S2 Ep32: GDPR Radio
Hosted by Caine Glancy and Amber Sivill
Caine Glancy and Amber Sivill discuss the latest data protection news, including proposed GDPR reform, cyber incidents, automated identity checks, smart glasses, staff training and online safety.
S2 Ep32: GDPR Radio – Data Protection News of the Week
Caine Glancy and Amber Sivill discuss the latest developments affecting data protection professionals.
In this episode of the Data Protection Made Easy podcast, Caine and Amber examine several stories raising important questions about privacy, cyber security, artificial intelligence and accountability.
Their conversation covers proposed changes to UK data protection law, a cyber incident affecting airport customers, facial recognition technology, smart glasses, personal data breaches and online safety.
Could the UK Replace GDPR?
The episode begins with a discussion about reports that Reform UK wants to replace GDPR with a lighter-touch approach.
Caine and Amber consider whether data protection law genuinely prevents organisations from innovating. They also discuss what weaker enforcement and reduced individual rights could mean in practice.
Amber explains that GDPR is based on principles. This allows organisations to consider the purpose, necessity and risk involved in their processing.
“Whenever you look at anything within GDPR or data protection, it is always a matter of risk, what is proportionate to that risk and what is necessary.”
What Can Organisations Learn From the Airport Cyber Incident?
Caine and Amber discuss a reported cyber incident involving customer information collected through airport Wi-Fi registrations and car park bookings.
The conversation focuses on the volume of information affected, how connected systems can increase the impact of an incident and why organisations should only collect the personal data they genuinely need.
Amber also raises the importance of separating systems and databases. This is known as network segmentation, which means dividing a network into smaller sections to limit unauthorised access.
Should Retention Periods Be Based on Systems or Purposes?
The hosts explore whether organisations should assign retention periods to entire systems or connect them to individual processing purposes.
A single system may hold several types of personal data. Each type may be needed for a different reason and for a different length of time.
“Storage limitation is based on the purpose of processing and how long you require the information for that purpose.”
Amber explains that a more detailed approach can help organisations meet legal requirements and avoid retaining information for longer than necessary.
What Are the Risks of Automated Identity Checks?
The episode examines a case involving an eVisa identification problem which reportedly prevented a UK resident from boarding a return flight.
Caine and Amber consider the risks of relying on automated identity systems. These include inaccurate matches, a lack of effective human review and difficulties correcting errors.
They connect this discussion to the wider use of facial recognition by police forces and other organisations.
Smart Glasses, Facial Recognition and Covert Recording
Caine and Amber discuss smart glasses that can record people or use facial recognition technology.
Although this technology may support accessibility and language interpretation, it can also create privacy concerns when people do not know they are being recorded.
The hosts consider whether every function is necessary and whether useful features could operate without recording or identifying individuals.
Why Does Context Matter When Assessing a Data Breach?
The Metropolitan Police reportedly exposed the email addresses of people receiving updates about the investigation into Mohamed Al-Fayed.
An email address may appear low risk when viewed alone. However, the surrounding circumstances could reveal a connection to an investigation, witness group or affected individual.
“The context is ultimately so important with everything. It is a big decider when assessing risk.”
This example shows why organisations need clear breach-reporting processes. A proper assessment should consider who is affected, what the information may reveal and the possible consequences for those individuals.
Can Better Training Reduce Email-Related Breaches?
Caine and Amber discuss how simple email mistakes can lead to serious incidents, including using CC instead of BCC.
They explain that effective training should build awareness without making employees afraid to report mistakes or ask questions.
“If you do not know something, how do you know it is wrong?”
Staff need practical guidance, clear reporting routes and the confidence to raise concerns quickly.
Age Assurance and the Online Safety Debate
The episode closes with a discussion about age-assurance measures under the Online Safety Act.
Caine and Amber consider whether strict controls could push children towards less responsible websites. They also discuss the challenge of protecting children without creating systems that people simply try to bypass.
The discussion highlights the need for proportionate controls which protect users while recognising how people behave online.
Key Takeaways
- Data protection law allows organisations to assess risk and act proportionately
- Organisations should only collect personal data they genuinely need
- Retention periods should reflect the purpose of processing
- Automated identity systems need accuracy checks and effective human oversight
- The context of a breach can make seemingly ordinary information highly sensitive
- Training should help employees recognise and report mistakes without creating fear
- New technologies need privacy safeguards from the beginning
Meet Your Hosts
Caine Glancy
Caine is the Data Protection Support Desk Manager at Data Protection People. He brings practical insight from supporting organisations with their everyday data protection responsibilities.
Amber Sivill
Amber joins Caine to examine the practical risks behind the latest data protection stories and explain what organisations should consider.
About the Data Protection Made Easy Podcast
The Data Protection Made Easy podcast turns complex privacy and data protection topics into clear, practical conversations.
GDPR Radio examines recent news, regulatory developments and emerging technology to help organisations understand what has happened and why it matters.