Grumpy GDPR podcast

Interesting, fascinating, provoking, insightful – or all of the above – GDPR decisions, rulings and other tidbits discussed by two very opinionated people.

~ A podcast by Miloš Novović & Rie Aleksandra Walle

🎧 Listen to the show on your favorite podcast platform (and here's the RSS feed).

I'm a huge fan of your podcast! I love that I can listen to it on my way to work and be all fired up and grumpy by the time I arrive.
I hope to see more of that 😊

Season 6, 2025

Grumpy Old Year

28 Jan

🧩 Is EDPB’s dense techspeak an impossible puzzle even for Rie, and public consultations just an internal checkbox exercise? And will 2025 finally bring some clarity, or are we doomed to rearrange the pieces of the same broken puzzle?

Get your (AI) act together

26 Feb

40% is the new 80%. The grumpsters tackle AI madness with a dose of reality: We're prescribing Back to Basics, MMA (Map-Manage-Adapt), bananas for potassium, and a healthy serving of "just get started already!"

And remember, sometimes a Word doc titled "Got AI? Call DPO" is better than nothing at all.

Join the conversation on LinkedIn and send us all your grumpy questions!

Resources mentioned:

💌 Don't forget to sign up for the free newsletter The Rieview for more Back to Basics and practical tips.

Conflicted

3 Apr – w/Paul Breitbarth, member 🇯🇪 DPA, former 🇳🇱 DPA

With years at the Dutch DPA, then real-world experience in the trenches of data protection, also teaching compliance at Maastricht University and a member of the Jersey DPA – who better to dive into the latest dynamite DPO decision with than Paul Breitbarth himself. 😎

Join the conversation on LinkedIn.

Resources mentioned:

Under the Bus

18 Dec – w/Max Schrems

🚌 Today: missed stops, wrong turns and someone definitely ending up under the wheels. Buckle up!

Join the conversation on LinkedIn.

Season 5, 2024

Have you noticed?

6 Aug

Miloš and Rie hotly debate whether asking for consent for or even informing of new 🇺🇸 transfers is legally required when Rie changes her free newsletter provider (due to hefty annoyances).

What do you think is correct? Would you:

  • Ask for consent?
  • Not ask for consent but inform?
  • Or, as one subscriber responded right away, "simply update the general privacy policy and not inform the recipients"?

Join the discussion 👉 on LinkedIn!

Grumpy on purpose

12 Dec

👉 Join the discussion on LinkedIn

Resources mentioned:

  • WP29's Opinion 03/2013 on purpose limitation
  • EDPB's Guidelines 07/2020 on the concepts of controller and processor does actually define purpose in para 33: Dictionaries define “purpose” as “an anticipated outcome that is intended or that guides your planned actions and “means” as “how a result is obtained or an end is achieved.
  • Read Rie's new webform snippet for consent-based newletter processing (PS: if you sign up, please respond with your thoughts to the automated email you receive OR connect on LinkedIn and tell her why you didn't want to sign up)
  • 🎙️ Listen to my chat with Sergio on Masters of Privacy
  • 🎙️ And Paul and K's episode which also mentions the KLNTB ruling

Season 4, 2024

How I met your grumpster

18 Jan

In this episode we not only reveal how we met, but also discuss the (in my view) nefarious world of learning analytics in schools.

So what do 𝐲𝐨𝐮 think: Does learning analytics lead to more successful pupils? How? And where's the limit of what's OK?

👉 Join the discussion on LinkedIn.

🇩🇰 Piece of Cake!

8 Feb – w/Allan Frank, 🇩🇰 DPA Datatilsynet

Once again we revisit the infamous Chromebook case of Denmark – Helsingør. And once again the lovely Allan Frank from the DPA joins to discuss what makes the cake inedible and how we can make something tasty instead.

👉 Join the discussion on LinkedIn.

Prior 🎙️ Grumpy GDPR episodes:

European Court of Jawstice

21 Mar

We're quite proud of this one, to be honest. If we can inspire just one person to dare speak up, whether about something you're unsure of or afraid to be judged because of, our mission would be complete! 🔥

👉 Join the discussion on LinkedIn.

    You Shall Pay

    25 Apr

    This might be just the grumpiest episode we've ever recorded (even took out a couple of bits 😱)! And not just because of the 45 min. technical issues to begin with...

    Take a listen and let us know what you think! Rie also posted a super grumpy post on LinkedIn.

    AI am tired 😩

    7 Jun

    We are! Who else? Join the discussion 👉 on LinkedIn

    PS: This is the last episode of this side of the year. Thanks for sticking with us and have a wonderful summer ahead! ☀️🏖️

    Season 3, 2023

    Illegitimate interest

    31 Aug

    The Swedish DPA IMY has really ramped up their game. First ordering controllers to stop using Google Analytics; now Bonnier gets slapped with a SEK 13 million fine for (mis)using their customers' personal data for targeted ads without consent.

    And, true or false: "Targeted ads is illegal based on legitimate interest assessment."

    This episode's resources:

    Testing our patience

    21 Sep

    Today, we're revisiting a prior topic, which has made Rie even grumpier since last year! Tune in to listen. 👇

    This episode's resources:

    Unreasonable expectations

    12 Oct

    You made it clear on our LinkedIn poll what you wanted us to discuss next on the podcast, so here you go!

    Tune in to listen and join the discussion (link coming).

    This episode's resources:

    • Sep 2023: The Norwegian DPA asks the EDPB to make their Meta ban on behavioural advertising permanent + extend it to the entire EEA.
    • July 2023: The Norwegian DPA imposes a temporary ban on Meta
      Platforms Ireland Limited and Facebook Norway AS collectively, restricting them from processing personal data of Norwegian data subjects for behavioral advertising.
    • 🗓️ As discussed on the episode, this dates back to December 2022 and the DPC/EDPB (Binding) decisions on Meta and contractual necessity, mentioned on two former episodes: Basket Case(s) and The Evils of the World.

    Back on the Ban Wagon

    2 Nov

    Although the plan was to do TikTok, we had to jump on to discuss the GDPR 💣 from last night: the EDPB extended the Meta ban to the entire EEA, permanently.

    Has their business model been banned?
    Will Meta go out of business?
    Are they working on a consent solution?
    Is that even possible... 🤔

    And so many other questions!

    Tune in to listen and join the heated discussion on LinkedIn!

    This episode's resources:

    Season 2, 2023

    Network of Strings

    5 Jan

    For those celebrating Christmas, the holiday is now over. Miloš disconnected and took some well-deserved time off, while Rie tried, but ended up reading old WP29 stuff... Ah well, maybe next Christmas!

    Anyway, we're all starting a new (amazing 🤞) year and we can't wait to continue our podcasting journey with you!

    🗓️ We're switching things up a bit this season, though, and we'll be podcasting every 3. weeks and releasing new episodes on Thursdays.

    This episode's resources:

    Basket Case(s)

    26 Jan

    Who is/are the Basket Case(s)? Who gets the rotten 🥚? Find out in today's unusually grumpy Grumpy GDPR episode.

    PS:️ In case you missed it – we're only podcasting every 3. weeks this season. (Although we're getting quite a few episode request, so do let us know too if you'd like to hear from us more often.)

    PS: Join our conversation here and voice your opinion on our poll. 📊

    This episode's resources:

    Overstretching

    16 Feb

    Let's try to stretch this argument just a liiiiiiitle bit more...

    What do you think? Did the controller overstretch? Not stretch enough? Stretch the wrong places? 🤔 Join our conversation here!

    This episode's resources:

    Directing privacy

    Bonus! 22 Feb – w/Line Coll, Director General 🇳🇴 DPA Datatilsynet

    Tune in for today's brilliant discussion with Line Coll, the Head of the Norwegian data protection authority Datatilsynet: How do DPAs see the GDPR? What do they expect small businesses to do and how do they support them? How does a DPA pick its cases and what hot tips do they have for the DPOs?

    (Yes, we talked about third-country transfers too!)

    What was your favorite part? What do you agree or disagree with? Was anything surprising? 👉 Join the conversation

    This episode's resources:

    • The Norwegian DPA's website in English

    Thou Shall Not Pass

    9 Mar

    Today we discuss two (thought)provoking decisions from the Danish data protection authority regarding the (mis)use of cookie walls.

    And we are grumpy. Very grumpy. You? 🤔 Join in the conversation 👈 this post also summarizes the decisions + the cookie wall guidance.

    This episode's resources:

    72:00:00

    30 Mar

    We meant to record something else for this episode but Rie read a decision which is pretty explosive and – in our opinion – sends the opposite signal of what the DPA likely meant to do.

    Some are even grumpier than Miloš and Rie! See LinkedIn post no. 1 and no. 2 – highlights below. This shows how tricky GDPR compliance can be (and why there's no such thing as 100%).

    And become my pen pal to stay in touch onwards:

    From one of the LinkedIn discussions:

    • Most concerned by the lack of predictability. For the last 4-5 years the Norwegian DPA have said that the 72 hours rule is not vital or important?
    • The DPA is certainly setting an example here with this case, but for everyone saying the fine is too high: too high compared to what? I would argue the fine is one the lower side of the scale for a company with this economy?
    • There is no justification for this level of legal uncertainty and arbitrary enforcement, especially when the rules stem from non-democratic bodies.
    • In the absence of dissuasive fines, no one will take the necessary steps to solve the root cause of the problem ... And waiting two months for the legal opinion should not be a mitigating factor, lawyers can answer five minutes ago if needed 😊
    • Looking at the data in scope, the data subjects affected, and the several measures the company took to understand and remediate the situation, this does look like a disproportionate approach and I believe it sends out the wrong message, unfortunately
    • If they only one employee was victim of phishing and they did their investigations, the fine seems exagarated to me.
    • DPA's really need to agree on criterias regarding the level of sanctions. Legal security is at stake. 🤔
    • So if the Norwegian SA believes this should all be reportable, they either like to have too much to do or they are the best funded SA in the European Economic Area by being able to handle the work load.

    This episode's resources:

    Nothing personal

    11 May

    A controversial ruling on the concept of personal data by the General Court of the Court of Justice – or simply a ruling on a procedural error?

    We'd love to hear your thoughts! Join the debate 👉 on LinkedIn.

    This episode's resources:

    • The ruling in Case T-557/20, the Single Resolution Board (SRB) v the European Data Protection Supervisor (EDPS) on, amongst other things, the concept of personal data cf. Article 3(1) of Regulation 2018/1725 (i.e., not the GDPR but the GDPR's twin regulation for the EU institutions)

    Border Control

    1 Jun

    • ❌ Privacy Shield
    • ❌ 2010 SCCs
    • ❌ 2021 SCCs
    • ❌ Supplementary measures
    • ❌ Derogations
    • ❌ EO 14086

    = ❌ US transfers...

    Is this case a "privacy win" all around or are there nuances? Join the debate 👉 on LinkedIn.

    This episode's resources:

    The Irish Job

    22 Jun – w/Cian O'Brien 🇮🇪 DPC (NB! This was recorded before the Border Control episode)

    🗓️ NB! This episode was recorded before Border Control. Join us for a great chat with a special guest!

    This is our last episode before the grumpy lot goes on summer hols. 🏖️ What would you like to listen to next? Do let us know! We're back in the fall sometime.

    Season 1, 2022

    Banking on Emotions

    22 May

    In today's episode we discuss an intriguing case, summarised here on the GDPRhub (thanks Cesar!). Apart from revolving around AI failing 91.96% of the time, this is the gist of it:

    The Hungarian DPA fined Budapest Bank €700,000 for automated decision-making and profiling based on emotional AI analysis of customer service calls, without a valid legal basis, a proper balancing of interests, and adequate safeguards. The DPA also held that the bank failed to provide data subjects with information related to the processing and their right to object.

    Standard Confusing Clauses?

    25 May

    On 25 May, the European Commission gave us a GDPR birthday present: a Q&A document for the 2021 SCCs. Are they really clarifying key issues, or creating more confusion?

    Are the "DPA-SCCs" mandatory to use for your data processing agreements (Article 28(3) terms)? Do you have to sign every document part of your contractual setup? If a controller objects to a suggested new sub-processor, do you have to oblige – meaning you can never appoint new ones, ever?  🤔 So many questions! And we try to cover some of these in today's episode.

    Links and resources:

    💡 Did you know that the term "standard contractual clauses", that is, "SCCs", is a generic term in the GDPR? Last year, the Commission published two sets of SCCs: one you can think of as "DPA-SCCs" because these can only be used as a data processing agreement ("DPA") as per Article 28(3) and are intended for use between controllers and processors in the EEA. The second set, what people usually refer to as "SCCs", are for transferring personal data to third countries as a safeguard under Chapter V (specifically Article 46(2)(c)). And to make the confusion complete, data protection authorities can also get SCCs approved, like the Danish one did for Article 28(3) agreements back in 2019 (which can, by the way, still be used!).

    Club Can't Handle Us

    8 Jun

    "A loyalty program is a marketing strategy designed to encourage customers to continue to shop at or use the services of a business associated with the program." (from Wikipedia).

    ❌ There's no such thing as a free lunch.

    And there is likely no such thing as free rewards, either. Sure, you can get 10, 20, 30 or even 50% off for "being loyal" – but you don't simply get this.

    You're paying, just not in cash, but with your personal data. (And you might also be forced to receive spam...)

    "Join our loyalty program and get free stuff" is a sham.

    👉 Such programs aren't necessarily problematic, as long as companies are honest and transparent about the trade-off. And we need to be conscious about what we're agreeing to give up in return for discounts and other benefits.

    Links and resources:

    • Guidance from the Norwegian Consumer Authority (Forbrukertilsynet) on email marketing as per the Marketing Control Act (only in Norwegian)
    • Guidance from the Norwegian Consumer Authority and the Data Protection Authority (Datatilsynet) on digital services and consumer data:  in Norwegian and in English
    • Guidance from the Norwegian Data Protection Authority on customer clubs (only in Norwegian)
    • Guidance from the Norwegian Data Protection Authority on newsletters, email lists and SMS (only in Norwegian)
    • Guidance from the ICO, UK's Data Protection Authority, on the Privacy and Electronic Communications Regulations (PECR) and the "soft opt-in"

    This is not a test

    15 Jun

    Personality tests, behavior tests, skills tests, IQ tests: are any of these necessary to get or keep a job? 🤔 Or even legal – as per the GDPR?

    This episode was inspired by a series of news articles in the Norwegian media, where big employers like Elkjøp (the largest consumer electronics retailer in the Nordics), Rema 1000 and Coop (grocery chains) use various tests to shortlist and select employees.

    💡 Tip: The articles are all in Norwegian, but you can read them easily in the Vivaldi browser with the automatic translation feature enabled.

    Links and resources:

    Excessively confused!

    5 Jul

    One of our fundamental rights as per the GDPR is the right of access outlined in Article 15, stating that we 1) have the right to know whether or not our personal data is being processed, 2) access to it, as well as 3) a copy.

    ⚠️ However, we might be refused these rights if our requests are found "manifestly unfounded or excessive", as described in Article 12(5).

    Unfortunately, the GDPR doesn't define the term “excessive”, leaving it up to data protection authorities and courts to decide where someone has lodged a complaint after being refused access.

    And despite the key objective behind a 'regulation' vs. a 'directive' in EU law to streamline application, we, unfortunately, see not only varying enforcement, but outright contrary court rulings. Take a listen to our episode discussing this in more detail – and check out several decisions and rulings below. 👇

    Links and resources:

    • The EDPB's Guidelines 01/2022 on data subject rights – Right of access (NB! These were only public consultation until 11 March and has not been finalized yet.)
    • The Higher Regional Court Dresden held that an insurance company can reject a request to access as excessive if the request's purpose is not to be aware of or verify the lawfulness of the processing but to verify the validity of increases to insurance premiums. Read more on the GDPRhub
    • The Regional Court of Essen held that an insurance company can reject an access request as excessive if the request's purpose is not to be aware of or verify the lawfulness of the processing but to check why the premium has increased. Read more on the GDPRhub
    • The Higher Regional Court of Köln held that an access request of an insurance holder aimed to verify the lawfulness of premium increases – and not the lawfulness of the data processing – cannot be considered excessive under Article 12(5) GDPR. Read more on the GDPRhub
    • The Higher Regional Court Nuremberg held that a controller can reject an access request according to Article 12(5)(b) GDPR if the purpose of the request is not to be aware of or verify the lawfulness of the processing. Read more on the GDPRhub
    • The Regional Labour Court of Hesse decided that an employer who cannot prove the existence of overriding confidentiality interests has to provide information pursuant to Article 15 GDPR to an employee, even if such information can be used in defence against criminal proceedings initiated by the employer. Read more on the GDPRhub
    • The Financial Court of Berlin-Brandenburg held that data subjects must specify the data requested under Article 15(1) GDPR when the controller processes large amounts of data, and that a request concerning any type of data over a period of more than 50 years is excessive. Read more on the GDPRhub
    • The Danish DPA also held that an access request by a data subject asking his previous employer to provide all emails, notes and letters sent or signed by him was excessive according to Article 12(5)(b) GDPR, since it comprised a very large amount of personal data predominantly connected to his duties and not personal attributes. Read more on the GDPRhub

    Google Got Schooled

    19 Jul

    Oh wow, what a week for privacy and data protection! 🤯 In a landmark decision, the Danish DPA Datatilsynet outright banned the use of Google Workspace for Education and banned US transfers until a municipality gets their processing in line with the GDPR.

    You can't fire me

    2 Aug

    True story – a company has been (and still are!) stuck with their external DPO for 12 years.

    Is the DPO requirement reasonable? Or the frequent recommendations from data protection authorities (like the French CNIL) to 'always' appoint one even though you don't have to? 🤔 We think not.

    The requirement (for certain businesses and organizations) to appoint a data protection officer was not new with the GDPR and actual requirements can also vary between member states.

    For example, in Germany, in addition to Article 37(1)(b) and (c), you must appoint a DPO if you "generally employ at least 20 people at all times with the automated processing of personal data" (see BDSG § 38(1)). It used to be 10 people, but at least they increased this to 20 in November 2019.

    Now, the European Court of Justice (CJEU) recently ruled that member states can make it even harder to dismiss a DPO – internal or external – in national legislation, like in the German case discuss on our episode.

    Unfortunately, the minority view from the referring court didn't win in this case, stating that "the links between that protection and the position of data protection officer conflict with EU law and give rise to economic pressure to retain a data protection officer on a long-term basis once he or she has been designated."

    Links and resources:

    Back to School!

    Bonus! 3 Aug – w/Allan Frank, 🇩🇰 DPA Datatilsynet

    Not only did the online space for privacy and data protection professionals take fire last week following the Danish DPA's ban on the use of Google Workspace and US transfers – our last podcast episode did, too. 🔥

    So much so that we ended up chatting directly with the Danish DPA – and the man himself who wrote the actual decision. He even agreed to come onto our grumpy podcast to clarify on some misconceptions surrounding the decision, such as "Google has been banned in Denmark".

    Oh and we got to check his GDPR-grumpy-meter. 🌡 Tune in now to listen!

    Links and resources:

    TIA Superhero 🦸

    9 Aug – w/David Rosenthal

    You ever get stuck on doing transfer impact assessments? Don't despair, help is here! The SCCs Superhero from last year, David Rosenthal, is back with another massive PDF to help out our community.

    Some of our peers, however, have been very grumpy with regards to the "Rosenthal method", so Miloš and I invited David on our Grumpy GDPR podcast to discuss some of the concerns and questions.

    Privacy crusaders 🫡

    16 Aug

    If you thought we were grumpy before, you ain't seen (heard) nothin' yet! 🔥

    🧨 Join us and other DPOs and GDPR/privacy/data protection folks for a hefty discussion on this LinkedIn Audio (only!) Event Tuesday 23 August 6:30 PM CEST.

    This is a topic I have strong opinions about. Extremes/fundamentalism, is never good – in any way, shape or form. Here, though, we're not talking about two opposite extremes.

    At the far end of the scale you have the Privacy Purist, but the Privacy Pragmatist is not on the opposite end – here you'll find complete and blatant ignorance (Privacy Anarchist, perhaps?). I'd say the pragmatists are more towards the Purist end of the scale.

    But as a DPO – internal or external – I don' think you can do your job responsibly while being on (and advising from) either extreme of the privacy scale.

    Purists are about absolutes. DPOs cannot be about or advise in absolutes. The GDPR is not absolute. And privacy is not an absolute right – see GDPR Recital 4!

    Links and resources:

    • Recital 4
    • Recital 47

    And since I don't want to send readers to little privacy-friendly dictionaries, here's a screenshot of various definitions:

    School is Cancelled

    Bonus! 30 Aug – w/Allan Frank, 🇩🇰 DPA Datatilsynet

    The GDPR case which could serve as next year's Easter crime drama!

    For the now three-part series, check out:

    • Our first Grumpy GDPR podcast episode where Miloš and I discussed the case: Google Got Schooled.
    • The second podcast, starring the one and only Allan Frank from the Danish DPA – i.e., the man who wrote all decisions: Back to School!
    • And, following their third decision, Allan's revisit: School is Cancelled:

    Data malnutrition

    13 Sep

    Today, we are grumpy about data collection and retention – and ask our listeners about Spanish national regulations for storing passport copies for hotel bookings – are these really necessary/required? 🤔 And, if so, are they required to store the copy of the whole passport page? And for how long?

    Reach out if you know – easiest is on LinkedIn, where every podcast episode is promoted.

    Guiding dissent

    Bonus! 20 Sep

    So you thought the Schrems II saga was over? Far from it!

    On 15 September 2022, a group of Norwegian authorities published a guidance for the public sector's use of cloud services – taking a different stance on key issues than the Norwegian and Danish data protection authorities.

    Unfortunately, the guidance, articles etc. are only in Norwegian, but I've summarized the key issues in English here.

    The guidance, which spans over several (web) pages, is substantial. I managed to squeeze it into 40 pages, but only after using font size 9 throughout, two columns and reducing all images... You can read it online here or download the PDF version from my LinkedIn post here.

    And after receiving numerous inquiries, the Norwegian DPA and the representatives for the guidance (DFØ and Digdir) shared a joint statement here. There are likely quite hefty discussions at the moment and we're all curious to see what comes out of this, in the end.

    Stay tuned for upcoming episodes on this topic!

    I'll be watching you

    4 Oct

    Monitoring vs. surveilling – where does the limit go? 👉 Join the discussion on LinkedIn, where every podcast episode is shared.

    Links and resources:

    • In 2018, Gartner surveyed 239 large corporations and found that more than 50% are using some type of nontraditional monitoring techniques, and a YouGov 2020 report found that 1 in 5 companies have or intend to engage in using a form of employee monitoring tool.
    • The Norwegian DPA's guidance Monitoring and control of employees' digital activities (only in Norwegian).
    • The Norwegian DPA on the use of MyAnalytics in Microsoft Office 365 after changes to user terms.
    • Some relevant GDPRhub decisions:
    • The Spanish DPA held that, whilst audio recording of the workplace is legal under Spanish law, the employer responsible must inform its employee in advance. Failure to inform the employees was in violation of Article 13 GDPR.
    • The Landesbeauftragte , the DPA of Lower Saxony, Germany, fined notebooksbilliger.de €10,4 million for monitoring their employees over video without a legal basis.
    • The Italian DPA fined a municipality €84,000 for indiscriminate monitoring of employees in violation of Articles 5 (1)(a) and (c), 6, 9,13, 88, and 35 GDPR.
    • The Finnish DPA ordered a hospital to delete any historical data, location logs, and other employee personal data generated by Windows 10 for Workstations. One of the OS features violated the "data protection by default" principle under Article 25(2) GDPR.

    This is a robbery

    18 Oct

    ⚠️ "Easylife Limited, registered at 94 Orchard Gate, Greenford, England, UB6 0QP, is a company selling household products through catalogues. The brand was founded in 1992, and Easylife was incorporated on 3 September 2004 (at that date "Easylife Group Limited"). Easylife has one active director registered at Companies House, Gregory Grant Caplan, who is the Chief Executive Officer and also a director of "Easylife Holdings Limited", which is registered as a person of significant control of Easylife." Source: ICO enforcement notices.

    Easylife's statement:

    "Easylife has simply done what the ICO has already admitted to us that lots of businesses do day in day out. Easylife was simply trying to minimise the number of calls it made to its customers, but it seems that the ICO and its new Commissioner, John Edwards, would prefer it if businesses like Easylife made more untargeted calls to their customers and not fewer more targeted calls … Easylife fundamentally disagrees with the ICO both that it has broken the law and also in relation to the level of fine imposed, which is out of all proportion to the alleged wrong."

    However they also said to the ICO that:

    ... it did not want to be competitively disadvantaged compared to others in its sector.

    💬 What's your take on this case? Are monetary penalties enough?

    👉 Join the discussion on LinkedIn, where this decision was shared 7 October.

    Links and resources:

    • ICO press release Catalogue retailer Easylife fined £1.48 million for breaking data protection and electronic marketing laws
    • ICO enforcement notices for Easylife Limited, including Easylife Limited enforcement notice and Easylife Limited monetary penalty notices
    • News articles (worth a read!) from the Mirror and Which? (where Easylife's statement is from)

    No harm, no foul

    1 Nov – w/Max Schrems

    ⚠️ Are our rights to compensation for damages under the GDPR under threat? A(nother) recent Opinion from the CJEU is making waves this year, and today we discussed the case with Max Schrems, who has tweeted ferociously about it over the past weeks.

    The recent Opinion coming out of the Court of Justice of the European Union regards:

    • Non-material damage resulting from unlawful processing of data
    • Conditions for the right to compensation
    • Damage above a certain threshold of seriousness

    But does it actually clarify on (any of) these areas? 🤔 We're not sure!

    👉 Listen in and join the discussion on LinkedIn.

    Links and resources:

    Overdue diligence

    15 Nov

    Are you diligent in your due diligence? 🧐 And how diligent should you (not) be? Listen in as we discuss what to think about not only before you appoint processors – but also after.

    👉 How do you vet and audit your processors? Join the discussion on LinkedIn.

    Accountability zucks

    13 Dec

    From Twelve Days of Christmas to Twelve Days of Breaches – although this decision is rather short compared to the other ones. 😉

    👉 If you've also geeked through one or more of these decisions, what's your take-away? Join the discussion on LinkedIn.

    Links and resources:

    • (spoiler alert!) Link to the press release and full decision
    • Legislative mistakes in the GDPR by Jeroen Terstegge on LinkedIn

    Grumpy Christmas! (And a Grumpy New Year!)

    27 Dec

    Listen in to this recap of all episodes from this year. And thank you, dear listener, for spending your valuable time on our banter and grumpy discussions. We truly appreciate your support and feedback. 🙏 Best wishes from Miloš & Rie!

    👉 Have we been too grumpy, or just not grumpy enough, so far in our podcast journey? Join the discussion on LinkedIn.

    Links and resources: