Explore every episode of GDPR Now!
Pub. Date | Title | Duration | |
---|---|---|---|
28 Jan 2020 | Episode 16: Digital Detox - how to cleanse yourself on Data Protection Day | 00:43:17 | |
On the day after Data Protection Day (or Privacy Day, depending on whether you are tomato or tomato) we take a look at privacy enhancing technologies - how to control, restrict and eliminate your personal data footprint (if that’s what you want to do). This podcast will be invaluable for privacy professionals that want to know what PETs are available and for consumers that would like to have greater control of their digital profiles. GDPR Now! Is brought to you by This Is DPO. Guest/s Host Materials Links to PETs Want a pretty version or more explanation? Check out my LinkedIn profile for a Slideshare of a presentation and handy Infographic – available next week. Let’s help build this list. Which PETs are you using or curious to try? If they’re not here, let Abigail know via contact details in the show notes so I can update my list. Inform yourself, update software, adjust privacy settings, use 2FA! Privacy Analyzer DuckDuckGo Device Privacy Tips Consumer Reports articles & videos with quick-fixes in bite-sized pieces: https://www.consumerreports.org/privacy/linkedin-privacy-settings/ Terms of Service, Didn’t Read (TOSDR https://tosdr.org/): one-stop shop for digested Ts & Cs of most popular online providers, including score cards. Brilliant browser add-on offers automatic assessment of pages you access. Addresses privacy notices & terms e.g. cancellation, etc. Ghostery Baycloud (https://baycloud.com) was one of the early champions of privtech, starting in the DNT space. They offer B2C and B2B resources. Baycloud Bouncer let reveals who’s tracking you and gives you a handy dashboard to adjust your preferences (https://baycloud.com/bouncer). You can also pre-scan websites you’d like to visit from the comfort of Baycloud’s site. Try before you buy (so to speak, with your data I mean). Free!! Have I been pwned?(https://haveibeenpwned.com) will help you check whether your account or credentials has been compromised based on research into the (sigh) multitudinous data breaches. Free!! DuckDuckGo privacy report card for websites (https://duckduckgo.com/app): instantly evaluates and remediates websites you visit to give you a before and after score. Browser add-on for various browser types on desktop but only available for iOS on mobile. Free!! Deseat.Me (www.deseat.me) : Helps you clean up your online presence by instantly getting a list of all your accounts, allowing you to sort through and delete them / unsubscribe. Personal Data.io: A self-named “integrated toolbox addressing surveillance capitalism”. This advocacy group goes beyond providing tools for e.g. filing DSARs, there is a forum (https://forum.personaldata.io) and a number of chat groups for trouble-shooting, contributing, advocacy and knowledge-exchange) You can share your experience or tap into people’s expertise, commiserate or find journalists to raise awareness about your experience or discoveries. This is the group that helped journalist Judith Duportail, who was researching dating apps, learn that Tinder had over 800 (disturbing) pages of data on her. Worth a read here: https://www.theguardian.com/technology/2017/sep/26/tinder-personal-data-dating-app-messages-hacked-sold My Permissions(https://mypermissions.com): app that does a privacy scan (Privacy Cleaner) of your social media / collaboration apps to help you identify who can access your data. It identifies your current permissions and let’s you quickly and efficiently manage them all from one place. A small fee required to manage permissions, but there is a free tier. Princeton IoT Inspector (https://iot-inspector.princeton.edu/) let’s you watch your smart devices back. Automatically discovers IoT devices and analyzes their network traffic to identify security and privacy issues. Currently only available on MacOS High Sierra or Mojave (waitlist for Windows, Linus and MacOS Catalina). PiHole for Raspberry Pi (https://pi-hole.net): Protect your entire network from ads and targeting. Block in-app and SmartTV ads. Free!! but powered by donations. You need a supported OS and hardware (Raspberry Pi). Strong Passwords: NCSC ‘3 random words’ guidance: | |||
08 Jul 2021 | Episode 30: The Future: Proving your Identity | 00:42:08 | |
In this episode, we talk about the future of credential management – Self Sovereign Identity (SSI) also known as decentralised identity. SSI is an efficient, secure and privacy enhancing solution for identity verification. It puts individuals at the centre of the verification process and is the future of identity management. Our special guest, James Monaghan, talks about how Evernym provides solutions in the area of SSI for businesses today. We talk about what SSI means, how it works, the benefits for individuals and businesses and importantly, examples of how it is being used to great effect today. For any businesses interested in learning more about how they could benefit from building an SSI or decentralised identity solution, please contact James directly. As we enter what is arguably, the start of our journey into a new era of digital innovation with huge benefits to individuals and businesses, we are excited to follow developments around the growth of Self Soverign Identity. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest Contact James on: World Web Consortium (W3C) specifications for existing SSI solutions:
Relevant industry bodies include:
Special Guest: James Monaghan. | |||
03 Jun 2021 | Episode 29: Regulating the future of AI and ML | 00:41:29 | |
In this episode, we are going to talk about the regulation of Artificial Intelligence and Machine Learning to understand what businesses need to think about from a regulatory perspective. Our special guest, Ben, talks about the global context of regulations around AI and the complexity of the parallel 'race to AI' and 'race to regulation' . In particular we look at the proposed Artificial Intelligence Act from the European Union and consider the impact on innovation. We explore what businesses and DPOs need to consider when building, using or deploying Machine learning or Artificial Intelligence systems. As we enter what is arguably, the start of our journey into a new era of innovation with huge benefits to humankind, this podcast will follow developments in and around the regulation of future Artificial Intelligence and Machine Learning. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest Read Ben's note on: AI Act Explainer is here: https://datainnovation.org/2021/05/the-artificial-intelligence-act-a-quick-explainer/ Special Guest: Benjamin Mueller. | |||
15 Aug 2019 | Episode 6: Cyber insurance - everything you need to know | 00:38:33 | |
About this episode. GDPR Now! Is brought to you by This Is DPO. Guest/s Host Materials On breach and planning for breach, see also: Questions, suggestion for improvement, ideas for issues to be covered in future episodes, or if you would like to appear one of our podcasts, please contact us at info@thisisdpo.co.uk Special Guest: Richard Spragg. | |||
21 Jul 2019 | Episode 3: Disproportionate, intrusive and unfair – the ICO reports on ad tech and real time bidding (Part 1). | 00:44:38 | |
GDPR Now! brought to you by This is DPO. Disproportionate, intrusive and unfair – the ICO report on ad tech and real time bidding (Part 1). About this episode: Although the ICO has stated that it will take another six months to investigate further, it is already clear that the ICO will intervene. The ICO’s paper, and its forthcoming intervention, are likely to have a substantial impact in the programmatic industry in the EU and the US. It is no exaggeration to say that the ICO’s intervention is likely to have a bigger impact on this industry than the GDPR. To give some idea of scale: the worldwide spend of on digital advertising is expected to reach US$98bn in 2020. In Europe, the UK is by far the largest market, followed by Germany and then France (approx. US$15bn, US$8bn, US$4bn, respectively, in 2018). In this episode, three luminaries from digital advertising get together to discuss the ICO’s report and the possible ways forward. Guests: Andy Houston Omar Oakes John Mitchison Host: Mark Sherwood-Edwards of This Is DPO. Material referred to: Update report into adtech and real time bidding, ICO. Crimtan’s ActivID Contact details You can contact the show at info@thisisdpo.co.uk. Special Guests: Andy Houston, John Mitchison, and Omar Oakes. | |||
01 Oct 2019 | Episode 10: Cookie Consent Software Reviewed! Part 1: What the Regulators expect | 00:35:55 | |
Managing consent for cookies has become a key issue. In this two-parter, we look at what the regulators (and in particular the UK ICO) require in relation to cookies (Part 1) and then – in an industry first - review three industry leading consent management tools: Cookie Control, Cookiebot, and Cookie Pro (Part 2). GDPR Now! Is brought to you by This Is DPO. Guest Host Corrections & Clarifications Cookie Control from Civic UK: Materials The three cookie consent tools reviewed are: Cookie Control CookiePro Questions, suggestion for improvement, ideas for issues to be covered in future episodes, or if you would like to appear one of our podcasts, please contact us at info@thisisdpo.co.uk Special Guest: Karen Heaton. | |||
18 May 2020 | Episode 18: Group Action lawsuits from data breaches: what business leaders and your DPO needs to know | 00:27:00 | |
Welcome to another episode of GDPR Now, a podcast dedicated to data protection and all things data security and privacy. This week’s episode is Group Action lawsuits arising from data breaches. We continue our series of podcasts addressing concerns resulting from the coronavirus pandemic, such as increases in data breaches arising from IT security issues and the increased risks resulting from the huge shift to remote working for 100,000s businesses across the UK and the world. In the studio today we are delighted to have Kingsley Hayes, Managing Director of Hayes Connor Solicitors based in Widnes, Cheshire. In this second episode, we are going to talk about Group Action lawsuits, what they are, how they operate and the British Airways case. For anyone who wants to join the BA data breach action if they have been affected - the link is here. If you missed it, Kingsley and I discussed COVID19 and the impact on Data Protection in Episode 17. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest/s Special Guest: Kingsley Hayes. | |||
01 Oct 2019 | Episode 11: Cookie Consent Software Reviewed! Part 2: Cookiebot v. Cookie Control v. CookiePro | 00:30:11 | |
Managing consent for cookies has become a key issue. In this two-parter, we look at what the regulators (and in particular the UK ICO) require in relation to cookies (Part 1) and then – in an industry first - review three industry leading consent management tools: Cookie Control, Cookiebot, and Cookie Pro (Part 2). GDPR Now! Is brought to you by This Is DPO. Guest Host Corrections & Clarifications Cookie Control from Civic UK Materials The three cookie consent tools reviewed are: Cookie Control CookiePro Questions Special Guest: Karen Heaton. | |||
08 Mar 2022 | Episode 35: Online content - how to protect and secure your digital rights | 00:31:41 | |
Online Content - how to protect and secure your digital rights In today's world of content creation, sharing, posting and blogging, it is more important than ever to be able to protect and control your online content. Whether you are a musician, artist, parent, small business or large organisation, your digital content is who you are as an individual, family, group or company. This episode is a fantastic insight into the world of managing and controlling your online content with our guest, Adam Rumanek, Founder and CEO of Aux Mode, global specialists in digital rights management and revenue reporting. We discuss: digital rights management - what is it? - how can you protect your online content; video privacy protection; audio privacy protection and understanding your rights on YouTube. Anyone with an online presence will learn from listening to this episode, so we are grateful to Adam for his advice. Guest GDPR Now! Is brought to you by Data Protection 4 Business Special Guest: Adam Rumanek. | |||
27 Nov 2019 | Episode 14: Privacy by Design | 00:40:13 | |
Privacy By Design is one of the key elements of good data protection, and is made mandatory by Article 25 of the GDPR. But what does PbD mean in practice? In this podcast, we look at the key elements of PbD, discuss some actual use cases, and examine how to apply PbD on the ground. GDPR Now! Is brought to you by This Is DPO. Guest Host Materials Recommended By Sam Bouso Book Ann Cavoukian’s 7 principles of PbD Proactive not reactive; preventive not remedial Privacy as the default Privacy embedded into design Full functionality – positive-sum, not zero-sum End-to-end security – full lifecycle protection Visibility and transparency – keep it open Respect for user privacy – keep it user-centric See also: https://iapp.org/resources/article/privacy-by-design-the-7-foundational-principles/ Looking for something long and technical? Questions, suggestion for improvement, ideas for issues to be covered in future episodes, or if you would like to appear one of our podcasts, please contact us at info@thisisdpo.co.uk Special Guest: Sam Bouso. | |||
11 Jan 2023 | Cyber Security Tips for businesses | 00:32:29 | |
In this episode we are delighted to have Andrew Alston, founding director at Breach Aware and Business Intelligence Theoroms. Andrew brings us up to date on the current cyber security issues affecting businesses and offers a range of easy to action steps businesses can take to protect their systems and data. He reminds us that the basic security steps, done well, can go a long way to preventing security issues. As always, we present affordable solutions that can be used for SME's and individuals as well as large organisations. GDPR Now! Is brought to you by Data Protection 4 Business **Guest** | |||
02 Jun 2020 | Episode 20: Track and trace apps: views from Australia | 00:23:55 | |
This episode is part of our series of updated podcasts addressing security & privacy concerns resulting from the coronavirus pandemic and the shift in working practises for millions of businesses across the UK and the world. In this episode, we start our series of discussions on track and trace apps from around the world. Today, we are are discovering how track and trace is being managed in Australia. To discuss this with us, we are delighted to have Katherine Sainty and Belyndy Rowe from Sainty Law, a boutique law firm specialising in privacy, big data, technology & cybersecurity in Sydney. Katherine and Belyndy are going to talk to us about what is happening in Australia. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest/s Belyndy Rowe Special Guests: Belyndy Rowe and Katherine Sainty. | |||
22 Jul 2019 | Episode 4: Disproportionate, intrusive and unfair – the ICO report on ad tech and real time bidding – Part 2. | 00:23:20 | |
GDPR Now! brought to you by This is DPO. www. thisisdpo.co.uk Disproportionate, intrusive and unfair – the ICO report on ad tech and real time bidding – Part 2. This is part 2 of a two-parter. About this episode: In this episode, three luminaries from digital advertising get together to discuss the ICO’s report and the possible ways forward. Guests: Omar Oakes John Mitchison Host: Mark Sherwood-Edwards of This Is DPO. Material referred to: Crimtan’s ActivID Contact details Special Guests: Andy Houston, John Mitchison, and Omar Oakes. | |||
08 Jul 2020 | Episode 22: How do you know if your data has been compromised? | 00:21:49 | |
This episode is part of our series of updated podcasts addressing security & privacy concerns resulting from the coronavirus pandemic and the shift in working practises for millions of businesses across the UK and the world. In this episode we are delighted to have Andrew Alston, founding director at Breach Aware and Business intelligence Theoroms. Andrew talks to us about Breach Aware which is a data breach monitoring and reporting application designed to help organisations detect and prevent crime, as part of their system of risk management. The solution can be used for SME's and individuals as well as large organisations. Andrew and his team pride themselves in offering this solution at affordable rates for SME's. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest Special Guest: Andrew Alston. | |||
17 Sep 2019 | Episode 8: Third Party Cookies - ECJ lays down new rules in Fashion ID case | 00:18:15 | |
In the Fashion ID case, the European Court of Justice decides that website owners are now joint controllers with the provider of the third-party cookie, and that website owners are responsible for issuing the privacy notices for third party cookies and for collecting any consents that are required. And, to make things a bit more complicated, the ECJ comes up with a new approach to analysing the data journey and who is the controller! All this and more in this episode of GDPR Now! GDPR Now! Is brought to you by This Is DPO. Host Materials Fashion ID Advocate General’s Opinion: Related documents Guidance On The Use Of Cookies And Similar Technologies, ICO. https://ico.org.uk/for-organisations/guide-to-pecr/guidance-on-the-use-of-cookies-and-similar-technologies/ Délibération N° 2019-093 Du 4 Juillet 2019 Portant Adoption De Lignes Directrices Relatives À L'application De L'article 82 De La Loi Du 6 Janvier 1978 Modifiée Aux Opérations De Lecture Et Écriture Dans Le Terminal D'un Utilisateur (Notamment Aux Cookies Et Autres Traceurs), CNIL. https://www.legifrance.gouv.fr/affichTexte.do?cidTexte=JORFTEXT000038778053&dateTexte=&categorieLien=id Opinion 5/2019 On The Interplay Between The Eprivacy Directive And The Gdpr, in particular regarding the competence, tasks and powers of data protection authorities, adopted on 12 March 2019, EDPB. Questions, suggestion for improvement, ideas for issues to be covered in future episodes, or if you would like to appear one of our podcasts, please contact us at info@thisisdpo.co.uk | |||
06 Oct 2020 | Episode 24: NHS Track and Trace App: are privacy and practicality issues a barrier to success? | 00:51:25 | |
This episode is part of our series of updated podcasts addressing security & privacy concerns resulting from the coronavirus pandemic and the shift in working practises for millions of businesses across the UK and the world. In our discussion we first talk about the NHS Track and Trace app and ask "how did we get here?" with app #2 being released five months after app #1. We then explore whether track and trace apps are prevented from being successful due to privacy and practicality issues and whether this is a worldwide problem. During our discussion, I recommend a very important film "The Social Dilemma" which is available on Netflix. This is an must-watch film for everyone, especially parents with teenagers, pre-teens and young adults. Given some of the important issues raised in this episode, we will be recording Part 2, where we bring in a panel of specialists to start the discussions on how to address the practicality and privacy issues which can prevent track and trace apps from being effective during a pandemic. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest | |||
27 Jul 2020 | Episode 23: The end of the EU-US Privacy Shield. Now what? | 00:37:03 | |
Today we depart from the corornavirus related stories to bring you an update on the landmark ruling from the European Court of Justice on the EU - US Privacy Shield. The decision by the ECJ on 16th July 2020, to invalidate the EU - US Privacy Shield has sent shockwaves across organisations in the EU and US. We are joined by fellow host, Mark Sherwood-Edwards, lawyer, data protection specialist and founder of ThisisDPO. Mark has read the judgement and is going to talk to us today about what it means for data protection, for businesses and for DPO’s. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest | |||
01 Dec 2020 | Episode 25: Track and Trace apps: What price for data privacy? We need to find better solutions. | 01:02:02 | |
In today’s episode, we are delving into the issues we discussed in our previous episode #24 on the NHS Track and Trace app and considering in more detail the legal, privacy and practicality barriers to many track and trace apps in Europe. We discuss the take up of Track and Trace apps in the EU and find it is mostly 30% of the population and lower. Data privacy when using apps has been protected due to EU GDPR, however, other basic freedoms have been taken from us and our way of life severely impacted over the course of 2020. Track and trace apps have not had the hoped-for beneficial impact in the EU. Had we taken a different approach to using more data and made the apps mandatory, could the outcomes have been different? What does this mean in practise for track and trace apps as future solutions to help governments manage pandemics? Compare and contrast to other Asian countries. If 70 - 80% app usage is realistically needed to be effective, then why did we not make track and trace apps mandatory? What are we to learn from countries in Asia? How do we find a rapid and effective way to discuss and agree the extended use of our data to improve outcomes, rapidly, either during pandemics or outside of them? As Privacy, Legal and Tech professionals we must continue this conversation and find a framework for agreeing the greater use of data in a mandatory way to support better pandemic and health outcomes. The economic costs of lockdowns are extremely high and have a direct effect on a nation's ability to provide future healthcare. Our short term fix to today's problem could cause many more problems for the future. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guests Guests Founder Special Guests: Mark Sherwood-Edwards and Roger Marlow. | |||
15 Nov 2021 | Episode 34: Making AI Regulation Strategic for businesses | 00:45:40 | |
In this episode, we talk about Making AI Regulation Strategic for businesses and discuss what businesses can do to keep abreast of regulations, compliance solutions and protect their developments in AI. Our special guest is Ayisha Piotti, Co-Founder & Managing Partner of RegHorizons, a business decidated to helping build trust in emerging technologies through promoting policy solutions and by facilitating dialogue be-tween governments, academia, businesses and civil society. To learn about the work that RegHorizon do, check out this link to their latest AI Policy event https://reghorizon.com/events/ GDPR Now! Is brought to you by Data Protection 4 Business. Guest Contact Ayisha Piotti on: Special Guest: Ayisha Piotti. | |||
18 Jun 2020 | Episode 21: Whose data is it anyway? Impact on track and track apps | 00:24:01 | |
This episode is part of our series of updated podcasts addressing security & privacy concerns resulting from the coronavirus pandemic and the shift in working practises for millions of businesses across the UK and the world. In this episode, we are going discuss personal data in detail and explore the question of: whose data is it anyway? And what are we prepared to tolerate regarding track and trace programmes as governments around the world implement track and track apps. To discuss this we are delighted to have Phil Brown, The Norfolk Data Protection Mardler, who advices clients in Norfolk on data protection. _Please note: Phil makes reference to the need for self reporting but would like to clarify that in the NHS Test and Trace scheme, an NHS Tracker will only contact individuals who have tested positive for Covid19. Whether someone should be tested at all is heavily dependent on self reporting. Furthermore, responses to a possible request to us to identify those with whom we may have had recent close contact is based on our ‘civic duty’ rather than a legal requirement - so it’s very much down to our willingness or judgment to do so. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest/s Phil is an independent data protection consultant based in North Norfolk and has provided data protection advice and support to a wide variety of industries across Norfolk and beyond, mostly to small businesses. Prior to that, Phil had a 20 year career as a military communications officer which was then followed by 12 years in the world of mobile phone standardisation, mostly consulting for a Japanese mobile phone operator. During the latter phase, he chaired an international working group that developed mobile phone conformance tests and also chaired the Global Certification Forum when is became a legal entity in 2008. Such work has seen him travel widely and has, at various times, studied French, German, Japanese and Mandarin Chinese none of which prepared him for life in Norfolk when he moved there in 2016! He has a Masters degree in Design of Information Systems and his currently trading as Norfolk’s Data Protection Mardler. Special Guest: Phil Brown. | |||
16 Jan 2020 | Episode 15: Cyber security - everything a DPO needs to know. Part 2. | 00:43:35 | |
Cyber security is an area of key concern for any DPO or privacy professional. Having looked at people and training issues in episode 7, this episode focuses on the key physical issues: physical and technical access controls, network design considerations, default deny and least privilege, separation of duties and working in key areas. GDPR Now! Is brought to you by This Is DPO. Guest/s Host Materials From previous episode on cyber security ISO 27001 Training: Questions, suggestion for improvement, ideas for issues to be covered in future episodes, or if you would like to appear one of our podcasts, please contact us at info@thisisdpo.co.uk Special Guest: Andy Larkum. | |||
14 May 2020 | COVID 19 Pandemic and the impact on Data Protection | 00:27:43 | |
Welcome to another episode of GDPR Now, a podcast dedicated to data protection and all things data security and data privacy. This week’s episode is COVID 19 and the impact on Data Protection. Regular listeners will have already heard our episodes on what DPOs need to know about cyber security, for those that missed them, they are episodes 7 & 15. Today, we start a series of podcasts addressing concerns resulting from the coronavirus pandemic and the shift in working practises for 100,000s businesses across the UK and the world. In the studio today we are delighted to have Kingsley Hayes, Managing Director of Hayes Connor Solicitors based in Widnes, Cheshire. In this first of two episodes, we are going to talk about Covid 19 and the impact on data protection. In our second episode, Kingsley and I will be discussing data breach Group Action law suits in general, and the BA action in particular. We cover the reputational and financial risks businesses need to be aware of when Group Actions, are filed as a result of data breaches. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest/s Host This podcast is brought to you by thisisdpo.co.uk and Data Protection 4 Business. For more information, go to thisisdpo.co.uk or dpo4business.co.uk. All suggestions for topics, improvement etc are gratefully received or if you want to appear on the podcast, please contact us at info@dpo4business.co.uk. Special Guest: Kingsley Hayes. | |||
08 Sep 2021 | Episode 31: Challenging the Privacy narrative | 00:41:03 | |
In this episode, we discuss, controversially, why data privacy, including regulations like GDPR, are counterproductive and why we would all be better off without the current notion of data privacy. Our special guest, Ben Malisow, is our 'privacy provocateur' on our show and talks about why he believes we are living an 'illusion of privacy'. Ben has over 30 years experience in information security and education and is currently a professional certification training lead for SGS Cybersecurity Services, a multinational corporation involved in a wide range of product and process certification/validation. Some of Ben’s roles have also included professor of English, a computer teacher for troubled teens as well as his extensive experience working with clients such as FedEx, US Special Forces Command, the United Nations, HSBC, and Barclays. Ben is the author of ''Exposed: How Revealing Your Data and Eliminating Privacy Increases Trust and Liberates Humanity.'' GDPR Now! Is brought to you by Data Protection 4 Business. Guest Special Guest: Ben Malisow. | |||
15 Apr 2021 | Episode 28: Digital Vaccine Passports and Certificates? What could possibly go wrong? | 00:47:16 | |
In today’s episode, we are delving into the hot topic of Digital Vaccine Passports and Certificates. We outline the complex mix of technology, privacy and practical issues in a global context. As we did in Episodes 24 & 25, we look at the significant practical, technical and privacy issues surrounding how nation states and governments want to use technology to prove human beings can travel internationally, cross borders in the EU and get access to domestic venues, events, retail outlets and much more besides. Arguably a more complex problem to solve than tracking and tracing individuals. We consider the lack of effectiveness of the Track and Trace apps in the UK & EU and wonder how acceptable solutions can be found for Vaccine Passports and Certificates - a wider problem involving citizens, businesses, medical records and often new and emerging technology. Again, we find ourselves asking the same question: how do we find a rapid and effective way to discuss and agree the extended use of our data to manage this pandemic and halt the damage from lockdowns? We urgently need a forum to be able to have these discussions. As Privacy, Legal and Techology professionals we must contribute to solutions to help support governments to enable better pandemic management. There are far more questions than answers, so this episode will be the start of our journey to keep up to date with developments. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guests Special Guest: Roger Marlow. | |||
24 Jun 2019 | Episode 1: GDPR One Year On - with James Leaton Gray | 00:44:52 | |
GDPR Now! brought to you by This is DPO. Episode 1 – GDPR One Year On. About this episode: Guest: James Leaton Gray, Director of The Privacy Practice. Host: Mark Sherwood-Edwards of This Is DPO. Material referred to: Tim Berners Lee’s company The Furman report Contact details | |||
09 Oct 2019 | Episode 12: Brexit! | 00:37:20 | |
What do UK companies need to do if the UK crashes out of the EU? This podcast discusses the privacy implications for UK companies after October 31st and what they should be doing – now – to prepare for a hard Brexit. At the time this podcast was recorded, a hard Brexit is scheduled for October 31st GDPR Now! Is brought to you by This Is DPO. Guest D2 Legal Technology LLP Host Materials The Data Protection Implications of a 'No-Deal Brexit', Douwe Korff EDPB Information note on data transfers under the GDPR in the EDPB view on Article 49 derogations Questions, ideas, appearing Special Guest: Oana Dolea. | |||
29 Jan 2021 | Episode 26: What next for EU-US data transfers post-Privacy Shield? Keep hiding in that herd! | 00:38:31 | |
The decision by the ECJ on 16th July 2020, to invalidate the EU - US Privacy Shield sent shockwaves across organisations in the EU and US. We are now in January 2021 and there have been some solutions offered by the European Commission. But how workable are they for businesses in practise?? Join me, Karen Heaton and guest Mark Sherwood-Edwards, lawyer, data protection specialist and founder of Clearview Legal to discuss the latest pronouncements from the EC, on a revision of the Standard Contractual Clauses, Safeguards for transfers to the US (and other third countries) and of course, the impact of Brexit and what this will mean if the EC does not grant adequacy status to the UK. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest Check out some great resources: Tools to help with assessing data transfers Special Guest: Mark Sherwood-Edwards. | |||
19 Jan 2022 | Episode 33: Age Check Certification Scheme - what technology companies need to know | 00:30:28 | |
In this episode, we talk about the first officially approved certification schemes under Art.42 of UK GDPR by the ICO: the Data Protection and Privacy for ID & Age Assurance Services, and the Age Appropriate Design Certification. Our special guest, Tony Allen CEO of The Age Check Certification Scheme (ACCS) talks about the scope and applicability of the certification schemes and what technology companies need to consider. Tony also explains more about the ACCS which is a UKAS-accredited conformity assessment body, comprised of auditors, certification specialists, and data protection experts and how they independently test and certify online and offline systems that check age and identity, such as passport scanners, biometric technology, and age verification software. GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest Contact Tony Allen on: Special Guest: Tony Allen. | |||
05 Aug 2019 | Episode 5: Cookies and the GDPR – ICO v CNIL | 00:31:05 | |
GDPR Now! is brought to you by This is DPO, www,thisisdpo.co.uk. *Cookies and the GDPR– ICO v CNIL. * About this episode: Host: Mark Sherwood-Edwards of This Is DPO. Material referred to: Here’s the important paragraph from the ICO’s Guidance on the use of cookies and similar technologies (bottom of page 46): The ICO cannot exclude the possibility of formal action in any area. However, it is unlikely that priority for any formal action would be given to uses of cookies where there is a low level of intrusiveness and low risk of harm to individuals. The ICO will consider whether you can demonstrate that you have done everything you can to clearly inform users about the cookies in question and to provide them with clear details of how to make choices. For example, the ICO is unlikely to prioritise first party cookies used for analytics purposes where these have a low privacy risk, or those that merely support the accessibility of sites and services, for regulatory action. Guidance on the use of cookies and similar technologies, ICO Délibération n° 2019-093 du 4 juillet 2019 portant adoption de lignes directrices relatives à l'application de l'article 82 de la loi du 6 janvier 1978 modifiée aux opérations de lecture et écriture dans le terminal d'un utilisateur (notamment aux cookies et autres traceurs), CNIL Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities, adopted on 12 March 2019, EDPB. Contact details | |||
29 May 2020 | Episode 19: The rise of Cyber crime: security challenges for SME's | 00:25:26 | |
Regular listeners will have already heard our episodes on what DPOs need to know about cyber security, and COVID 19 impact on data protection.
gdpr, privacy, data security, cyber crime, data protection, SME We are delighted to have Zohar Rozenberg (Col. Ret.) who is the Chief Security Officer at Elron, a leading Israeli holding company dedicated to building technology companies. Aside from an impressive career in Israeli defence and cyber security, Zohar has written a number of recent articles on cyber issues: https://www.cisomag.com/cyber-startup-hub-in-israel-declines-as-global-competition-rises-elron-vp/ GDPR Now! Is brought to you by Data Protection 4 Business & This Is DPO. Guest/s Special Guest: Zohar Rosenberg. | |||
27 Aug 2019 | Episode 7: Cyber security - everything a DPO needs to know. Part 1. | 01:07:37 | |
Cyber security for DPOs. Cyber security isn’t usually the primary responsibility of the DPO, but you can’t be an effective DPO if you don’t understand the security regime in your organisation and the trade-offs behind them. In this episode, we look at cyber security: what does it really consist of? how best to think about it? and what are the most common areas of vulnerability? GDPR Now! Is brought to you by This Is DPO. Guest/s Host Materials Breaking News! Cyber Essentials self-assessment questionnaire: ISO 27001 Training: Questions, suggestion for improvement, ideas for issues to be covered in future episodes, or if you would like to appear one of our podcasts, please contact us at info@thisisdpo.co.uk Special Guest: Andy Larkum. | |||
12 Jul 2019 | Episode 2: Subject access requests, personal data and the case of Rudd v Bridle with Ashley Winton and Laura Scaife. | 00:53:52 | |
GDPR Now! brought to you by This is DPO. Subject access requests, personal data and the case of Rudd v Bridle with Ashley Winton and Laura Scaife. About this episode: Guests: Dr. Laura Scaife, McDermott, Will & Emery Host: Mark Sherwood-Edwards of This Is DPO. Material referred to: For a written analysis of the case: https://thisisdpo.co.uk/2019/07/12/durant-rides-again-subject-access-requests-and-personal-data-revisited-in-rudd-v-bridle/ Contact details Special Guests: Ashley Winton and Laura Scaife. | |||
04 Nov 2019 | Episode 13: Governance – what’s needed to run a good data protection regime? | 00:44:03 | |
What are the building blocks of good data protection governance? In this broad-ranging discussion, we talk to James Leaton Gray about his assessment of current data protection in the UK, what it takes to run a good data protection regime, different target operating models, how different parts of the business need to work together, the evolving role of the DPO, privacy and privsec, common mistakes and – critically – how move the data protection regime up the value chain. Plus the opportunities open to organisations that manage to establish a relationship of trust with their data subjects. GDPR Now! Is brought to you by This Is DPO. Guest Host Materials Questions, suggestion for improvement, ideas for issues to be covered in future episodes, or if you would like to appear one of our podcasts, please contact us at info@thisisdpo.co.uk Special Guest: James Leaton Gray. | |||
07 Oct 2021 | Episode 32: Decentralised Identity - digital ID solutions for our future | 00:36:59 | |
In this episode, we continue our discussions about the digital ID solution of decentralised identity, and how more and more organisations are starting to take notice of of this technology as a means to verify the identity of people in a secure, efficient, cost effective and privacy enhancing way. Our special guests, Khalid Maliki and Jimmy Snoek talk about decentralised identity, also known as Self Sovereign Identity (SSI), how it can be implemented, the benefits and in particular, how they created the awarding winning digital ID company Tykn. We talk about the growth of SSI and how they believe it will positively impact billions of peoples lives. As we enter what is arguably, the start of our journey into a new era of digital innovation with huge benefits to individuals and businesses, we are excited to follow developments around the growth of digitial ID solutions such as decentralised identity. GDPR Now! Is brought to you by Data Protection 4 Business Guest Contact Khalid on: Contact Jimmy on: Website: https://tykn.tech/ Special Guests: Jimmy Snoek and Khalid Maliki. |