it also has to be leveraged to combat them.”

The discussion also covers the cyber attack affecting the Department for Education. This demonstrates why organisations need both effective security systems and staff who understand how to recognise potential threats.

Privacy by Design and AI Tools

Amber and Mark discuss reports that shared Claude conversations appeared in Google search results.

The incident raises questions about transparency, default privacy settings and whether users understand when their conversations may become publicly available.

Amber says:

“You need to embed that sort of privacy, privacy by design, privacy by default, making sure that you know the default setting isn’t that my personal conversations are being shared publicly for other people to see.”

Organisations should understand how an AI service handles information before employees enter personal, confidential or commercially sensitive data into it.

AI Decisions and Regulatory Oversight

The hosts examine a case involving information believed to have been generated by AI and used during an asylum decision.

They discuss the risks of relying on AI-generated material without proper fact-checking or meaningful human oversight. Meaningful human oversight means a person genuinely reviews the information and can challenge or change the outcome.

The conversation also covers EU AI Act transparency requirements and the need for clearer UK rules.

Amber explains:

“I think this just goes to show that the current legislation doesn’t fit. I think it fits in so many ways in terms of the principles, but we need more specifics that are tailored towards AI use.”

Paper Records and Employee Access

Not every data protection incident involves sophisticated technology.

Amber and Mark discuss confidential paper records reportedly found in an unsecured former council building. They also examine cases involving employees accessing personal records without authorisation.

These stories show why organisations must protect information throughout its lifecycle. This includes digital files, archived documents and paper records.

Access controls should also ensure that employees can only view information they genuinely need for their role.

AI Inferences and Anonymised Data

The episode considers how AI may infer sensitive information from data that appears to be aggregated or anonymised.

Anonymised data is information that can no longer be linked to an identifiable person. However, more capable technology may make it easier to identify patterns or combine information from different sources.

Amber and Mark discuss whether existing definitions and safeguards will remain effective as AI develops.

Facial Recognition and Smart Surveillance

The hosts also examine AI-enabled street technology that can use cameras and facial recognition to identify people or detect potential offences.

These tools may support law enforcement and public safety. However, they also create questions about proportionality, transparency and function creep. Function creep happens when information or technology is gradually used for purposes beyond the reason it was originally introduced.

Mark summarises one of the central concerns:

“You behave differently when you’re being watched.”

Recent ICO Enforcement

The episode closes with recent action from the Information Commissioner’s Office relating to nuisance marketing about motor finance claims.

Amber and Mark discuss the use of search warrants and cooperation between different regulators. They also consider whether enforcement is being applied consistently across organisations and sectors.

Practical Takeaways for Organisations

Organisations should:

  • Include practical software skills in data protection training
  • Review the privacy settings of AI tools before using them
  • Avoid entering sensitive information into systems without appropriate safeguards
  • Apply meaningful human oversight to AI-supported decisions
  • Protect paper records as carefully as digital information
  • Regularly review employee access permissions
  • Assess whether anonymised information could be re-identified
  • Consider privacy risks before introducing surveillance technology

Watch or Listen

Watch or listen to the full episode of GDPR Radio:

📺 Watch the episode on YouTube

🎧 Listen to the episode on Spotify

Meet Your Hosts

Amber Sivill

Amber explores how emerging technology, AI governance and privacy risks affect organisations in practice.

Mark Farrell

Mark examines recent data protection developments and the practical lessons organisations can take from them.

Data Protection Made Easy

Data Protection Made Easy helps organisations understand and meet their responsibilities under UK GDPR and related data protection law.