S2 Ep30: GDPR Radio – Data Protection News of the Week
Hosted by Caine Glancy and Catarina Santos
Join Caine Glancy and Catarina Santos as they break down the latest data protection news and explain what it means for organisations in practice.
S2 Ep30: GDPR Radio – Data Protection News of the Week
Practical discussion on the latest data protection news
In this episode of GDPR Radio, Caine Glancy and Catarina Santos discuss recent developments affecting data protection, workplace monitoring, media reporting and information security.
They explore the risks behind misleading headlines, AI systems that claim to detect employee emotion, smart glasses and a reported NHS data breach involving an unsecured pager network.
What This Episode Covers
- A Court of Appeal decision on misleading headlines and the fair processing of personal data
- Why images and headlines can shape public perception before people read the full story
- AI emotion-detection tools and the risks of monitoring employees based on facial expressions, voice or body language
- Why organisations must consider necessity, fairness, transparency and less intrusive alternatives before introducing workplace monitoring
- Smart glasses, hidden recording and the need for clear acceptable-use policies
- Lessons from a reported NHS pager network data breach
- Why access controls, staff awareness and practical policies all matter
Key Discussion Points
“Someone who only saw the headlines and photographs together could just reasonably get the impression that actually it was Vince, the person that the article was referring to.”
The hosts discuss why data protection law can apply even where a full article clarifies the facts. The way a headline, image and article appear together can still affect whether personal data has been processed fairly.
“Could you not achieve the same objective with a completely less intrusive way?”
Caine and Catarina question the value of emotion-detection technology in the workplace. They explore why one-to-one conversations, objective work outputs and appropriate management may be more proportionate than analysing an employee’s voice, face or behaviour.
“Technical controls can only go so far, which is why the emphasis in the law is on technical and organisational measures.”
The episode also looks at why information governance needs to work in practice. Policies must reflect how an organisation operates, staff need to understand them and clear action needs to follow when rules are not followed.
Why This Episode Matters
Data protection risks do not always start with a major cyber incident. They can arise through misleading content, new workplace technology, weak access controls or policies that exist on paper but are not understood in practice.
This episode helps organisations consider where their own controls may need attention and why proportionate, people-focused