
Data protection officer
50
MENTIONS
6
EPISODES
5
PODCASTS
Search complete. 50 mentions across 6 episodes found for "Data protection officer".
Oct 7, 2026
ASOS's own app became the ransom note: who can speak in your name?
S
3:24speaker_0HOST
If you're a UK director, there are five questions worth asking this week.
S
3:29speaker_0HOST
Which platforms can send customers a message in our name, and who holds the keys? Is access protected by phishing-resistant multi-factor authentication with keys that expire and can be revoked? Does an unusual send, such as new wording or a full list blast, need a second person to approve it? Can we shut every channel off within minutes, and have we practiced it? And who tells the DPO, the board, and the ICO, and when does the seventy-two-hour UK GDPR clock start? None of this is expensive.
S
4:04speaker_0HOST
A second approver adds minutes to a campaign.
S
4:07speaker_0HOST
Key rotation is a calendar entry.
Episode 18 - "You're Absolutely Right, Simon"
D
6:15Darren HamptonGUEST
And I, I, I think that's where we work.
D
6:18Darren HamptonGUEST
The, the value we add as DPO, as a service, as consultants into businesses, is that we, we give them that visibility into what other peer organizations do.
T
6:28TashHOST
Mm.
T
6:28TashHOST
Yeah.
T
8:03TashHOST
I've been in exactly the same situation this week.
T
8:05TashHOST
ICBs, um, where half of our ICBs say we're a processor, the other half say we're not, and yet they are all determining what data we collect, why we collect it.
T
8:19TashHOST
And I'm, you know, we're just at, at a bit of a loss because when you've got one DPO saying, "No, you're definitely a controller." I'm like, "Great.
T
8:25TashHOST
Does that mean we can take all this patient data you've just given us and go and do what we like with it?"
The Data Diva E309 - Julian Gage and Debbie Reynolds
D
1:12Debbie ReynoldsHOST
So I thought you'd be a really great person to talk to, especially because of your role.
D
1:19Debbie ReynoldsHOST
Like, you do DPO work and a couple of other things that we can get into.
D
1:24Debbie ReynoldsHOST
But tell me a little bit about yourself, your interest in data protection and privacy, and h- uh, how you decided to start your own company.
J
1:32Julian GageGUEST
Yeah, happy to.
J
1:52Julian GageGUEST
But y- in terms of my, my general interests, first off, within the privacy space, I started my own company here five years ago.
J
1:59Julian GageGUEST
It's been really interesting to build this up from scratch, doing some freelance work initially.
J
2:04Julian GageGUEST
I'm now moving into DPO services, Article 27 representative services, EU AI Act, especially over the last year, work too.
J
2:14Julian GageGUEST
And yeah, it's been very interesting just to build this from the ground up, especially in the last year.
Episode 16 - Masterclass
T
12:23Tash WhittakerHOST
That's the big things, isn't it? It's the little things, some of the case law coming out.
T
12:27Tash WhittakerHOST
There was something that came out, I can't remember where I saw this, in Belgium possibly, where the DPO should not be signing off a SAR from the DPO.
T
12:41Tash WhittakerHOST
It must come from the data protection team, not the DPO themselves.
T
12:45Tash WhittakerHOST
And just all this stuff, and I'm just like, oh my God, it's constant.
S
12:49Simon PillingerHOST
And it's, it's difficult with the European law, particularly because there are some bits, I think that's a really good example where there is actually, that's partly because of the way the Belgium law works, or at least how their data protection act equivalents works in.
T
14:09Tash WhittakerHOST
but you know I do sort of envy your position a little bit Claire where you are education and you can get really into the education stuff what I don't envy is the number of education laws
C
14:19Claire ArchibaldGUEST
and guidance and everything else that you have to deal with.
C
14:22Claire ArchibaldGUEST
I think before I came into Brown Jacobson I thought I was just a DPO I was quite arrogant about what I thought I knew about education law and came and thought oh heck I knew nothing I think my and i hadn't realized just how interspersed to say exclusions law and data protection or or admissions law and these tiny little nuances and that's what's great about working in that team who are specialists i don't know in academy transfers or exclusions admissions is they know those little nuances and the right time to ask for information for instance um So, again, I think being really immersed in it's really, really useful.
Julian Gage: the evolving shape and role of DPIAs
S
1:18Sergio MaldonadoHOST
Please do reach out if you have any ideas on future topics or speakers.
S
1:33Sergio MaldonadoHOST
Okay, today we're going to revisit DPIAs or Data Protection Impact Assessments in the context of the GDPR with Julian Hache, who is a fractional DPO based in the Netherlands and the founder of Engage Compliance.
S
1:48Sergio MaldonadoHOST
Julian has acted as an external DPO and Article 27 GDPR representative for over 100 companies, including Coinbase and Robinhood, as well as plenty of startups.
S
2:01Sergio MaldonadoHOST
Before we start, a couple of things to keep you posted on the progress of the toolbox that remains open to all of you.
S
2:07Sergio MaldonadoHOST
If, like Julian, you're working as a DPO or as a lawyer and you struggle producing relevant DPIAs or Privacy Impact Assessments that check all the boxes across multiple legal frameworks beyond the GDPR, like CCPA, CDPA and so on, you have a DPIA builder in DPO Central.
S
2:27Sergio MaldonadoHOST
which is entirely rules-based and not LLM-driven, and you'll find the link here in our show notes.
S
2:33Sergio MaldonadoHOST
It's free as well.
J
2:35Julian GageGUEST
If,
Data Sovereignty, Population Linkage, and DPO Leadership with James Robson
A
2:18Aakash SuriHOST
With me, your host, Akash Suri, privacy and AI thought leader.
A
2:23Aakash SuriHOST
My returning guest today is a former data protection officer for the Labour Party and founder and CEO of Datum Longevitys.
A
2:33Aakash SuriHOST
When he joined me previously, we explored life inside a political DPO role.
A
2:38Aakash SuriHOST
Since our last conversation, he's attended two fascinating conferences, one involving Sir Tim Berners-Lee and another focused on the International Population Data Linkage Network.
A
2:50Aakash SuriHOST
Today, we're going to explore what he learned from those events, what they tell us about the future of privacy and data governance, and what it really takes to become a confident, credible and effective data protection officer.
J
4:10James RobsonGUEST
Maybe they're within research, they're within charities, they want to do something with data, but they don't necessarily have the resources to be able to do it, to get the insights, to get the analytics, to be able to make choices on that data because they think privacy legislation says no. We're the department of no to a lot of people.
J
4:31James RobsonGUEST
But really, it comes down to a lot of it.
J
4:34James RobsonGUEST
Some of the really great DPOs, you