Skip to main content
Data protection officer

Data protection officer

Search complete. 50 mentions across 6 episodes found for "Data protection officer".

Oct 7, 2026

speaker_0HOST
3:24
If you're a UK director, there are five questions worth asking this week.
speaker_0HOST
3:29
Which platforms can send customers a message in our name, and who holds the keys? Is access protected by phishing-resistant multi-factor authentication with keys that expire and can be revoked? Does an unusual send, such as new wording or a full list blast, need a second person to approve it? Can we shut every channel off within minutes, and have we practiced it? And who tells the DPO, the board, and the ICO, and when does the seventy-two-hour UK GDPR clock start? None of this is expensive.
speaker_0HOST
4:04
A second approver adds minutes to a campaign.
speaker_0HOST
4:07
Key rotation is a calendar entry.
Darren HamptonGUEST
6:15
And I, I, I think that's where we work.
Darren HamptonGUEST
6:18
The, the value we add as DPO, as a service, as consultants into businesses, is that we, we give them that visibility into what other peer organizations do.
TashHOST
6:28
Mm.
TashHOST
6:28
Yeah.
TashHOST
8:03
I've been in exactly the same situation this week.
TashHOST
8:05
ICBs, um, where half of our ICBs say we're a processor, the other half say we're not, and yet they are all determining what data we collect, why we collect it.
TashHOST
8:19
And I'm, you know, we're just at, at a bit of a loss because when you've got one DPO saying, "No, you're definitely a controller." I'm like, "Great.
TashHOST
8:25
Does that mean we can take all this patient data you've just given us and go and do what we like with it?"
Debbie ReynoldsHOST
1:12
So I thought you'd be a really great person to talk to, especially because of your role.
Debbie ReynoldsHOST
1:19
Like, you do DPO work and a couple of other things that we can get into.
Debbie ReynoldsHOST
1:24
But tell me a little bit about yourself, your interest in data protection and privacy, and h- uh, how you decided to start your own company.
Julian GageGUEST
1:32
Yeah, happy to.
Julian GageGUEST
1:52
But y- in terms of my, my general interests, first off, within the privacy space, I started my own company here five years ago.
Julian GageGUEST
1:59
It's been really interesting to build this up from scratch, doing some freelance work initially.
Julian GageGUEST
2:04
I'm now moving into DPO services, Article 27 representative services, EU AI Act, especially over the last year, work too.
Julian GageGUEST
2:14
And yeah, it's been very interesting just to build this from the ground up, especially in the last year.
Tash WhittakerHOST
12:23
That's the big things, isn't it? It's the little things, some of the case law coming out.
Tash WhittakerHOST
12:27
There was something that came out, I can't remember where I saw this, in Belgium possibly, where the DPO should not be signing off a SAR from the DPO.
Tash WhittakerHOST
12:41
It must come from the data protection team, not the DPO themselves.
Tash WhittakerHOST
12:45
And just all this stuff, and I'm just like, oh my God, it's constant.
Simon PillingerHOST
12:49
And it's, it's difficult with the European law, particularly because there are some bits, I think that's a really good example where there is actually, that's partly because of the way the Belgium law works, or at least how their data protection act equivalents works in.
Tash WhittakerHOST
14:09
but you know I do sort of envy your position a little bit Claire where you are education and you can get really into the education stuff what I don't envy is the number of education laws
Claire ArchibaldGUEST
14:19
and guidance and everything else that you have to deal with.
Claire ArchibaldGUEST
14:22
I think before I came into Brown Jacobson I thought I was just a DPO I was quite arrogant about what I thought I knew about education law and came and thought oh heck I knew nothing I think my and i hadn't realized just how interspersed to say exclusions law and data protection or or admissions law and these tiny little nuances and that's what's great about working in that team who are specialists i don't know in academy transfers or exclusions admissions is they know those little nuances and the right time to ask for information for instance um So, again, I think being really immersed in it's really, really useful.
Sergio MaldonadoHOST
1:18
Please do reach out if you have any ideas on future topics or speakers.
Sergio MaldonadoHOST
1:33
Okay, today we're going to revisit DPIAs or Data Protection Impact Assessments in the context of the GDPR with Julian Hache, who is a fractional DPO based in the Netherlands and the founder of Engage Compliance.
Sergio MaldonadoHOST
1:48
Julian has acted as an external DPO and Article 27 GDPR representative for over 100 companies, including Coinbase and Robinhood, as well as plenty of startups.
Sergio MaldonadoHOST
2:01
Before we start, a couple of things to keep you posted on the progress of the toolbox that remains open to all of you.
Sergio MaldonadoHOST
2:07
If, like Julian, you're working as a DPO or as a lawyer and you struggle producing relevant DPIAs or Privacy Impact Assessments that check all the boxes across multiple legal frameworks beyond the GDPR, like CCPA, CDPA and so on, you have a DPIA builder in DPO Central.
Sergio MaldonadoHOST
2:27
which is entirely rules-based and not LLM-driven, and you'll find the link here in our show notes.
Sergio MaldonadoHOST
2:33
It's free as well.
Julian GageGUEST
2:35
If,
Aakash SuriHOST
2:18
With me, your host, Akash Suri, privacy and AI thought leader.
Aakash SuriHOST
2:23
My returning guest today is a former data protection officer for the Labour Party and founder and CEO of Datum Longevitys.
Aakash SuriHOST
2:33
When he joined me previously, we explored life inside a political DPO role.
Aakash SuriHOST
2:38
Since our last conversation, he's attended two fascinating conferences, one involving Sir Tim Berners-Lee and another focused on the International Population Data Linkage Network.
Aakash SuriHOST
2:50
Today, we're going to explore what he learned from those events, what they tell us about the future of privacy and data governance, and what it really takes to become a confident, credible and effective data protection officer.
James RobsonGUEST
4:10
Maybe they're within research, they're within charities, they want to do something with data, but they don't necessarily have the resources to be able to do it, to get the insights, to get the analytics, to be able to make choices on that data because they think privacy legislation says no. We're the department of no to a lot of people.
James RobsonGUEST
4:31
But really, it comes down to a lot of it.
James RobsonGUEST
4:34
Some of the really great DPOs, you

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.