The Privacy Partnership Podcast with Robert Bateman

treborjnametab1

Robert Bateman provides the latest on data protection and privacy, with regular solo news updates and short-form interviews. Brought to you by Privacy Partnership: www.privacypartnership.com

  1. 3d ago

    New EDPB guidance: When to issue a GDPR fine

    How does a data protection regulator decide whether to hand down a multi-million euro fine or issue a simple reprimand? In this episode, Robert Bateman breaks down the European Data Protection Board’s (EDPB) newly published draft Guidelines 04/2026. Adopted for public consultation on 17 September 2026, these guidelines replace the 2017 Article 29 Working Party guidance and aim to heavily harmonise the enforcement playbook across Europe. We explore how the EDPB has baked recent CJEU case law directly into a new, five-step methodology that regulators will use to determine the appropriate corrective measure for GDPR infringements. Whether you are a controller, processor, or DPO, this episode is essential listening for understanding your organisation's true liability surface. Key Topics Covered: The New 5-Step Methodology: A comprehensive walkthrough of the EDPB’s structured test for imposing administrative fines. Closing the Article 24 Loophole (Step 1): Why certain obligations missing from Article 83 won't give you a free pass, and how regulators use the Article 5(2) accountability principle. Direct Corporate Liability (Step 2): Why management doesn't need to know about a violation for the company to be liable, and why blaming a "rogue employee" might still leave you on the hook under Article 32. The "Unwritten" Rule of Culpability (Step 3): How recent CJEU judgments have established intent or negligence as a prerequisite for fines, why the bar for "negligence" is remarkably low, and why blindly trusting external legal advice won't save you. Defining a "Minor" Infringement (Step 4): Understanding when an infringement warrants a reprimand instead of a fine, the danger of "repeated" minor infringements, and why having no previous infringements is not a mitigating factor. The Threat of Enforcement (Step 5): The balancing act of effectiveness, proportionality, and dissuasiveness, and why a penalty must present a credible prospect of actually being imposed. Cases and Resources Mentioned: EDPB Draft Guidelines 04/2026 on the application of the power to impose administrative fines (Adopted for public consultation, 17 September 2026) EDPB Guidelines 04/2022 on the calculation of administrative fines CJEU Case: Deutsche Wohnen (C‑807/21) CJEU Case: Nacionalinis visuomenės sveikatos centras (C‑683/21)

  2. Sep 15

    Are Meta Ray-Bans legal under the GDPR? A roundup of regulatory positions

    In this episode of the Privacy Partnership Podcast, Robert Bateman looks at the mounting regulatory scrutiny and public backlash across Europe regarding Meta’s Ray-Ban smart glasses. Is data protection law actually equipped to handle a world where consumers wear data-scraping AI devices on their faces? From striking guerrilla protest ads on the London Underground to a 55-page technical and legal teardown by the Hamburg Data Protection Authority, Robert breaks down the current legal landscape. He explores Hamburg's argument that ordinary users could be considered "joint controllers" with Meta, the practical nightmare of Article 26 compliance, and why Norway's data protection leadership is questioning if the GDPR is fit for purpose when it comes to consumer AI hardware. Key Takeaways: Introduction: Public backlash and guerrilla ads on the London transport network. The Hamburg DPA Report: A look at the 55-page teardown of the Gen 1 Wayfarers published on 10 September 2026. The Household Exemption: When does private use cross the line into commercial processing? The Joint Controller Problem: Why capturing and transmitting third-party data to train Meta's AI could theoretically make you a joint controller—and the glaring absence of an Article 26 arrangement. Transparency and Notice: Why a tiny LED light isn't a privacy notice. Could commercial wearers really be expected to wear high-vis warning vests? The European Landscape: How Luxembourg's CNPD and Sweden's IMY are attempting to map existing CCTV and filming rules onto new behaviours. A Call for New Rules? Norway’s Datatilsynet leadership questions the feasibility of policing thousands of private individuals and suggests we look at product requirements and sale restrictions instead.

  3. Sep 8

    Grindr settles for £26 million... But wait, what about Lloyd v Google?

    In this episode of the Privacy Partnership Podcast, Robert Bateman unpacks Grindr's recent agreement to pay £26 million to settle a major UK data privacy lawsuit. The UK is currently viewed as a highly conservative, even hostile, environment for mass privacy claims. So how did a payout of this magnitude happen? Robert breaks down the historical data sharing allegations, the regulatory backdrop, and the critical procedural differences that set this actively managed group litigation apart from recent representative action failures. Key Topics Discussed The £26 Million Settlement: An overview of Grindr’s agreement to settle UK High Court proceedings brought by approximately 12,000 users. The claims concerned pre-2020 data practices (under former owner Kunlun) and included allegations of the unauthorised sharing of highly sensitive information, such as HIV status and testing dates. Grindr's Position: Grindr disputes the allegations, and the settlement includes no findings or admission of liability. The company says it has overhauled its privacy programme since 2020 and agreed to pay the £26 million in two installments by March 2027. The Regulatory Backdrop: A look back at how regulators have previously handled Grindr’s adtech practices, including a 2022 reprimand from the UK’s ICO and a 65 million NOK fine from Norway’s Datatilsynet (upheld on appeal in October 2025). The UK Litigation Landscape: Why the UK is currently a tough jurisdiction for mass privacy claims. Robert explores how the landmark Lloyd v Google Supreme Court decision blocked uniform damages for "loss of control" under the Data Protection Act 1998 without proving individual damage or distress. Why This Case is Different: Why didn't this claim fail like the representative action involving sensitive medical records in Prismall v Google? We discuss how claimant firm Austen Hays gathered 12,000 signed-up individuals to bring specific allegations of distress, and why the immense cost and complexity of defending a bifurcated trial likely drove a pragmatic settlement. Cases & Regulatory Actions Mentioned Grindr High Court Settlement (Sept 2026): £26 million settlement for UK users represented by Austen Hays. Lloyd v Google (2021): Supreme Court ruling effectively blocking opt-out representative actions for uniform data protection damages under the DPA 1998. Farley v Paymaster (Aug 2025): Court of Appeal ruling establishing that claims for compensation based on a fear of third-party misuse must be "well-founded" and assessed case-by-case. (The Supreme Court appeal is listed for 7-8 October 2026). Prismall v Google: High Court case demonstrating that representative actions involving even highly sensitive data (medical records) will fail if they attempt to bypass individual assessments. Datatilsynet vs. Grindr (2021/2025): 65 million NOK fine for unlawful behavioural advertising disclosures, upheld by the Borgarting Court of Appeal. ICO Reprimand (July 2022): UK regulator's finding against Grindr regarding transparent privacy information. Get in Touch If your organisation needs support navigating adtech compliance, data protection litigation, or evaluating its financial exposure, reach out to us at Privacy Partnership.

  4. Sep 2

    Summer Special: Privacy action you might have missed

    n this late-summer roundup episode of the Privacy Partnership Podcast, host Robert Bateman unpacks a massive €825 million GDPR fine, the immediate impact of the EU AI Act taking effect, and a wave of enforcement actions across the UK, Europe, and the United States. In this episode, we cover: Mind the Gap (UK ICO Enforcement): Why the disconnect between an organisation's written privacy policies and its actual practices is a major regulatory red flag. Robert discusses recent reprimands for the Metropolitan Police Service and ACRO Criminal Records Office, highlighting the dangers of ignored mandatory training, unpatched software, and inadequate logging. Automated Decision-Making Under Fire: A deep dive into the Dutch DPA's record-breaking €825 million fine against Uber for automatically deactivating drivers' accounts without human review. Plus, we look at similar Article 22 enforcement actions by the Italian Garante against energy suppliers, and noyb's data retention challenge against SCHUFA. The EU AI Act Meets the GDPR: The AI Act reached its general application date in August. We break down the immediate impact of Article 50's transparency rules for generative AI and deepfakes. Furthermore, a recent Italian Garante ruling on satirical deepfakes of a journalist serves as a stark reminder that complying with the AI Act does not mean you can ignore the GDPR. US Privacy Updates: A quick-fire roundup of major transatlantic developments, including California's regulatory action against unregistered data brokers, New Jersey's new Kids Code Act, the FTC's consultation on the privacy implications of personalised pricing, and TikTok’s massive $400 million children's privacy settlement with the DOJ. Resources & Links Links to all the regulatory decisions, enforcement notices, and legislation discussed in this episode are available in the September Privacy Partnership newsletter, delivered directly to our clients.

  5. Aug 6

    Is TikTok a patron of the arts? How an appeal under the "special purposes" exemption failed

    In this episode of the Privacy Partnership Podcast, Robert Bateman dives into a fascinating and highly creative legal defense recently mounted by TikTok. Facing a £12.7 million fine from the UK Information Commissioner's Office (ICO) for processing the data of underage children, TikTok attempted to use a jurisdictional trump card: the "special purposes" exemption under Section 156 of the Data Protection Act 2018. Did TikTok’s recommender algorithm process user data for "artistic purposes"? Should the platform be shielded by freedom of expression laws? And how did a philosophy professor from Oxford end up testifying at a data protection tribunal? Robert breaks down the Upper Tribunal's July 2026 ruling, explaining why tech platforms can't retrofit a fundamental rights defense onto an engagement-driven algorithm. Key Topics Covered: The £12.7m Penalty: The background of the ICO's enforcement action against TikTok for age-gating failures and processing the data of under-13s without parental consent. The "Special Purposes" Exemption: A look at Section 156 of the DPA 2018, which provides procedural safeguards (including court approval) before a regulator can penalize processing done for journalistic, academic, literary, or artistic purposes. The "What is Art?" Debate: TikTok's argument that its platform facilitates artistic expression, and why the Upper Tribunal decided to sidestep the philosophical debate entirely. Algorithm vs. Intent: Why the Upper Tribunal ruled that an engagement-driven recommender system—which is completely indifferent to whether a video is actually "art"—cannot be said to be processing data for an artistic purpose. The Underage Contradiction: The fatal flaw in TikTok claiming to facilitate the artistic expression of under-13s while simultaneously banning them in their own Terms of Service. Articles 12 & 13 as Procedural Obligations: Why the Tribunal rejected TikTok’s attempt to classify transparency and privacy notice failings as "processing" breaches.

  6. Jul 29

    Web scraping under the GDPR: The EDPB's uncharacteristically pragmatic solution

    Can you scrape the internet for AI training data without completely running afoul of the GDPR? The European Data Protection Board (EDPB) has finally offered an answer: Yes, but get ready to implement a massive amount of filtering. In this episode of the Privacy Partnership Podcast, Robert Bateman breaks down the EDPB’s newly adopted Draft Guidelines 03/2026 on web scraping for generative AI. Robert begins by exploring the political context behind this unexpectedly pragmatic guidance, discussing how the EDPB is effectively front-running the European Commission’s upcoming "Digital Omnibus" proposal to cement its authority over how privacy law applies to AI development. Then, Robert walks listeners through a practical, 10-point checklist for developers and privacy teams trying to navigate this regulatory minefield, from mapping out complex controllership arrangements to leveraging a fascinating loophole for the "incidental and residual" scraping of sensitive, special category data. Key Topics Discussed: The Digital Omnibus Context: Why the EDPB’s new guidance is "deceptively permissive" and how it serves as a strategic maneuver to preempt upcoming EU legislation. Controllership in the AI Supply Chain: How to define your role—whether you are dictating instructions to a scraper, co-determining collection criteria, or buying a pre-scraped dataset. Establishing a Lawful Basis: Why consent is a non-starter at this scale, how to lean on Legitimate Interests, and why a missing "robots.txt" file does not equal a green light. Designing the Collection: The end of indiscriminate web hoovering, the importance of data minimisation, and respecting technical barriers (like CAPTCHAs and ai.txt). Transparency at Scale: How to utilize the Article 14 "disproportionate effort" exception while maintaining a highly detailed, searchable public scraping notice. Cleaning and Accuracy: Applying syntax-based filters to weed out format-identifiable data on the fly, and utilizing synthetic data where feasible. The Article 9 Workaround: How the EDPB is applying the 2019 GC & Others CJEU search engine ruling to allow the incidental scraping of special category data—and the rigorous output filters required to justify it. Accountability: The massive documentation burden required to prove your technical measures and filters remain effective against the evolving state of the art.

  7. Jul 21

    The EDPB's new anonymisation framework: 5 things you need to know

    This week, Robert Bateman breaks down the newly adopted EDPB Guidelines 02/2026 on Anonymisation. Dragging the ancient 2014 Working Party 29 framework into the age of generative AI and EU data spaces, these new rules are dense, highly technical, and will undoubtedly complicate your compliance programmes. Robert explores the new concept of "relative anonymity," explains the rebranded technical criteria, and discusses why making your data anonymous might actually trigger a 72-hour data breach notification down the line. In this episode, we cover: Relative Anonymity: What the EDPS v SRB case means for controllers, and how data can be anonymous to a recipient but still constitute personal data for the sender. The Assessment Gauntlet: Navigating the "contextual" vs. "simplified" approaches (and why the EDPB expects you to evaluate the capabilities of cybercriminals and foreign spies). The New Technical Criteria: A look at the replacement tests for anonymity: No Record Isolation, No Linkage, and No Inference. The AI Threat: How "membership inference" attacks against AI training data are raising the bar for the No Inference test. The Processing Trap: Why the sheer act of running an anonymisation algorithm is a processing activity requiring its own Article 6 (and potentially Article 9) legal basis. The Expiry Date on Anonymity: How a completely unrelated security incident on the other side of the internet can instantly turn your anonymous dataset back into personal data.

About

Robert Bateman provides the latest on data protection and privacy, with regular solo news updates and short-form interviews. Brought to you by Privacy Partnership: www.privacypartnership.com

You Might Also Like