Grumpy Old Year
🧩 Is EDPB’s dense techspeak an impossible puzzle even for Rie, and public consultations just an internal checkbox exercise? And will 2025 finally bring some clarity, or are we doomed to rearrange the pieces of the same broken puzzle?
Interesting, fascinating, provoking, insightful – or all of the above – GDPR decisions, rulings and other tidbits discussed by two very opinionated people.
~ A podcast by Miloš Novović & Rie Aleksandra Walle
🎧 Listen to the show on your favorite podcast platform (and here's the RSS feed).
I'm a huge fan of your podcast! I love that I can listen to it on my way to work and be all fired up and grumpy by the time I arrive.
I hope to see more of that 😊
🧩 Is EDPB’s dense techspeak an impossible puzzle even for Rie, and public consultations just an internal checkbox exercise? And will 2025 finally bring some clarity, or are we doomed to rearrange the pieces of the same broken puzzle?
40% is the new 80%. The grumpsters tackle AI madness with a dose of reality: We're prescribing Back to Basics, MMA (Map-Manage-Adapt), bananas for potassium, and a healthy serving of "just get started already!"
And remember, sometimes a Word doc titled "Got AI? Call DPO" is better than nothing at all.
Join the conversation on LinkedIn and send us all your grumpy questions!
💌 Don't forget to sign up for the free newsletter The Rieview for more Back to Basics and practical tips.
With years at the Dutch DPA, then real-world experience in the trenches of data protection, also teaching compliance at Maastricht University and a member of the Jersey DPA – who better to dive into the latest dynamite DPO decision with than Paul Breitbarth himself. 😎
Join the conversation on LinkedIn.
🚌 Today: missed stops, wrong turns and someone definitely ending up under the wheels. Buckle up!
Join the conversation on LinkedIn.
Miloš and Rie hotly debate whether asking for consent for or even informing of new 🇺🇸 transfers is legally required when Rie changes her free newsletter provider (due to hefty annoyances).
What do you think is correct? Would you:
Join the discussion 👉 on LinkedIn!
Sharpen your ✏️ pencil, 'cause it's 📚 Yellow Pages time!
👉 Join the discussion on LinkedIn
👉 Watch the recording and join the discussion on LinkedIn
In this episode we not only reveal how we met, but also discuss the (in my view) nefarious world of learning analytics in schools.
So what do 𝐲𝐨𝐮 think: Does learning analytics lead to more successful pupils? How? And where's the limit of what's OK?
👉 Join the discussion on LinkedIn.
Once again we revisit the infamous Chromebook case of Denmark – Helsingør. And once again the lovely Allan Frank from the DPA joins to discuss what makes the cake inedible and how we can make something tasty instead.
👉 Join the discussion on LinkedIn.
👉 Join the discussion on LinkedIn.
We're quite proud of this one, to be honest. If we can inspire just one person to dare speak up, whether about something you're unsure of or afraid to be judged because of, our mission would be complete! 🔥
👉 Join the discussion on LinkedIn.
This might be just the grumpiest episode we've ever recorded (even took out a couple of bits 😱)! And not just because of the 45 min. technical issues to begin with...
Take a listen and let us know what you think! Rie also posted a super grumpy post on LinkedIn.
We are! Who else? Join the discussion 👉 on LinkedIn
PS: This is the last episode of this side of the year. Thanks for sticking with us and have a wonderful summer ahead! ☀️🏖️
Grumpy GDPR is back after a summer break! But privacy and data protection never rests, so there's much to talk about.
Join the debate on LinkedIn. 👇
The Swedish DPA IMY has really ramped up their game. First ordering controllers to stop using Google Analytics; now Bonnier gets slapped with a SEK 13 million fine for (mis)using their customers' personal data for targeted ads without consent.
And, true or false: "Targeted ads is illegal based on legitimate interest assessment."
Today, we're revisiting a prior topic, which has made Rie even grumpier since last year! Tune in to listen. 👇
You made it clear on our LinkedIn poll what you wanted us to discuss next on the podcast, so here you go!
Tune in to listen and join the discussion (link coming).
Although the plan was to do TikTok, we had to jump on to discuss the GDPR 💣 from last night: the EDPB extended the Meta ban to the entire EEA, permanently.
Has their business model been banned?
Will Meta go out of business?
Are they working on a consent solution?
Is that even possible... 🤔
And so many other questions!
Tune in to listen and join the heated discussion on LinkedIn!
As always, the shownotes are cryptic so we don't spoil the surprise!
Join the discussion on LinkedIn.
Our last episode of the year! We're super thankful you've tagged along with us so far and we can't wait for 2024. 🎄
Join the discussion on LinkedIn.
For those celebrating Christmas, the holiday is now over. Miloš disconnected and took some well-deserved time off, while Rie tried, but ended up reading old WP29 stuff... Ah well, maybe next Christmas!
Anyway, we're all starting a new (amazing 🤞) year and we can't wait to continue our podcasting journey with you!
🗓️ We're switching things up a bit this season, though, and we'll be podcasting every 3. weeks and releasing new episodes on Thursdays.
Who is/are the Basket Case(s)? Who gets the rotten 🥚? Find out in today's unusually grumpy Grumpy GDPR episode.
PS:️ In case you missed it – we're only podcasting every 3. weeks this season. (Although we're getting quite a few episode request, so do let us know too if you'd like to hear from us more often.)
PS: Join our conversation here and voice your opinion on our poll. 📊
Let's try to stretch this argument just a liiiiiiitle bit more...
What do you think? Did the controller overstretch? Not stretch enough? Stretch the wrong places? 🤔 Join our conversation here!
Tune in for today's brilliant discussion with Line Coll, the Head of the Norwegian data protection authority Datatilsynet: How do DPAs see the GDPR? What do they expect small businesses to do and how do they support them? How does a DPA pick its cases and what hot tips do they have for the DPOs?
(Yes, we talked about third-country transfers too!)
What was your favorite part? What do you agree or disagree with? Was anything surprising? 👉 Join the conversation
Today we discuss two (thought)provoking decisions from the Danish data protection authority regarding the (mis)use of cookie walls.
And we are grumpy. Very grumpy. You? 🤔 Join in the conversation 👈 this post also summarizes the decisions + the cookie wall guidance.
We meant to record something else for this episode but Rie read a decision which is pretty explosive and – in our opinion – sends the opposite signal of what the DPA likely meant to do.
Some are even grumpier than Miloš and Rie! See LinkedIn post no. 1 and no. 2 – highlights below. This shows how tricky GDPR compliance can be (and why there's no such thing as 100%).
And become my pen pal to stay in touch onwards:
...
A controversial ruling on the concept of personal data by the General Court of the Court of Justice – or simply a ruling on a procedural error?
We'd love to hear your thoughts! Join the debate 👉 on LinkedIn.
= ❌ US transfers...
Is this case a "privacy win" all around or are there nuances? Join the debate 👉 on LinkedIn.
🗓️ NB! This episode was recorded before Border Control. Join us for a great chat with a special guest!
This is our last episode before the grumpy lot goes on summer hols. 🏖️ What would you like to listen to next? Do let us know! We're back in the fall sometime.
In today's episode we discuss an intriguing case, summarised here on the GDPRhub (thanks Cesar!). Apart from revolving around AI failing 91.96% of the time, this is the gist of it:
The Hungarian DPA fined Budapest Bank €700,000 for automated decision-making and profiling based on emotional AI analysis of customer service calls, without a valid legal basis, a proper balancing of interests, and adequate safeguards. The DPA also held that the bank failed to provide data subjects with information related to the processing and their right to object.
On 25 May, the European Commission gave us a GDPR birthday present: a Q&A document for the 2021 SCCs. Are they really clarifying key issues, or creating more confusion?
Are the "DPA-SCCs" mandatory to use for your data processing agreements (Article 28(3) terms)? Do you have to sign every document part of your contractual setup? If a controller objects to a suggested new sub-processor, do you have to oblige – meaning you can never appoint new ones, ever? 🤔 So many questions! And we try to cover some of these in today's episode.
💡 Did you know that the term "standard contractual clauses", that is, "SCCs", is a generic term in the GDPR? Last year, the Commission published two sets of SCCs: one you can think of as "DPA-SCCs" because these can only be used as a data processing agreement ("DPA") as per Article 28(3) and are intended for use between controllers and processors in the EEA. The second set, what people usually refer to as "SCCs", are for transferring personal data to third countries as a safeguard under Chapter V (specifically Article 46(2)(c)). And to make the confusion complete, data protection authorities can also get SCCs approved, like the Danish one did for Article 28(3) agreements back in 2019 (which can, by the way, still be used!).
"A loyalty program is a marketing strategy designed to encourage customers to continue to shop at or use the services of a business associated with the program." (from Wikipedia).
❌ There's no such thing as a free lunch.
And there is likely no such thing as free rewards, either. Sure, you can get 10, 20, 30 or even 50% off for "being loyal" – but you don't simply get this.
You're paying, just not in cash, but with your personal data. (And you might also be forced to receive spam...)
"Join our loyalty program and get free stuff" is a sham.
👉 Such programs aren't necessarily problematic, as long as companies are honest and transparent about the trade-off. And we need to be conscious about what we're agreeing to give up in return for discounts and other benefits.
Personality tests, behavior tests, skills tests, IQ tests: are any of these necessary to get or keep a job? 🤔 Or even legal – as per the GDPR?
This episode was inspired by a series of news articles in the Norwegian media, where big employers like Elkjøp (the largest consumer electronics retailer in the Nordics), Rema 1000 and Coop (grocery chains) use various tests to shortlist and select employees.
💡 Tip: The articles are all in Norwegian, but you can read them easily in the Vivaldi browser with the automatic translation feature enabled.
One of our fundamental rights as per the GDPR is the right of access outlined in Article 15, stating that we 1) have the right to know whether or not our personal data is being processed, 2) access to it, as well as 3) a copy.
⚠️ However, we might be refused these rights if our requests are found "manifestly unfounded or excessive", as described in Article 12(5).
Unfortunately, the GDPR doesn't define the term “excessive”, leaving it up to data protection authorities and courts to decide where someone has lodged a complaint after being refused access.
And despite the key objective behind a 'regulation' vs. a 'directive' in EU law to streamline application, we, unfortunately, see not only varying enforcement, but outright contrary court rulings. Take a listen to our episode discussing this in more detail – and check out several decisions and rulings below. 👇
Oh wow, what a week for privacy and data protection! 🤯 In a landmark decision, the Danish DPA Datatilsynet outright banned the use of Google Workspace for Education and banned US transfers until a municipality gets their processing in line with the GDPR.
True story – a company has been (and still are!) stuck with their external DPO for 12 years.
Is the DPO requirement reasonable? Or the frequent recommendations from data protection authorities (like the French CNIL) to 'always' appoint one even though you don't have to? 🤔 We think not.
The requirement (for certain businesses and organizations) to appoint a data protection officer was not new with the GDPR and actual requirements can also vary between member states.
For example, in Germany, in addition to Article 37(1)(b) and (c), you must appoint a DPO if you "generally employ at least 20 people at all times with the automated processing of personal data" (see BDSG § 38(1)). It used to be 10 people, but at least they increased this to 20 in November 2019.
Now, the European Court of Justice (CJEU) recently ruled that member states can make it even harder to dismiss a DPO – internal or external – in national legislation, like in the German case discuss on our episode.
Unfortunately, the minority view from the referring court didn't win in this case, stating that "the links between that protection and the position of data protection officer conflict with EU law and give rise to economic pressure to retain a data protection officer on a long-term basis once he or she has been designated."
Not only did the online space for privacy and data protection professionals take fire last week following the Danish DPA's ban on the use of Google Workspace and US transfers – our last podcast episode did, too. 🔥
So much so that we ended up chatting directly with the Danish DPA – and the man himself who wrote the actual decision. He even agreed to come onto our grumpy podcast to clarify on some misconceptions surrounding the decision, such as "Google has been banned in Denmark".
Oh and we got to check his GDPR-grumpy-meter. 🌡 Tune in now to listen!
You ever get stuck on doing transfer impact assessments? Don't despair, help is here! The SCCs Superhero from last year, David Rosenthal, is back with another massive PDF to help out our community.
Some of our peers, however, have been very grumpy with regards to the "Rosenthal method", so Miloš and I invited David on our Grumpy GDPR podcast to discuss some of the concerns and questions.
If you thought we were grumpy before, you ain't seen (heard) nothin' yet! 🔥
🧨 Join us and other DPOs and GDPR/privacy/data protection folks for a hefty discussion on this LinkedIn Audio (only!) Event Tuesday 23 August 6:30 PM CEST.
This is a topic I have strong opinions about. Extremes/fundamentalism, is never good – in any way, shape or form. Here, though, we're not talking about two opposite extremes.
At the far end of the scale you have the Privacy Purist, but the Privacy Pragmatist is not on the opposite end – here you'll find complete and blatant ignorance (Privacy Anarchist, perhaps?). I'd say the pragmatists are more towards the Purist end of the scale.
But as a DPO – internal or external – I don' think you can do your job responsibly while being on (and advising from) either extreme of the privacy scale.
Purists are about absolutes. DPOs cannot be about or advise in absolutes. The GDPR is not absolute. And privacy is not an absolute right – see GDPR Recital 4!
And since I don't want to send readers to little privacy-friendly dictionaries, here's a screenshot of various definitions:
The GDPR case which could serve as next year's Easter crime drama!
For the now three-part series, check out:
Today, we are grumpy about data collection and retention – and ask our listeners about Spanish national regulations for storing passport copies for hotel bookings – are these really necessary/required? 🤔 And, if so, are they required to store the copy of the whole passport page? And for how long?
Reach out if you know – easiest is on LinkedIn, where every podcast episode is promoted.
So you thought the Schrems II saga was over? Far from it!
On 15 September 2022, a group of Norwegian authorities published a guidance for the public sector's use of cloud services – taking a different stance on key issues than the Norwegian and Danish data protection authorities.
Unfortunately, the guidance, articles etc. are only in Norwegian, but I've summarized the key issues in English here.
The guidance, which spans over several (web) pages, is substantial. I managed to squeeze it into 40 pages, but only after using font size 9 throughout, two columns and reducing all images... You can read it online here or download the PDF version from my LinkedIn post here.
And after receiving numerous inquiries, the Norwegian DPA and the representatives for the guidance (DFØ and Digdir) shared a joint statement here. There are likely quite hefty discussions at the moment and we're all curious to see what comes out of this, in the end.
Stay tuned for upcoming episodes on this topic!
Monitoring vs. surveilling – where does the limit go? 👉 Join the discussion on LinkedIn, where every podcast episode is shared.
⚠️ "Easylife Limited, registered at 94 Orchard Gate, Greenford, England, UB6 0QP, is a company selling household products through catalogues. The brand was founded in 1992, and Easylife was incorporated on 3 September 2004 (at that date "Easylife Group Limited"). Easylife has one active director registered at Companies House, Gregory Grant Caplan, who is the Chief Executive Officer and also a director of "Easylife Holdings Limited", which is registered as a person of significant control of Easylife." Source: ICO enforcement notices.
Easylife's statement:
"Easylife has simply done what the ICO has already admitted to us that lots of businesses do day in day out. Easylife was simply trying to minimise the number of calls it made to its customers, but it seems that the ICO and its new Commissioner, John Edwards, would prefer it if businesses like Easylife made more untargeted calls to their customers and not fewer more targeted calls … Easylife fundamentally disagrees with the ICO both that it has broken the law and also in relation to the level of fine imposed, which is out of all proportion to the alleged wrong."
However they also said to the ICO that:
... it did not want to be competitively disadvantaged compared to others in its sector.
💬 What's your take on this case? Are monetary penalties enough?
👉 Join the discussion on LinkedIn, where this decision was shared 7 October.
⚠️ Are our rights to compensation for damages under the GDPR under threat? A(nother) recent Opinion from the CJEU is making waves this year, and today we discussed the case with Max Schrems, who has tweeted ferociously about it over the past weeks.
The recent Opinion coming out of the Court of Justice of the European Union regards:
But does it actually clarify on (any of) these areas? 🤔 We're not sure!
👉 Listen in and join the discussion on LinkedIn.
Are you diligent in your due diligence? 🧐 And how diligent should you (not) be? Listen in as we discuss what to think about not only before you appoint processors – but also after.
👉 How do you vet and audit your processors? Join the discussion on LinkedIn.
All is fine. Or not. What else do the supervisory authorities have in their toolbox?
👉 What GDPR penalty do you think is the worst? Join the discussion on LinkedIn.
From Twelve Days of Christmas to Twelve Days of Breaches – although this decision is rather short compared to the other ones. 😉
👉 If you've also geeked through one or more of these decisions, what's your take-away? Join the discussion on LinkedIn.
Listen in to this recap of all episodes from this year. And thank you, dear listener, for spending your valuable time on our banter and grumpy discussions. We truly appreciate your support and feedback. 🙏 Best wishes from Miloš & Rie!
👉 Have we been too grumpy, or just not grumpy enough, so far in our podcast journey? Join the discussion on LinkedIn.