Let's Talk Privacy

Aakash Suri

“Let’s Talk Privacy” isn’t just another GDPR or data protection podcast, it’s a fresh, lively, and truly accessible conversation led by the uniquely engaging hosting style of Aakash Suri. No legal jargon, no gatekeeping, and definitely no need for a law degree. Each episode breaks down privacy concepts in simple, relatable language while exploring how everyday choices shape our fundamental digital rights. Aakash speaks with professionals at all levels and business leaders across sectors to uncover how they really implement GDPR—sharing honest lessons, practical wins, and SMART, actionable takeaways. Designed to inspire the next generation of privacy pros, the show encourages young people to see privacy as a meaningful, future-shaping career. And with AI reshaping the world, we dive into how privacy underpins safe, ethical, and compliant AI use. Expect clarity, authenticity, and conversations that make privacy matter to everyone.

  1. Bitesize AI Briefings: Why Mythos Changes the Privacy Governance Game

    5H AGO

    Bitesize AI Briefings: Why Mythos Changes the Privacy Governance Game

    Imagine a tool so capable at finding software vulnerabilities that its own creators are hesitant to release it. We’re looking at Mythos, the latest frontier model from Anthropik that has the tech world divided between genuine fear and intense curiosity. While the "hacker's dream" headlines make for great clicks, the reality for privacy and security professionals is much more complex. This briefing cuts through the noise to explore why a model's ability to chain exploits and reason through code changes the balance of power in cyber security. We move past the panic to discuss the essential governance questions: Who gets access? What happens when a model does its job too well?. It’s time to stop viewing AI risk as theoretical and start preparing for a future where the battlefield is human plus AI versus human plus AI. Key Takeaways Capabilities over Hype: Mythos represents a shift toward advanced reasoning and serious cyber security capabilities rather than just simple text generation. The Access Dilemma: Anthropik has restricted access to Mythos due to concerns that its power could be misused in a security context. Privacy and Cyber are Linked: Any model that simplifies finding vulnerabilities creates a direct risk of data breaches and privacy loss. Avoid the Binary Reaction: The danger lies in either overreacting with panic or underreacting by assuming developers have handled all safeguards. New Governance Standards: Businesses must implement strict access controls, red teaming, and human oversight to manage high-capability models. Quotes "The big story here is that Anthropik's latest model appears to be extremely capable at cyber security style tasks." "We are no longer just asking, can the model do the job? We are now asking, can it do the job too well?" "If a model helps attackers find vulnerabilities faster, that can lead to breaches, data loss, and a whole chain of privacy consequences." "The future of cyber is not just human versus human. It's human plus AI versus human plus AI." "If a model is powerful enough to be called a hacker's dream, then it's powerful enough to need serious guardrails." TO CONNECT WITH YOUR HOST: ⁠https://www.linkedin.com/in/aakashsuri-thoughtleader/⁠  ⁠https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/⁠ ⁠Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos⁠ ⁠https://www.tiktok.com/@letstalkprivacypodcast⁠ HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. ⁠https://disruptivemedia.co.uk⁠/

    7 min
  2. How Privacy and AI Governance Work at Scale in Public Service Media with Marissa Valerio

    5D AGO

    How Privacy and AI Governance Work at Scale in Public Service Media with Marissa Valerio

    In this episode, Aakash sits down with Marissa Valerio, a senior data privacy lawyer with extensive experience across UK, EU, and global privacy law. Together, they dive into the realities of translating complex legal requirements into actionable strategies that tech and business teams can actually use. Marissa shares her insights on moving privacy away from a dreaded "tick-box compliance" exercise and repositioning it as a strategic business enabler.  KEY TAKEAWAYS Speak the Business's Language: To get buy-in from senior leadership, privacy professionals must translate complex legal concepts into clear, risk-based language that aligns with what the stakeholders are actually trying to achieve. Privacy is About Human Rights: Effective data protection goes beyond strict academic compliance; it fundamentally requires protecting the rights, freedoms, and psychological well-being of the individuals behind the data. Reposition Privacy as an Enabler: The privacy function must shed its reputation as the "Department of No." By adopting a pragmatic, risk-based approach, privacy teams can help businesses innovate safely and responsibly. AI Requires Case-by-Case Governance: There is no blanket approach to AI compliance. Organizations must establish clear internal policies to manage how the business uses data within AI tools, and just as importantly, how those AI tools use the business's data. Embrace the Unknown in Your Career: Taking calculated risks like moving across the world to restart a career can be daunting, but stepping out of your comfort zone is often the catalyst for the greatest professional and personal growth. BEST MOMENTS "The way we speak... to a DPO about privacy is not the same way you would speak to a systems engineer or to a contract manager."  "It's important to remember that we are talking about human rights and about human beings and their rights and their freedoms... you can't be too rigid or too academical about it either."  "We should move away from that and just think about privacy as an enabler. I like to use that phrase when I deliver training."  "You can't have a blanket approach for deploying AI. All AI initiatives should be looked at on a case-by-case basis."  "The human has to be in the loop in the end. You can't just take the human out."  TO CONNECT WITH MARISSA linkedin.com/in/marissa-valerio-llm-1909b5119 TO CONNECT WITH YOUR HOST https://www.linkedin.com/in/aakashsuri-thoughtleader/  Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/posts/?feedView=all  https://www.tiktok.com/@letstalkprivacypodcast HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/

    40 min
  3. Bitesize AI Briefings: Shadow AI is quietly running in the background of your business

    APR 24

    Bitesize AI Briefings: Shadow AI is quietly running in the background of your business

    In this bite-sized episode, Aakash tackles the growing and often invisible threat of Shadow AI, the unauthorized use of artificial intelligence tools within an organization. Aakash explains how AI quietly creeps into daily operations, from developers plugging in unapproved APIs to employees carelessly pasting sensitive data into generative AI tools.  KEY TAKEAWAYS Assume it's already there: Don't wait for a formal, company-wide AI project launch to start caring about governance. Shadow AI is very likely already operating in the background of your day-to-day business operations. Go beyond self-reporting: You cannot rely entirely on employees to disclose their AI use. Organizations need true visibility, which means checking vendor contracts, procurement records, and software usage logs to see what's actually running. Audit existing, approved software: Shadow AI often sneaks in through the back door when trusted SaaS platforms, browser extensions, and productivity tools quietly roll out new generative AI features. BEST MOMENTS "AI is already there, quietly running in the background. And that's exactly what we're talking about in today's bite-size episode: Shadow AI." "If people are pasting customer data, employee data, confidential documents, or internal plans into unapproved AI tools, you've got a serious risk on your hands." "A lot of organizations still think Shadow AI only exists if someone formally launches a big AI project. But that's not how it usually shows up." TO CONNECT WITH YOUR HOST https://www.linkedin.com/in/aakashsuri-thoughtleader/  Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos https://www.tiktok.com/@letstalkprivacypodcast https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/posts/?feedView=all  HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/

    9 min
  4. DPDP in Practice: Privacy by Design, Cloud Resilience, and Real-World Data Protection with Anuuj Medirattaa

    APR 17

    DPDP in Practice: Privacy by Design, Cloud Resilience, and Real-World Data Protection with Anuuj Medirattaa

    FREE GIVEAWAY Following is the link for the Podcast listeners: https://bit.ly/4vaXnhw. Here are the details about the books: In this episode, Aakash sits down with Anuuj Medirattaa, Founder and CTO of Ace Data Devices, to unpack the practical realities of data privacy and protection. They discuss the critical shift in mindset required to view privacy not as a strict legal hurdle, but as a genuine business optimization opportunity. Anuuj brings his extensive background in cloud backup, disaster recovery, and ransomware readiness to the conversation, explaining how organizations must prioritize understanding their data inventory before getting bogged down in policy paperwork.  KEY TAKEAWAYS Privacy is Business Optimization: Rather than treating data privacy purely as a terrifying legal or compliance issue, organizations should view it as a structural behavioral change that optimizes how personal data is handled and secured. Start with a Data Baseline: Before rushing to create complex privacy policies and notices, businesses must first audit their environment to understand exactly what personal data they possess, where it is stored, and who has access to it. Education Must Be Relatable: To successfully implement privacy principles across an entire company, training content needs to avoid dense legal jargon and be tailored specifically to the daily tasks of the audience, whether they are in sales, human resources, or IT. Backup and Retention Go Hand-in-Hand: While disaster recovery and robust backups are essential for ransomware protection, organizations must balance this with strict data retention policies to ensure they are safely purging old data that is no longer needed. Embrace Risk to Keep Growing: Deciding that you know everything about a topic is the exact moment you stop growing; continuous learning, taking calculated risks, and adapting to new regulations are vital for navigating the evolving data privacy landscape. BEST MOMENTS "I actually feel privacy is a business optimization issue, not a legal issue. In India, when we talk of a law, we get scared that we might have to file returns, we might have to deposit some taxes... No, privacy is not that." "Start step-by-step from the rock bottom and you will quickly achieve the top rather than getting scared and looking at the top and making documents." "The hardest audience is the people who believe they know everything. I don't know everything. I am still learning whatever is coming." "The moment we say 'I am perfect in this', it means I have decided that I don't want to grow." "Can I just run away by saying DPDP applies only to digital data? Yes, that way it is fine, but that misuse, if it is known that that happened with my team member, then my reputation, my team's reputation, and my organization's reputation... they are all at stake." TO CONNECT WITH ANUUJ www.linkedin.com/in/anuujmedirattaa TO CONNECT WITH YOUR HOST https://www.linkedin.com/in/aakashsuri-thoughtleader/  Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos https://www.tiktok.com/@letstalkprivacypodcast https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/posts/?feedView=all  HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/   Data Privacy, SimplifiedA practical introduction to data privacy designed for real-world understanding.This book focuses on simplifying core privacy concepts and explaining how they apply inside organisations — beyond legal definitions and theory.It is ideal for professionals, founders, and teams who want to understand privacy in a clear, structured, and usable way, and begin applying it in day-to-day decisions.Data Privacy Simplified: DPDP in PracticeA practical interpretation of India’s Digital Personal Data Protection framework, focused on how organisations can apply it in real scenarios.Instead of legal analysis, this book breaks down key concepts like consent, data handling, retention, and governance into an actionable understanding.While grounded in the Indian context, the insights are relevant for organisations globally looking to align privacy with everyday operations.

    41 min
  5. Gamechanger in AI: Claude & Cowork

    APR 14

    Gamechanger in AI: Claude & Cowork

    In this episode, Aakash dives into the evolving landscape of artificial intelligence, focusing on the shift from simple chatbots to sophisticated "working partners." The spotlight is on Claude and Co-work by Anthropic, exploring how these tools assist with complex tasks like drafting policies, analyzing data, and summarizing reports.  KEY TAKEAWAYS The Evolution of AI Utility: AI is transitioning from a "chat-based" tool used for short tasks to a collaborative assistant capable of supporting long-term, practical workflows. The Data Privacy Paradox: As AI becomes more integrated into daily business tasks, there is an increased risk of users inputting sensitive, confidential, or personal data without proper safeguards. The Necessity of Governance: To prevent "shadow use," organizations must establish clear rules, human review processes, and staff training rather than letting employees create their own unofficial workflows. BEST MOMENTS "Think of Claude as the prompt-based tool... on the other hand, think of Co-work as your actual assistant." "The danger is simple: people love tools that save time, so they start using them more and more... and then before long, they’re pasting in customer data, employee data, or internal strategy." "If your organization doesn’t have clear rules, people will make their own, and that is where the trouble begins." TO CONNECT WITH YOUR HOST https://www.linkedin.com/in/aakashsuri-thoughtleader/  Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos https://www.tiktok.com/@letstalkprivacypodcast linkedin.com/company/as-privacy-ai-solutions-ltd/ HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/

    9 min
  6. Data Armageddon and Trust: Luke Beckley on Fixing Governance Before It’s Too Late with

    APR 10

    Data Armageddon and Trust: Luke Beckley on Fixing Governance Before It’s Too Late with

    FREE GIVEAWAY Luke is giving away a full day of in-person training using the “What would you do game“. A 6-hour session will include breaks, and lunch will be very interactive in the afternoon. Aimed predominantly at senior management, but happy to undertake a group of 15 persons max.  HOW TO ENTER (ONLY 1 WINNER) ENTRIES CLOSE 3 DAYS AFTER THE RELEASE OF THE EPISODE! CONNECT WITH AAKASH SURI ON LINKEDIN AND DIRECT MESSAGE HIM OUTLINING WHY YOUR ORGANISATION SHOULD WIN THIS TRAINING? ALL ENTRIES WILL BE PUT IN A RANDOMISER TO DRAW OUT A WINNER AND RECIPIENT OF THIS TRAINING FOR THEIR ORGANISATION. ALSO FOLLOW THE INSTAGRAM AND TIK TOK PAGES OF THE LETS TALK PRIVACY PODCAST - LINKS BELOW: Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos https://www.tiktok.com/@letstalkprivacypodcast To Connect With Luke For data intelligence and protection LinkedIn: linkedin.com/in/luke-beckley Email: luke@dcharmonised.com For Adventure challenges to raise money for charities or undertake Team building and Leadership training Email: luke@unchartedsummits.world Website: www.unchartedsummits.world  In this episode, Aakash sits down with data governance expert Luke Beckley. With nearly three decades of experience, Luke dismantles the dangerous misconception that cybersecurity alone equals data protection. Together, they explore the pitfalls of tick-box compliance, the critical importance of continuous, human-led data training, and how mid-sized organizations can safely integrate AI tools without exposing sensitive information.  KEY TAKEAWAYS  Cybersecurity does not equal data protection: Building a digital fortress is useless if you don't understand what data you are storing, why you collected it, and whether you actually need to keep it. Training must go beyond the annual PowerPoint: Generic, once-a-year compliance presentations are ineffective. Organizations must implement consistent, targeted, and engaging human-led training to cultivate a genuine culture of privacy. "Tick-box" compliance creates false security: Merely having privacy policies on paper or purchasing security software is insufficient if those policies are not actively understood and practiced by the employees handling the data daily. Assess AI risks before deployment: With the rapid adoption of new AI tools, organizations must conduct Data Protection Impact Assessments to fully understand how data is being scraped, stored, and utilized by these platforms. Good governance builds business trust: Treating data protection as a core ethical responsibility rather than a regulatory burden builds consumer trust, ultimately turning a compliance necessity into a driver for business growth. BEST MOMENTS "It's almost like we'll just pour more money at security to protect the data and not worry about actually mitigating the risk in the first place." "If you lead with the human, the people in your organization, you will make better decisions around how you process that data, and your customers will see that." "We are in a desperate kind of, almost like a race to the bottom to see who can get AI in as quickly as possible... but we've not done the prep." "You've got to treat data protection as a driver for more business, as a driver for customer trust, as a driver for a more ethical-based organization." "When data is clean and trusted, people stop arguing about the numbers and start making better decisions." TO CONNECT WITH YOUR HOST https://www.linkedin.com/in/aakashsuri-thoughtleader/  HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/

    1h 3m
  7. Bitesize AI Briefings: Last Year, VIBE Coding Changed How the World Built

    APR 3

    Bitesize AI Briefings: Last Year, VIBE Coding Changed How the World Built

    In this bite-sized AI episode, Aakash Suri dives into the trendy new world of vibe coding. Vibe coding allows anyone to build software and applications simply by describing their ideas to an AI in plain English. While tools like Lovable, Replit, and Cursor are democratizing app development and drastically increasing speed, they also introduce significant privacy and security risks if left unchecked. KEY TAKEAWAYS Vibe coding lowers the barrier to entry: Anyone can now build software by using plain English prompts to tell an AI what they need. This empowers non-technical staff to create tools without waiting weeks for developers. Establish strict guardrails: Organizations need clear rules regarding who is authorized to use Vibe coding tools. This prevents the creation of unmonitored shadow IT systems right under your nose. Privacy must be proactive, not reactive: Incorporate privacy controls early in the vibe coding process. Do not wait until the end or after launch when the app has already grown legs and become business-critical. BEST MOMENTS "In the simplest possible terms, it means using AI to help you build software by describing what you want in plain English." "Instead of thinking, right, I need to build a database, connect an API, create a front end, fix the errors, you just simply say, build me a simple app to track my podcast guests, store notes, and remind me how to follow up. And the AI gets to work." "If people start building tools with real customer data, employee data, or sensitive business information without proper controls, then, in my opinion, you've got a massive issue." "You may not even know someone has built a shadow IT system right under your nose." "Bring privacy in early. Not at the end, not after launch, but early. Before the thing grows legs and becomes business-critical." TO CONNECT WITH YOUR HOST https://www.linkedin.com/in/aakashsuri-thoughtleader/  HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/

    8 min
  8. Are ISO 27001 Certificates Lying to You? Data Privacy, Red Flags, and Recent Deadlines with Jennifer Hirst

    MAR 27

    Are ISO 27001 Certificates Lying to You? Data Privacy, Red Flags, and Recent Deadlines with Jennifer Hirst

    FREE GIVEAWAY  Jennifer is offering a 1-hour extended discussion and review of your organisation's compliance with ISO standards. This could include discussion on: Is ISO certification worth it for you? Whether to get certified? How should we prepare for stage 1 or stage 2 audits before certification? How to improve your internal audits? What to do if your external audits keep finding non-conformances.  How to improve your ISO manual. ALSO, Free review of your certificate:  Please send Jennifer a copy of your certificate, and she will review it and let you know whether it covers what you are expecting.  If you are sending a copy of a third-party certificate, typically a supplier's, please ensure you can share it. We may need additional information, but we will request it once we have reviewed the certificate.  Certificate reviews are limited to three certificates per company requesting them. Please contact Jennifer here, linkedin.com/in/jennifer-hirst-44b3b5b7   In this episode, Aakash Suri sits down with Jennifer Hirst, a seasoned compliance and ISO consultant, to demystify the ISO 27001 certification. Moving beyond the idea that ISO is just an IT security badge, Jennifer explains how it serves as a structured framework for organizations of all sizes to implement best practices in data protection.  KEY TAKEAWAYS ISO 27001 is a Framework, Not Just a Label: It is a structured way of working that focuses on the confidentiality, integrity, and availability of data, regardless of company size. Regulatory Alignment is Embedded: ISO 27001 is not separate from laws like GDPR; it requires organizations to be aware of and integrate their legal and regulatory obligations into their security controls. The "Human Firewall" is Critical: Technical tools are insufficient without staff awareness. Training employees to recognize simple risks—like leaving a workstation unlocked or working on public transport—is vital to preventing breaches. Scope Matters in Certification: A major red flag is a certificate with a limited "scope" that excludes the specific departments or processes where sensitive data is actually handled. Continuous Improvement is Mandatory: Certification is not a one-time event. It requires regular internal audits, annual external assessments, and a full recertification every three years to adapt to new risks. BEST MOMENTS  "It's not a badge, it's a way of working. It's making sure that IT security... is there high on the agenda for that company." "While we all live in a very technical world... we don't. You just click on a link because it all looks so perfect." "A certificate on the wall means very little if people are still bypassing processes, hoarding data, or ignoring basic hygiene." "Top management needs to have the buy-in... if top management hasn't got the buy-in, you're never going to sustain it." "Just putting one question into AI uses the amount of water that a town might use in a day... It's a staggering amount." TO CONNECT WITH JENNIFER linkedin.com/in/jennifer-hirst-44b3b5b7  https://qualityexcellence.co.uk/  TO CONNECT WITH YOUR HOST https://www.linkedin.com/in/aakashsuri-thoughtleader/  HOST BIO Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance. This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/

    39 min

About

“Let’s Talk Privacy” isn’t just another GDPR or data protection podcast, it’s a fresh, lively, and truly accessible conversation led by the uniquely engaging hosting style of Aakash Suri. No legal jargon, no gatekeeping, and definitely no need for a law degree. Each episode breaks down privacy concepts in simple, relatable language while exploring how everyday choices shape our fundamental digital rights. Aakash speaks with professionals at all levels and business leaders across sectors to uncover how they really implement GDPR—sharing honest lessons, practical wins, and SMART, actionable takeaways. Designed to inspire the next generation of privacy pros, the show encourages young people to see privacy as a meaningful, future-shaping career. And with AI reshaping the world, we dive into how privacy underpins safe, ethical, and compliant AI use. Expect clarity, authenticity, and conversations that make privacy matter to everyone.