<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <atom:link href="https://feeds.megaphone.fm/ACS9927107381" rel="self" type="application/rss+xml"/>
    <title>Life with GDPR</title>
    <link>https://compliancepodcastnetwork.net</link>
    <language>en</language>
    <copyright></copyright>
    <description>How does GDPR, data privacy, and data protection impact your business? 



In this podcast, Tom Fox, the Voice of Compliance, hosts Data Privacy/Data Security expert Jonathan Armstrong, co-founder of Cordery Compliance. They use the framework of GDPR to discuss a wide range of issues relating to data privacy and data protection. 



If you are a compliance professional, business leader, or InfoSec security expert, this is the podcast to learn about what is happening in the UK, EU, US, and beyond.</description>
    <image>
      <url>https://megaphone.imgix.net/podcasts/27fd5d8c-d617-11e8-a728-533c66bc2ca3/image/6580b638a96d1b2bad913b1249b04607.png?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress</url>
      <title>Life with GDPR</title>
      <link>https://compliancepodcastnetwork.net</link>
    </image>
    <itunes:explicit>no</itunes:explicit>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>What Compliance and InfoSec Experts need to know about GDPR</itunes:subtitle>
    <itunes:author>Tom Fox</itunes:author>
    <itunes:summary>How does GDPR, data privacy, and data protection impact your business? 



In this podcast, Tom Fox, the Voice of Compliance, hosts Data Privacy/Data Security expert Jonathan Armstrong, co-founder of Cordery Compliance. They use the framework of GDPR to discuss a wide range of issues relating to data privacy and data protection. 



If you are a compliance professional, business leader, or InfoSec security expert, this is the podcast to learn about what is happening in the UK, EU, US, and beyond.</itunes:summary>
    <content:encoded>
      <![CDATA[<p>How does GDPR, data privacy, and data protection impact your business? </p>
<p><br></p>
<p>In this podcast, Tom Fox, the Voice of Compliance, hosts Data Privacy/Data Security expert Jonathan Armstrong, co-founder of Cordery Compliance. They use the framework of GDPR to discuss a wide range of issues relating to data privacy and data protection. </p>
<p><br></p>
<p>If you are a compliance professional, business leader, or InfoSec security expert, this is the podcast to learn about what is happening in the UK, EU, US, and beyond.</p>]]>
    </content:encoded>
    <itunes:owner>
      <itunes:name>Tom Fox</itunes:name>
      <itunes:email>tfox@tfoxlaw.com</itunes:email>
    </itunes:owner>
    <itunes:image href="https://megaphone.imgix.net/podcasts/27fd5d8c-d617-11e8-a728-533c66bc2ca3/image/6580b638a96d1b2bad913b1249b04607.png?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
    <itunes:category text="Business">
      <itunes:category text="Management"/>
    </itunes:category>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <item>
      <title>A Compliance Roadmap for ADS/ADMT - Part 2: Understanding Opt-In and Opt-Out Requirements</title>
      <description>Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance &amp; risk management expert, with an extensive background in HR,  will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.

In this second episode, Tom Fox and Alyssa DeSimone review the opt-in and opt-out requirements introduced in the recent updates to the California Consumer Privacy Act (CCPA). They discuss what opting in and out entails, the concept of anti-retaliation in this context, and how disparate impact analysis can help regulators assess compliance. Additionally, they explore the importance of clear communication and training for HR departments on the use of AI in hiring, as well as the role of vendors in ensuring compliance. The episode wraps up with a discussion on the ambiguous term 'significant decision making' and its potential for litigation.

Key highlights:


  Understanding Opt-In and Opt-Out Requirements

  Anti-Retaliation Measures

  Disparate Impact Analysis

  Applicant Rights and Training

  Vendor Collaboration and Compliance

  Significant Decision Making


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Alyssa DeSimone


  LinkedIn

  Website


Life with GDPR was recently honored as a Top Data Security Podcast
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Tue, 14 Oct 2025 04:00:00 -0000</pubDate>
      <itunes:episodeType>bonus</itunes:episodeType>
      <itunes:episode>2</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/65ece980-a786-11f0-b20e-831a0dae0dae/image/29e358a74463e3b5fad887c816e2a50e.png?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In Part 2, we consider opt-in and opt-out. </itunes:subtitle>
      <itunes:summary>Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance &amp; risk management expert, with an extensive background in HR,  will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.

In this second episode, Tom Fox and Alyssa DeSimone review the opt-in and opt-out requirements introduced in the recent updates to the California Consumer Privacy Act (CCPA). They discuss what opting in and out entails, the concept of anti-retaliation in this context, and how disparate impact analysis can help regulators assess compliance. Additionally, they explore the importance of clear communication and training for HR departments on the use of AI in hiring, as well as the role of vendors in ensuring compliance. The episode wraps up with a discussion on the ambiguous term 'significant decision making' and its potential for litigation.

Key highlights:


  Understanding Opt-In and Opt-Out Requirements

  Anti-Retaliation Measures

  Disparate Impact Analysis

  Applicant Rights and Training

  Vendor Collaboration and Compliance

  Significant Decision Making


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Alyssa DeSimone


  LinkedIn

  Website


Life with GDPR was recently honored as a Top Data Security Podcast
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance &amp; risk management expert, with an extensive background in HR,  will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.</p>
<p>In this second episode, Tom Fox and Alyssa DeSimone review the opt-in and opt-out requirements introduced in the recent updates to the California Consumer Privacy Act (CCPA). They discuss what opting in and out entails, the concept of anti-retaliation in this context, and how disparate impact analysis can help regulators assess compliance. Additionally, they explore the importance of clear communication and training for HR departments on the use of AI in hiring, as well as the role of vendors in ensuring compliance. The episode wraps up with a discussion on the ambiguous term 'significant decision making' and its potential for litigation.</p>
<p><strong>Key highlights:</strong></p>
<ul>
  <li>Understanding Opt-In and Opt-Out Requirements</li>
  <li>Anti-Retaliation Measures</li>
  <li>Disparate Impact Analysis</li>
  <li>Applicant Rights and Training</li>
  <li>Vendor Collaboration and Compliance</li>
  <li>Significant Decision Making</li>
</ul>
<p><strong>Resources:</strong></p>
<p><strong>Connect with Tom Fox</strong></p>
<ul>
  <li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li>
</ul>
<p><strong>Connect with Alyssa DeSimone</strong></p>
<ul>
  <li><a href="https://www.linkedin.com/in/alyssa-desimone/">LinkedIn</a></li>
  <li><a href="https://altuscxo.com/team/alyssa-desimone/">Website</a></li>
</ul>
<p><strong>Life with GDPR was recently honored as a </strong><a href="https://podcast.feedspot.com/data_security_podcasts/?feedid=5184233&amp;_src=f2_featured_email">Top Data Security Podcast</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1116</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[65ece980-a786-11f0-b20e-831a0dae0dae]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1687465571.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>A Compliance Roadmap for ADS/ADMT - Part 1: Introduction &amp; Jurisdiction</title>
      <description>Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance &amp; risk management expert with an extensive background in HR, will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.

In this first episode, we break down the essentials of ADS/ADMT, focusing on who is covered, the nuances of jurisdiction, and the broader business implications of evolving employment laws. ADS is an automated decision system, and ADMT is an automated decision-making technology. Whether you are an HR professional, compliance professional, or legal eagle, this discussion will help you navigate the complexities of compliance in a changing legal landscape.

Key highlights:


  What is ADS/ADMT?

  Applies to 5+ employees (including part-time/out-of-state).

  Coverage limits for out-of-state conduct.

  Jurisdiction can reach beyond California.

  Risk mitigation tips for businesses.


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Alyssa DeSimone


  LinkedIn



  Website


Life with GDPR was recently honored as a Top Data Security Podcast
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Mon, 13 Oct 2025 10:23:00 -0000</pubDate>
      <itunes:episodeType>bonus</itunes:episodeType>
      <itunes:episode>1</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/d60187da-a786-11f0-9ad4-f79bb0283bdd/image/f91323fab87496dc36a289a94111973e.jpeg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In Part 1, we introduce the amendments to the CCPA on ADS. </itunes:subtitle>
      <itunes:summary>Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance &amp; risk management expert with an extensive background in HR, will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.

In this first episode, we break down the essentials of ADS/ADMT, focusing on who is covered, the nuances of jurisdiction, and the broader business implications of evolving employment laws. ADS is an automated decision system, and ADMT is an automated decision-making technology. Whether you are an HR professional, compliance professional, or legal eagle, this discussion will help you navigate the complexities of compliance in a changing legal landscape.

Key highlights:


  What is ADS/ADMT?

  Applies to 5+ employees (including part-time/out-of-state).

  Coverage limits for out-of-state conduct.

  Jurisdiction can reach beyond California.

  Risk mitigation tips for businesses.


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Alyssa DeSimone


  LinkedIn



  Website


Life with GDPR was recently honored as a Top Data Security Podcast
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance &amp; risk management expert with an extensive background in HR, will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.</p>
<p>In this first episode, we break down the essentials of ADS/ADMT, focusing on who is covered, the nuances of jurisdiction, and the broader business implications of evolving employment laws. ADS is an automated decision system, and ADMT is an automated decision-making technology. Whether you are an HR professional, compliance professional, or legal eagle, this discussion will help you navigate the complexities of compliance in a changing legal landscape.</p>
<p><strong>Key highlights:</strong></p>
<ul>
  <li>What is ADS/ADMT?</li>
  <li>Applies to 5+ employees (including part-time/out-of-state).</li>
  <li>Coverage limits for out-of-state conduct.</li>
  <li>Jurisdiction can reach beyond California.</li>
  <li>Risk mitigation tips for businesses.</li>
</ul>
<p><strong>Resources:</strong></p>
<p><strong>Connect with Tom Fox</strong></p>
<ul>
  <li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li>
</ul>
<p><strong>Connect with Alyssa DeSimone</strong></p>
<ul>
  <li><a href="https://www.linkedin.com/in/alyssa-desimone/">LinkedIn</a></li>
</ul>
<ul>
  <li><a href="https://altuscxo.com/team/alyssa-desimone/">Website</a></li>
</ul>
<p><strong>Life with GDPR was recently honored as a </strong><a href="https://podcast.feedspot.com/data_security_podcasts/?feedid=5184233&amp;_src=f2_featured_email"><strong>Top Data Security Podcast</strong></a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1039</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[d60187da-a786-11f0-9ad4-f79bb0283bdd]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN2668069055.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Endpoint Security and Data Protection: Uncovering the Hidden Compliance Risks in Printer Security with Jim LaRoe</title>
      <description>Jonathan Armstrong remains on assignment. Today, Tom Fox visits with fellow Texan Jim LaRoe, CEO of Symphion, to discuss data privacy, data protection, and compliance related to printer security in one of the most interesting podcasts Tom has done in some time.

Jim provides insight into how 20-30% of network endpoints are printers, and alarmingly, 99% of these are unprotected. Printers, despite being integral to business functions, are typically left vulnerable, making them prime targets for sophisticated phishing and cyber-attacks. Jim shares his journey from a trial lawyer to founding Symphion in 1999 and explains Symphion’s groundbreaking work in developing comprehensive security software for printers. Jim highlights the importance of a culture of compliance in managing endpoint security and the multifaceted challenges that come with securing printers.  He emphasizes the collaborative effort needed among GRC compliance teams, IT, and supply chain departments to manage printer security effectively, and offers actionable steps for businesses to mitigate these risks.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 09 Oct 2025 04:00:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>116</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/b2d5a530-a433-11f0-ba69-b33028773993/image/6580b638a96d1b2bad913b1249b04607.png?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Jim LaRoe joins Tom Fox to talk about printers as a data security risk. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong remains on assignment. Today, Tom Fox visits with fellow Texan Jim LaRoe, CEO of Symphion, to discuss data privacy, data protection, and compliance related to printer security in one of the most interesting podcasts Tom has done in some time.

Jim provides insight into how 20-30% of network endpoints are printers, and alarmingly, 99% of these are unprotected. Printers, despite being integral to business functions, are typically left vulnerable, making them prime targets for sophisticated phishing and cyber-attacks. Jim shares his journey from a trial lawyer to founding Symphion in 1999 and explains Symphion’s groundbreaking work in developing comprehensive security software for printers. Jim highlights the importance of a culture of compliance in managing endpoint security and the multifaceted challenges that come with securing printers.  He emphasizes the collaborative effort needed among GRC compliance teams, IT, and supply chain departments to manage printer security effectively, and offers actionable steps for businesses to mitigate these risks.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong remains on assignment. Today, Tom Fox visits with fellow Texan Jim LaRoe, CEO of Symphion, to discuss data privacy, data protection, and compliance related to printer security in one of the most interesting podcasts Tom has done in some time.</p>
<p>Jim provides insight into how 20-30% of network endpoints are printers, and alarmingly, 99% of these are unprotected. Printers, despite being integral to business functions, are typically left vulnerable, making them prime targets for sophisticated phishing and cyber-attacks. Jim shares his journey from a trial lawyer to founding Symphion in 1999 and explains Symphion’s groundbreaking work in developing comprehensive security software for printers. Jim highlights the importance of a culture of compliance in managing endpoint security and the multifaceted challenges that come with securing printers.  He emphasizes the collaborative effort needed among GRC compliance teams, IT, and supply chain departments to manage printer security effectively, and offers actionable steps for businesses to mitigate these risks.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1471</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[b2d5a530-a433-11f0-ba69-b33028773993]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9004213129.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>From IT to Total Compliance Tracking with Adam Goslin</title>
      <description>Jonathan Armstrong remains on assignment. Today, Tom visits with Adam Goslin, founder of Total Compliance Tracking, to discuss his journey from IT development and management to becoming a leader in the security and compliance sector.

Adam shares his professional background, the challenges he faced with achieving PCI compliance, and the insights that led him to create a system to streamline compliance management. He details how his company, TCT, helps organizations efficiently manage various certifications and compliance standards. Adam also discusses the unique, direct marketing approach TCT employs and shares the philosophy behind providing accessible compliance resources. This conversation offers valuable insights into the importance of pragmatic, user-friendly compliance solutions.

Key takeaways:


  Adam Goslin’s Professional Journey

  Founding Total Compliance Tracking

  Marketing Strategy and Philosophy

  Future of TCT and Industry Insights


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Adam Goslin


  LinkedIn


Connect with Total Compliance Tracking


  Website

  LinkedIn


Life with GDPR was recently honored as a Top Data Security Podcast.  
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Oct 2025 04:00:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>114</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/ea919c3e-9c9c-11f0-9a89-57ebdaee2006/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom Fox visits Adam Goslin, founder of Total Compliance Tracking, about his transition from IT development and management to leadership in the security and compliance field.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong remains on assignment. Today, Tom visits with Adam Goslin, founder of Total Compliance Tracking, to discuss his journey from IT development and management to becoming a leader in the security and compliance sector.

Adam shares his professional background, the challenges he faced with achieving PCI compliance, and the insights that led him to create a system to streamline compliance management. He details how his company, TCT, helps organizations efficiently manage various certifications and compliance standards. Adam also discusses the unique, direct marketing approach TCT employs and shares the philosophy behind providing accessible compliance resources. This conversation offers valuable insights into the importance of pragmatic, user-friendly compliance solutions.

Key takeaways:


  Adam Goslin’s Professional Journey

  Founding Total Compliance Tracking

  Marketing Strategy and Philosophy

  Future of TCT and Industry Insights


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Adam Goslin


  LinkedIn


Connect with Total Compliance Tracking


  Website

  LinkedIn


Life with GDPR was recently honored as a Top Data Security Podcast.  
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong remains on assignment. Today, Tom visits with Adam Goslin, founder of Total Compliance Tracking, to discuss his journey from IT development and management to becoming a leader in the security and compliance sector.</p>
<p>Adam shares his professional background, the challenges he faced with achieving PCI compliance, and the insights that led him to create a system to streamline compliance management. He details how his company, TCT, helps organizations efficiently manage various certifications and compliance standards. Adam also discusses the unique, direct marketing approach TCT employs and shares the philosophy behind providing accessible compliance resources. This conversation offers valuable insights into the importance of pragmatic, user-friendly compliance solutions.</p>
<p><strong>Key takeaways:</strong></p>
<ul>
  <li>Adam Goslin’s Professional Journey</li>
  <li>Founding Total Compliance Tracking</li>
  <li>Marketing Strategy and Philosophy</li>
  <li>Future of TCT and Industry Insights</li>
</ul>
<p><strong>Resources:</strong></p>
<p>Connect with Tom Fox</p>
<ul>
  <li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li>
</ul>
<p>Connect with Adam Goslin</p>
<ul>
  <li><a href="https://www.linkedin.com/in/adamgoslin?lipi=urn%3Ali%3Apage%3Ad_flagship3_profile_view_base_contact_details%3BpQqWaYIlRFi54zSQaGAnDA%3D%3D">LinkedIn</a></li>
</ul>
<p>Connect with Total Compliance Tracking</p>
<ul>
  <li><a href="https://www.totalcompliancetracking.com/">Website</a></li>
  <li><a href="https://www.linkedin.com/company/total-compliance-tracking-llc/">LinkedIn</a></li>
</ul>
<p>Life with GDPR was recently honored as a <a href="https://podcast.feedspot.com/data_security_podcasts/?feedid=5184233&amp;_src=f2_featured_email">Top Data Security Podcast.  </a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1268</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[ea919c3e-9c9c-11f0-9a89-57ebdaee2006]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6478925023.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title> Navigating GDPR in Global Outsourcing with Inge Zwick</title>
      <description>Tom Fox takes a solo turn as Jonathan Armstrong is on assignment. Today, Tom visits with Inge Zwick, Executive Director, Head of Europe, and ESG Lead at Emapta Global, a global outsourcing company.

They discuss the company’s operations, with a particular focus on managing GDPR compliance within the outsourcing framework. They also discuss common misconceptions about outsourcing under the GDPR, risk assessment processes, handling data subject access requests, and integrating compliance into business operations. Zwick also shares insights into how EMAPTA collaborates with clients to ensure compliance and offers advice to business leaders on future-proofing their outsourcing strategies in light of GDPR requirements. Additionally, the discussion explores the integration of ESG initiatives within the company’s operations.

Key takeaways:


  Outsourcing and GDPR Compliance

  Risk Assessment and Data Security

  Subject Access Requests (SAR)

  Outsourcing Contracts and GDPR Obligations

  Integrating Compliance into Operations


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Inge Zwick


  LinkedIn


Connect with Emapta Global


  Website

  LinkedIn


Life with GDPR was recently honored as a Top Data Security Podcast.  
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 24 Jul 2025 04:00:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>114</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/ecb86e50-67dd-11f0-bfad-c7d6b1dff57a/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom takes a solo turn with Inge Zwick. </itunes:subtitle>
      <itunes:summary>Tom Fox takes a solo turn as Jonathan Armstrong is on assignment. Today, Tom visits with Inge Zwick, Executive Director, Head of Europe, and ESG Lead at Emapta Global, a global outsourcing company.

They discuss the company’s operations, with a particular focus on managing GDPR compliance within the outsourcing framework. They also discuss common misconceptions about outsourcing under the GDPR, risk assessment processes, handling data subject access requests, and integrating compliance into business operations. Zwick also shares insights into how EMAPTA collaborates with clients to ensure compliance and offers advice to business leaders on future-proofing their outsourcing strategies in light of GDPR requirements. Additionally, the discussion explores the integration of ESG initiatives within the company’s operations.

Key takeaways:


  Outsourcing and GDPR Compliance

  Risk Assessment and Data Security

  Subject Access Requests (SAR)

  Outsourcing Contracts and GDPR Obligations

  Integrating Compliance into Operations


Resources:

Connect with Tom Fox


  LinkedIn


Connect with Inge Zwick


  LinkedIn


Connect with Emapta Global


  Website

  LinkedIn


Life with GDPR was recently honored as a Top Data Security Podcast.  
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox takes a solo turn as Jonathan Armstrong is on assignment. Today, Tom visits with Inge Zwick, Executive Director, Head of Europe, and ESG Lead at Emapta Global, a global outsourcing company.</p>
<p>They discuss the company’s operations, with a particular focus on managing GDPR compliance within the outsourcing framework. They also discuss common misconceptions about outsourcing under the GDPR, risk assessment processes, handling data subject access requests, and integrating compliance into business operations. Zwick also shares insights into how EMAPTA collaborates with clients to ensure compliance and offers advice to business leaders on future-proofing their outsourcing strategies in light of GDPR requirements. Additionally, the discussion explores the integration of ESG initiatives within the company’s operations.</p>
<p><strong>Key takeaways:</strong></p>
<ul>
  <li>Outsourcing and GDPR Compliance</li>
  <li>Risk Assessment and Data Security</li>
  <li>Subject Access Requests (SAR)</li>
  <li>Outsourcing Contracts and GDPR Obligations</li>
  <li>Integrating Compliance into Operations</li>
</ul>
<p><strong>Resources:</strong></p>
<p>Connect with Tom Fox</p>
<ul>
  <li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li>
</ul>
<p>Connect with Inge Zwick</p>
<ul>
  <li><a href="https://www.linkedin.com/in/inge-zwick-emapta/">LinkedIn</a></li>
</ul>
<p>Connect with Emapta Global</p>
<ul>
  <li><a href="https://emapta.com/">Website</a></li>
  <li><a href="https://www.linkedin.com/company/emaptaglobal/">LinkedIn</a></li>
</ul>
<p>Life with GDPR was recently honored as a <a href="https://podcast.feedspot.com/data_security_podcasts/?feedid=5184233&amp;_src=f2_featured_email">Top Data Security Podcast.  </a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1400</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[ecb86e50-67dd-11f0-bfad-c7d6b1dff57a]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8628058616.mp3?updated=1753944574" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>AI in Recruitment: Navigating GDPR Compliance and Challenges</title>
      <description>Tom Fox and Jonathan Armstrong, renowned cybersecurity experts, co-host the award-winning Life with GDPR. This episode explores the complex intersection of AI and recruitment, focusing on compliance challenges under GDPR and potential risks.
Jonathan highlights that AI is often more prevalent in recruitment processes than many compliance officers realize, often through third-party vendors. He discusses the regulatory landscape in the UK and EU, sharing insights on recent cases related to automated decision-making and the transparency required for such systems. Jonathan offers a seven-point plan for organizations that use or are considering using AI in recruitment, covering provider selection, due diligence, transparency obligations, and mechanisms for handling data subject requests. The conversation underscores the need for proactive engagement between data protection officers, compliance teams, and recruiters to ensure that AI tools are used responsibly and transparently.
Key takeaways:

AI in Recruitment: An Overview

Legal and Ethical Concerns

Transparency and Fairness in AI Decisions

Practical Steps for Companies

Future of AI in Recruitment

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall

Life with GDPR was recently honored as a Top Data Security Podcast.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 10 Apr 2025 05:00:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>113</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/6f08778c-14bf-11f0-b375-3ffdaccf2487/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>This episode delves into the intricate link between AI and recruitment, highlighting the challenges associated with GDPR compliance and potential risks.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned cybersecurity experts, co-host the award-winning Life with GDPR. This episode explores the complex intersection of AI and recruitment, focusing on compliance challenges under GDPR and potential risks.
Jonathan highlights that AI is often more prevalent in recruitment processes than many compliance officers realize, often through third-party vendors. He discusses the regulatory landscape in the UK and EU, sharing insights on recent cases related to automated decision-making and the transparency required for such systems. Jonathan offers a seven-point plan for organizations that use or are considering using AI in recruitment, covering provider selection, due diligence, transparency obligations, and mechanisms for handling data subject requests. The conversation underscores the need for proactive engagement between data protection officers, compliance teams, and recruiters to ensure that AI tools are used responsibly and transparently.
Key takeaways:

AI in Recruitment: An Overview

Legal and Ethical Concerns

Transparency and Fairness in AI Decisions

Practical Steps for Companies

Future of AI in Recruitment

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall

Life with GDPR was recently honored as a Top Data Security Podcast.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned cybersecurity experts, co-host the award-winning Life with GDPR. This episode explores the complex intersection of AI and recruitment, focusing on compliance challenges under GDPR and potential risks.</p><p class="ql-align-justify">Jonathan highlights that AI is often more prevalent in recruitment processes than many compliance officers realize, often through third-party vendors. He discusses the regulatory landscape in the UK and EU, sharing insights on recent cases related to automated decision-making and the transparency required for such systems. Jonathan offers a seven-point plan for organizations that use or are considering using AI in recruitment, covering provider selection, due diligence, transparency obligations, and mechanisms for handling data subject requests. The conversation underscores the need for proactive engagement between data protection officers, compliance teams, and recruiters to ensure that AI tools are used responsibly and transparently.</p><p><strong>Key takeaways:</strong></p><ul>
<li>AI in Recruitment: An Overview</li>
<li>Legal and Ethical Concerns</li>
<li>Transparency and Fairness in AI Decisions</li>
<li>Practical Steps for Companies</li>
<li>Future of AI in Recruitment</li>
</ul><p><strong>Resources:</strong></p><p>Connect with Tom Fox</p><ul><li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li></ul><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
<li><a href="https://puntersouthall.law/">PunterSouthall</a></li>
</ul><p class="ql-align-justify">Life with GDPR was recently honored as a <a href="https://podcast.feedspot.com/data_security_podcasts/?feedid=5184233&amp;_src=f2_featured_email">Top Data Security Podcast</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>992</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[6f08778c-14bf-11f0-b375-3ffdaccf2487]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN2821394926.mp3?updated=1744271970" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Cookie Compliance</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss Cookie Compliance Under GDPR.
Their discussion highlights the increasing enforcement actions surrounding website cookies, emphasizing that this is a data protection issue and a broader compliance challenge. Specific case studies, such as the Dutch regulator’s fine against Pool Blue and fines in other EU countries, illustrate the significant financial penalties companies can face for non-compliance. Jonathan outlines an eight-point plan to help organizations ensure their cookie practices are current, including regular checks, proper configuration of cookie banners, and transparency about data retention periods.
The episode also touches on the role of third-party cookies, potential litigation, and regulatory actions. Compliance with cookie regulations is becoming increasingly important, with groups like NOYB driving many complaints and regulatory bodies across Europe ramping up enforcement efforts. Listeners are encouraged to assess their cookie practices and make necessary adjustments to avoid fines and maintain compliance.
Key takeaways:

The Rise of Cookie Enforcement

Global Fines and Consequences

Practical Compliance Tips

Challenges with Cookie Banners

Understanding Your Own Cookies

Guidelines for Cookie Retention

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall

Life with GDPR was recently honored as a Top Data Security Podcast.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 27 Mar 2025 05:00:00 -0000</pubDate>
      <itunes:title>Cookie Compliance</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>112</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/24f39632-0a91-11f0-845e-5b8f17cd5a55/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom Fox and Jonathan Armstrong discuss Cookie Compliance Under GDPR.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss Cookie Compliance Under GDPR.
Their discussion highlights the increasing enforcement actions surrounding website cookies, emphasizing that this is a data protection issue and a broader compliance challenge. Specific case studies, such as the Dutch regulator’s fine against Pool Blue and fines in other EU countries, illustrate the significant financial penalties companies can face for non-compliance. Jonathan outlines an eight-point plan to help organizations ensure their cookie practices are current, including regular checks, proper configuration of cookie banners, and transparency about data retention periods.
The episode also touches on the role of third-party cookies, potential litigation, and regulatory actions. Compliance with cookie regulations is becoming increasingly important, with groups like NOYB driving many complaints and regulatory bodies across Europe ramping up enforcement efforts. Listeners are encouraged to assess their cookie practices and make necessary adjustments to avoid fines and maintain compliance.
Key takeaways:

The Rise of Cookie Enforcement

Global Fines and Consequences

Practical Compliance Tips

Challenges with Cookie Banners

Understanding Your Own Cookies

Guidelines for Cookie Retention

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall

Life with GDPR was recently honored as a Top Data Security Podcast.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss Cookie Compliance Under GDPR.</p><p>Their discussion highlights the increasing enforcement actions surrounding website cookies, emphasizing that this is a data protection issue and a broader compliance challenge. Specific case studies, such as the Dutch regulator’s fine against Pool Blue and fines in other EU countries, illustrate the significant financial penalties companies can face for non-compliance. Jonathan outlines an eight-point plan to help organizations ensure their cookie practices are current, including regular checks, proper configuration of cookie banners, and transparency about data retention periods.</p><p class="ql-align-justify">The episode also touches on the role of third-party cookies, potential litigation, and regulatory actions. Compliance with cookie regulations is becoming increasingly important, with groups like NOYB driving many complaints and regulatory bodies across Europe ramping up enforcement efforts. Listeners are encouraged to assess their cookie practices and make necessary adjustments to avoid fines and maintain compliance.</p><p><strong>Key takeaways:</strong></p><ul>
<li>The Rise of Cookie Enforcement</li>
<li>Global Fines and Consequences</li>
<li>Practical Compliance Tips</li>
<li>Challenges with Cookie Banners</li>
<li>Understanding Your Own Cookies</li>
<li>Guidelines for Cookie Retention</li>
</ul><p><strong>Resources:</strong></p><p>Connect with Tom Fox</p><ul><li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li></ul><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
<li><a href="https://puntersouthall.law/">PunterSouthall</a></li>
</ul><p class="ql-align-justify">Life with GDPR was recently honored as a <a href="https://podcast.feedspot.com/data_security_podcasts/?feedid=5184233&amp;_src=f2_featured_email">Top Data Security Podcast</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1066</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[24f39632-0a91-11f0-845e-5b8f17cd5a55]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1532832876.mp3?updated=1743071858" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Navigating CCO and CISO Liability Trends</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. This episode discusses the complex topic of liability for the Chief Compliance Officer (CCO) and Chief Information Security Officer (CISO).
Tom and Jonathan begin by examining notable cases like Joe Sullivan, the former CISO at Uber, who faced prosecution for mishandling a ransomware threat. They also cover other significant cases like Carlos Abarca from TSB Bank and Tim Brown from SolarWinds, highlighting the increasing trend towards personal liability among high-ranking compliance and security officers. Jonathan points out that prosecutors and legislators focus more on individual accountability, driven by the belief that this approach will encourage others to adhere to standards more rigorously. They explore the implications of misleading LinkedIn profiles and the importance of thorough due diligence when taking on new roles. The episode provides practical advice for C-suite executives to protect themselves, including negotiating indemnity clauses and ensuring accurate job descriptions.
Key takeaways:

Chief Compliance Officer Liability Overview

Case Studies: Joe Sullivan and Uber, Carlos Barker and TSB Bank and Tim Brown and SolarWinds

Legislation and Trends in Personal Liability

SEC Formula for CCO Liability

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall

Life with GDPR was recently honored as a Top Data Security Podcast 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 06 Feb 2025 13:15:00 -0000</pubDate>
      <itunes:title>Navigating CCO and CISO Liability Trends</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>111</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/7ae8e38a-e3d6-11ef-978f-373b74cfcf04/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan look at CCO and CISO liabilities. </itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. This episode discusses the complex topic of liability for the Chief Compliance Officer (CCO) and Chief Information Security Officer (CISO).
Tom and Jonathan begin by examining notable cases like Joe Sullivan, the former CISO at Uber, who faced prosecution for mishandling a ransomware threat. They also cover other significant cases like Carlos Abarca from TSB Bank and Tim Brown from SolarWinds, highlighting the increasing trend towards personal liability among high-ranking compliance and security officers. Jonathan points out that prosecutors and legislators focus more on individual accountability, driven by the belief that this approach will encourage others to adhere to standards more rigorously. They explore the implications of misleading LinkedIn profiles and the importance of thorough due diligence when taking on new roles. The episode provides practical advice for C-suite executives to protect themselves, including negotiating indemnity clauses and ensuring accurate job descriptions.
Key takeaways:

Chief Compliance Officer Liability Overview

Case Studies: Joe Sullivan and Uber, Carlos Barker and TSB Bank and Tim Brown and SolarWinds

Legislation and Trends in Personal Liability

SEC Formula for CCO Liability

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall

Life with GDPR was recently honored as a Top Data Security Podcast 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. This episode discusses the complex topic of liability for the Chief Compliance Officer (CCO) and Chief Information Security Officer (CISO).</p><p class="ql-align-justify">Tom and Jonathan begin by examining notable cases like Joe Sullivan, the former CISO at Uber, who faced prosecution for mishandling a ransomware threat. They also cover other significant cases like Carlos Abarca from TSB Bank and Tim Brown from SolarWinds, highlighting the increasing trend towards personal liability among high-ranking compliance and security officers. Jonathan points out that prosecutors and legislators focus more on individual accountability, driven by the belief that this approach will encourage others to adhere to standards more rigorously. They explore the implications of misleading LinkedIn profiles and the importance of thorough due diligence when taking on new roles. The episode provides practical advice for C-suite executives to protect themselves, including negotiating indemnity clauses and ensuring accurate job descriptions.</p><p><strong>Key takeaways:</strong></p><ul>
<li>Chief Compliance Officer Liability Overview</li>
<li>Case Studies: Joe Sullivan and Uber, Carlos Barker and TSB Bank and Tim Brown and SolarWinds</li>
<li>Legislation and Trends in Personal Liability</li>
<li>SEC Formula for CCO Liability</li>
</ul><p><strong>Resources:</strong></p><p>Connect with Tom Fox</p><ul><li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li></ul><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
<li><a href="https://puntersouthall.law/">PunterSouthall</a></li>
</ul><p class="ql-align-justify">Life with GDPR was recently honored as a <a href="https://podcast.feedspot.com/data_security_podcasts/?feedid=5184233&amp;_src=f2_featured_email">Top Data Security Podcast </a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1465</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[7ae8e38a-e3d6-11ef-978f-373b74cfcf04]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8976023282.mp3?updated=1738848010" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Navigating the EU AI Act</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss a pressing deadline for compliance officers: the February 2nd enforcement of the EU AI Act’s prohibitions on unacceptable AI risk.

Tom and Jonathan look at the phased implementation of this complex legislation, detailing the obligations of businesses using AI in their EU operations. Jonathan emphasizes the importance of identifying ‘shadow AI’ within organizations, from HR recruitment tools to consumer applications, and the substantial penalties for non-compliance, which can reach up to $35 million or 7% of global annual revenue. They also cover a practical five-step plan to help companies move towards compliance, involving board awareness, an AI inventory, assessment of AI tools, contract reviews, and transparency measures. Tune in to understand the nuances of this legislation and how to prepare your organization before the rapidly approaching deadline.
Key takeaways:

Understanding the EU AI Act

Prohibited AI Applications

Corporate and Personal Liability

Steps to Compliance

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall


Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 09 Jan 2025 06:00:00 -0000</pubDate>
      <itunes:title>Navigating the EU AI Act</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>110</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/942f6b34-ce05-11ef-b584-27e32268ad6a/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan take a deep dive into the EU AI Act.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss a pressing deadline for compliance officers: the February 2nd enforcement of the EU AI Act’s prohibitions on unacceptable AI risk.

Tom and Jonathan look at the phased implementation of this complex legislation, detailing the obligations of businesses using AI in their EU operations. Jonathan emphasizes the importance of identifying ‘shadow AI’ within organizations, from HR recruitment tools to consumer applications, and the substantial penalties for non-compliance, which can reach up to $35 million or 7% of global annual revenue. They also cover a practical five-step plan to help companies move towards compliance, involving board awareness, an AI inventory, assessment of AI tools, contract reviews, and transparency measures. Tune in to understand the nuances of this legislation and how to prepare your organization before the rapidly approaching deadline.
Key takeaways:

Understanding the EU AI Act

Prohibited AI Applications

Corporate and Personal Liability

Steps to Compliance

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall


Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss a pressing deadline for compliance officers: the February 2nd enforcement of the EU AI Act’s prohibitions on unacceptable AI risk.</p><p class="ql-align-justify"><br></p><p class="ql-align-justify">Tom and Jonathan look at the phased implementation of this complex legislation, detailing the obligations of businesses using AI in their EU operations. Jonathan emphasizes the importance of identifying ‘shadow AI’ within organizations, from HR recruitment tools to consumer applications, and the substantial penalties for non-compliance, which can reach up to $35 million or 7% of global annual revenue. They also cover a practical five-step plan to help companies move towards compliance, involving board awareness, an AI inventory, assessment of AI tools, contract reviews, and transparency measures. Tune in to understand the nuances of this legislation and how to prepare your organization before the rapidly approaching deadline.</p><p><strong>Key takeaways:</strong></p><ul>
<li>Understanding the EU AI Act</li>
<li>Prohibited AI Applications</li>
<li>Corporate and Personal Liability</li>
<li>Steps to Compliance</li>
</ul><p><strong>Resources:</strong></p><p>Connect with Tom Fox</p><ul><li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li></ul><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
<li><a href="https://puntersouthall.law/">PunterSouthall</a></li>
</ul><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1805</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[942f6b34-ce05-11ef-b584-27e32268ad6a]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5996875425.mp3?updated=1736415511" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Understanding the UK’s Failure to Prevent Fraud</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. This episode delves into the UK’s Failure to Prevent Fraud guidance.

The podcast spans the initial implications and conflicts these new provisions present, especially in the context of GDPR and compliance with bribery investigations. Jonathan explains the concept of ‘failure to prevent fraud,’ drawing parallels with the 2010 UK Bribery Act, and outlines six key principles organizations must adhere to to demonstrate compliance. Additionally, the episode delves into specific steps compliance professionals should take before the new provisions come into force by July 2025, including gap analysis, policy updating, training, and more.
Key takeaways:

Failure to Prevent Bribery and Fraud

New Legislation and Its Implications

Reasonable Procedures Under the Failure to Prevent Fraud Act

Comparing Fraud and Bribery Compliance

Steps for Compliance Professionals

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall


Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 21 Nov 2024 06:00:00 -0000</pubDate>
      <itunes:title>Understanding the UK’s Failure to Prevent Fraud</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>109</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/10484886-a6c3-11ef-b4bb-233cd2529edc/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan reviewed the MoJ Guidance on the FTPF.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. This episode delves into the UK’s Failure to Prevent Fraud guidance.

The podcast spans the initial implications and conflicts these new provisions present, especially in the context of GDPR and compliance with bribery investigations. Jonathan explains the concept of ‘failure to prevent fraud,’ drawing parallels with the 2010 UK Bribery Act, and outlines six key principles organizations must adhere to to demonstrate compliance. Additionally, the episode delves into specific steps compliance professionals should take before the new provisions come into force by July 2025, including gap analysis, policy updating, training, and more.
Key takeaways:

Failure to Prevent Bribery and Fraud

New Legislation and Its Implications

Reasonable Procedures Under the Failure to Prevent Fraud Act

Comparing Fraud and Bribery Compliance

Steps for Compliance Professionals

Resources:
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn

PunterSouthall


Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. This episode delves into the UK’s Failure to Prevent Fraud guidance.</p><p class="ql-align-justify"><br></p><p class="ql-align-justify">The podcast spans the initial implications and conflicts these new provisions present, especially in the context of GDPR and compliance with bribery investigations. Jonathan explains the concept of ‘failure to prevent fraud,’ drawing parallels with the 2010 UK Bribery Act, and outlines six key principles organizations must adhere to to demonstrate compliance. Additionally, the episode delves into specific steps compliance professionals should take before the new provisions come into force <strong>by July 2025</strong>, including gap analysis, policy updating, training, and more.</p><p><strong>Key takeaways:</strong></p><ul>
<li>Failure to Prevent Bribery and Fraud</li>
<li>New Legislation and Its Implications</li>
<li>Reasonable Procedures Under the Failure to Prevent Fraud Act</li>
<li>Comparing Fraud and Bribery Compliance</li>
<li>Steps for Compliance Professionals</li>
</ul><p><strong>Resources:</strong></p><p>Connect with Tom Fox</p><ul><li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li></ul><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
<li><a href="https://puntersouthall.law/"><u>PunterSouthall</u></a></li>
</ul><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1273</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[10484886-a6c3-11ef-b4bb-233cd2529edc]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9202829831.mp3?updated=1732182335" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>AI Regulation in The EU</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR.

In this episode, we delve into the complex provisions of the new EU AI Act, exploring its global effects and extraterritorial implications similar to the GDPR.

Tom, Jonathan and a few friends discuss the multifaceted regulatory framework, which combines elements from EU antitrust law, GDPR, and EU medical device rules, and highlight the need for transparency and compliance for AI developers and corporations using AI. We also address enforcement timelines, the importance of an AI inventory, and practical steps for compliance officers to ensure adherence to the new regulations.

Key Takeaways:


Overview of the EU AI Act

Enforcement and Compliance

Corporate Responsibilities and Compliance Strategies

Enforcement Mechanisms and Penalties

Practical Steps for Organizations

Challenges and Governance


Resources:

Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Connect with Jonathan Armstrong

Twitter

LinkedIn


Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 15 Aug 2024 04:00:00 -0000</pubDate>
      <itunes:title>AI Regulation in The EU</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>108</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/75632de0-5352-11ef-8138-c748288e7c9c/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>We look at AI Regulation in The EU.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR.

In this episode, we delve into the complex provisions of the new EU AI Act, exploring its global effects and extraterritorial implications similar to the GDPR.

Tom, Jonathan and a few friends discuss the multifaceted regulatory framework, which combines elements from EU antitrust law, GDPR, and EU medical device rules, and highlight the need for transparency and compliance for AI developers and corporations using AI. We also address enforcement timelines, the importance of an AI inventory, and practical steps for compliance officers to ensure adherence to the new regulations.

Key Takeaways:


Overview of the EU AI Act

Enforcement and Compliance

Corporate Responsibilities and Compliance Strategies

Enforcement Mechanisms and Penalties

Practical Steps for Organizations

Challenges and Governance


Resources:

Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Connect with Jonathan Armstrong

Twitter

LinkedIn


Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR.</p><p><br></p><p>In this episode, we delve into the complex provisions of the new EU AI Act, exploring its global effects and extraterritorial implications similar to the GDPR.</p><p><br></p><p class="ql-align-justify">Tom, Jonathan and a few friends discuss the multifaceted regulatory framework, which combines elements from EU antitrust law, GDPR, and EU medical device rules, and highlight the need for transparency and compliance for AI developers and corporations using AI. We also address enforcement timelines, the importance of an AI inventory, and practical steps for compliance officers to ensure adherence to the new regulations.</p><p class="ql-align-justify"><br></p><p><strong>Key Takeaways:</strong></p><p><br></p><ul>
<li>Overview of the EU AI Act</li>
<li>Enforcement and Compliance</li>
<li>Corporate Responsibilities and Compliance Strategies</li>
<li>Enforcement Mechanisms and Penalties</li>
<li>Practical Steps for Organizations</li>
<li>Challenges and Governance</li>
</ul><p><br></p><p><strong>Resources:</strong></p><p><br></p><p>Connect with Tom Fox</p><ul>
<li><a href="https://www.instagram.com/voiceofcompliance">Instagram</a></li>
<li><a href="https://www.facebook.com/compliancepodcastnetwork">Facebook</a></li>
<li><a href="https://www.youtube.com/channel/UC0-IWb69P1srF_uZOmGtBfQ">YouTube</a></li>
<li><a href="https://www.twitter.com/tfoxlaw">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li>
</ul><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
</ul><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>2122</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[75632de0-5352-11ef-8138-c748288e7c9c]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN2240963023.mp3?updated=1723665480" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>What Does The UK Election Mean for Compliance?</title>
      <description>Tom Fox and Jonathan Armstrong, a renowned expert in cybersecurity, co-host the award-winning “Life with GDPR.” Jonathan has returned from his hiatus, and in this episode, we examine the UK election results and their potential impact on compliance.

The recent UK election has significant implications for compliance, particularly concerning the dynamics between the UK’s Serious Fraud Office (SFO) and the new government. Jonathan Armstrong, an expert on bribery enforcement, anticipates that the new administration under Keir Starmer will focus on high-profile issues like the PPE scandal while maintaining robust enforcement actions, including dawn raids.

Armstrong and Fox bring deep insights into the potential compliance landscape, shaped by their extensive backgrounds: Armstrong’s expertise in corruption investigations and Fox’s experience with the criminal justice system.

Fox highlights the impact of the new Prime Minister’s legal background in bolstering enforcement efforts and contemplates the future governance of AI under this administration. Both experts foresee a political shift, with Armstrong expecting the Conservative Party to lean rightward yet occupy the political center, and Fox emphasizing the continuity and experience the new government brings to compliance and enforcement issues.
 
Key Takeaways:

Heightened Bribery Enforcement Under New Government

Russian Sanctions and Uighur Import Regulations

Data Protection Bill Changes Post-UK Election

UK’s New Administration Faces Challenges and Changes

Center-Ground Positioning in UK Politics


Resources:

Connect with Tom Fox


Instagram

Facebook

YouTube

Twitter

LinkedIn

Connect with Jonathan Armstrong


Twitter

LinkedIn


Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 11 Jul 2024 05:00:00 -0000</pubDate>
      <itunes:title>What Does The UK Election Mean for Compliance?</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>107</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/cd5b62fe-3efa-11ef-955a-0fc05c91bacb/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan return to look at the UK election results. </itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, a renowned expert in cybersecurity, co-host the award-winning “Life with GDPR.” Jonathan has returned from his hiatus, and in this episode, we examine the UK election results and their potential impact on compliance.

The recent UK election has significant implications for compliance, particularly concerning the dynamics between the UK’s Serious Fraud Office (SFO) and the new government. Jonathan Armstrong, an expert on bribery enforcement, anticipates that the new administration under Keir Starmer will focus on high-profile issues like the PPE scandal while maintaining robust enforcement actions, including dawn raids.

Armstrong and Fox bring deep insights into the potential compliance landscape, shaped by their extensive backgrounds: Armstrong’s expertise in corruption investigations and Fox’s experience with the criminal justice system.

Fox highlights the impact of the new Prime Minister’s legal background in bolstering enforcement efforts and contemplates the future governance of AI under this administration. Both experts foresee a political shift, with Armstrong expecting the Conservative Party to lean rightward yet occupy the political center, and Fox emphasizing the continuity and experience the new government brings to compliance and enforcement issues.
 
Key Takeaways:

Heightened Bribery Enforcement Under New Government

Russian Sanctions and Uighur Import Regulations

Data Protection Bill Changes Post-UK Election

UK’s New Administration Faces Challenges and Changes

Center-Ground Positioning in UK Politics


Resources:

Connect with Tom Fox


Instagram

Facebook

YouTube

Twitter

LinkedIn

Connect with Jonathan Armstrong


Twitter

LinkedIn


Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, a renowned expert in cybersecurity, co-host the award-winning “Life with GDPR.” Jonathan has returned from his hiatus, and in this episode, we examine the UK election results and their potential impact on compliance.</p><p><br></p><p>The recent UK election has significant implications for compliance, particularly concerning the dynamics between the UK’s Serious Fraud Office (SFO) and the new government. Jonathan Armstrong, an expert on bribery enforcement, anticipates that the new administration under Keir Starmer will focus on high-profile issues like the PPE scandal while maintaining robust enforcement actions, including dawn raids.</p><p><br></p><p>Armstrong and Fox bring deep insights into the potential compliance landscape, shaped by their extensive backgrounds: Armstrong’s expertise in corruption investigations and Fox’s experience with the criminal justice system.</p><p><br></p><p class="ql-align-justify">Fox highlights the impact of the new Prime Minister’s legal background in bolstering enforcement efforts and contemplates the future governance of AI under this administration. Both experts foresee a political shift, with Armstrong expecting the Conservative Party to lean rightward yet occupy the political center, and Fox emphasizing the continuity and experience the new government brings to compliance and enforcement issues.</p><p class="ql-align-justify"><strong> </strong></p><p><strong>Key Takeaways:</strong></p><ul>
<li>Heightened Bribery Enforcement Under New Government</li>
<li>Russian Sanctions and Uighur Import Regulations</li>
<li>Data Protection Bill Changes Post-UK Election</li>
<li>UK’s New Administration Faces Challenges and Changes</li>
<li>Center-Ground Positioning in UK Politics</li>
</ul><p><br></p><p><strong>Resources:</strong></p><p><br></p><p><strong>Connect with Tom Fox</strong></p><p><br></p><ul>
<li><a href="https://www.instagram.com/voiceofcompliance">Instagram</a></li>
<li><a href="https://www.facebook.com/compliancepodcastnetwork">Facebook</a></li>
<li><a href="https://www.youtube.com/channel/UC0-IWb69P1srF_uZOmGtBfQ">YouTube</a></li>
<li><a href="https://www.twitter.com/tfoxlaw">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li>
</ul><p><strong>Connect with Jonathan Armstrong</strong></p><p><br></p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
</ul><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>2167</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[cd5b62fe-3efa-11ef-955a-0fc05c91bacb]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6547105337.mp3?updated=1720683047" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Karen Moore on The EU, Corporate Sustainability Due Diligence Directive</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. Jonathan is on a short hiatus and in this episode, we have a special guest, Karen Moore who discusses the EU’s Corporate Sustainability-Due Diligence Directive.
Karen Moore is a well-versed professional in the area of impact assessments and due diligence, with a particular focus on human rights and environmental issues to prevent and address potential harm. Her perspective, shaped by her extensive experience, is that impact assessments and due diligence are key indicators of a corporation’s commitment to preserving the environment and upholding human rights.
Moore emphasizes the importance of these processes not only within a company’s own activities, but also within those of its suppliers and indirect suppliers. She stresses the need for a robust due diligence process, including tracking progress, publishing annual statements, implementing complaints procedures, and involving all employees.
Additionally, she highlights the challenges of managing these processes, such as complex questionnaires for third-party suppliers and the need for streamlined assessments. She believes in a proactive approach to corporate responsibility, going beyond regulatory requirements to foster sustainable practices and ethical decision-making.

 Key Takeaways:

Ethical and Sustainable Business Practices Compliance Guidelines

Ethical Evaluation for Data Privacy Compliance in the US

Ethical Data Handling for GDPR Compliance

Ethical Business Practices in Supply Chains

 Resources:
Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn


Connect with Jonathan Armstrong

Twitter

LinkedIn


Connect with Karen Moore
LinkedIn

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 18 Apr 2024 04:00:00 -0000</pubDate>
      <itunes:title>Karen Moore on The EU, Corporate Sustainability Due Diligence Directive</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/a6a2cc44-fc2c-11ee-be3d-cb1e78b90fff/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom visits with Karen Moore on the EU CS-DDD.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. Jonathan is on a short hiatus and in this episode, we have a special guest, Karen Moore who discusses the EU’s Corporate Sustainability-Due Diligence Directive.
Karen Moore is a well-versed professional in the area of impact assessments and due diligence, with a particular focus on human rights and environmental issues to prevent and address potential harm. Her perspective, shaped by her extensive experience, is that impact assessments and due diligence are key indicators of a corporation’s commitment to preserving the environment and upholding human rights.
Moore emphasizes the importance of these processes not only within a company’s own activities, but also within those of its suppliers and indirect suppliers. She stresses the need for a robust due diligence process, including tracking progress, publishing annual statements, implementing complaints procedures, and involving all employees.
Additionally, she highlights the challenges of managing these processes, such as complex questionnaires for third-party suppliers and the need for streamlined assessments. She believes in a proactive approach to corporate responsibility, going beyond regulatory requirements to foster sustainable practices and ethical decision-making.

 Key Takeaways:

Ethical and Sustainable Business Practices Compliance Guidelines

Ethical Evaluation for Data Privacy Compliance in the US

Ethical Data Handling for GDPR Compliance

Ethical Business Practices in Supply Chains

 Resources:
Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn


Connect with Jonathan Armstrong

Twitter

LinkedIn


Connect with Karen Moore
LinkedIn

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. Jonathan is on a short hiatus and in this episode, we have a special guest, Karen Moore who discusses the EU’s Corporate Sustainability-Due Diligence Directive.</p><p class="ql-align-justify">Karen Moore is a well-versed professional in the area of impact assessments and due diligence, with a particular focus on human rights and environmental issues to prevent and address potential harm. Her perspective, shaped by her extensive experience, is that impact assessments and due diligence are key indicators of a corporation’s commitment to preserving the environment and upholding human rights.</p><p class="ql-align-justify">Moore emphasizes the importance of these processes not only within a company’s own activities, but also within those of its suppliers and indirect suppliers. She stresses the need for a robust due diligence process, including tracking progress, publishing annual statements, implementing complaints procedures, and involving all employees.</p><p class="ql-align-justify">Additionally, she highlights the challenges of managing these processes, such as complex questionnaires for third-party suppliers and the need for streamlined assessments. She believes in a proactive approach to corporate responsibility, going beyond regulatory requirements to foster sustainable practices and ethical decision-making.</p><p class="ql-align-justify"><br></p><p class="ql-align-justify"><strong> Key Takeaways:</strong></p><ul>
<li>Ethical and Sustainable Business Practices Compliance Guidelines</li>
<li>Ethical Evaluation for Data Privacy Compliance in the US</li>
<li>Ethical Data Handling for GDPR Compliance</li>
<li>Ethical Business Practices in Supply Chains</li>
</ul><p><strong> Resources:</strong></p><p><strong>Connect with Tom Fox</strong></p><ul>
<li><a href="https://www.instagram.com/voiceofcompliance">Instagram</a></li>
<li><a href="https://www.facebook.com/compliancepodcastnetwork">Facebook</a></li>
<li><a href="https://www.youtube.com/channel/UC0-IWb69P1srF_uZOmGtBfQ">YouTube</a></li>
<li><a href="https://www.twitter.com/tfoxlaw">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li>
</ul><p><br></p><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
</ul><p><br></p><p class="ql-align-justify">Connect with Karen Moore</p><ul><li><a href="https://www.linkedin.com/in/karen-moore-97264660/">LinkedIn</a></li></ul><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1247</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[a6a2cc44-fc2c-11ee-be3d-cb1e78b90fff]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4296763708.mp3?updated=1713384851" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>NIS2 Balancing Obligations and Challenges for Compliance</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Today we consider the NIS2 Directive, which is the EU-wide legislation on cybersecurity. It provides legal measures to boost the overall level of cybersecurity in the EU.
Cybersecurity regulations are reshaping the landscape, demanding swift action and accountability from organizations and individuals. The NIS2 Directive tightens reporting deadlines, putting pressure on organizations to comply with cybersecurity incidents. This means that organizations need to be prepared to act quickly and efficiently in the event of a cyber incident to avoid penalties and maintain trust with their stakeholders. Management faces increased personal liability under the NIS 2 Directive, highlighting the need for proactive cybersecurity measures. This emphasizes the importance of implementing strong cybersecurity protocols and staying ahead of potential threats to protect both the organization and individual leaders from legal and financial repercussions.
Regulatory bodies advocate for a shift towards prevention in cybersecurity to combat rising cyber threats. This shift in focus underscores the importance of investing in proactive cybersecurity measures rather than simply reacting to incidents after they occur, ultimately leading to a more secure and resilient digital environment. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic on this episode of the Life with GDPR podcast.

Key Takeaways:

NIS Two Directive: Stricter Reporting and Jurisdiction

NIS Two Directive: Management’s Cybersecurity Liability

Operational Resilience: Proactive Cybersecurity Measures


Resources:
Connect with Tom Fox
Instagram
Facebook
YouTube
Twitter
LinkedIn
Connect with Jonathan Armstrong
Twitter
LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 28 Mar 2024 04:00:00 -0000</pubDate>
      <itunes:title>NIS2 Balancing Obligations and Challenges for Compliance</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>102</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/fd6b911c-eac2-11ee-943e-577ac7914338/image/24a48eb14eff51c9c713d12008d8ce82.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Today we consider the NIS2 Directive, which is the EU-wide legislation on cybersecurity. It provides legal measures to boost the overall level of cybersecurity in the EU.
Cybersecurity regulations are reshaping the landscape, demanding swift action and accountability from organizations and individuals. The NIS2 Directive tightens reporting deadlines, putting pressure on organizations to comply with cybersecurity incidents. This means that organizations need to be prepared to act quickly and efficiently in the event of a cyber incident to avoid penalties and maintain trust with their stakeholders. Management faces increased personal liability under the NIS 2 Directive, highlighting the need for proactive cybersecurity measures. This emphasizes the importance of implementing strong cybersecurity protocols and staying ahead of potential threats to protect both the organization and individual leaders from legal and financial repercussions.
Regulatory bodies advocate for a shift towards prevention in cybersecurity to combat rising cyber threats. This shift in focus underscores the importance of investing in proactive cybersecurity measures rather than simply reacting to incidents after they occur, ultimately leading to a more secure and resilient digital environment. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic on this episode of the Life with GDPR podcast.

Key Takeaways:

NIS Two Directive: Stricter Reporting and Jurisdiction

NIS Two Directive: Management’s Cybersecurity Liability

Operational Resilience: Proactive Cybersecurity Measures


Resources:
Connect with Tom Fox
Instagram
Facebook
YouTube
Twitter
LinkedIn
Connect with Jonathan Armstrong
Twitter
LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Today we consider the NIS2 Directive, which is the EU-wide legislation on cybersecurity. It provides legal measures to boost the overall level of cybersecurity in the EU.</p><p class="ql-align-justify">Cybersecurity regulations are reshaping the landscape, demanding swift action and accountability from organizations and individuals. The NIS2 Directive tightens reporting deadlines, putting pressure on organizations to comply with cybersecurity incidents. This means that organizations need to be prepared to act quickly and efficiently in the event of a cyber incident to avoid penalties and maintain trust with their stakeholders. Management faces increased personal liability under the NIS 2 Directive, highlighting the need for proactive cybersecurity measures. This emphasizes the importance of implementing strong cybersecurity protocols and staying ahead of potential threats to protect both the organization and individual leaders from legal and financial repercussions.</p><p class="ql-align-justify">Regulatory bodies advocate for a shift towards prevention in cybersecurity to combat rising cyber threats. This shift in focus underscores the importance of investing in proactive cybersecurity measures rather than simply reacting to incidents after they occur, ultimately leading to a more secure and resilient digital environment. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic on this episode of the Life with GDPR podcast.</p><p class="ql-align-justify"><br></p><p class="ql-align-justify"><strong>Key Takeaways:</strong></p><ul>
<li>NIS Two Directive: Stricter Reporting and Jurisdiction</li>
<li>NIS Two Directive: Management’s Cybersecurity Liability</li>
<li>Operational Resilience: Proactive Cybersecurity Measures</li>
</ul><p class="ql-align-justify"><br></p><p><strong>Resources:</strong></p><p><strong>Connect with Tom Fox</strong></p><p><a href="https://www.instagram.com/voiceofcompliance">Instagram</a></p><p><a href="https://www.facebook.com/compliancepodcastnetwork">Facebook</a></p><p><a href="https://www.youtube.com/channel/UC0-IWb69P1srF_uZOmGtBfQ">YouTube</a></p><p><a href="https://www.twitter.com/tfoxlaw">Twitter</a></p><p class="ql-align-justify"><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p><a href="https://twitter.com/armstrongjp">Twitter</a></p><p><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>856</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[fd6b911c-eac2-11ee-943e-577ac7914338]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9970180710.mp3?updated=1711607776" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Solar Winds and Your Mother - Tell The Truth</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at the continued fallout from the Solar Winds data breach.
In the complex world of data protection, the General Data Protection Regulation (GDPR) has placed a spotlight on the importance of transparency, honesty, and corporate responsibility. Experts Tom Fox and Jonathan Armstrong bring their unique perspectives to this topic, shaped by their extensive experience in compliance and data protection. Fox emphasizes the potential legal consequences for corporate leaders who fail to disclose vulnerabilities or engage in dishonest practices, while Armstrong highlights the increasing pressure on individuals and corporations to disclose data breaches, with regulators focusing more on individual liability. Both stress the importance of transparency, the potential for litigation, and the role of whistleblowers.
Join Fox and Armstrong as they delve deeper into these issues on this episode of the Life with GDPR podcast.

Key Takeaways:

The Importance of Truthfulness in GDPR

The Importance of Transparency in Data Breaches

Legal risks in data breaches and cybersecurity

The Impact of Budget Constraints on Vulnerability Fixes

 Resources:
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. Check out the Cordery Data Breach Academy here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 08 Feb 2024 05:00:00 -0000</pubDate>
      <itunes:title>Solar Winds and Your Mother - Tell The Truth</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>104</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/1fc19bd0-b7d8-11ee-9b54-6fbe36c9383a/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan look at the SEC enforcement action against Solar Winds and its CISO.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at the continued fallout from the Solar Winds data breach.
In the complex world of data protection, the General Data Protection Regulation (GDPR) has placed a spotlight on the importance of transparency, honesty, and corporate responsibility. Experts Tom Fox and Jonathan Armstrong bring their unique perspectives to this topic, shaped by their extensive experience in compliance and data protection. Fox emphasizes the potential legal consequences for corporate leaders who fail to disclose vulnerabilities or engage in dishonest practices, while Armstrong highlights the increasing pressure on individuals and corporations to disclose data breaches, with regulators focusing more on individual liability. Both stress the importance of transparency, the potential for litigation, and the role of whistleblowers.
Join Fox and Armstrong as they delve deeper into these issues on this episode of the Life with GDPR podcast.

Key Takeaways:

The Importance of Truthfulness in GDPR

The Importance of Transparency in Data Breaches

Legal risks in data breaches and cybersecurity

The Impact of Budget Constraints on Vulnerability Fixes

 Resources:
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. Check out the Cordery Data Breach Academy here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at the continued fallout from the Solar Winds data breach.</p><p class="ql-align-justify">In the complex world of data protection, the General Data Protection Regulation (GDPR) has placed a spotlight on the importance of transparency, honesty, and corporate responsibility. Experts Tom Fox and Jonathan Armstrong bring their unique perspectives to this topic, shaped by their extensive experience in compliance and data protection. Fox emphasizes the potential legal consequences for corporate leaders who fail to disclose vulnerabilities or engage in dishonest practices, while Armstrong highlights the increasing pressure on individuals and corporations to disclose data breaches, with regulators focusing more on individual liability. Both stress the importance of transparency, the potential for litigation, and the role of whistleblowers.</p><p class="ql-align-justify">Join Fox and Armstrong as they delve deeper into these issues on this episode of the Life with GDPR podcast.</p><p class="ql-align-justify"><br></p><p class="ql-align-justify"><strong>Key Takeaways:</strong></p><ul>
<li>The Importance of Truthfulness in GDPR</li>
<li>The Importance of Transparency in Data Breaches</li>
<li>Legal risks in data breaches and cybersecurity</li>
<li>The Impact of Budget Constraints on Vulnerability Fixes</li>
</ul><p class="ql-align-justify"><strong> Resources:</strong></p><p class="ql-align-justify"><strong>For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website </strong><a href="http://www.corderycompliance.com/">here</a>. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. Check out the Cordery Data Breach Academy <a href="https://www.corderycompliance.com/cordery-data-breach-academy-2-2-2/">here</a>.</p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p><strong>Connect with Jonathan Armstrong</strong></p><p><strong>●      </strong><a href="https://twitter.com/armstrongjp">Twitter</a></p><p><strong>●      </strong><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1266</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[1fc19bd0-b7d8-11ee-9b54-6fbe36c9383a]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1925113298.mp3?updated=1707336751" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Critical Perspectives on Big Law Firm Cybersecurity</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at a breach of a big law.
In the wake of a recent spearphishing attack and data breach at a UK law firm, the legal community is abuzz with discussions on the responsibility of lawyers to prevent such attacks. Tom Fox, known for his critical perspective on big law firms, highlights the mistakes made by the firm in question, emphasizing the increasing concern over cyber-attacks targeting law firms and the need for timely reporting to regulatory authorities. Jonathan Armstrong, on the other hand, underscores the importance of proactive cybersecurity measures and timely reporting, commending the firm for taking immediate action but criticizing the delay in reporting the breach. Both Fox and Armstrong bring their unique perspectives shaped by their experiences in the field. Join them on this episode of the Life with GDPR podcast as they delve deeper into this topic.

Key Takeaways:

A spearphishing Attack Leads to Data Breach

Cybersecurity Measures for Law Firms

The Power of Dedicated Data Protection Training


  Resources:
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here.
Also, check out the GDPR Navigator, one of the top resources for GDPR compliance, by clicking here. Check out the Cordery Data Breach Academy here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 25 Jan 2024 05:00:00 -0000</pubDate>
      <itunes:title>Critical Perspectives on Big Law Firm Cybersecurity</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>103</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/39d4f0dc-b7e0-11ee-9747-3398dc83fb18/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan look at a breach in big law. </itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at a breach of a big law.
In the wake of a recent spearphishing attack and data breach at a UK law firm, the legal community is abuzz with discussions on the responsibility of lawyers to prevent such attacks. Tom Fox, known for his critical perspective on big law firms, highlights the mistakes made by the firm in question, emphasizing the increasing concern over cyber-attacks targeting law firms and the need for timely reporting to regulatory authorities. Jonathan Armstrong, on the other hand, underscores the importance of proactive cybersecurity measures and timely reporting, commending the firm for taking immediate action but criticizing the delay in reporting the breach. Both Fox and Armstrong bring their unique perspectives shaped by their experiences in the field. Join them on this episode of the Life with GDPR podcast as they delve deeper into this topic.

Key Takeaways:

A spearphishing Attack Leads to Data Breach

Cybersecurity Measures for Law Firms

The Power of Dedicated Data Protection Training


  Resources:
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here.
Also, check out the GDPR Navigator, one of the top resources for GDPR compliance, by clicking here. Check out the Cordery Data Breach Academy here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at a breach of a big law.</p><p class="ql-align-justify">In the wake of a recent spearphishing attack and data breach at a UK law firm, the legal community is abuzz with discussions on the responsibility of lawyers to prevent such attacks. Tom Fox, known for his critical perspective on big law firms, highlights the mistakes made by the firm in question, emphasizing the increasing concern over cyber-attacks targeting law firms and the need for timely reporting to regulatory authorities. Jonathan Armstrong, on the other hand, underscores the importance of proactive cybersecurity measures and timely reporting, commending the firm for taking immediate action but criticizing the delay in reporting the breach. Both Fox and Armstrong bring their unique perspectives shaped by their experiences in the field. Join them on this episode of the Life with GDPR podcast as they delve deeper into this topic.</p><p class="ql-align-justify"><br></p><p class="ql-align-justify"><strong>Key Takeaways:</strong></p><ul>
<li>A spearphishing Attack Leads to Data Breach</li>
<li>Cybersecurity Measures for Law Firms</li>
<li>The Power of Dedicated Data Protection Training</li>
</ul><p class="ql-align-justify"><br></p><p class="ql-align-justify"><strong>  Resources:</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>.</p><p>Also, check out the GDPR Navigator, one of the top resources for GDPR compliance, by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. Check out the Cordery Data Breach Academy <a href="https://www.corderycompliance.com/cordery-data-breach-academy-2-2-2/">here</a>.</p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p><strong>Connect with Jonathan Armstrong</strong></p><p><strong>●      </strong><a href="https://twitter.com/armstrongjp">Twitter</a></p><p><strong>●      </strong><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1254</itunes:duration>
      <guid isPermaLink="false"><![CDATA[39d4f0dc-b7e0-11ee-9747-3398dc83fb18]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6228948556.mp3?updated=1706122811" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title> Lessons Learned from The Singtel Opus Data Breach</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at litigation over a data breach against Singtel Opus in Australia and the fallout from an investigation report.
The recent data breach at Intel Optus, affecting 1.2 million individuals, has brought to light the critical role of strategic communication in managing cybersecurity breaches. Tom and Jonathan Armstrong, offer their unique perspectives on this issue. Fox emphasizes the inevitability of cybersecurity breaches and the need for a comprehensive strategy, including effective communication, to manage them. He warns against the potential consequences of mishandling communication during a breach, such as jeopardizing insurance coverage.
Armstrong highlights the complexity of maintaining privilege in a global corporate structure and the importance of careful language to avoid invalidating insurance or causing unnecessary speculation. He also underscores the need for a holistic approach to cybersecurity, encompassing prevention, detection, remediation, and crisis communication. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic in the latest Life with GDPR podcast episode.
 Key Takeaways:

Implications of Language in Data Breach Reporting

Navigating CEO Communication and Insurance Coverage

Navigating Insurance Coverage in Data Breaches



 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go to their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. Check out the Cordery Data Breach Academy here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 16 Nov 2023 05:00:00 -0000</pubDate>
      <itunes:title> Lessons Learned from The Singtel Opus Data Breach</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>102</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/982be326-828d-11ee-a7d3-5f504f346c97/image/7d630f.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan look at  Lessons Learned from The Singtel Opus Data Breach.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at litigation over a data breach against Singtel Opus in Australia and the fallout from an investigation report.
The recent data breach at Intel Optus, affecting 1.2 million individuals, has brought to light the critical role of strategic communication in managing cybersecurity breaches. Tom and Jonathan Armstrong, offer their unique perspectives on this issue. Fox emphasizes the inevitability of cybersecurity breaches and the need for a comprehensive strategy, including effective communication, to manage them. He warns against the potential consequences of mishandling communication during a breach, such as jeopardizing insurance coverage.
Armstrong highlights the complexity of maintaining privilege in a global corporate structure and the importance of careful language to avoid invalidating insurance or causing unnecessary speculation. He also underscores the need for a holistic approach to cybersecurity, encompassing prevention, detection, remediation, and crisis communication. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic in the latest Life with GDPR podcast episode.
 Key Takeaways:

Implications of Language in Data Breach Reporting

Navigating CEO Communication and Insurance Coverage

Navigating Insurance Coverage in Data Breaches



 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go to their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. Check out the Cordery Data Breach Academy here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. In this episode, they look at litigation over a data breach against Singtel Opus in Australia and the fallout from an investigation report.</p><p class="ql-align-justify">The recent data breach at Intel Optus, affecting 1.2 million individuals, has brought to light the critical role of strategic communication in managing cybersecurity breaches. Tom and Jonathan Armstrong, offer their unique perspectives on this issue. Fox emphasizes the inevitability of cybersecurity breaches and the need for a comprehensive strategy, including effective communication, to manage them. He warns against the potential consequences of mishandling communication during a breach, such as jeopardizing insurance coverage.</p><p class="ql-align-justify">Armstrong highlights the complexity of maintaining privilege in a global corporate structure and the importance of careful language to avoid invalidating insurance or causing unnecessary speculation. He also underscores the need for a holistic approach to cybersecurity, encompassing prevention, detection, remediation, and crisis communication. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic in the latest Life with GDPR podcast episode.</p><p class="ql-align-justify"><strong> Key Takeaways:</strong></p><ul>
<li>Implications of Language in Data Breach Reporting</li>
<li>Navigating CEO Communication and Insurance Coverage</li>
<li>Navigating Insurance Coverage in Data Breaches</li>
<li><br></li>
</ul><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. Check out the Cordery Data Breach Academy <a href="https://www.corderycompliance.com/cordery-data-breach-academy-2-2-2/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1228</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[982be326-828d-11ee-a7d3-5f504f346c97]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6668394578.mp3?updated=1700126228" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The Hidden Dangers of CEO Behavior: Patterns and Consequences</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. We take things in a different direction today as we discuss the somewhat lurid allegations around former Abercrombie &amp; Fitch CEO Mike Jeffries. This matter illustrates the need for robust background checks and support of those who bring forward complaints against top management.
The topic of CEO risk, specifically the importance of accountability and investigations in corporate compliance, is a critical issue in today’s business world. It explores the potential dangers CEOs can pose to corporations and the necessity of holding them accountable for compliance initiatives. Tom Fox, a renowned compliance expert, emphasizes the importance of conducting thorough due diligence on individuals, particularly at the senior executive level, to mitigate risks. He believes that behavior patterns often exist before public scandals occur and that it is crucial to identify these patterns through deep investigations. On the other hand, Jonathan Armstrong highlights the challenge of pushing compliance up the organization and the need for thorough due diligence when hiring senior executives. He also stresses the importance of accountability and investigations in addressing misconduct allegations, even if they are historic. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic on this episode of the Life with GDPR podcast.

Key Takeaways:

CEO Accountability and Risk Exposure

Allegations of Sex Trafficking and Abuse

The Significance of Investigating Past Misconduct


 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Connect with Tom Fox
●      LinkedIn
●      Twitter
●      YouTube
●      Facebook
●      Instagram
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Nov 2023 04:00:00 -0000</pubDate>
      <itunes:title>The Hidden Dangers of CEO Behavior: Patterns and Consequences</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>101</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/9e3fe594-78ee-11ee-8975-bb494d4ae6b3/image/159033.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan look at the sordid case of ex-Abercrombie and Fitch CEO Mike Jeffries.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. We take things in a different direction today as we discuss the somewhat lurid allegations around former Abercrombie &amp; Fitch CEO Mike Jeffries. This matter illustrates the need for robust background checks and support of those who bring forward complaints against top management.
The topic of CEO risk, specifically the importance of accountability and investigations in corporate compliance, is a critical issue in today’s business world. It explores the potential dangers CEOs can pose to corporations and the necessity of holding them accountable for compliance initiatives. Tom Fox, a renowned compliance expert, emphasizes the importance of conducting thorough due diligence on individuals, particularly at the senior executive level, to mitigate risks. He believes that behavior patterns often exist before public scandals occur and that it is crucial to identify these patterns through deep investigations. On the other hand, Jonathan Armstrong highlights the challenge of pushing compliance up the organization and the need for thorough due diligence when hiring senior executives. He also stresses the importance of accountability and investigations in addressing misconduct allegations, even if they are historic. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic on this episode of the Life with GDPR podcast.

Key Takeaways:

CEO Accountability and Risk Exposure

Allegations of Sex Trafficking and Abuse

The Significance of Investigating Past Misconduct


 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Connect with Tom Fox
●      LinkedIn
●      Twitter
●      YouTube
●      Facebook
●      Instagram
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. We take things in a different direction today as we discuss the somewhat lurid allegations around former Abercrombie &amp; Fitch CEO Mike Jeffries. This matter illustrates the need for robust background checks and support of those who bring forward complaints against top management.</p><p class="ql-align-justify">The topic of CEO risk, specifically the importance of accountability and investigations in corporate compliance, is a critical issue in today’s business world. It explores the potential dangers CEOs can pose to corporations and the necessity of holding them accountable for compliance initiatives. Tom Fox, a renowned compliance expert, emphasizes the importance of conducting thorough due diligence on individuals, particularly at the senior executive level, to mitigate risks. He believes that behavior patterns often exist before public scandals occur and that it is crucial to identify these patterns through deep investigations. On the other hand, Jonathan Armstrong highlights the challenge of pushing compliance up the organization and the need for thorough due diligence when hiring senior executives. He also stresses the importance of accountability and investigations in addressing misconduct allegations, even if they are historic. Join Tom Fox and Jonathan Armstrong as they delve deeper into this topic on this episode of the Life with GDPR podcast.</p><p class="ql-align-justify"><br></p><p class="ql-align-justify"><strong>Key Takeaways:</strong></p><ul>
<li class="ql-align-justify">CEO Accountability and Risk Exposure</li>
<li class="ql-align-justify">Allegations of Sex Trafficking and Abuse</li>
<li class="ql-align-justify">The Significance of Investigating Past Misconduct</li>
</ul><p class="ql-align-justify"><br></p><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>●      <a href="https://www.twitter.com/tfoxlaw">Twitter</a></p><p>●      <a href="https://www.youtube.com/channel/UC0-IWb69P1srF_uZOmGtBfQ">YouTube</a></p><p>●      <a href="https://www.facebook.com/compliancepodcastnetwork">Facebook</a></p><p>●      <a href="https://www.instagram.com/voiceofcompliance">Instagram</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>923</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[9e3fe594-78ee-11ee-8975-bb494d4ae6b3]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7830472406.mp3?updated=1698918690" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>WhatsApp Breach: Hospital's GDPR Failures Exposed</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. The recent controversy surrounding Nigel Farage’s banking situation highlights the risks and compliance challenges faced by the banking industry in relation to data protection. In this episode, Tom and Jonathan discuss a data breach in a Scottish hospital during the COVID-19 pandemic.
The breach occurred when hospital staff shared patient details on WhatsApp, raising concerns about GDPR compliance. The hospital informed the ICO about the breach but chose not to notify affected patients, highlighting the need for appropriate advice and support when making such decisions. The conversation also explores communication challenges in internal investigations and the privacy and security risks of platforms like WhatsApp. It emphasizes the importance of organizations adapting to the preferences of digital native employees and conducting data protection impact assessments. The podcast also highlights the importance of effective policies, training, and proactive phishing training to prevent cyber-attacks and protect sensitive information.
Key Takeaways:
·      Data breach in Scottish hospital
·      The Challenges of Communication in Internal Investigations
·      Importance of Policies and Training
·      Phishing Training Effectiveness
 Resources:
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 14 Sep 2023 04:00:00 -0000</pubDate>
      <itunes:title>WhatsApp Breach: Hospital's GDPR Failures Exposed</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>100</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/7eece6c0-3c66-11ee-b141-dff54f0ca71f/image/159415.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan discuss a GDPR breach involving the use of WhatsApp.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. The recent controversy surrounding Nigel Farage’s banking situation highlights the risks and compliance challenges faced by the banking industry in relation to data protection. In this episode, Tom and Jonathan discuss a data breach in a Scottish hospital during the COVID-19 pandemic.
The breach occurred when hospital staff shared patient details on WhatsApp, raising concerns about GDPR compliance. The hospital informed the ICO about the breach but chose not to notify affected patients, highlighting the need for appropriate advice and support when making such decisions. The conversation also explores communication challenges in internal investigations and the privacy and security risks of platforms like WhatsApp. It emphasizes the importance of organizations adapting to the preferences of digital native employees and conducting data protection impact assessments. The podcast also highlights the importance of effective policies, training, and proactive phishing training to prevent cyber-attacks and protect sensitive information.
Key Takeaways:
·      Data breach in Scottish hospital
·      The Challenges of Communication in Internal Investigations
·      Importance of Policies and Training
·      Phishing Training Effectiveness
 Resources:
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. The recent controversy surrounding Nigel Farage’s banking situation highlights the risks and compliance challenges faced by the banking industry in relation to data protection. In this episode, Tom and Jonathan discuss a data breach in a Scottish hospital during the COVID-19 pandemic.</p><p class="ql-align-justify">The breach occurred when hospital staff shared patient details on WhatsApp, raising concerns about GDPR compliance. The hospital informed the ICO about the breach but chose not to notify affected patients, highlighting the need for appropriate advice and support when making such decisions. The conversation also explores communication challenges in internal investigations and the privacy and security risks of platforms like WhatsApp. It emphasizes the importance of organizations adapting to the preferences of digital native employees and conducting data protection impact assessments. The podcast also highlights the importance of effective policies, training, and proactive phishing training to prevent cyber-attacks and protect sensitive information.</p><p class="ql-align-justify"><strong>Key Takeaways:</strong></p><p class="ql-align-justify">·      Data breach in Scottish hospital</p><p class="ql-align-justify">·      The Challenges of Communication in Internal Investigations</p><p class="ql-align-justify">·      Importance of Policies and Training</p><p class="ql-align-justify">·      Phishing Training Effectiveness</p><p class="ql-align-justify"><strong> Resources:</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1065</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[7eece6c0-3c66-11ee-b141-dff54f0ca71f]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4145730225.mp3?updated=1694701000" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Exposed: The Shocking PSNI Data Release</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, Tom and Jonathan discuss a troubling inadvertent data release by the Police Service of Northern Ireland (PSNI).
The release occurred when a document containing sensitive information about PSNI employees was mistakenly uploaded to a public site, putting officers at risk. The document, inadvertently released based upon a valid FOIA request, wrongfully included the names, ranks, locations, and even surveillance and intelligence details from the Northern Ireland constabulary. This inadvertent release highlights how the bypassing of security checks the caused the breach, emphasizing the real-world impact of data breaches on individuals. Tom and Jonathan also discuss the use of spreadsheets in data breaches and express frustration with the lack of attention given to these incidents. Overall, the conversation stresses the importance of data protection and compliance, and the urgent need for improved measures to address this issue.
 Key Takeaways:
·      Data release at PSNI
·      Data release implications
·      Regulator's Call for Improved Data Protection
·      Spreadsheets are evil
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 31 Aug 2023 04:00:00 -0000</pubDate>
      <itunes:title>Exposed: The Shocking PSNI Data Release</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>99</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/278f4c92-3c4d-11ee-9f32-1f71d247296b/image/5d0c07.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan review a troubling inadvertent data release and how to protect yourself.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, Tom and Jonathan discuss a troubling inadvertent data release by the Police Service of Northern Ireland (PSNI).
The release occurred when a document containing sensitive information about PSNI employees was mistakenly uploaded to a public site, putting officers at risk. The document, inadvertently released based upon a valid FOIA request, wrongfully included the names, ranks, locations, and even surveillance and intelligence details from the Northern Ireland constabulary. This inadvertent release highlights how the bypassing of security checks the caused the breach, emphasizing the real-world impact of data breaches on individuals. Tom and Jonathan also discuss the use of spreadsheets in data breaches and express frustration with the lack of attention given to these incidents. Overall, the conversation stresses the importance of data protection and compliance, and the urgent need for improved measures to address this issue.
 Key Takeaways:
·      Data release at PSNI
·      Data release implications
·      Regulator's Call for Improved Data Protection
·      Spreadsheets are evil
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, Tom and Jonathan discuss a troubling inadvertent data release by the Police Service of Northern Ireland (PSNI).</p><p class="ql-align-justify">The release occurred when a document containing sensitive information about PSNI employees was mistakenly uploaded to a public site, putting officers at risk. The document, inadvertently released based upon a valid FOIA request, wrongfully included the names, ranks, locations, and even surveillance and intelligence details from the Northern Ireland constabulary. This inadvertent release highlights how the bypassing of security checks the caused the breach, emphasizing the real-world impact of data breaches on individuals. Tom and Jonathan also discuss the use of spreadsheets in data breaches and express frustration with the lack of attention given to these incidents. Overall, the conversation stresses the importance of data protection and compliance, and the urgent need for improved measures to address this issue.</p><p class="ql-align-justify"><strong> Key Takeaways:</strong></p><p class="ql-align-justify">·      Data release at PSNI</p><p class="ql-align-justify">·      Data release implications</p><p class="ql-align-justify">·      Regulator's Call for Improved Data Protection</p><p class="ql-align-justify">·      Spreadsheets are evil</p><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>926</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[278f4c92-3c4d-11ee-9f32-1f71d247296b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9156120572.mp3?updated=1692201568" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Farage's Account Closure &amp; the Risks of Data Breach</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. The recent controversy surrounding Nigel Farage's banking situation highlights the risks and compliance challenges faced by the banking industry in relation to data protection. 
In this episode, Tom and Jonathan discuss the closure of Farage's bank account with Coutts, a high-end bank owned by NatWest, and the potential data breach that ensued. They discuss the risks of internal emails being exposed through subject access requests (SARs) and emphasize the importance of caution in email communication. The conversation also explores the cost and consequences of non-compliance with GDPR obligations, particularly in relation to SARs. The potential legal implications for banks that violate their own policies or delete data that should be provided in response to a SAR are highlighted. Overall, the episode underscores the need for banks to prioritize data protection, compliance, and proper decision-making in the financial industry.
 Key Takeaways:
·      Nigel Farage's Banking Controversy
·      Data Protection Risks in Banking
·      The Cost and Consequences of Subject Access Requests
·      Serious concerns about data protection and access to banking
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 17 Aug 2023 04:00:00 -0000</pubDate>
      <itunes:title>Farage's Account Closure &amp; the Risks of Data Breach</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>98</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/d54fe884-3c32-11ee-9624-27615ac3c5ed/image/d8ed8f.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan discuss the closure of Nigel Farage's bank account with Coutts, a high-end bank owned by NatWest, and the potential data breach that ensued.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. The recent controversy surrounding Nigel Farage's banking situation highlights the risks and compliance challenges faced by the banking industry in relation to data protection. 
In this episode, Tom and Jonathan discuss the closure of Farage's bank account with Coutts, a high-end bank owned by NatWest, and the potential data breach that ensued. They discuss the risks of internal emails being exposed through subject access requests (SARs) and emphasize the importance of caution in email communication. The conversation also explores the cost and consequences of non-compliance with GDPR obligations, particularly in relation to SARs. The potential legal implications for banks that violate their own policies or delete data that should be provided in response to a SAR are highlighted. Overall, the episode underscores the need for banks to prioritize data protection, compliance, and proper decision-making in the financial industry.
 Key Takeaways:
·      Nigel Farage's Banking Controversy
·      Data Protection Risks in Banking
·      The Cost and Consequences of Subject Access Requests
·      Serious concerns about data protection and access to banking
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. The recent controversy surrounding Nigel Farage's banking situation highlights the risks and compliance challenges faced by the banking industry in relation to data protection. </p><p class="ql-align-justify">In this episode, Tom and Jonathan discuss the closure of Farage's bank account with Coutts, a high-end bank owned by NatWest, and the potential data breach that ensued. They discuss the risks of internal emails being exposed through subject access requests (SARs) and emphasize the importance of caution in email communication. The conversation also explores the cost and consequences of non-compliance with GDPR obligations, particularly in relation to SARs. The potential legal implications for banks that violate their own policies or delete data that should be provided in response to a SAR are highlighted. Overall, the episode underscores the need for banks to prioritize data protection, compliance, and proper decision-making in the financial industry.</p><p class="ql-align-justify"><strong> Key Takeaways:</strong></p><p class="ql-align-justify">·      Nigel Farage's Banking Controversy</p><p class="ql-align-justify">·      Data Protection Risks in Banking</p><p class="ql-align-justify">·      The Cost and Consequences of Subject Access Requests</p><p class="ql-align-justify">·      Serious concerns about data protection and access to banking</p><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1198</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[d54fe884-3c32-11ee-9624-27615ac3c5ed]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4179695390.mp3?updated=1692190364" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Joe Sullivan Sentence</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. Matt Kelly and Jonathan Marks join Tom and Jonathan Armstrong on this episode, as they explore the case of former Uber CISO Joe Sullivan and the lessons compliance officers can learn from his lenient sentence. From growing trends of personal accountability to conflict of interests, the hosts provide six tips for chief compliance officers to protect themselves, including rehearsing responses and seeking external advice when necessary. This eye-opening episode also delves into the challenges faced by compliance officers in situations like Etsy's ransomware scheme and how they must be cautious with threat actors' demands. Don't miss out on this insightful episode that will leave you questioning whether Sullivan was unfairly punished and whether executives' remuneration packages will receive greater scrutiny going forward. Tune in now to Life With GDPR.
 Key Takeaways:
·      The Joe Sullivan Uber Case and Lessons Learned
·      Individual Liability in Corporate Malpractice
·      Compensation and Conflicts of Interest
·      The Challenges of Compliance Officers in Wrongdoing Incidents
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 22 Jun 2023 04:00:00 -0000</pubDate>
      <itunes:title>Joe Sullivan Sentence</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>97</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/727a5d60-0e16-11ee-91c0-238dabe5718f/image/f22ad8.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Matt Kelly and Jonathan Marks join Jonathan and Tom to consider the Joe Sullivan Sentence.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. Matt Kelly and Jonathan Marks join Tom and Jonathan Armstrong on this episode, as they explore the case of former Uber CISO Joe Sullivan and the lessons compliance officers can learn from his lenient sentence. From growing trends of personal accountability to conflict of interests, the hosts provide six tips for chief compliance officers to protect themselves, including rehearsing responses and seeking external advice when necessary. This eye-opening episode also delves into the challenges faced by compliance officers in situations like Etsy's ransomware scheme and how they must be cautious with threat actors' demands. Don't miss out on this insightful episode that will leave you questioning whether Sullivan was unfairly punished and whether executives' remuneration packages will receive greater scrutiny going forward. Tune in now to Life With GDPR.
 Key Takeaways:
·      The Joe Sullivan Uber Case and Lessons Learned
·      Individual Liability in Corporate Malpractice
·      Compensation and Conflicts of Interest
·      The Challenges of Compliance Officers in Wrongdoing Incidents
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. Matt Kelly and Jonathan Marks join Tom and Jonathan Armstrong on this episode, as they explore the case of former Uber CISO Joe Sullivan and the lessons compliance officers can learn from his lenient sentence. From growing trends of personal accountability to conflict of interests, the hosts provide six tips for chief compliance officers to protect themselves, including rehearsing responses and seeking external advice when necessary. This eye-opening episode also delves into the challenges faced by compliance officers in situations like Etsy's ransomware scheme and how they must be cautious with threat actors' demands. Don't miss out on this insightful episode that will leave you questioning whether Sullivan was unfairly punished and whether executives' remuneration packages will receive greater scrutiny going forward. Tune in now to Life With GDPR.</p><p class="ql-align-justify"><strong> Key Takeaways:</strong></p><p class="ql-align-justify">·      The Joe Sullivan Uber Case and Lessons Learned</p><p class="ql-align-justify">·      Individual Liability in Corporate Malpractice</p><p class="ql-align-justify">·      Compensation and Conflicts of Interest</p><p class="ql-align-justify">·      The Challenges of Compliance Officers in Wrongdoing Incidents</p><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/ec-gdpr-0523-01/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1075</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[727a5d60-0e16-11ee-91c0-238dabe5718f]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5561854861.mp3?updated=1687120440" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>$1 Billion Fine: Meta's GDPR Violation</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss the recent billion-dollar fine imposed on Meta (formerly Facebook) for violating data protection laws. They break down the significance of this ruling which limits the use of standard contractual clauses and requires due diligence checks when transferring data from the EU to the US. Discover the consequences and potential appeal arguments of the European Court of Justice's ruling on data privacy. They delve into the challenges of harmonizing data protection authorities in the EU and how this affects corporations. Find out why the lack of consistency among regulators cannot be fixed overnight. Don't miss out on the engaging and informative discussion that can help organizations navigate the complex landscape of GDPR and data privacy. Tune in to "Life with GDPR" now!
 Key Takeaways:
·      Facebook fined $1 billion for data transfer
·      Meta's GDPR Noncompliance and Data Transfer Suspension
·      Irish Data Protection decision overruled by EDPB
·      Challenging GDPR court order in Ireland
·      Data Transfer from EU to US: Safe or Unsafe?
·      GDPR differences in privacy enforcement
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 08 Jun 2023 04:00:00 -0000</pubDate>
      <itunes:title>Meta's $1bn GDPR Violation</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>96</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/5db0926c-0585-11ee-bd7a-b78569ddf4be/image/f31a2e.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan consider the recent EU fine against Meta. </itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss the recent billion-dollar fine imposed on Meta (formerly Facebook) for violating data protection laws. They break down the significance of this ruling which limits the use of standard contractual clauses and requires due diligence checks when transferring data from the EU to the US. Discover the consequences and potential appeal arguments of the European Court of Justice's ruling on data privacy. They delve into the challenges of harmonizing data protection authorities in the EU and how this affects corporations. Find out why the lack of consistency among regulators cannot be fixed overnight. Don't miss out on the engaging and informative discussion that can help organizations navigate the complex landscape of GDPR and data privacy. Tune in to "Life with GDPR" now!
 Key Takeaways:
·      Facebook fined $1 billion for data transfer
·      Meta's GDPR Noncompliance and Data Transfer Suspension
·      Irish Data Protection decision overruled by EDPB
·      Challenging GDPR court order in Ireland
·      Data Transfer from EU to US: Safe or Unsafe?
·      GDPR differences in privacy enforcement
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the award-winning Life with GDPR. In this episode, they discuss the recent billion-dollar fine imposed on Meta (formerly Facebook) for violating data protection laws. They break down the significance of this ruling which limits the use of standard contractual clauses and requires due diligence checks when transferring data from the EU to the US. Discover the consequences and potential appeal arguments of the European Court of Justice's ruling on data privacy. They delve into the challenges of harmonizing data protection authorities in the EU and how this affects corporations. Find out why the lack of consistency among regulators cannot be fixed overnight. Don't miss out on the engaging and informative discussion that can help organizations navigate the complex landscape of GDPR and data privacy. Tune in to "Life with GDPR" now!</p><p class="ql-align-justify"><strong> Key Takeaways:</strong></p><p class="ql-align-justify">·      Facebook fined $1 billion for data transfer</p><p class="ql-align-justify">·      Meta's GDPR Noncompliance and Data Transfer Suspension</p><p class="ql-align-justify">·      Irish Data Protection decision overruled by EDPB</p><p class="ql-align-justify">·      Challenging GDPR court order in Ireland</p><p class="ql-align-justify">·      Data Transfer from EU to US: Safe or Unsafe?</p><p class="ql-align-justify">·      GDPR differences in privacy enforcement</p><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/meta-fines-0523-09/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1930</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[5db0926c-0585-11ee-bd7a-b78569ddf4be]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8029469643.mp3?updated=1686178386" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Class Action Update</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Join them in this episode as they discuss the recent court decision in the Austrian case and its implications on GDPR claims. Discover the guidelines for GDPR damage compensation, assessment of damages, liability provisions, and how businesses can make themselves more robust to avoid such claims. They also delve into the importance of acting quickly in the event of a breach and insurers’ sophistication in cyberattack policies. Tune in to learn more, and check out the article on the quarterly compliance website. Don’t miss out on their engaging conversation and valuable insights!
 Key Takeaways:

Understanding GDPR compensation claims

Insurance Claims and Breach Response Strategy

Cyber insurance is becoming more selective in writing cover


Notable Quotes:
“I would say when you have a title like that, you get the attention of many class action lawyers.”
“Not every infringement of GDPR automatically gives rise to compensation.”
“The right to compensation under GDPR needs 3 things. Firstly, an infringement of GDPR; secondly, material damage resulting; and thirdly, a causal link between the damage and the infringement.”
“If you haven’t got the right team in place, Even on New Year’s Day or Christmas day, Easter or Passover or, you know, during fasting, then that’s your fault, not ours, and regulators are not forgiving.”
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go to their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 25 May 2023 04:00:00 -0000</pubDate>
      <itunes:title>Class Action Update</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>95</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/bb30f51a-ee8f-11ed-afa8-abe868f5d8dc/image/48608d.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan are back with a Class Action Update.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Join them in this episode as they discuss the recent court decision in the Austrian case and its implications on GDPR claims. Discover the guidelines for GDPR damage compensation, assessment of damages, liability provisions, and how businesses can make themselves more robust to avoid such claims. They also delve into the importance of acting quickly in the event of a breach and insurers’ sophistication in cyberattack policies. Tune in to learn more, and check out the article on the quarterly compliance website. Don’t miss out on their engaging conversation and valuable insights!
 Key Takeaways:

Understanding GDPR compensation claims

Insurance Claims and Breach Response Strategy

Cyber insurance is becoming more selective in writing cover


Notable Quotes:
“I would say when you have a title like that, you get the attention of many class action lawyers.”
“Not every infringement of GDPR automatically gives rise to compensation.”
“The right to compensation under GDPR needs 3 things. Firstly, an infringement of GDPR; secondly, material damage resulting; and thirdly, a causal link between the damage and the infringement.”
“If you haven’t got the right team in place, Even on New Year’s Day or Christmas day, Easter or Passover or, you know, during fasting, then that’s your fault, not ours, and regulators are not forgiving.”
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go to their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Join them in this episode as they discuss the recent court decision in the Austrian case and its implications on GDPR claims. Discover the guidelines for GDPR damage compensation, assessment of damages, liability provisions, and how businesses can make themselves more robust to avoid such claims. They also delve into the importance of acting quickly in the event of a breach and insurers’ sophistication in cyberattack policies. Tune in to learn more, and check out the article on the quarterly compliance website. Don’t miss out on their engaging conversation and valuable insights!</p><p><strong> Key Takeaways:</strong></p><ul>
<li>Understanding GDPR compensation claims</li>
<li>Insurance Claims and Breach Response Strategy</li>
<li>Cyber insurance is becoming more selective in writing cover</li>
</ul><p><br></p><p><strong>Notable Quotes:</strong></p><p>“I would say when you have a title like that, you get the attention of many class action lawyers.”</p><p>“Not every infringement of GDPR automatically gives rise to compensation.”</p><p>“The right to compensation under GDPR needs 3 things. Firstly, an infringement of GDPR; secondly, material damage resulting; and thirdly, a causal link between the damage and the infringement.”</p><p class="ql-align-justify">“If you haven’t got the right team in place, Even on New Year’s Day or Christmas day, Easter or Passover or, you know, during fasting, then that’s your fault, not ours, and regulators are not forgiving.”</p><p class="ql-align-justify"><strong>Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/ec-gdpr-0523-01/">News Section</a>. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1344</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[bb30f51a-ee8f-11ed-afa8-abe868f5d8dc]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6936673540.mp3?updated=1685544447" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Data Transfer Update</title>
      <description>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Join them in this episode as they delve into the hot-button issue of data transfers from the EU to the US. With potential new rulings looming, the replacement for privacy shield is said to be doomed to fail. The European data protection board is investigating complaints against Google and Facebook that could affect up to 95% of US corporations using Google Analytics! How can your organization comply with GDPR regulations while avoiding the nearly €3 billion in fines levied since 2018, including practical tips such as conducting compliance checks and due diligence? Don't miss the explosive potential of this episode and what it could mean for businesses around the world.
Key Takeaways:
·      Data transfers from the EU to the US and privacy concerns
·      Data Transfer Regulations &amp; Compliance
·      Data Protection Compliance for Business Websites
·      Impending Large GDPR Fine
Notable Quotes:
"It is not going to get any easier anytime soon, unfortunately."
"This case is likely to affect, I think, 95% of corporate America."
"Regulators definitely have an appetite to investigate this."
"I expect that the find that I'm hearing rumors of will tip us over the €300MM level."
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go to their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 11 May 2023 15:43:07 -0000</pubDate>
      <itunes:title>Data Transfer Update</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>94</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/2a240e3e-f012-11ed-b1a4-b32535a9a17b/image/eafb1c.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan return to provide a data transfer update. </itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Join them in this episode as they delve into the hot-button issue of data transfers from the EU to the US. With potential new rulings looming, the replacement for privacy shield is said to be doomed to fail. The European data protection board is investigating complaints against Google and Facebook that could affect up to 95% of US corporations using Google Analytics! How can your organization comply with GDPR regulations while avoiding the nearly €3 billion in fines levied since 2018, including practical tips such as conducting compliance checks and due diligence? Don't miss the explosive potential of this episode and what it could mean for businesses around the world.
Key Takeaways:
·      Data transfers from the EU to the US and privacy concerns
·      Data Transfer Regulations &amp; Compliance
·      Data Protection Compliance for Business Websites
·      Impending Large GDPR Fine
Notable Quotes:
"It is not going to get any easier anytime soon, unfortunately."
"This case is likely to affect, I think, 95% of corporate America."
"Regulators definitely have an appetite to investigate this."
"I expect that the find that I'm hearing rumors of will tip us over the €300MM level."
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go to their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox and Jonathan Armstrong, renowned experts in cyber security, co-host the award-winning Life with GDPR. Join them in this episode as they delve into the hot-button issue of data transfers from the EU to the US. With potential new rulings looming, the replacement for privacy shield is said to be doomed to fail. The European data protection board is investigating complaints against Google and Facebook that could affect up to 95% of US corporations using Google Analytics! How can your organization comply with GDPR regulations while avoiding the nearly €3 billion in fines levied since 2018, including practical tips such as conducting compliance checks and due diligence? Don't miss the explosive potential of this episode and what it could mean for businesses around the world.</p><p>Key Takeaways:</p><p>·      Data transfers from the EU to the US and privacy concerns</p><p>·      Data Transfer Regulations &amp; Compliance</p><p>·      Data Protection Compliance for Business Websites</p><p>·      Impending Large GDPR Fine</p><p>Notable Quotes:</p><p>"It is not going to get any easier anytime soon, unfortunately."</p><p>"This case is likely to affect, I think, 95% of corporate America."</p><p>"Regulators definitely have an appetite to investigate this."</p><p>"I expect that the find that I'm hearing rumors of will tip us over the €300MM level."</p><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/eu-dpa-rr-0423-04-5/">News Section</a>. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1284</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[2a240e3e-f012-11ed-b1a4-b32535a9a17b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6242754606.mp3?updated=1683820091" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>DPO Update</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, host the award-winning Life with GDPR. In this episode, Tom and Jonathan discuss the role of the Data Protection Officer (DPO) in light of GDPR - an important requirement outlined in Article 37. They discuss how the European Court of Justice views the role, how Germany had a DPO system in place prior to GDPR  and the fact that DPOs should be supported by their employer and protected against any potential conflicts of interests. They touch on the shortage of suitable DPOs due to the price and resource requirements of the role, as well as the example of a data protection authority showing up to an organization and finding a person who had been recently trained. Tune in to discover more key insights about the role of the DPO as you stay knowledgeable on GDPR compliance with Live with GDPR.
Key Takeaways:
European Court of Justice and the GDPR System [00:05:46]
DPO Roles and Responsibilities [00:10:50]
Data Protection Authority Visit to an Organization [00:15:26]
Notable Quotes:
1.     “The Role of a DPO in simple terms is to sort of act as a sort of police officer to police the organization's handling of data.” 
2.     “If you look at GDPR article 37 5, it says that a data protection officer must be designated on the basis of professional qualities. In particular, expert knowledge of data protection law and practices, and there's a number of duties in Article 39 they have to be able to perform.”
3.     “Regulators will expect to see competency. And it's probably easier for a regulator to judge competency than it is to judge conflict of interest.”
4.     “I think it is definitely worthwhile putting resources in training and also currency.”
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 23 Mar 2023 04:00:00 -0000</pubDate>
      <itunes:title>DPO Update</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>93</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/f83a6e94-c75e-11ed-bf1b-434b407d686d/image/4188e4.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan provide an update on the rights, roles and responsibilities of DPOs. </itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, host the award-winning Life with GDPR. In this episode, Tom and Jonathan discuss the role of the Data Protection Officer (DPO) in light of GDPR - an important requirement outlined in Article 37. They discuss how the European Court of Justice views the role, how Germany had a DPO system in place prior to GDPR  and the fact that DPOs should be supported by their employer and protected against any potential conflicts of interests. They touch on the shortage of suitable DPOs due to the price and resource requirements of the role, as well as the example of a data protection authority showing up to an organization and finding a person who had been recently trained. Tune in to discover more key insights about the role of the DPO as you stay knowledgeable on GDPR compliance with Live with GDPR.
Key Takeaways:
European Court of Justice and the GDPR System [00:05:46]
DPO Roles and Responsibilities [00:10:50]
Data Protection Authority Visit to an Organization [00:15:26]
Notable Quotes:
1.     “The Role of a DPO in simple terms is to sort of act as a sort of police officer to police the organization's handling of data.” 
2.     “If you look at GDPR article 37 5, it says that a data protection officer must be designated on the basis of professional qualities. In particular, expert knowledge of data protection law and practices, and there's a number of duties in Article 39 they have to be able to perform.”
3.     “Regulators will expect to see competency. And it's probably easier for a regulator to judge competency than it is to judge conflict of interest.”
4.     “I think it is definitely worthwhile putting resources in training and also currency.”
 Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, host the award-winning Life with GDPR. In this episode, Tom and Jonathan discuss the role of the Data Protection Officer (DPO) in light of GDPR - an important requirement outlined in Article 37. They discuss how the European Court of Justice views the role, how Germany had a DPO system in place prior to GDPR  and the fact that DPOs should be supported by their employer and protected against any potential conflicts of interests. They touch on the shortage of suitable DPOs due to the price and resource requirements of the role, as well as the example of a data protection authority showing up to an organization and finding a person who had been recently trained. Tune in to discover more key insights about the role of the DPO as you stay knowledgeable on GDPR compliance with Live with GDPR.</p><p class="ql-align-justify"><strong>Key Takeaways:</strong></p><p class="ql-align-justify">European Court of Justice and the GDPR System [00:05:46]</p><p class="ql-align-justify">DPO Roles and Responsibilities [00:10:50]</p><p class="ql-align-justify">Data Protection Authority Visit to an Organization [00:15:26]</p><p class="ql-align-justify"><strong>Notable Quotes:</strong></p><p class="ql-align-justify">1.     “The Role of a DPO in simple terms is to sort of act as a sort of police officer to police the organization's handling of data.” </p><p class="ql-align-justify">2.     “If you look at GDPR article 37 5, it says that a data protection officer must be designated on the basis of professional qualities. In particular, expert knowledge of data protection law and practices, and there's a number of duties in Article 39 they have to be able to perform.”</p><p class="ql-align-justify">3.     “Regulators will expect to see competency. And it's probably easier for a regulator to judge competency than it is to judge conflict of interest.”</p><p class="ql-align-justify">4.     “I think it is definitely worthwhile putting resources in training and also currency.”</p><p class="ql-align-justify"><strong> Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/ecr-dpo-0223/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1284</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[f83a6e94-c75e-11ed-bf1b-434b407d686d]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8146781412.mp3?updated=1679344922" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>SARs Update</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, host the award-winning Life with GDPR. In this episode, Jonathan Armstrong shares that SARs remain a significant area of concern for businesses. He joins Tom to discuss a recent individual’s complaint with the Austrian DPA, in which the response was incomplete and the individual took their case to an Austrian Federal Administrative Court. Jonathan shares that this tactic is being used by those under regulatory and governmental investigation. Tom and Jonathan's insight is invaluable for staying informed of the most up-to-date news on SARs.
 Key Highlights
·      Challenges of Filing Data Protection Complaints in Austria [00:057]
·      Legal Implications of Acquiring a Business Under Regulatory or Governmental Investigation [00:11:03]
·      Ending a Podcast[00:15:50]
Notable Quotes
1.     "We know that SARS are onerous, and it may be that the GIST route might be a way of saving some of the effort involved, not in searching for data necessarily, but in the whole redaction task, which is substantial because obviously you have to redact records so as not to expose the data of other individuals in many cases." 
2.     "And the officer stream result also seems to be in accordance with guidance from other DPAs as well. So probably the right decisions in both cases but obviously still some complexity involved in dealing with hours." 
3.     "We've definitely seen [SARs] in the context of regulatory or other governmental investigation. There are the cases in the public domain, for example, which is a case, which involves Russian oligarchs battling it out in the UK courts after group a investigated group b."
4.     "And as I say, we've used the gist route previously. We know that people have complained to the ICR to other regulators but so far, that hasn't been anything that regulators criticized in the cases that we've been involved with.""
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 09 Mar 2023 05:00:00 -0000</pubDate>
      <itunes:title>SARs Update</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>92</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/903b8a7a-b93b-11ed-9081-3f74e8db5484/image/828201.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode Tom and Jonathan provide a SARs Update.</itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, host the award-winning Life with GDPR. In this episode, Jonathan Armstrong shares that SARs remain a significant area of concern for businesses. He joins Tom to discuss a recent individual’s complaint with the Austrian DPA, in which the response was incomplete and the individual took their case to an Austrian Federal Administrative Court. Jonathan shares that this tactic is being used by those under regulatory and governmental investigation. Tom and Jonathan's insight is invaluable for staying informed of the most up-to-date news on SARs.
 Key Highlights
·      Challenges of Filing Data Protection Complaints in Austria [00:057]
·      Legal Implications of Acquiring a Business Under Regulatory or Governmental Investigation [00:11:03]
·      Ending a Podcast[00:15:50]
Notable Quotes
1.     "We know that SARS are onerous, and it may be that the GIST route might be a way of saving some of the effort involved, not in searching for data necessarily, but in the whole redaction task, which is substantial because obviously you have to redact records so as not to expose the data of other individuals in many cases." 
2.     "And the officer stream result also seems to be in accordance with guidance from other DPAs as well. So probably the right decisions in both cases but obviously still some complexity involved in dealing with hours." 
3.     "We've definitely seen [SARs] in the context of regulatory or other governmental investigation. There are the cases in the public domain, for example, which is a case, which involves Russian oligarchs battling it out in the UK courts after group a investigated group b."
4.     "And as I say, we've used the gist route previously. We know that people have complained to the ICR to other regulators but so far, that hasn't been anything that regulators criticized in the cases that we've been involved with.""
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, host the award-winning Life with GDPR. In this episode, Jonathan Armstrong shares that SARs remain a significant area of concern for businesses. He joins Tom to discuss a recent individual’s complaint with the Austrian DPA, in which the response was incomplete and the individual took their case to an Austrian Federal Administrative Court. Jonathan shares that this tactic is being used by those under regulatory and governmental investigation. Tom and Jonathan's insight is invaluable for staying informed of the most up-to-date news on SARs.</p><p class="ql-align-justify"><strong> Key Highlights</strong></p><p class="ql-align-justify">·      Challenges of Filing Data Protection Complaints in Austria [00:057]</p><p class="ql-align-justify">·      Legal Implications of Acquiring a Business Under Regulatory or Governmental Investigation [00:11:03]</p><p class="ql-align-justify">·      Ending a Podcast[00:15:50]</p><p class="ql-align-justify"><strong>Notable Quotes</strong></p><p class="ql-align-justify">1.     "We know that SARS are onerous, and it may be that the GIST route might be a way of saving some of the effort involved, not in searching for data necessarily, but in the whole redaction task, which is substantial because obviously you have to redact records so as not to expose the data of other individuals in many cases." </p><p class="ql-align-justify">2.     "And the officer stream result also seems to be in accordance with guidance from other DPAs as well. So probably the right decisions in both cases but obviously still some complexity involved in dealing with hours." </p><p class="ql-align-justify">3.     "We've definitely seen [SARs] in the context of regulatory or other governmental investigation. There are the cases in the public domain, for example, which is a case, which involves Russian oligarchs battling it out in the UK courts after group a investigated group b."</p><p class="ql-align-justify">4.     "And as I say, we've used the gist route previously. We know that people have complained to the ICR to other regulators but so far, that hasn't been anything that regulators criticized in the cases that we've been involved with.""</p><p class="ql-align-justify"><strong>Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/eu-gdpr-sar-0223/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1048</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[903b8a7a-b93b-11ed-9081-3f74e8db5484]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8662617075.mp3?updated=1677790830" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Russian Cyber Attack Gangs Sanctioned</title>
      <description>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the podcast Life with GDPR. In the most recent episode, they review the recent sanctions the UK and US have imposed on seven Russia-based individuals linked to ransomware. They explain that there are around 20-30 known vulnerabilities in software that could be responsible for the majority of ransomware attacks, and if these are taken care of, individuals and organizations are less likely to become susceptible. Finally, the host delve into how some ransomware attackers may become public about their actions in order to try and make those affected pay up. Listen to Life with GDPR for the most up-to-date and helpful advice about cyber security and ransomware.
 Key Highlights
·      Sanctions levied against Russian cyber-attack gangs [00:01:28]
·      Steps to take to Protect Against Ransomware Attacks [00:06:12] 
·      The Dangers of Ransomware Attacks [00:10:49]
 Notable Quotes
1.     "Sanctioning ransomware gangs is not especially new. The US has done it before, but this is a move that's a giant move from the UK and the US to sanction 7 Russia based individuals." 
2.     "It's good business sense to payers because x is less than y. So just because GDPR is on the agenda of ransomware gangs, it obviously means that organizations have to take that much more seriously because ransomware gangs trying to push GDPR figures." 
3.     "Have a plan to deal with ransomware. It is inevitable a ball that somebody will target you. Maybe create a playbox so that you can work through key considerations in add advance." 
4.     "You're only as strong as your weaker link. And oftentimes, it is suppliers, HR providers, payroll providers, outsourced sales solutions that are a real area of vulnerability.""
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Mar 2023 05:00:00 -0000</pubDate>
      <itunes:title>Russian Cyber Attack Gangs Sanctioned</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>91</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/75653530-b6d8-11ed-b463-ef3d1ab04d62/image/b8023a.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan look at issues around Russian cyber attack gangs. </itunes:subtitle>
      <itunes:summary>Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the podcast Life with GDPR. In the most recent episode, they review the recent sanctions the UK and US have imposed on seven Russia-based individuals linked to ransomware. They explain that there are around 20-30 known vulnerabilities in software that could be responsible for the majority of ransomware attacks, and if these are taken care of, individuals and organizations are less likely to become susceptible. Finally, the host delve into how some ransomware attackers may become public about their actions in order to try and make those affected pay up. Listen to Life with GDPR for the most up-to-date and helpful advice about cyber security and ransomware.
 Key Highlights
·      Sanctions levied against Russian cyber-attack gangs [00:01:28]
·      Steps to take to Protect Against Ransomware Attacks [00:06:12] 
·      The Dangers of Ransomware Attacks [00:10:49]
 Notable Quotes
1.     "Sanctioning ransomware gangs is not especially new. The US has done it before, but this is a move that's a giant move from the UK and the US to sanction 7 Russia based individuals." 
2.     "It's good business sense to payers because x is less than y. So just because GDPR is on the agenda of ransomware gangs, it obviously means that organizations have to take that much more seriously because ransomware gangs trying to push GDPR figures." 
3.     "Have a plan to deal with ransomware. It is inevitable a ball that somebody will target you. Maybe create a playbox so that you can work through key considerations in add advance." 
4.     "You're only as strong as your weaker link. And oftentimes, it is suppliers, HR providers, payroll providers, outsourced sales solutions that are a real area of vulnerability.""
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here. 
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p class="ql-align-justify">Tom Fox and Jonathan Armstrong, renowned expert in cyber security, co-host the podcast Life with GDPR. In the most recent episode, they review the recent sanctions the UK and US have imposed on seven Russia-based individuals linked to ransomware. They explain that there are around 20-30 known vulnerabilities in software that could be responsible for the majority of ransomware attacks, and if these are taken care of, individuals and organizations are less likely to become susceptible. Finally, the host delve into how some ransomware attackers may become public about their actions in order to try and make those affected pay up. Listen to Life with GDPR for the most up-to-date and helpful advice about cyber security and ransomware.</p><p class="ql-align-justify"><strong> Key Highlights</strong></p><p class="ql-align-justify">·      Sanctions levied against Russian cyber-attack gangs [00:01:28]</p><p class="ql-align-justify">·      Steps to take to Protect Against Ransomware Attacks [00:06:12] </p><p class="ql-align-justify">·      The Dangers of Ransomware Attacks [00:10:49]</p><p class="ql-align-justify"><strong> Notable Quotes</strong></p><p class="ql-align-justify">1.     "Sanctioning ransomware gangs is not especially new. The US has done it before, but this is a move that's a giant move from the UK and the US to sanction 7 Russia based individuals." </p><p class="ql-align-justify">2.     "It's good business sense to payers because x is less than y. So just because GDPR is on the agenda of ransomware gangs, it obviously means that organizations have to take that much more seriously because ransomware gangs trying to push GDPR figures." </p><p class="ql-align-justify">3.     "Have a plan to deal with ransomware. It is inevitable a ball that somebody will target you. Maybe create a playbox so that you can work through key considerations in add advance." </p><p class="ql-align-justify">4.     "You're only as strong as your weaker link. And oftentimes, it is suppliers, HR providers, payroll providers, outsourced sales solutions that are a real area of vulnerability.""</p><p class="ql-align-justify"><strong>Resources</strong></p><p class="ql-align-justify">For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/rr-gangs-sanction-0223/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>. </p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>986</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[75653530-b6d8-11ed-b463-ef3d1ab04d62]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1638811448.mp3?updated=1677532172" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>NIS II</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we take up NIS II and are pleased to be joined by Jonathan Marks and Matt Kelly for a robust conversation.
Highlights include:

What is NIS II and how does it differ from NIS I?

NIS II governs by sectors.

What are the implications for global companies?

Where can you go for more information.

 
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn


Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 16 Feb 2023 05:00:00 -0000</pubDate>
      <itunes:title>NIS II</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>90</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/1cfbb6ec-aaff-11ed-a74d-2f943a238353/image/da67e2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan are joined by Matt Kelly and Jonathan Marks to review NIS II.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we take up NIS II and are pleased to be joined by Jonathan Marks and Matt Kelly for a robust conversation.
Highlights include:

What is NIS II and how does it differ from NIS I?

NIS II governs by sectors.

What are the implications for global companies?

Where can you go for more information.

 
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Connect with Tom Fox
LinkedIn
Connect with Jonathan Armstrong

Twitter

LinkedIn


Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we take up NIS II and are pleased to be joined by Jonathan Marks and Matt Kelly for a robust conversation.</p><p>Highlights include:</p><ul>
<li>What is NIS II and how does it differ from NIS I?</li>
<li>NIS II governs by sectors.</li>
<li>What are the implications for global companies?</li>
<li>Where can you go for more information.</li>
</ul><p> </p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/eu-nis2-cyber-rules-1/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p>Connect with Tom Fox</p><ul><li><a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></li></ul><p>Connect with Jonathan Armstrong</p><ul>
<li><a href="https://twitter.com/armstrongjp">Twitter</a></li>
<li><a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></li>
</ul><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1131</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[1cfbb6ec-aaff-11ed-a74d-2f943a238353]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4661659067.mp3?updated=1676226222" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Cookies, Cookies &amp; More Cookies</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. Data protection has become a priority for many authorities with the French regulator, CNIL,  recently issuing fines and penalties to Microsoft for not complying with the data protection laws. Changes were made to their practices in March 2022, and similar action was taken against Google and Amazon.
In this episode, we discuss the regulatory landscape for cookies which has become difficult for businesses to maneuver, requiring board-level oversight of data privacy, data protection, and data security. Together, these measures are deemed necessary in order to mitigate the biggest risks to organizations. Max Schrems and his pressure group were two of the key adjutants and had filed a substantial number of complaints. This eventually led to a large fine at the end of 2022, announced this month, from CNIL, the French Data Protection Regulator, against Microsoft, for €60 million. This fine highlighted the fact that cookies had been on the agenda for many Data Protection Authorities and the severity of the consequences for not following GDPR requirements. The implications of this case will have a lasting effect on the relations between European Data Protection Authorities and corporations, as well as the resources necessary to stay compliant.
Highlights include:
·      [00:04:16] Microsoft's Changes to Cookie Practices
·      [00:09:21] Navigating Regulatory Landscapes for Businesses
·      [00:14:21] The Importance of Data Privacy Board Oversight
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Feb 2023 05:00:00 -0000</pubDate>
      <itunes:title>Cookies, Cookies &amp; More Cookies</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>89</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/703a7ed2-a23b-11ed-a305-f7b5dcc8240b/image/491cdc.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan review the CNIL enforcement action against Microsoft for violation of its cookie policies. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. Data protection has become a priority for many authorities with the French regulator, CNIL,  recently issuing fines and penalties to Microsoft for not complying with the data protection laws. Changes were made to their practices in March 2022, and similar action was taken against Google and Amazon.
In this episode, we discuss the regulatory landscape for cookies which has become difficult for businesses to maneuver, requiring board-level oversight of data privacy, data protection, and data security. Together, these measures are deemed necessary in order to mitigate the biggest risks to organizations. Max Schrems and his pressure group were two of the key adjutants and had filed a substantial number of complaints. This eventually led to a large fine at the end of 2022, announced this month, from CNIL, the French Data Protection Regulator, against Microsoft, for €60 million. This fine highlighted the fact that cookies had been on the agenda for many Data Protection Authorities and the severity of the consequences for not following GDPR requirements. The implications of this case will have a lasting effect on the relations between European Data Protection Authorities and corporations, as well as the resources necessary to stay compliant.
Highlights include:
·      [00:04:16] Microsoft's Changes to Cookie Practices
·      [00:09:21] Navigating Regulatory Landscapes for Businesses
·      [00:14:21] The Importance of Data Privacy Board Oversight
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Connect with Tom Fox
●      LinkedIn
Connect with Jonathan Armstrong
●      Twitter
●      LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. Data protection has become a priority for many authorities with the French regulator, CNIL,  recently issuing fines and penalties to Microsoft for not complying with the data protection laws. Changes were made to their practices in March 2022, and similar action was taken against Google and Amazon.</p><p>In this episode, we discuss the regulatory landscape for cookies which has become difficult for businesses to maneuver, requiring board-level oversight of data privacy, data protection, and data security. Together, these measures are deemed necessary in order to mitigate the biggest risks to organizations. Max Schrems and his pressure group were two of the key adjutants and had filed a substantial number of complaints. This eventually led to a large fine at the end of 2022, announced this month, from CNIL, the French Data Protection Regulator, against Microsoft, for €60 million. This fine highlighted the fact that cookies had been on the agenda for many Data Protection Authorities and the severity of the consequences for not following GDPR requirements. The implications of this case will have a lasting effect on the relations between European Data Protection Authorities and corporations, as well as the resources necessary to stay compliant.</p><p>Highlights include:</p><p>·      [00:04:16] Microsoft's Changes to Cookie Practices</p><p>·      [00:09:21] Navigating Regulatory Landscapes for Businesses</p><p>·      [00:14:21] The Importance of Data Privacy Board Oversight</p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/ireland-fines-meta-fb-insta-3/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p>Connect with Tom Fox</p><p>●      <a href="https://www.linkedin.com/in/thomasfox13/">LinkedIn</a></p><p>Connect with Jonathan Armstrong</p><p>●      <a href="https://twitter.com/armstrongjp">Twitter</a></p><p>●      <a href="https://www.linkedin.com/in/jparmstrong/?originalSubdomain=uk">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1302</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[703a7ed2-a23b-11ed-a305-f7b5dcc8240b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8201189475.mp3?updated=1675262420" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Meta Fined In Ireland</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recently released find by the Ireland Data Protection Commission against Meta for two legacy companies, €210m for its Facebook operation and €180m for Instagram for GDPR breaches.  The DPC also ordered Meta to change its data protection practices within three months.  Those changes may have more lasting effect on Meta than the fines.  The two fines come in at fifth and sixth places respectively in the largest GDPR fines of all time .   Some of the highlights  include: 
1.     What were the facts?
2.     Why this matter has far wider implications that simply Big Tech.
3.     Max Schrems says this is a huge blow for Meta.
4.     The convoluted appeal process going forward.
5.     Lessons learned. 
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 19 Jan 2023 05:00:00 -0000</pubDate>
      <itunes:title>Meta Fined In Ireland</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>88</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/0d82d5a2-9799-11ed-abac-aff0d07dd383/image/c6a9d9.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan look at the Ireland DPC fine against Meta. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recently released find by the Ireland Data Protection Commission against Meta for two legacy companies, €210m for its Facebook operation and €180m for Instagram for GDPR breaches.  The DPC also ordered Meta to change its data protection practices within three months.  Those changes may have more lasting effect on Meta than the fines.  The two fines come in at fifth and sixth places respectively in the largest GDPR fines of all time .   Some of the highlights  include: 
1.     What were the facts?
2.     Why this matter has far wider implications that simply Big Tech.
3.     Max Schrems says this is a huge blow for Meta.
4.     The convoluted appeal process going forward.
5.     Lessons learned. 
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recently released find by the Ireland Data Protection Commission against Meta for two legacy companies, €210m for its Facebook operation and €180m for Instagram for GDPR breaches.  The DPC also ordered Meta to change its data protection practices within three months.  Those changes may have more lasting effect on Meta than the fines.  The two fines come in at fifth and sixth places respectively in the largest GDPR fines of all time .   Some of the highlights  include: </p><p>1.     What were the facts?</p><p>2.     Why this matter has far wider implications that simply Big Tech.</p><p>3.     Max Schrems says this is a huge blow for Meta.</p><p>4.     The convoluted appeal process going forward.</p><p>5.     Lessons learned. </p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/ireland-fines-meta-fb-insta-3/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1452</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[0d82d5a2-9799-11ed-abac-aff0d07dd383]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8478427396.mp3?updated=1674094838" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The ABB Enforcement Action from a UK Perspective</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent ABB Foreign Corrupt Practices Act resolution. Jonathan considers the ABB enforcement action from the UK perspective and opines how a UK judge might consider the company’s recidivism differently than the DOJ did. He rants about ongoing tech scams.   Some of the highlights  include: 
1.     What were the facts?
2.     How would UK court’s view recidivist behavior under the UK Bribery Act?
3.     Where was the SFO?
4.     What is the status of the investigation in Germany?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 05 Jan 2023 05:00:00 -0000</pubDate>
      <itunes:title>The ABB Enforcement Action from a UK Perspective</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>87</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/aef66a9c-8c3c-11ed-83ee-9bb6d59cc296/image/bfb3a3.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan look at the ABB resolution from the UK perspective. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent ABB Foreign Corrupt Practices Act resolution. Jonathan considers the ABB enforcement action from the UK perspective and opines how a UK judge might consider the company’s recidivism differently than the DOJ did. He rants about ongoing tech scams.   Some of the highlights  include: 
1.     What were the facts?
2.     How would UK court’s view recidivist behavior under the UK Bribery Act?
3.     Where was the SFO?
4.     What is the status of the investigation in Germany?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent ABB Foreign Corrupt Practices Act resolution. Jonathan considers the ABB enforcement action from the UK perspective and opines how a UK judge might consider the company’s recidivism differently than the DOJ did. He rants about ongoing tech scams.   Some of the highlights  include: </p><p>1.     What were the facts?</p><p>2.     How would UK court’s view recidivist behavior under the UK Bribery Act?</p><p>3.     Where was the SFO?</p><p>4.     What is the status of the investigation in Germany?</p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/js-case-gdpr1/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>837</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[aef66a9c-8c3c-11ed-83ee-9bb6d59cc296]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1883027780.mp3?updated=1672845481" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Sullivan Conviction from GDPR Perspective</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent conviction of Joe Sullivan former CISO at Uber for his role in hiding a data breach which hit the company. Sullivan was convicted in the US in October 2022 in connection with an investigation into a ransomware attack on Uber in 2016. However, we look at the conviction from the GDPR and UK perspective and ask does it portend potential liability for CISOs and CCOs in the EU and UK.  For instance, does this mean that there are likely to be more prosecutions against executives?  And could we see similar prosecutions in Europe? For a more detailed discussion and links to the case, check out the Cordery Compliance News Alert on the case, which you can find in the link below.  Some of the highlights  include: 
1.     What were the facts?
2.     Was Sullivan guilty of negligence or intentional conduct?
3.     Why were prior Uber convictions so significant?
4.     What happens next?
5.     Could this lead to more prosecutions of executives?
6.     What does this mean under GDPR and in the UK?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 15 Dec 2022 05:00:00 -0000</pubDate>
      <itunes:title>Sullivan Conviction from GDPR Perspective</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>86</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/17fd3a44-7aee-11ed-b7c7-53d304769918/image/ea2f2e.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan return to look at the conviction of former Uber CISO Joe Sullivan. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent conviction of Joe Sullivan former CISO at Uber for his role in hiding a data breach which hit the company. Sullivan was convicted in the US in October 2022 in connection with an investigation into a ransomware attack on Uber in 2016. However, we look at the conviction from the GDPR and UK perspective and ask does it portend potential liability for CISOs and CCOs in the EU and UK.  For instance, does this mean that there are likely to be more prosecutions against executives?  And could we see similar prosecutions in Europe? For a more detailed discussion and links to the case, check out the Cordery Compliance News Alert on the case, which you can find in the link below.  Some of the highlights  include: 
1.     What were the facts?
2.     Was Sullivan guilty of negligence or intentional conduct?
3.     Why were prior Uber convictions so significant?
4.     What happens next?
5.     Could this lead to more prosecutions of executives?
6.     What does this mean under GDPR and in the UK?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent conviction of Joe Sullivan former CISO at Uber for his role in hiding a data breach which hit the company. Sullivan was convicted in the US in October 2022 in connection with an investigation into a ransomware attack on Uber in 2016. However, we look at the conviction from the GDPR and UK perspective and ask does it portend potential liability for CISOs and CCOs in the EU and UK.  For instance, does this mean that there are likely to be more prosecutions against executives?  And could we see similar prosecutions in Europe? For a more detailed discussion and links to the case, check out the Cordery Compliance News Alert on the case, which you can find in the link below.  Some of the highlights  include: </p><p>1.     What were the facts?</p><p>2.     Was Sullivan guilty of negligence or intentional conduct?</p><p>3.     Why were prior Uber convictions so significant?</p><p>4.     What happens next?</p><p>5.     Could this lead to more prosecutions of executives?</p><p>6.     What does this mean under GDPR and in the UK?</p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/js-case-gdpr1/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1207</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[17fd3a44-7aee-11ed-b7c7-53d304769918]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3609429069.mp3?updated=1670975948" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>ICO Gets Serious About Subject Access Requests</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent action by the ICO against seven UK organizations that failed to respond to Subject Access Requests (SAR), which follows a trend across Europe of more enforcement action on SAR. Some of the highlights  include: 
1.     What is a Subject Access Request (SAR)?
2.     Why are these companies in the ‘Naughty Corner.’
3.     How does this follow a trend across Europe of more enforcement action on SAR? 
4.     What happens next?
5.     Who is the constituency for change in the SAR process in the UK?
6.     What are the lessons learned?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 27 Oct 2022 04:00:00 -0000</pubDate>
      <itunes:title>ICO Gets Serious About Subject Access Requests</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>85</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/7bb10030-4f0a-11ed-9937-af913e1ba80b/image/9f4e1d.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we discuss the recent action by the ICO against seven UK organizations who failed to respond to Subject Access Requests,</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent action by the ICO against seven UK organizations that failed to respond to Subject Access Requests (SAR), which follows a trend across Europe of more enforcement action on SAR. Some of the highlights  include: 
1.     What is a Subject Access Request (SAR)?
2.     Why are these companies in the ‘Naughty Corner.’
3.     How does this follow a trend across Europe of more enforcement action on SAR? 
4.     What happens next?
5.     Who is the constituency for change in the SAR process in the UK?
6.     What are the lessons learned?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent action by the ICO against seven UK organizations that failed to respond to Subject Access Requests (SAR), which follows a trend across Europe of more enforcement action on SAR. Some of the highlights  include: </p><p>1.     What is a Subject Access Request (SAR)?</p><p>2.     Why are these companies in the ‘Naughty Corner.’</p><p>3.     How does this follow a trend across Europe of more enforcement action on SAR? </p><p>4.     What happens next?</p><p>5.     Who is the constituency for change in the SAR process in the UK?</p><p>6.     What are the lessons learned?</p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance <a href="https://www.corderycompliance.com/ico-sar-uk1/">News Section</a>. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>960</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[7bb10030-4f0a-11ed-9937-af913e1ba80b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1817344766.mp3?updated=1666797013" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Meta Fined €405 million by Irish Data Protection Commission   </title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent fine by the Irish Data Protection Commission levied against Meta for €405 million for Instagram Data Protection Infringements. Some of the highlights  include: 
1.     What is the background to the case?
2.     What was the basis for the fine?
3.     What happens next?
4.     What did other national agencies and commission, particularly the EDPB say?
5.     What are the lessons learned?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 20 Oct 2022 04:00:00 -0000</pubDate>
      <itunes:title>Meta Fined €405 million</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>84</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/9bafce7e-4f01-11ed-9bed-7f63916f0160/image/e5c0bf.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we discuss the recent fine by the Irish Data Protection Commission levied against Meta for €405 million for Instagram Data Protection Infringements. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent fine by the Irish Data Protection Commission levied against Meta for €405 million for Instagram Data Protection Infringements. Some of the highlights  include: 
1.     What is the background to the case?
2.     What was the basis for the fine?
3.     What happens next?
4.     What did other national agencies and commission, particularly the EDPB say?
5.     What are the lessons learned?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the recent fine by the Irish Data Protection Commission levied against Meta for €405 million for Instagram Data Protection Infringements. Some of the highlights  include: </p><p>1.     What is the background to the case?</p><p>2.     What was the basis for the fine?</p><p>3.     What happens next?</p><p>4.     What did other national agencies and commission, particularly the EDPB say?</p><p>5.     What are the lessons learned?</p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/ireland-fines-meta-dp/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1204</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[9bafce7e-4f01-11ed-9bed-7f63916f0160]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7038772954.mp3?updated=1666116508" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>US Response to GDPR Data Flow Protections</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the US/EU/UK agreement for data transfer from the EU/UK to the United States under the Data Protection Framework. Some of the highlights  include:
1.     What is the Data Protection Framework?
2.     How will the Data Protection Review Court work?
3.     What dare the safeguards around the US national security review be?
4.     What happens next?
5.     What are the views of Max Schrems?
6.     Will there be an EU/UK split?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 13 Oct 2022 04:00:00 -0000</pubDate>
      <itunes:title>US Response to GDPR Data Flow Protections</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>83</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/f6396764-48ea-11ed-b698-e32c625345f6/image/326e16.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan return to look at the US/EU/UK agreement for transfer of data to the United States under the Data Protection Framework. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the US/EU/UK agreement for data transfer from the EU/UK to the United States under the Data Protection Framework. Some of the highlights  include:
1.     What is the Data Protection Framework?
2.     How will the Data Protection Review Court work?
3.     What dare the safeguards around the US national security review be?
4.     What happens next?
5.     What are the views of Max Schrems?
6.     Will there be an EU/UK split?
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance News Section. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of the award-winning Life with GDPR. In this episode, we discuss the US/EU/UK agreement for data transfer from the EU/UK to the United States under the Data Protection Framework. Some of the highlights  include:</p><p>1.     What is the Data Protection Framework?</p><p>2.     How will the Data Protection Review Court work?</p><p>3.     What dare the safeguards around the US national security review be?</p><p>4.     What happens next?</p><p>5.     What are the views of Max Schrems?</p><p>6.     Will there be an EU/UK split?</p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance <a href="https://www.corderycompliance.com/changes-uk-dp-regime-3/">News Section</a>. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1305</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[f6396764-48ea-11ed-b698-e32c625345f6]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3664137642.mp3?updated=1665590336" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Changes to UK Data Protection Regime</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss the changes in the UK Data Privacy regime currently proposed in the wake of Brexit. Some of the highlights include:

Why these changes are so significant.

Are things really more complicated now?

What does it mean for compliance?

What happens next?

Will the new PM request any changes?

Practical steps you can take now.

Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 29 Sep 2022 04:00:00 -0000</pubDate>
      <itunes:title>Changes to UK Data Protection Regime</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>82</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/7dc2fee6-2ed5-11ed-bd8f-fbab07ed68c8/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Jonathan and Tom return to look at the changes in the UK Data Privacy regime currently proposed in the wake of Brexit. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss the changes in the UK Data Privacy regime currently proposed in the wake of Brexit. Some of the highlights include:

Why these changes are so significant.

Are things really more complicated now?

What does it mean for compliance?

What happens next?

Will the new PM request any changes?

Practical steps you can take now.

Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss the changes in the UK Data Privacy regime currently proposed in the wake of Brexit. Some of the highlights include:</p><ol>
<li>Why these changes are so significant.</li>
<li>Are things really more complicated now?</li>
<li>What does it mean for compliance?</li>
<li>What happens next?</li>
<li>Will the new PM request any changes?</li>
<li>Practical steps you can take now.</li>
</ol><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/changes-uk-dp-regime-3/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1338</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[7dc2fee6-2ed5-11ed-bd8f-fbab07ed68c8]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6913289866.mp3?updated=1664316344" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Changes to Cyber-Breach Insurance</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss Lloyd’s of London announcement of its coverages for cyber-breaches by state actors. Some of the highlights  include: 
1.     Why this change is so significant.
2.     What does it mean for compliance?
3.     What happens next?
4.     Practical steps you can take now.
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 15 Sep 2022 04:00:00 -0000</pubDate>
      <itunes:title>Changes to Cyber-Breach Insurance</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>81</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/845f07b0-2ec4-11ed-a92b-23a58e5a570d/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this special episode, we are joined by Matt Kelly and Jonathan Marks to consider the changes in cyber-breach insurance coverage. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss Lloyd’s of London announcement of its coverages for cyber-breaches by state actors. Some of the highlights  include: 
1.     Why this change is so significant.
2.     What does it mean for compliance?
3.     What happens next?
4.     Practical steps you can take now.
Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss Lloyd’s of London announcement of its coverages for cyber-breaches by state actors. Some of the highlights  include: </p><p>1.     Why this change is so significant.</p><p>2.     What does it mean for compliance?</p><p>3.     What happens next?</p><p>4.     Practical steps you can take now.</p><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/lloyds-cyber-insurance1/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1539</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[845f07b0-2ec4-11ed-a92b-23a58e5a570d]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6766740160.mp3?updated=1662572792" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Update on Cookie Banners</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss the NOYB announcement that it had filed an additional 226 complaints to Data Protection Authorities in 18 countries over the use of OneTrust cookie banners. Some of the highlights include:

Previous enforcement actions on cookie banners.

The NOYB campaign.

What happens next?

Practical steps you can take now.

Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 18 Aug 2022 04:00:00 -0000</pubDate>
      <itunes:title>Update on Cookie Banners</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>80</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/51e1c98a-1e25-11ed-b3ef-1f8f47ed7715/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode we look at the NOYB campaign against cookie banners. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss the NOYB announcement that it had filed an additional 226 complaints to Data Protection Authorities in 18 countries over the use of OneTrust cookie banners. Some of the highlights include:

Previous enforcement actions on cookie banners.

The NOYB campaign.

What happens next?

Practical steps you can take now.

Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss the NOYB announcement that it had filed an additional 226 complaints to Data Protection Authorities in 18 countries over the use of OneTrust cookie banners. Some of the highlights include:</p><ol>
<li>Previous enforcement actions on cookie banners.</li>
<li>The NOYB campaign.</li>
<li>What happens next?</li>
<li>Practical steps you can take now.</li>
</ol><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/cookie-banners-complaints/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1277</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[51e1c98a-1e25-11ed-b3ef-1f8f47ed7715]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3502049942.mp3?updated=1660747540" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Boris Johnson Announces Resignation</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss British Prime Minster Boris Johnson’s recent announcement that he will be resigning as British PM when his successor is announced. Some of the highlights include:

Reasons for the resignation.

Candidates for the PM role going forward.

Key compliance and related issues for the new PM going forward .

Lessons learned from the Pincher Affair and the BoJo resignation.

Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Wed, 13 Jul 2022 10:11:06 -0000</pubDate>
      <itunes:title>Boris Johnson Announces Resignation</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>79</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/9eb214f8-012a-11ed-88f2-dfe500eaa384/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan return to look at the BoJo resignation and what it might mean for the compliance professional. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss British Prime Minster Boris Johnson’s recent announcement that he will be resigning as British PM when his successor is announced. Some of the highlights include:

Reasons for the resignation.

Candidates for the PM role going forward.

Key compliance and related issues for the new PM going forward .

Lessons learned from the Pincher Affair and the BoJo resignation.

Resources
For more information on the issues raised in this podcast, check out the Cordery Compliance, News Section. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we discuss British Prime Minster Boris Johnson’s recent announcement that he will be resigning as British PM when his successor is announced. Some of the highlights include:</p><ol>
<li>Reasons for the resignation.</li>
<li>Candidates for the PM role going forward.</li>
<li>Key compliance and related issues for the new PM going forward .</li>
<li>Lessons learned from the Pincher Affair and the BoJo resignation.</li>
</ol><p><strong>Resources</strong></p><p>For more information on the issues raised in this podcast, check out the Cordery Compliance, <a href="https://www.corderycompliance.com/news/">News Section</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1250</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[9eb214f8-012a-11ed-88f2-dfe500eaa384]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9150230131.mp3?updated=1657552568" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>GDPR Draft Guidance on Fines Calculation</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we review the recently released European Data Protection Board (EDPB) draft guidance on calculating fines entitled “Guidelines 04/2022 on the calculation of administrative fines under the GDPR”. Some of the highlights  include: 
1.     There have been just under 1.5 billion in overall fines under GDPR.
2.     Spain has the largest number of fines but the smallest monetary amount of fines.
3.     The five-step calculation methodology.
4.     What are the aggravating and mitigating factors.
5.     Key takeaways from the draft guidance.
Resources
For more information on the draft guidance, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 30 Jun 2022 04:00:00 -0000</pubDate>
      <itunes:title>GDPR Draft Guidance on Fines Calculation</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>78</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/43f6c5c2-f26b-11ec-99a9-3334c5d2217a/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we review the recently released the EDPB recently issued draft guidance on calculating GDPR fines. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we review the recently released European Data Protection Board (EDPB) draft guidance on calculating fines entitled “Guidelines 04/2022 on the calculation of administrative fines under the GDPR”. Some of the highlights  include: 
1.     There have been just under 1.5 billion in overall fines under GDPR.
2.     Spain has the largest number of fines but the smallest monetary amount of fines.
3.     The five-step calculation methodology.
4.     What are the aggravating and mitigating factors.
5.     Key takeaways from the draft guidance.
Resources
For more information on the draft guidance, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we review the recently released European Data Protection Board (EDPB) draft guidance on calculating fines entitled “Guidelines 04/2022 on the calculation of administrative fines under the GDPR”. Some of the highlights  include: </p><p>1.     There have been just under 1.5 billion in overall fines under GDPR.</p><p>2.     Spain has the largest number of fines but the smallest monetary amount of fines.</p><p>3.     The five-step calculation methodology.</p><p>4.     What are the aggravating and mitigating factors.</p><p>5.     Key takeaways from the draft guidance.</p><p><strong>Resources</strong></p><p>For more information on the draft guidance, check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/eu-dpb-gdpr-fines/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1464</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[43f6c5c2-f26b-11ec-99a9-3334c5d2217a]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5584286319.mp3?updated=1656349933" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>FRC Report on Compliance with the UK Modern Slavery Act Update</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we review the recently released Financial Reporting Council (FRC), the UK Anti-Slavery Commissioner, and Lancaster University (Management School) report on a sample of a hundred major companies’ modern slavery statements and their strategic and governance reports. Some of the highlights  include:
1.     Why the Report?
2.     Some successes but much criticism.
3.     Public responses when slavery issues are uncovered.
4.     Why contracts are a part of the solution.
5.     Key takeaways from the Report.
Resources
For more information on the FRC Report, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 23 Jun 2022 04:00:00 -0000</pubDate>
      <itunes:title>FRC Report on Compliance with the UK Modern Slavery Act Update</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/0e9b4c1e-f24c-11ec-ab99-23022900ef1c/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we review the recently report on a sample of a hundred major companies’ modern slavery statements and their strategic and governance reports.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we review the recently released Financial Reporting Council (FRC), the UK Anti-Slavery Commissioner, and Lancaster University (Management School) report on a sample of a hundred major companies’ modern slavery statements and their strategic and governance reports. Some of the highlights  include:
1.     Why the Report?
2.     Some successes but much criticism.
3.     Public responses when slavery issues are uncovered.
4.     Why contracts are a part of the solution.
5.     Key takeaways from the Report.
Resources
For more information on the FRC Report, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we review the recently released Financial Reporting Council (FRC), the UK Anti-Slavery Commissioner, and Lancaster University (Management School) report on a sample of a hundred major companies’ modern slavery statements and their strategic and governance reports. Some of the highlights  include:</p><p>1.     Why the Report?</p><p>2.     Some successes but much criticism.</p><p>3.     Public responses when slavery issues are uncovered.</p><p>4.     Why contracts are a part of the solution.</p><p>5.     Key takeaways from the Report.</p><p><strong>Resources</strong></p><p>For more information on the FRC Report, check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/uk-modern-slavery-update/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1276</itunes:duration>
      <guid isPermaLink="false"><![CDATA[0e9b4c1e-f24c-11ec-ab99-23022900ef1c]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5015149005.mp3?updated=1655930819" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Clearview AI Fine by the ICO</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take up a fine in the UK by the ICO against Clearview AI. We have discussed other EU countries’ fines against Clearview previously. Some of the highlights include:

What is this case all about?

What did the ICO decide?

Why is AI under the spotlight again?

Other actions and penalties against Clearview?

Key takeaways.


Resources
For more information on the Clearview AI fine by the ICO, check out the Cordery Compliance client alert on this topic; click here. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 16 Jun 2022 04:00:00 -0000</pubDate>
      <itunes:title>Clearview AI Fine by the ICO</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>76</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/3e5158aa-ecd8-11ec-9882-23f97c801670/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan take a look int the Clearview AI Fine by the ICO in the UK.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take up a fine in the UK by the ICO against Clearview AI. We have discussed other EU countries’ fines against Clearview previously. Some of the highlights include:

What is this case all about?

What did the ICO decide?

Why is AI under the spotlight again?

Other actions and penalties against Clearview?

Key takeaways.


Resources
For more information on the Clearview AI fine by the ICO, check out the Cordery Compliance client alert on this topic; click here. For more information on Cordery Compliance, go to their website here. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take up a fine in the UK by the ICO against Clearview AI. We have discussed other EU countries’ fines against Clearview previously. Some of the highlights include:</p><ol>
<li>What is this case all about?</li>
<li>What did the ICO decide?</li>
<li>Why is AI under the spotlight again?</li>
<li>Other actions and penalties against Clearview?</li>
<li>Key takeaways.</li>
</ol><p><br></p><p><strong>Resources</strong></p><p>For more information on the Clearview AI fine by the ICO, check out the Cordery Compliance client alert on this topic; click <a href="https://www.corderycompliance.com/ico-fines-dp/">here</a>. For more information on Cordery Compliance, go to their website <a href="http://www.corderycompliance.com/">here</a>. Also, check out the GDPR Navigator, one of the top resources for GDPR Compliance, by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1234</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[3e5158aa-ecd8-11ec-9882-23f97c801670]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6209429170.mp3?updated=1655322503" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>André Paris on the Brazilian GDPR</title>
      <description>Tom Fox returns for another episode of Life with GDPR. Jonathan Armstrong is on assignment this week, so we are joined by our colleague André Paris, a Brazilian Privacy and Compliance Consultant, Professor and Lawyer. Andre is the author of the book "Ethics and Transparency - A Path to Compliance". He is a specialist in building a Corporate Culture based on Ethics, Transparency and Respect. Experienced in Corporate Risk Analysis and Management, as well as in Protecting Corporate Reputation and Crisis Management. He is also an enthusiast on building a more ethical and transparent business environment.
In this episode, we take up the Brazilian national GDPR-like data privacy law.  Some of the issues we consider include: 
1.     What is the Brazilian law?
2.     Who does it apply to?
3.     What does a compliance program look like?
 Resources
Check out Andre’s book, ETHICS &amp; TRANSPARENCY: A Path To Compliance.
Andre Paris on LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 26 May 2022 04:00:00 -0000</pubDate>
      <itunes:title>André Paris on the Brazilian GDPR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>75</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/fefeaf84-cc81-11ec-9910-c3bb9c572670/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we are joined by our colleague Andre Paris, author of the book "Ethics and Transparency - A Path to Compliance". </itunes:subtitle>
      <itunes:summary>Tom Fox returns for another episode of Life with GDPR. Jonathan Armstrong is on assignment this week, so we are joined by our colleague André Paris, a Brazilian Privacy and Compliance Consultant, Professor and Lawyer. Andre is the author of the book "Ethics and Transparency - A Path to Compliance". He is a specialist in building a Corporate Culture based on Ethics, Transparency and Respect. Experienced in Corporate Risk Analysis and Management, as well as in Protecting Corporate Reputation and Crisis Management. He is also an enthusiast on building a more ethical and transparent business environment.
In this episode, we take up the Brazilian national GDPR-like data privacy law.  Some of the issues we consider include: 
1.     What is the Brazilian law?
2.     Who does it apply to?
3.     What does a compliance program look like?
 Resources
Check out Andre’s book, ETHICS &amp; TRANSPARENCY: A Path To Compliance.
Andre Paris on LinkedIn
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Tom Fox returns for another episode of Life with GDPR. Jonathan Armstrong is on assignment this week, so we are joined by our colleague André Paris, a Brazilian Privacy and Compliance Consultant, Professor and Lawyer. Andre is the author of the book "<em>Ethics and Transparency - A Path to Compliance</em>". He is a specialist in building a Corporate Culture based on Ethics, Transparency and Respect. Experienced in Corporate Risk Analysis and Management, as well as in Protecting Corporate Reputation and Crisis Management. He is also an enthusiast on building a more ethical and transparent business environment.</p><p>In this episode, we take up the Brazilian national GDPR-like data privacy law.  Some of the issues we consider include: </p><p>1.     What is the Brazilian law?</p><p>2.     Who does it apply to?</p><p>3.     What does a compliance program look like?</p><p> <strong>Resources</strong></p><p>Check out Andre’s book, ETHICS &amp; TRANSPARENCY: A Path To Compliance.</p><p>Andre Paris on <a href="https://www.linkedin.com/in/andr%C3%A9-h-paris-cipm-ccep-i-cdpo-br-b37667122/">LinkedIn</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1501</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[fefeaf84-cc81-11ec-9910-c3bb9c572670]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5225265484.mp3?updated=1653344898" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Data Transfers from EU/UK to US</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take up the proposed agreement for data transfers from the EU (and UK) to the US. Some of the issues we consider in the myriad of questions around this latest version of Privacy Shield include: 
1.     Is this simply an agreement to agree?
2.     Who will populate the independent court review in the US?
3.     Will US spy agencies ever comply?
4.     Will there be a real deal by the end of 2022?
5.     Is this simply a temporary solution.
 Resources
For more information on the new data transfer agreement, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 12 May 2022 04:00:00 -0000</pubDate>
      <itunes:title>Data Transfers from EU/UK to US</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>74</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/d6f0285a-bf1c-11ec-bae2-1f3f173e25c7/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom ad Jonathan take up the new proposed regulations for data transfers from EU &amp; UK to the US.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take up the proposed agreement for data transfers from the EU (and UK) to the US. Some of the issues we consider in the myriad of questions around this latest version of Privacy Shield include: 
1.     Is this simply an agreement to agree?
2.     Who will populate the independent court review in the US?
3.     Will US spy agencies ever comply?
4.     Will there be a real deal by the end of 2022?
5.     Is this simply a temporary solution.
 Resources
For more information on the new data transfer agreement, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take up the proposed agreement for data transfers from the EU (and UK) to the US. Some of the issues we consider in the myriad of questions around this latest version of Privacy Shield include: </p><p>1.     Is this simply an agreement to agree?</p><p>2.     Who will populate the independent court review in the US?</p><p>3.     Will US spy agencies ever comply?</p><p>4.     Will there be a real deal by the end of 2022?</p><p>5.     Is this simply a temporary solution.</p><p> <strong>Resources</strong></p><p>For more information on the new data transfer agreement, check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/datatransfers-ukdates/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1440</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[d6f0285a-bf1c-11ec-bae2-1f3f173e25c7]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9811046383.mp3?updated=1650310801" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Clearview AI Redux</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we consider the Italian Data Protection Authority (the Garante) fine against Clearview AI €20m for GDPR violations.  It is the latest in a series of regulatory actions in Europe and in Australia against Clearview AI and it also continues a trend of AI enforcement in Italy.
1.     Who is Clearview AI?
2.     What is this matter about?
3.     The background facts and the Italian investigation.
4.     What did the Garante say?
5.     Lessons learned and next steps.
Resources
For more information on the Italian Clearview AI enforcement action, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 28 Apr 2022 04:00:00 -0000</pubDate>
      <itunes:title>Clearview AI Redux</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>73</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/c38404b0-b9b5-11ec-b485-b3471529c06b/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode of Life with GDPR, Tom and Jonathan look at the recent Italian Data Protection Authority fine against Clearview AI €20m for GDPR violations.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we consider the Italian Data Protection Authority (the Garante) fine against Clearview AI €20m for GDPR violations.  It is the latest in a series of regulatory actions in Europe and in Australia against Clearview AI and it also continues a trend of AI enforcement in Italy.
1.     Who is Clearview AI?
2.     What is this matter about?
3.     The background facts and the Italian investigation.
4.     What did the Garante say?
5.     Lessons learned and next steps.
Resources
For more information on the Italian Clearview AI enforcement action, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p><br></p><p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we consider the Italian Data Protection Authority (the Garante) fine against Clearview AI €20m for GDPR violations.  It is the latest in a series of regulatory actions in Europe and in Australia against Clearview AI and it also continues a trend of AI enforcement in Italy.</p><p>1.     Who is Clearview AI?</p><p>2.     What is this matter about?</p><p>3.     The background facts and the Italian investigation.</p><p>4.     What did the Garante say?</p><p>5.     Lessons learned and next steps.</p><p><strong>Resources</strong></p><p>For more information on the Italian Clearview AI enforcement action, check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/clearview-ai-italy-gdpr-fine/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1035</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[c38404b0-b9b5-11ec-b485-b3471529c06b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1713225221.mp3?updated=1651140051" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Tuckers Enforcement Action</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we consider the UK Data Protection Authority, the Information Commissioners Office (ICO) recent announcement that it had fined a law firm, Tuckers Solicitors LLP for GDPR breaches.  Tuckers was fined £98,000 after being hit by a ransomware attack.
1.     Law firms are not unique.
2.     What about other legal regulations and regulatory bodies?
3.     The background facts.
4.     What did the ICO say?
5.     Lessons learned.
Resources
For more information on the Tuckers enforcement action, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 14 Apr 2022 04:00:00 -0000</pubDate>
      <itunes:title>Tuckers Enforcement Action</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>72</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/9ba0996a-b9b3-11ec-bda9-dbd3e2c76975/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan take a look into the Tuckers GDPR enforcement action. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we consider the UK Data Protection Authority, the Information Commissioners Office (ICO) recent announcement that it had fined a law firm, Tuckers Solicitors LLP for GDPR breaches.  Tuckers was fined £98,000 after being hit by a ransomware attack.
1.     Law firms are not unique.
2.     What about other legal regulations and regulatory bodies?
3.     The background facts.
4.     What did the ICO say?
5.     Lessons learned.
Resources
For more information on the Tuckers enforcement action, check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we consider the UK Data Protection Authority, the Information Commissioners Office (ICO) recent announcement that it had fined a law firm, Tuckers Solicitors LLP for GDPR breaches.  Tuckers was fined £98,000 after being hit by a ransomware attack.</p><p>1.     Law firms are not unique.</p><p>2.     What about other legal regulations and regulatory bodies?</p><p>3.     The background facts.</p><p>4.     What did the ICO say?</p><p>5.     Lessons learned.</p><p><strong>Resources</strong></p><p>For more information on the Tuckers enforcement action, check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/law-firm-gdpr-breach-fine/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1195</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[9ba0996a-b9b3-11ec-bda9-dbd3e2c76975]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5029826382.mp3?updated=1649698304" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Privacy Shield 3</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, consider the recently announced EU/US resolution to allow data transfer from the EU to the United States through the mechanism of Privacy Shield 3. Some of the issues we consider include:
1.     Is it Déjà vu all over again?
2.     What about consent and standard contractual clauses as a basis for data transfer?
3.     What was the court’s ruling?
4.     Why double due diligence will be required going forward?
5.     What about the UK?
6.     What does Max Shrems have to say?  
 Resources
Check out the Cordery Compliance, client alert on this topic, click here and here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 31 Mar 2022 04:00:00 -0000</pubDate>
      <itunes:title>Privacy Shield 3</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>71</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/7420649a-b04b-11ec-8cce-273a300d6903/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom Fox and Jonathan Armstrong discuss the new data transfer agreement, Privacy Shield 3. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, consider the recently announced EU/US resolution to allow data transfer from the EU to the United States through the mechanism of Privacy Shield 3. Some of the issues we consider include:
1.     Is it Déjà vu all over again?
2.     What about consent and standard contractual clauses as a basis for data transfer?
3.     What was the court’s ruling?
4.     Why double due diligence will be required going forward?
5.     What about the UK?
6.     What does Max Shrems have to say?  
 Resources
Check out the Cordery Compliance, client alert on this topic, click here and here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, consider the recently announced EU/US resolution to allow data transfer from the EU to the United States through the mechanism of Privacy Shield 3. Some of the issues we consider include:</p><p>1.     Is it Déjà vu all over again?</p><p>2.     What about consent and standard contractual clauses as a basis for data transfer?</p><p>3.     What was the court’s ruling?</p><p>4.     Why double due diligence will be required going forward?</p><p>5.     What about the UK?</p><p>6.     What does Max Shrems have to say?  </p><p> <strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/datatransfer-eutous/">here</a> and <a href="https://www.corderycompliance.com/datatransfers-ukdates/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1004</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[7420649a-b04b-11ec-8cce-273a300d6903]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9776252232.mp3?updated=1648662547" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The Case of the Rogue Employee</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In the 2020 Morrisons case the UK Supreme Court ruled that an employer can be legally responsible for data breaches caused by their employees, although in the particular situation in that case the court ruled that Morrisons (the employer) was not liable for the actions of their rogue employee. In this episode, Tom and Jonathan look at the more recent case of Isma Ali v. Luton Borough Council where the High Court ruled that in committing the data security breach actions the rogue employee undertook, she had solely pursued her own interests and so the employer was not liable for her conduct. Some of the issues we consider include:
1.     What were the underlying facts of the case?
2.     What was the court’s ruling?
3.     Key Takeaways for the data privacy, data protection practitioner, including:
·      Take a close look at security measures and ensuring that access rights are policed. Data loss prevention and monitoring systems should also be in place to check for large data files leaving the organization - depending on the circumstances, a rogue employee might be after a lot of data;
·      Put in place appropriate policies and procedures to make sure that data protection principles like data security and data minimization are properly understood;
·      Perform a Data Protection Impact Assessment for new processes;
·      Make sure that employees in trusted roles are reliable and that their access rights are reviewed.  
·      Put in place and rehearse a data breach notification procedure, including detection and response capabilities;
·      Training staff on all of the above; and,
·      Check existing insurance or taking out new insurance to cover the range of potential risks from "innocent" errors to the actions of a rogue employee. 
 
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 17 Mar 2022 04:00:00 -0000</pubDate>
      <itunes:title>The Case of the Rogue Employee</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>71</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/a581ff22-98c1-11ec-bb9d-6b3372b30c34/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan look at the actions of a rogue employee under GDPR.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In the 2020 Morrisons case the UK Supreme Court ruled that an employer can be legally responsible for data breaches caused by their employees, although in the particular situation in that case the court ruled that Morrisons (the employer) was not liable for the actions of their rogue employee. In this episode, Tom and Jonathan look at the more recent case of Isma Ali v. Luton Borough Council where the High Court ruled that in committing the data security breach actions the rogue employee undertook, she had solely pursued her own interests and so the employer was not liable for her conduct. Some of the issues we consider include:
1.     What were the underlying facts of the case?
2.     What was the court’s ruling?
3.     Key Takeaways for the data privacy, data protection practitioner, including:
·      Take a close look at security measures and ensuring that access rights are policed. Data loss prevention and monitoring systems should also be in place to check for large data files leaving the organization - depending on the circumstances, a rogue employee might be after a lot of data;
·      Put in place appropriate policies and procedures to make sure that data protection principles like data security and data minimization are properly understood;
·      Perform a Data Protection Impact Assessment for new processes;
·      Make sure that employees in trusted roles are reliable and that their access rights are reviewed.  
·      Put in place and rehearse a data breach notification procedure, including detection and response capabilities;
·      Training staff on all of the above; and,
·      Check existing insurance or taking out new insurance to cover the range of potential risks from "innocent" errors to the actions of a rogue employee. 
 
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In the 2020 Morrisons case the UK Supreme Court ruled that an employer can be legally responsible for data breaches caused by their employees, although in the particular situation in that case the court ruled that Morrisons (the employer) was not liable for the actions of their rogue employee. In this episode, Tom and Jonathan look at the more recent case of <em>Isma Ali v. Luton Borough Council</em> where the High Court ruled that in committing the data security breach actions the rogue employee undertook, she had solely pursued her own interests and so the employer was not liable for her conduct. Some of the issues we consider include:</p><p>1.     What were the underlying facts of the case?</p><p>2.     What was the court’s ruling?</p><p>3.     Key Takeaways for the data privacy, data protection practitioner, including:</p><p>·      Take a close look at security measures and ensuring that access rights are policed. Data loss prevention and monitoring systems should also be in place to check for large data files leaving the organization - depending on the circumstances, a rogue employee might be after a lot of data;</p><p>·      Put in place appropriate policies and procedures to make sure that data protection principles like data security and data minimization are properly understood;</p><p>·      Perform a Data Protection Impact Assessment for new processes;</p><p>·      Make sure that employees in trusted roles are reliable and that their access rights are reviewed.  </p><p>·      Put in place and rehearse a data breach notification procedure, including detection and response capabilities;</p><p>·      Training staff on all of the above; and,</p><p>·      Check existing insurance or taking out new insurance to cover the range of potential risks from "innocent" errors to the actions of a rogue employee. </p><p> </p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/ali-v-luton-rogue-employee/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>947</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[a581ff22-98c1-11ec-bb9d-6b3372b30c34]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8822456579.mp3?updated=1647446060" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The Case of the Smart TV</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, dissect the case of the Smart TV and considers its implications for de minimis cases brought under GDPR. Some of the issues we consider include:
1.     What were the underlying facts of the case?
2.     Was the case filed in the correct court (High Court)? If not, why not?
3.     What was the court’s ruling?
4.     What is the viability of a de minimums claim going forward?
5.     When dealing with data protection infringement compensation claims, look to cases from other jurisdictions.
6.     No matter how seemingly trivial, organizations should be prepared for them and manage them with care.  
 Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 03 Mar 2022 05:00:00 -0000</pubDate>
      <itunes:title>The Case of the Smart TV</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>70</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/4793c3dc-98b7-11ec-9f85-a309c48cfba6/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, Tom and Jonathan take up the GDPR case of the Smart TV.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, dissect the case of the Smart TV and considers its implications for de minimis cases brought under GDPR. Some of the issues we consider include:
1.     What were the underlying facts of the case?
2.     Was the case filed in the correct court (High Court)? If not, why not?
3.     What was the court’s ruling?
4.     What is the viability of a de minimums claim going forward?
5.     When dealing with data protection infringement compensation claims, look to cases from other jurisdictions.
6.     No matter how seemingly trivial, organizations should be prepared for them and manage them with care.  
 Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, dissect the case of the Smart TV and considers its implications for <em>de minimis</em> cases brought under GDPR. Some of the issues we consider include:</p><p>1.     What were the underlying facts of the case?</p><p>2.     Was the case filed in the correct court (High Court)? If not, why not?</p><p>3.     What was the court’s ruling?</p><p>4.     What is the viability of a de minimums claim going forward?</p><p>5.     When dealing with data protection infringement compensation claims, look to cases from other jurisdictions.</p><p>6.     No matter how seemingly trivial, organizations should be prepared for them and manage them with care.  </p><p> <strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/dp-infringement-stadler-currys/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1062</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[4793c3dc-98b7-11ec-9f85-a309c48cfba6]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8629244528.mp3?updated=1646068638" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>GDPR-10 Years After Original Proposal</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we celebrate the 10-year anniversary of the initial proposal of the law which became GDPR. Some of the issues we consider include:

What was in the original proposal that did not become enacted in the final law?

Reduction in costs-what happened?

Right to be Forgotten, morphed into something very different than intended.

Fines, Fines, Fines.

Evolution of regulatory sophistication.

Criticism of regulators.

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 24 Feb 2022 05:00:00 -0000</pubDate>
      <itunes:title>GDPR-10 Years After Original Proposal</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>69</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/437dcc00-94a4-11ec-9e56-1f058c695bde/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan are back celebrate to the 10-year anniversary of the initial proposal of the law which became GDPR.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we celebrate the 10-year anniversary of the initial proposal of the law which became GDPR. Some of the issues we consider include:

What was in the original proposal that did not become enacted in the final law?

Reduction in costs-what happened?

Right to be Forgotten, morphed into something very different than intended.

Fines, Fines, Fines.

Evolution of regulatory sophistication.

Criticism of regulators.

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we celebrate the 10-year anniversary of the initial proposal of the law which became GDPR. Some of the issues we consider include:</p><ol>
<li>What was in the original proposal that did not become enacted in the final law?</li>
<li>Reduction in costs-what happened?</li>
<li>Right to be Forgotten, morphed into something very different than intended.</li>
<li>Fines, Fines, Fines.</li>
<li>Evolution of regulatory sophistication.</li>
<li>Criticism of regulators.</li>
</ol><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/gdpr-10-years-on/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1400</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[437dcc00-94a4-11ec-9e56-1f058c695bde]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8854745803.mp3?updated=1645619677" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Class Action Update</title>
      <description>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take a deep dive into class action litigation in the UK and EU around data privacy and data protection. Some of the issues we consider include:
1.     Has the tide turned in favor of defendants in class action litigation in the UK?
2.     Are actual damages now required to receive damages after a data breach?
3.     How can a company manage a regulatory investigation of a data breach during a class action litigation?
4.     What about suits against Boards of Directors?
 Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Life with GDPR named one of the top 30 Data Security Podcasts you must follow in 2022. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 10 Feb 2022 05:00:00 -0000</pubDate>
      <itunes:title>Class Action Update</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>67</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/f6537ca0-828c-11ec-8e0b-f33b94e75ac1/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom Fox and Jonathan Armstrong return to take a look at new developments in class action lawsuits involving data breaches. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take a deep dive into class action litigation in the UK and EU around data privacy and data protection. Some of the issues we consider include:
1.     Has the tide turned in favor of defendants in class action litigation in the UK?
2.     Are actual damages now required to receive damages after a data breach?
3.     How can a company manage a regulatory investigation of a data breach during a class action litigation?
4.     What about suits against Boards of Directors?
 Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Life with GDPR named one of the top 30 Data Security Podcasts you must follow in 2022. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong and Tom Fox return for another episode of Life with GDPR. In this episode, we take a deep dive into class action litigation in the UK and EU around data privacy and data protection. Some of the issues we consider include:</p><p>1.     Has the tide turned in favor of defendants in class action litigation in the UK?</p><p>2.     Are actual damages now required to receive damages after a data breach?</p><p>3.     How can a company manage a regulatory investigation of a data breach during a class action litigation?</p><p>4.     What about suits against Boards of Directors?</p><p> <strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/episode-271-techlaw10-legal-class-actions-us-europe/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p>Life with GDPR named one of the top <a href="https://blog.feedspot.com/data_security_podcasts/">30 Data Security Podcasts </a>you must follow in 2022. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1613</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[f6537ca0-828c-11ec-8e0b-f33b94e75ac1]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7285242376.mp3?updated=1644345546" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Update on Blackbaud</title>
      <description>Jonathan Armstrong returns from assignment to take on a potpourri of issues with co-host Tom Fox. In this episode, we consider some of the issues from the Blackbaud data breach enforcement action. Some of the issues we consider include:

Does this matter signal a priority in risk shifting by the regulators?

Implications for class actions involving customers.

Hardening of the insurance market regarding data breaches.

More due diligence coming in the B2B arena.

Steps your organization should take now.

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 03 Feb 2022 05:00:00 -0000</pubDate>
      <itunes:title>Update on Blackbaud</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>66</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/70fe25d8-8286-11ec-9055-2b03f7269db2/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan are back to take a fresh look at the Blackbaud data breach enforcement action. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong returns from assignment to take on a potpourri of issues with co-host Tom Fox. In this episode, we consider some of the issues from the Blackbaud data breach enforcement action. Some of the issues we consider include:

Does this matter signal a priority in risk shifting by the regulators?

Implications for class actions involving customers.

Hardening of the insurance market regarding data breaches.

More due diligence coming in the B2B arena.

Steps your organization should take now.

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong returns from assignment to take on a potpourri of issues with co-host Tom Fox. In this episode, we consider some of the issues from the Blackbaud data breach enforcement action. Some of the issues we consider include:</p><ol>
<li>Does this matter signal a priority in risk shifting by the regulators?</li>
<li>Implications for class actions involving customers.</li>
<li>Hardening of the insurance market regarding data breaches.</li>
<li>More due diligence coming in the B2B arena.</li>
<li>Steps your organization should take now.</li>
</ol><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/blackbaud-revisited/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1281</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[70fe25d8-8286-11ec-9055-2b03f7269db2]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6544374996.mp3?updated=1643629259" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Potpourri Edition</title>
      <description>Jonathan Armstrong returns from assignment to take on a potpourri of issues with co-host Tom Fox. We use the recent speech by Deputy Attorney General Lisa Monaco as a jumping off point to discuss how this change in DOJ enforcement policy and focus will be impacted by GDPR, the new EU Whistleblower Directive and how increased international cooperation around international anti-corruption compliance may play out. Some of the issues we consider include:

Data protection issues under the new DOJ FCPA enforcement policy?

Monitorships outside the US.

Data privacy and investigations.

Class actions in the UK going forward.

Increased cooperation between the DOJ/SEC and the UK Serious Fraud Office.

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Dec 2021 05:00:00 -0000</pubDate>
      <itunes:title>Potpourri Edition</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>65</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/637daa1c-5119-11ec-b384-0f27ae6e022b/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan look at a potpourri of issues coming out of the new DOJ focus on FCPA enforcement. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong returns from assignment to take on a potpourri of issues with co-host Tom Fox. We use the recent speech by Deputy Attorney General Lisa Monaco as a jumping off point to discuss how this change in DOJ enforcement policy and focus will be impacted by GDPR, the new EU Whistleblower Directive and how increased international cooperation around international anti-corruption compliance may play out. Some of the issues we consider include:

Data protection issues under the new DOJ FCPA enforcement policy?

Monitorships outside the US.

Data privacy and investigations.

Class actions in the UK going forward.

Increased cooperation between the DOJ/SEC and the UK Serious Fraud Office.

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong returns from assignment to take on a potpourri of issues with co-host Tom Fox. We use the recent speech by Deputy Attorney General Lisa Monaco as a jumping off point to discuss how this change in DOJ enforcement policy and focus will be impacted by GDPR, the new EU Whistleblower Directive and how increased international cooperation around international anti-corruption compliance may play out. Some of the issues we consider include:</p><ol>
<li>Data protection issues under the new DOJ FCPA enforcement policy?</li>
<li>Monitorships outside the US.</li>
<li>Data privacy and investigations.</li>
<li>Class actions in the UK going forward.</li>
<li>Increased cooperation between the DOJ/SEC and the UK Serious Fraud Office.</li>
</ol><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/lux-whistleblowing-echr-judgement/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>998</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[637daa1c-5119-11ec-b384-0f27ae6e022b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9566686919.mp3?updated=1638193445" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>EU Whistleblower Directive-Part 2</title>
      <description>Jonathan Armstrong is on assignment in Cornwall so for this episode Cordery Compliance co-founder Andre Bywater joins Tom Fox to discuss issues relating to the upcoming EU Whistleblower Directive, with a go live date of December 17. This is Part 2 of a special 2-part episode. Some of the questions we consider include:

What about whistleblowing and data protection issues?

Are individuals subject to whistleblowing allegations also protected?

Subject Access Requests.

False whistleblowing.

Sanctions for non-compliance.

Bounties for whistleblowing.

When must the EU whistleblowing rules be implemented?

Post-Brexit, how will the UK be implementing these rules?

What are Andre’s three takeaways?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 04 Nov 2021 04:00:00 -0000</pubDate>
      <itunes:title>EU Whistleblower Directive-Part 2</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/0f8b6122-2de4-11ec-b3e3-b7b2dd9f0d9d/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Andre Bywater joins Tom for Part 2 on the EU Whistleblower Directive.</itunes:subtitle>
      <itunes:summary>Jonathan Armstrong is on assignment in Cornwall so for this episode Cordery Compliance co-founder Andre Bywater joins Tom Fox to discuss issues relating to the upcoming EU Whistleblower Directive, with a go live date of December 17. This is Part 2 of a special 2-part episode. Some of the questions we consider include:

What about whistleblowing and data protection issues?

Are individuals subject to whistleblowing allegations also protected?

Subject Access Requests.

False whistleblowing.

Sanctions for non-compliance.

Bounties for whistleblowing.

When must the EU whistleblowing rules be implemented?

Post-Brexit, how will the UK be implementing these rules?

What are Andre’s three takeaways?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong is on assignment in Cornwall so for this episode Cordery Compliance co-founder Andre Bywater joins Tom Fox to discuss issues relating to the upcoming EU Whistleblower Directive, with a go live date of December 17. This is Part 2 of a special 2-part episode. Some of the questions we consider include:</p><ol>
<li>What about whistleblowing and data protection issues?</li>
<li>Are individuals subject to whistleblowing allegations also protected?</li>
<li>Subject Access Requests.</li>
<li>False whistleblowing.</li>
<li>Sanctions for non-compliance.</li>
<li>Bounties for whistleblowing.</li>
<li>When must the EU whistleblowing rules be implemented?</li>
<li>Post-Brexit, how will the UK be implementing these rules?</li>
<li>What are Andre’s three takeaways?</li>
</ol><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/lux-whistleblowing-echr-judgement/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1679</itunes:duration>
      <guid isPermaLink="false"><![CDATA[0f8b6122-2de4-11ec-b3e3-b7b2dd9f0d9d]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN2079183201.mp3?updated=1634322108" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>EU Whistleblower Directive-Part 1</title>
      <description>Jonathan Armstrong is on assignment in Cornwall so for this episode Cordery Compliance co-founder Andre Bywater joins Tom Fox to discuss the upcoming EU Whistleblower Directive go live date of December 17. This is Part 1 of a special 2-part episode. Some of the questions we consider include:
1.     Why is the EU tackling whistleblowing &amp; what EU areas fall in scope?
2.     Who can be a whistleblower?
3.     What about anonymity and confidentiality?
4.     Which whistleblowing route should a whistleblower follow?
5.     Are there any record-keeping obligations?
6.     Is retaliation prohibited?
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Wed, 27 Oct 2021 04:00:00 -0000</pubDate>
      <itunes:title>EU Whistleblower Directive-Part 1</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>63</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/c953b188-2de2-11ec-86d4-530513fa4c30/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Cordery Compliance co-founder Andre Bywater joins Tom Fox for Part 1 on the new EU Whistleblower Directive. </itunes:subtitle>
      <itunes:summary>Jonathan Armstrong is on assignment in Cornwall so for this episode Cordery Compliance co-founder Andre Bywater joins Tom Fox to discuss the upcoming EU Whistleblower Directive go live date of December 17. This is Part 1 of a special 2-part episode. Some of the questions we consider include:
1.     Why is the EU tackling whistleblowing &amp; what EU areas fall in scope?
2.     Who can be a whistleblower?
3.     What about anonymity and confidentiality?
4.     Which whistleblowing route should a whistleblower follow?
5.     Are there any record-keeping obligations?
6.     Is retaliation prohibited?
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Jonathan Armstrong is on assignment in Cornwall so for this episode Cordery Compliance co-founder Andre Bywater joins Tom Fox to discuss the upcoming EU Whistleblower Directive go live date of December 17. This is Part 1 of a special 2-part episode. Some of the questions we consider include:</p><p>1.     Why is the EU tackling whistleblowing &amp; what EU areas fall in scope?</p><p>2.     Who can be a whistleblower?</p><p>3.     What about anonymity and confidentiality?</p><p>4.     Which whistleblowing route should a whistleblower follow?</p><p>5.     Are there any record-keeping obligations?</p><p>6.     Is retaliation prohibited?</p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/lux-whistleblowing-echr-judgement/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>2077</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[c953b188-2de2-11ec-86d4-530513fa4c30]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3605053662.mp3?updated=1634321823" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>EU Whistleblower Update</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we take up a recent decision from Luxembourg which would seem antithetical to good whistleblower practices. We also consider the upcoming EU Whistleblower Directive go live date of December 17. Some of the questions we consider include:
1.     What are the facts of the enforcement actions? 
2.     When should company harm outweigh public good from whistleblowers?
3.     What lessons can companies learn from this matter in conjunction with the EU whistleblower directive?
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 21 Oct 2021 04:00:00 -0000</pubDate>
      <itunes:title>Whistleblower Update</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>62</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/5300ee00-2ac3-11ec-bcce-f3ffb8e6b1a7/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan consider a recent decision from Luxembourg and the upcoming EU Whistleblower Directive</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we take up a recent decision from Luxembourg which would seem antithetical to good whistleblower practices. We also consider the upcoming EU Whistleblower Directive go live date of December 17. Some of the questions we consider include:
1.     What are the facts of the enforcement actions? 
2.     When should company harm outweigh public good from whistleblowers?
3.     What lessons can companies learn from this matter in conjunction with the EU whistleblower directive?
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we take up a recent decision from Luxembourg which would seem antithetical to good whistleblower practices. We also consider the upcoming EU Whistleblower Directive go live date of December 17. Some of the questions we consider include:</p><p>1.     What are the facts of the enforcement actions? </p><p>2.     When should company harm outweigh public good from whistleblowers?</p><p>3.     What lessons can companies learn from this matter in conjunction with the EU whistleblower directive?</p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/lux-whistleblowing-echr-judgement/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1076</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[5300ee00-2ac3-11ec-bcce-f3ffb8e6b1a7]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3792905701.mp3?updated=1634554066" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Jonathan’s Favorite Enforcement Action</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we take up Jonathan’s (current) favorite GDPR enforcement action, involving the food deliver services Deliveroo and Foodinho, who ran afoul of the Italian data protection authority.
 Some of the questions we consider include:

What are the facts of the enforcement actions?

What do these cases tell us about the use of AI and data privacy?

What lessons can companies that use algorithmic management of staff learn?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 30 Sep 2021 04:00:00 -0000</pubDate>
      <itunes:title>Jonathan’s Favorite Enforcement Action</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/043919ae-211e-11ec-b9df-57c02043683c/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Tom and Jonathan explore AI and data privacy. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we take up Jonathan’s (current) favorite GDPR enforcement action, involving the food deliver services Deliveroo and Foodinho, who ran afoul of the Italian data protection authority.
 Some of the questions we consider include:

What are the facts of the enforcement actions?

What do these cases tell us about the use of AI and data privacy?

What lessons can companies that use algorithmic management of staff learn?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we take up Jonathan’s (current) favorite GDPR enforcement action, involving the food deliver services Deliveroo and Foodinho, who ran afoul of the Italian data protection authority.</p><p> Some of the questions we consider include:</p><ol>
<li>What are the facts of the enforcement actions?</li>
<li>What do these cases tell us about the use of AI and data privacy?</li>
<li>What lessons can companies that use algorithmic management of staff learn?</li>
</ol><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/ransomware-pay-or-not/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1085</itunes:duration>
      <guid isPermaLink="false"><![CDATA[043919ae-211e-11ec-b9df-57c02043683c]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5977194467.mp3?updated=1632917841" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>To Pay or Not to Pay</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode the always difficult decision of whether to pay or not to pay a ransomware demand. Some of the questions we consider include:

1.     How does a ransomware attack occur? 
2.     What are the potential legal and commercial risks of paying ransoms?
3.     What about specific new laws to ban ransomware payments?
4.     What should you do if your organization is faced with a ransomware attack?
5.     What can you do to guard against a ransomware attack?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 16 Sep 2021 04:00:00 -0000</pubDate>
      <itunes:title>To Pay or Not to Pay</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>60</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/779e4d40-1572-11ec-861f-67c5b6c1d638/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we take up the issue of whether to pay or not to pay in the event of a ransomware attack. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode the always difficult decision of whether to pay or not to pay a ransomware demand. Some of the questions we consider include:

1.     How does a ransomware attack occur? 
2.     What are the potential legal and commercial risks of paying ransoms?
3.     What about specific new laws to ban ransomware payments?
4.     What should you do if your organization is faced with a ransomware attack?
5.     What can you do to guard against a ransomware attack?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode the always difficult decision of whether to pay or not to pay a ransomware demand. Some of the questions we consider include:</p><p><br></p><p>1.     How does a ransomware attack occur? </p><p>2.     What are the potential legal and commercial risks of paying ransoms?</p><p>3.     What about specific new laws to ban ransomware payments?</p><p>4.     What should you do if your organization is faced with a ransomware attack?</p><p>5.     What can you do to guard against a ransomware attack?</p><p><br></p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/ransomware-pay-or-not/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1163</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[779e4d40-1572-11ec-861f-67c5b6c1d638]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4366586173.mp3?updated=1631634649" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Due Diligence in M&amp;A for Data Protection</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we consider due diligence in mergers and acquisitions from the data privacy/data protection perspective. What should you review? Who should you talk to? What reps and warranties should you consider? These questions and much more on this edition of Life with GDPR.
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Sep 2021 04:00:00 -0000</pubDate>
      <itunes:title>Due Diligence in M&amp;A for Data Protection</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>59</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/9ac508da-0b64-11ec-b70d-a3193f878856/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>What are the DD considerations for data protection in M&amp;A?</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we consider due diligence in mergers and acquisitions from the data privacy/data protection perspective. What should you review? Who should you talk to? What reps and warranties should you consider? These questions and much more on this edition of Life with GDPR.
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we consider due diligence in mergers and acquisitions from the data privacy/data protection perspective. What should you review? Who should you talk to? What reps and warranties should you consider? These questions and much more on this edition of Life with GDPR.</p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/dpdd-transactions-faqs/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1694</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[9ac508da-0b64-11ec-b70d-a3193f878856]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7393797553.mp3?updated=1630530930" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Happy Birthday GDPR, Part 2</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we conclude a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In Part 1, we looked at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.  In this Part 2, we consider the where of doing business, data security and customers issues as they have evolved over the past 3 years. 
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 03 Jun 2021 04:02:00 -0000</pubDate>
      <itunes:title>Happy Birthday GDPR, Part 2</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>58</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/400936d6-c3bc-11eb-8c55-334c8ee7e250/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Jonathan and Tom return to review key themes in the first 3 years of GDPR</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we conclude a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In Part 1, we looked at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.  In this Part 2, we consider the where of doing business, data security and customers issues as they have evolved over the past 3 years. 
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we conclude a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In Part 1, we looked at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.  In this Part 2, we consider the where of doing business, data security and customers issues as they have evolved over the past 3 years. </p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1713</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[400936d6-c3bc-11eb-8c55-334c8ee7e250]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8472278809.mp3?updated=1622650186" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Happy Birthday GDPR, Part 1</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we begin a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In this Part 1, we look at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.  
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 27 May 2021 04:04:00 -0000</pubDate>
      <itunes:title>Happy Birthday GDPR, Part 1</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>57</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/f9c0764a-be56-11eb-8f21-3bd11eb2201e/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode,  Tom Jonathan look back at 3 years of GDPR. In this Part 1, GDPR militancy and enforcement. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we begin a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In this Part 1, we look at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.  
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we begin a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In this Part 1, we look at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.  </p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1743</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[f9c0764a-be56-11eb-8f21-3bd11eb2201e]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4141492795.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Trade Sanctions, AML and Export Control after Brexit</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we conclude a 3-part series on issues relating to GDPR after Brexit. They include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider trade sanctions, anti-money laundering and export control after Brexit. 
Resources
Check out the Cordery Compliance Client alert on the data transfer after Brexit here.
 
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 18 Mar 2021 04:04:00 -0000</pubDate>
      <itunes:title>Trade Sanctions, AML and Export Control after Brexit</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/571e41ca-7c51-11eb-9b0e-b364d4ec56e1/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode we consider trade sanctions, anti-money laundering and export control after Brexit. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we conclude a 3-part series on issues relating to GDPR after Brexit. They include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider trade sanctions, anti-money laundering and export control after Brexit. 
Resources
Check out the Cordery Compliance Client alert on the data transfer after Brexit here.
 
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we conclude a 3-part series on issues relating to GDPR after Brexit. They include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider trade sanctions, anti-money laundering and export control after Brexit. </p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance Client alert on the data transfer after Brexit <a href="https://www.corderycompliance.com/kbr-sfo-litigation/">here</a>.</p><p> </p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1046</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[571e41ca-7c51-11eb-9b0e-b364d4ec56e1]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5404650281.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Data Transfers After Brexit</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we continue our 3-part series on issues relating to GDPR after Brexit. The topics we discuss include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider data privacy and data transfers after Brexit. 
Resources
Check out the Cordery Compliance Client alert on the data transfer after Brexit here.
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 11 Mar 2021 05:06:00 -0000</pubDate>
      <itunes:title>Data Transfers After Brexit</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>55</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/ff4f12d6-7c4f-11eb-9b0e-d38a67135a18/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode we consider data privacy and data transfers after Brexit. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we continue our 3-part series on issues relating to GDPR after Brexit. The topics we discuss include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider data privacy and data transfers after Brexit. 
Resources
Check out the Cordery Compliance Client alert on the data transfer after Brexit here.
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we continue our 3-part series on issues relating to GDPR after Brexit. The topics we discuss include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider data privacy and data transfers after Brexit. </p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance Client alert on the data transfer after Brexit <a href="https://www.corderycompliance.com/kbr-sfo-litigation/">here</a>.</p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>618</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[ff4f12d6-7c4f-11eb-9b0e-d38a67135a18]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1559472292.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Data Protection After Brexit</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we begin a 3-part series on issues relating to GDPR after Brexit. They include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider data protection. Highlights include:

Does GDPR still exist in the UK?

Does pre-Brexit case law still matter in the UK?

What is the temporary data protection deal between the EU &amp; UK all about?

How will extra-territorial reach work for the EU &amp; the UK?

Will I need a Data Protection Representative?

Will I need a new Data Protection Officer

Resources
Check out the Cordery Compliance Client alert on the data transfer after Brexit here.
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 04 Mar 2021 05:03:00 -0000</pubDate>
      <itunes:title>Data Protection After Brexit</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>54</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/dac39488-7c4e-11eb-9e02-0b400f7d1ef1/image/LifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>With this episode, we begin a 3-part series on issues relating to GDPR after Brexit. They include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider data protection. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we begin a 3-part series on issues relating to GDPR after Brexit. They include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider data protection. Highlights include:

Does GDPR still exist in the UK?

Does pre-Brexit case law still matter in the UK?

What is the temporary data protection deal between the EU &amp; UK all about?

How will extra-territorial reach work for the EU &amp; the UK?

Will I need a Data Protection Representative?

Will I need a new Data Protection Officer

Resources
Check out the Cordery Compliance Client alert on the data transfer after Brexit here.
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we begin a 3-part series on issues relating to GDPR after Brexit. They include data protection, data transfer and issues related to trade sanctions, AML and export control. In this episode we consider data protection. Highlights include:</p><ul>
<li>Does GDPR still exist in the UK?</li>
<li>Does pre-Brexit case law still matter in the UK?</li>
<li>What is the temporary data protection deal between the EU &amp; UK all about?</li>
<li>How will extra-territorial reach work for the EU &amp; the UK?</li>
<li>Will I need a Data Protection Representative?</li>
<li>Will I need a new Data Protection Officer</li>
</ul><p><strong>Resources</strong></p><p>Check out the Cordery Compliance Client alert on the data transfer after Brexit <a href="https://www.corderycompliance.com/kbr-sfo-litigation/">here</a>.</p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1019</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[dac39488-7c4e-11eb-9e02-0b400f7d1ef1]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3269166217.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The KBR Document Production Decision</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we take a look at the recent UK Supreme Court decision in the KBR document production case. KBR succeeded in its UK Supreme Court battle with the Serious Fraud Office (SFO). The case is interesting both in connection with the seizure of documents in SFO investigations and the sometimes criticized Section 2 notice procedure, which the UK Supreme Court held was unlawful in this case. 
Highlights Include:
·      What was this case about?
·      Why was it so important?
·      What is a Section 2 Notice?
·      What about extra-territoriality?
·      What was the Court’s decision based on?
·      Lessons for the compliance professional.
·      Wither the SFO?

Resources
Check out the Cordery Compliance Client alert on the KBR decision here. 
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 25 Feb 2021 05:03:00 -0000</pubDate>
      <itunes:title>The KBR Document Production Decision</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>53</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/486a80a4-76b0-11eb-8f93-a7a7877c9ea7/image/uploads_2F1614178417596-ifqyp80vsjt-967ee276b45a5460586d0c6c318185ac_2FLifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we take a look at the recent UK Supreme Court decision in the KBR document production case. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we take a look at the recent UK Supreme Court decision in the KBR document production case. KBR succeeded in its UK Supreme Court battle with the Serious Fraud Office (SFO). The case is interesting both in connection with the seizure of documents in SFO investigations and the sometimes criticized Section 2 notice procedure, which the UK Supreme Court held was unlawful in this case. 
Highlights Include:
·      What was this case about?
·      Why was it so important?
·      What is a Section 2 Notice?
·      What about extra-territoriality?
·      What was the Court’s decision based on?
·      Lessons for the compliance professional.
·      Wither the SFO?

Resources
Check out the Cordery Compliance Client alert on the KBR decision here. 
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p><br></p><p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we take a look at the recent UK Supreme Court decision in the KBR document production case. KBR succeeded in its UK Supreme Court battle with the Serious Fraud Office (SFO). The case is interesting both in connection with the seizure of documents in SFO investigations and the sometimes criticized Section 2 notice procedure, which the UK Supreme Court held was unlawful in this case. </p><p>Highlights Include:</p><p>·      What was this case about?</p><p>·      Why was it so important?</p><p>·      What is a Section 2 Notice?</p><p>·      What about extra-territoriality?</p><p>·      What was the Court’s decision based on?</p><p>·      Lessons for the compliance professional.</p><p>·      Wither the SFO?</p><p><br></p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance Client alert on the KBR decision <a href="https://www.corderycompliance.com/kbr-sfo-litigation/">here</a>. </p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>817</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[486a80a4-76b0-11eb-8f93-a7a7877c9ea7]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9821753167.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Looking Back and Looking Forward</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we take a look back at some of Jonathan’s most significant cases, enforcement actions and events in data privacy/data protection in 2020. We also consider the potential impact of Brexit on data transfers between the UK and the EU and how this will impact data transfers between the UK and US. 
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 07 Jan 2021 05:07:00 -0000</pubDate>
      <itunes:title>Looking Back and Looking Forward</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>52</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/be4e05ca-4b7c-11eb-b25e-479703a4aa32/image/uploads_2F1609428233587-am0q10i3pk-50f2416c6641afcb8c79b9e9bf4d318f_2FLifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode we look back at some of the most significant events and issues from 2020 in the world of GDPR.</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we take a look back at some of Jonathan’s most significant cases, enforcement actions and events in data privacy/data protection in 2020. We also consider the potential impact of Brexit on data transfers between the UK and the EU and how this will impact data transfers between the UK and US. 
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we take a look back at some of Jonathan’s most significant cases, enforcement actions and events in data privacy/data protection in 2020. We also consider the potential impact of Brexit on data transfers between the UK and the EU and how this will impact data transfers between the UK and US. </p><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>768</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[be4e05ca-4b7c-11eb-b25e-479703a4aa32]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7167751770.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Reduction to GDPR Fines by EU Courts and SARs</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider EU courts reducing fines and penalties assessed by data protection regulators. The case reminds us that, as we said before, data protection authorities are likely to face challenges to high fines in the courts. In some respects, the fine mechanism in GDPR is based on the system in use in competition law cases where the success rate in appeals has been high. Some of the highlights are:

﻿Background to several cases.

What did the court say?

What did the regulators say?

What are the lessons learned for the data protection/data privacy compliance specialist?

What steps can your organization take?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Fri, 18 Dec 2020 11:14:41 -0000</pubDate>
      <itunes:title>Reduction to GDPR Fines by EU Courts and SARs</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/844072fa-4122-11eb-800b-33a5791ce90a/image/uploads_2F1608290160991-b1if4pt2i3n-cb585f7c1bc08a1e9eb7a7622b8d7c7a_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Why re EU courts reducing EU Data Privacy Regulatory fines and what does it mean going forward?</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider EU courts reducing fines and penalties assessed by data protection regulators. The case reminds us that, as we said before, data protection authorities are likely to face challenges to high fines in the courts. In some respects, the fine mechanism in GDPR is based on the system in use in competition law cases where the success rate in appeals has been high. Some of the highlights are:

﻿Background to several cases.

What did the court say?

What did the regulators say?

What are the lessons learned for the data protection/data privacy compliance specialist?

What steps can your organization take?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider EU courts reducing fines and penalties assessed by data protection regulators. The case reminds us that, as we said before, data protection authorities are likely to face challenges to high fines in the courts. In some respects, the fine mechanism in GDPR is based on the system in use in competition law cases where the success rate in appeals has been high. Some of the highlights are:</p><ol>
<li>﻿Background to several cases.</li>
<li>What did the court say?</li>
<li>What did the regulators say?</li>
<li>What are the lessons learned for the data protection/data privacy compliance specialist?</li>
<li>What steps can your organization take?</li>
</ol><p><strong>Resources</strong></p><p>Check out the Cordery Compliance, client alert on this topic, click <a href="https://www.corderycompliance.com/1and1-gdpr-fine-reduced/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1036</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[844072fa-4122-11eb-800b-33a5791ce90a]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4450628084.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The Experian Enforcement Notice Case</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the Experian enforcement action. Recently, the UK Data Protection Authority, the Information Commissioner’s Office (ICO), slapped Experian with an enforcement notice requiring the company to make major changes to how it processes personal data in its UK marketing services business. The main themes in the investigation, which targeted various players in the credit referencing industry, centered on “invisible processing”, “over processing”, providing insufficiently clear privacy information and using certain lawful bases incorrectly for processing people’s data. Some of the highlights are:

Background to the case.

Why did the other credit rating agencies agree to the ICO terms?

This matter is about the Enforcement Notice and not fines and penalties.

Why is transparency essential in data processing?

How does big data make all this more difficult?

What are ‘legitimate interests’?


Check out the Cordery Compliance, client alert on the Experience matter, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 10 Dec 2020 05:02:00 -0000</pubDate>
      <itunes:title>The Experian Enforcement Notice Case</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>50</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/c2deb58a-37ea-11eb-b991-fb6865e1a821/image/uploads_2F1607276507492-ni612pv1bf-db94991cee19527ef1683f534c145c4e_2FLifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we consider the Experian enforcement action. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the Experian enforcement action. Recently, the UK Data Protection Authority, the Information Commissioner’s Office (ICO), slapped Experian with an enforcement notice requiring the company to make major changes to how it processes personal data in its UK marketing services business. The main themes in the investigation, which targeted various players in the credit referencing industry, centered on “invisible processing”, “over processing”, providing insufficiently clear privacy information and using certain lawful bases incorrectly for processing people’s data. Some of the highlights are:

Background to the case.

Why did the other credit rating agencies agree to the ICO terms?

This matter is about the Enforcement Notice and not fines and penalties.

Why is transparency essential in data processing?

How does big data make all this more difficult?

What are ‘legitimate interests’?


Check out the Cordery Compliance, client alert on the Experience matter, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the Experian enforcement action. Recently, the UK Data Protection Authority, the Information Commissioner’s Office (ICO), slapped Experian with an enforcement notice requiring the company to make major changes to how it processes personal data in its UK marketing services business. The main themes in the investigation, which targeted various players in the credit referencing industry, centered on “invisible processing”, “over processing”, providing insufficiently clear privacy information and using certain lawful bases incorrectly for processing people’s data. Some of the highlights are:</p><ol>
<li>Background to the case.</li>
<li>Why did the other credit rating agencies agree to the ICO terms?</li>
<li>This matter is about the Enforcement Notice and not fines and penalties.</li>
<li>Why is transparency essential in data processing?</li>
<li>How does big data make all this more difficult?</li>
<li>What are ‘legitimate interests’?</li>
</ol><p><br></p><p>Check out the Cordery Compliance, client alert on the Experience matter, click <a href="https://www.corderycompliance.com/client-alert-experian-fights-ico-enforcement-notice/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>984</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[c2deb58a-37ea-11eb-b991-fb6865e1a821]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1414995429.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>SARS and Liability Issues under GDPR</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the increase in subject access requests (SARs) and other liability issues under GDPR. Recently, the UK Data Protection Authority, the Information Commissioner’s Office (ICO), issued new guidance on handling SARs. The guidance follows responses from organization of all shapes and sizes however and is clearly an indication of what the ICO is thinking. Cordery also took part in the consultation process for this new guidance.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Sun, 06 Dec 2020 17:19:00 -0000</pubDate>
      <itunes:title>SARS and Liability Issues under GDPR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/713c58e8-37e7-11eb-8b47-bbf89c0e5b96/image/uploads_2F1607275207359-e2aoo66nqm-89d2fb2fd331a7f4f985899d506b655d_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode of Life with GDPR, we consider the increase in subject access requests (SARs) and other liability issues under GDPR.</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the increase in subject access requests (SARs) and other liability issues under GDPR. Recently, the UK Data Protection Authority, the Information Commissioner’s Office (ICO), issued new guidance on handling SARs. The guidance follows responses from organization of all shapes and sizes however and is clearly an indication of what the ICO is thinking. Cordery also took part in the consultation process for this new guidance.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the increase in subject access requests (SARs) and other liability issues under GDPR. Recently, the UK Data Protection Authority, the Information Commissioner’s Office (ICO), issued new guidance on handling SARs. The guidance follows responses from organization of all shapes and sizes however and is clearly an indication of what the ICO is thinking. Cordery also took part in the consultation process for this new guidance.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1376</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[713c58e8-37e7-11eb-8b47-bbf89c0e5b96]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5797823909.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>H&amp;M Fined €35.2 for Data Privacy Breaches</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode, we consider recent decision by the Hamburg Data Protection Authority which fined H&amp;M Germany €35.2m for GDPR violations. The case concerned excessive use of employee data and is the largest fine so far imposed by regulators for the handling of employee data. We are likely to see more pressure on employers to justify the handling of employee data as a result of today’s fine. Some of the highlights are: 

What did the regulator say?

What did H&amp;M do after the investigation began?

What about the current pandemic?

What are the implications going forward?

What is this decision’s precedential value?

What are some practical tips for compliance?

Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 08 Oct 2020 04:01:00 -0000</pubDate>
      <itunes:title>H&amp;M Fined €35.2 for Data Privacy Breaches</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>48</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/2b738940-089d-11eb-8b6c-db26e317873a/image/uploads_2F1602075616418-gug1gnmohq5-5dd0cfde51a7aefc95261229e06ee997_2FLifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we consider recent decision by the Hamburg Data Protection Authority which fined H&amp;M Germany €35.2m for GDPR violations.</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode, we consider recent decision by the Hamburg Data Protection Authority which fined H&amp;M Germany €35.2m for GDPR violations. The case concerned excessive use of employee data and is the largest fine so far imposed by regulators for the handling of employee data. We are likely to see more pressure on employers to justify the handling of employee data as a result of today’s fine. Some of the highlights are: 

What did the regulator say?

What did H&amp;M do after the investigation began?

What about the current pandemic?

What are the implications going forward?

What is this decision’s precedential value?

What are some practical tips for compliance?

Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode, we consider recent decision by the Hamburg Data Protection Authority which fined H&amp;M Germany €35.2m for GDPR violations. The case concerned excessive use of employee data and is the largest fine so far imposed by regulators for the handling of employee data. We are likely to see more pressure on employers to justify the handling of employee data as a result of today’s fine. Some of the highlights are: </p><ol>
<li>What did the regulator say?</li>
<li>What did H&amp;M do after the investigation began?</li>
<li>What about the current pandemic?</li>
<li>What are the implications going forward?</li>
<li>What is this decision’s precedential value?</li>
<li>What are some practical tips for compliance?</li>
</ol><p>Check out the Cordery Compliance, client alert on this case, click <a href="https://www.corderycompliance.com/hmbbfdi-fines-hm-for-gdpr-violations/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1376</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[2b738940-089d-11eb-8b6c-db26e317873a]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN8596005595.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Schrems III-Impact on the Transatlantic Digital Trade</title>
      <description>In this episode, I am joined by Jed Gardner of Linedata to discuss some of the practical aspects the Schrems III case, where the Court invalidated Privacy Shield. Some of the highlights are:

Why was this and what are the wider impacts to transatlantic digital trade? 

When does this come into effect? Is there any grace period? 

Let’s look at a transatlantic organization (Investment Firm). What risks are they now dealing with? 

What should businesses be doing with their technology to address the ruling and ensure they can meet the EU GDPR data privacy regulations? 

Check out the Linedata on their homepage here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 06 Aug 2020 04:03:00 -0000</pubDate>
      <itunes:title>Schrems III-Impact on the Transatlantic Digital Trade</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/b2f37f36-d76c-11ea-8162-0badbc9509da/image/uploads_2F1596666969485-yfe749sv3ag-68191b3562b312f3040c2f9628e3987d_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, I am joined by Jed Gardner of Linedata to discuss the impact of Schrems III on the transatlantic digital trade.</itunes:subtitle>
      <itunes:summary>In this episode, I am joined by Jed Gardner of Linedata to discuss some of the practical aspects the Schrems III case, where the Court invalidated Privacy Shield. Some of the highlights are:

Why was this and what are the wider impacts to transatlantic digital trade? 

When does this come into effect? Is there any grace period? 

Let’s look at a transatlantic organization (Investment Firm). What risks are they now dealing with? 

What should businesses be doing with their technology to address the ruling and ensure they can meet the EU GDPR data privacy regulations? 

Check out the Linedata on their homepage here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, I am joined by Jed Gardner of Linedata to discuss some of the practical aspects the <em>Schrems III </em>case, where the Court invalidated Privacy Shield. Some of the highlights are:</p><ul>
<li>Why was this and what are the wider impacts to transatlantic digital trade? </li>
<li>When does this come into effect? Is there any grace period? </li>
<li>Let’s look at a transatlantic organization (Investment Firm). What risks are they now dealing with? </li>
<li>What should businesses be doing with their technology to address the ruling and ensure they can meet the EU GDPR data privacy regulations? </li>
</ul><p>Check out the Linedata on their homepage <a href="https://www.linedata.com/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1262</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[b2f37f36-d76c-11ea-8162-0badbc9509da]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN2262902315.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Emergency Podcast on Schrems III</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we do our first emergency podcast based upon the European Court of Justice’s decision handed down July 16 on the Schrems III case, where the Court invalidated Privacy Shield. Some of the highlights are: 

What were the issues involved in this case?

What did the Court find wanting in Privacy Shield?

What are the differences in the European and American approach that led to this result?

What was the ruling around standard contract clauses for data transfer?

What are the implications going forward?

Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Fri, 17 Jul 2020 04:07:00 -0000</pubDate>
      <itunes:title>Emergency Podcast on Schrems III</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>46</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/bc9fcf4e-c790-11ea-bf6b-8b0f7989eff1/image/uploads_2F1594923308785-2x2w9wcqde3-abdb7bf9ce0cd6471bb277f09d8b5712_2FLifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, our we our first emergency podcast based upon the European Court of Justice’s decision handed down July 16 on the Schrems III case, where the Court invalidated Privacy Shield.</itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we do our first emergency podcast based upon the European Court of Justice’s decision handed down July 16 on the Schrems III case, where the Court invalidated Privacy Shield. Some of the highlights are: 

What were the issues involved in this case?

What did the Court find wanting in Privacy Shield?

What are the differences in the European and American approach that led to this result?

What was the ruling around standard contract clauses for data transfer?

What are the implications going forward?

Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we do our first emergency podcast based upon the European Court of Justice’s decision handed down July 16 on the <em>Schrems III </em>case, where the Court invalidated Privacy Shield. Some of the highlights are: </p><ol>
<li>What were the issues involved in this case?</li>
<li>What did the Court find wanting in Privacy Shield?</li>
<li>What are the differences in the European and American approach that led to this result?</li>
<li>What was the ruling around standard contract clauses for data transfer?</li>
<li>What are the implications going forward?</li>
</ol><p>Check out the Cordery Compliance, client alert on this case, click <a href="https://www.corderycompliance.com/ecj-rules-scc-valid-not-ps/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>997</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[bc9fcf4e-c790-11ea-bf6b-8b0f7989eff1]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3040198581.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Duty of Data Processor to Report Data Breach</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider recent decision by the Swedish Data Protection Authority recently imposed a fine of 200,000 Swedish kronor (approximately €18,700 or $21,320) on the Swedish National Government Service Centre (“the NGSC”) for failing to notify both the Data Protection Authority and others about a personal data breach in sufficient time.  Some of the highlights are:

What were the issues and interests involved in this case?

What are the requirements for a reporting of a data breach under GDPR?

What are the differences in duties of the Data Processor and Data Controller?

What are the implications going forward?

What is this decision’s precedential value?

Is the decision Kafkaesque in its reasoning?


Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Jul 2020 04:06:00 -0000</pubDate>
      <itunes:title>Duty of Data Processor to Report Data Breach</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>45</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/331e924e-bbe9-11ea-ba7d-1b832ddf702f/image/uploads_2F1593641801155-2dpzrnj0fkq-287f3c7d1e4cf2b1a3cba20092d61d21_2FLifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we consider recent decision by the Swedish Data Protection Authority to impose a fine for failing to notify both the Data Protection Authority and others about a personal data breach in sufficient time. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider recent decision by the Swedish Data Protection Authority recently imposed a fine of 200,000 Swedish kronor (approximately €18,700 or $21,320) on the Swedish National Government Service Centre (“the NGSC”) for failing to notify both the Data Protection Authority and others about a personal data breach in sufficient time.  Some of the highlights are:

What were the issues and interests involved in this case?

What are the requirements for a reporting of a data breach under GDPR?

What are the differences in duties of the Data Processor and Data Controller?

What are the implications going forward?

What is this decision’s precedential value?

Is the decision Kafkaesque in its reasoning?


Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider recent decision by the Swedish Data Protection Authority recently imposed a fine of 200,000 Swedish kronor (approximately €18,700 or $21,320) on the Swedish National Government Service Centre (“the NGSC”) for failing to notify both the Data Protection Authority and others about a personal data breach in sufficient time.  Some of the highlights are:</p><ol>
<li>What were the issues and interests involved in this case?</li>
<li>What are the requirements for a reporting of a data breach under GDPR?</li>
<li>What are the differences in duties of the Data Processor and Data Controller?</li>
<li>What are the implications going forward?</li>
<li>What is this decision’s precedential value?</li>
<li>Is the decision Kafkaesque in its reasoning?</li>
</ol><p><br></p><p>Check out the Cordery Compliance, client alert on this case, click <a href="https://www.corderycompliance.com/sdpr-fine-for-data-breach/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>942</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[331e924e-bbe9-11ea-ba7d-1b832ddf702f]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN2395166422.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Requirements for the DPO</title>
      <description>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider recent decision by the Belgian Data Protection Authority which imposed a fine of €50,000 ($54,203) on an un-named organization for non-compliance with the GDPR conflict of interest requirement; in the selection of its Data Protection Officer.  Some of the highlights are:

What were the issues and interests involved in this case?

What are the requirements for a DPO under GDPR?

How and why was the company ‘seriously negligent’?

What are the implications going forward?

What is this decision’s precedential value?

How much expertise, authority and autonomy must a DPO have going forward?


Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 18 Jun 2020 04:03:00 -0000</pubDate>
      <itunes:title>Requirements for the DPO</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>44</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/f055fc92-b01f-11ea-b132-3b85cf5ed6e8/image/uploads_2F1592345161478-kjh5obf5av-183efa35cc721aa27b1d44a161a94b3a_2FLifeGDPR2.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we consider recent decision by the Belgian DPA on an un-named organization for non-compliance in the selection of its Data Protection Officer. </itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider recent decision by the Belgian Data Protection Authority which imposed a fine of €50,000 ($54,203) on an un-named organization for non-compliance with the GDPR conflict of interest requirement; in the selection of its Data Protection Officer.  Some of the highlights are:

What were the issues and interests involved in this case?

What are the requirements for a DPO under GDPR?

How and why was the company ‘seriously negligent’?

What are the implications going forward?

What is this decision’s precedential value?

How much expertise, authority and autonomy must a DPO have going forward?


Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider recent decision by the Belgian Data Protection Authority which imposed a fine of €50,000 ($54,203) on an un-named organization for non-compliance with the GDPR conflict of interest requirement; in the selection of its Data Protection Officer.  Some of the highlights are:</p><ol>
<li>What were the issues and interests involved in this case?</li>
<li>What are the requirements for a DPO under GDPR?</li>
<li>How and why was the company ‘seriously negligent’?</li>
<li>What are the implications going forward?</li>
<li>What is this decision’s precedential value?</li>
<li>How much expertise, authority and autonomy must a DPO have going forward?</li>
</ol><p><br></p><p>Check out the Cordery Compliance, client alert on this case, click <a href="https://www.corderycompliance.com/belgian-dpa-dpo-fine/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p><br></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1434</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[f055fc92-b01f-11ea-b132-3b85cf5ed6e8]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN9044943004.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Verbal Reporting under GDPR</title>
      <description>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the issue of verbal reporting under GDPR, in the context of the case of Scott v. LGBT Foundation. Some of the highlights are:

What were the issues and interests involved in this case?

What is a relevant filing system for automated data under GPDR?

When does the public health and safety outweigh data privacy?

Was Scott’s data processed by the LGBT Foundation?

What is the necessity test?

Check out the Cordery Compliance, client alert on the case of Scott v. LGBT Foundation, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 14 May 2020 04:03:00 -0000</pubDate>
      <itunes:title>Verbal Reporting under GDPR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/3334ece2-873c-11ea-a109-33313d04b64c/image/uploads_2F1587850005538-ocy1gmpp0b-5af07be72365063818e4459477926265_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>What are the data privacy issues in the case of Scott v. LGBT Foundation? Jonathan Armstrong and Tom Fox explore in this episode of Life with GDPR</itunes:subtitle>
      <itunes:summary>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the issue of verbal reporting under GDPR, in the context of the case of Scott v. LGBT Foundation. Some of the highlights are:

What were the issues and interests involved in this case?

What is a relevant filing system for automated data under GPDR?

When does the public health and safety outweigh data privacy?

Was Scott’s data processed by the LGBT Foundation?

What is the necessity test?

Check out the Cordery Compliance, client alert on the case of Scott v. LGBT Foundation, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the issue of verbal reporting under GDPR, in the context of the case of Scott v. LGBT Foundation. Some of the highlights are:</p><ol>
<li>What were the issues and interests involved in this case?</li>
<li>What is a relevant filing system for automated data under GPDR?</li>
<li>When does the public health and safety outweigh data privacy?</li>
<li>Was Scott’s data processed by the LGBT Foundation?</li>
<li>What is the necessity test?</li>
</ol><p>Check out the Cordery Compliance, client alert on the case of Scott v. LGBT Foundation, click <a href="https://www.corderycompliance.com/uk-court-judgement-verbal-disclosure-under-dp-rules/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1184</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[3334ece2-873c-11ea-a109-33313d04b64c]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4503380285.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>CCTV and Data Privacy</title>
      <description>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the intersection of Closed Circuit Television (CCTV) and data privacy. Some of the highlights are:

CCTV is ubiquitous in the UK. Why is a DPIA so critical in GDPR compliance around this issue?

What about the safety implications for CCTV?

What about Subject Access Requests?

Transparency is critical. This means full notice to all employees.

What should be your retention policy?

Check out the Cordery Compliance, client alert on the CCTV and data privacy, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 07 May 2020 04:03:00 -0000</pubDate>
      <itunes:title>CCTV and Data Privacy</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/11cc9ebe-8738-11ea-8e7f-03790ea1f26b/image/uploads_2F1587848406622-vfi5osqn5y-9751715d7d99767128342da982911f8c_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>What are the data privacy issues in the UK around CCTV? Jonathan Armstrong and Tom Fox explore in this episode of Life with GDPR</itunes:subtitle>
      <itunes:summary>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the intersection of Closed Circuit Television (CCTV) and data privacy. Some of the highlights are:

CCTV is ubiquitous in the UK. Why is a DPIA so critical in GDPR compliance around this issue?

What about the safety implications for CCTV?

What about Subject Access Requests?

Transparency is critical. This means full notice to all employees.

What should be your retention policy?

Check out the Cordery Compliance, client alert on the CCTV and data privacy, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the intersection of Closed Circuit Television (CCTV) and data privacy. Some of the highlights are:</p><ol>
<li>CCTV is ubiquitous in the UK. Why is a DPIA so critical in GDPR compliance around this issue?</li>
<li>What about the safety implications for CCTV?</li>
<li>What about Subject Access Requests?</li>
<li>Transparency is critical. This means full notice to all employees.</li>
<li>What should be your retention policy?</li>
</ol><p>Check out the Cordery Compliance, client alert on the CCTV and data privacy, click <a href="https://www.corderycompliance.com/client-alert-using-cctv-on-business-premises-dp-implications/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>944</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[11cc9ebe-8738-11ea-8e7f-03790ea1f26b]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4468632774.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Morrisons at the UK Supreme Court</title>
      <description>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the recent decision by the UK Supreme Court on the Morrisons case. Some of the highlights are:

What were the background facts of the case and the trial court ruling?

What did the UK Supreme Court rule?

Does the SCt ruling leave the door open for subsequent class actions?

What are the differences between primary liability and vicarious liability?

What steps should a company take in response to the Morrisons ruling?

What does all of this mean for US companies, trying to get data out of the UK and EU?

Check out the Cordery Compliance, client alert on the Morrisons decision, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 30 Apr 2020 04:03:00 -0000</pubDate>
      <itunes:title>Morrisons at the UK Supreme Court</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>41</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/e715f45a-8731-11ea-94ee-7b0c3a9feadd/image/uploads_2F1587845685812-2crv6afuedi-a2ef41dd4c58bce7e26c597306c06623_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>What are the lessons learned from the UK Supreme Court's decision in the Morrisons case? Find out on this episode of Life with GDPR. </itunes:subtitle>
      <itunes:summary>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the recent decision by the UK Supreme Court on the Morrisons case. Some of the highlights are:

What were the background facts of the case and the trial court ruling?

What did the UK Supreme Court rule?

Does the SCt ruling leave the door open for subsequent class actions?

What are the differences between primary liability and vicarious liability?

What steps should a company take in response to the Morrisons ruling?

What does all of this mean for US companies, trying to get data out of the UK and EU?

Check out the Cordery Compliance, client alert on the Morrisons decision, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the recent decision by the UK Supreme Court on the Morrisons case. Some of the highlights are:</p><ol>
<li>What were the background facts of the case and the trial court ruling?</li>
<li>What did the UK Supreme Court rule?</li>
<li>Does the SCt ruling leave the door open for subsequent class actions?</li>
<li>What are the differences between primary liability and vicarious liability?</li>
<li>What steps should a company take in response to the Morrisons ruling?</li>
<li>What does all of this mean for US companies, trying to get data out of the UK and EU?</li>
</ol><p>Check out the Cordery Compliance, client alert on the Morrisons decision, <a href="https://www.corderycompliance.com/uk-court-of-appeal-ruling-in-morrisons-vicarious-liability-case/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1320</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[e715f45a-8731-11ea-94ee-7b0c3a9feadd]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN4656397492.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Cathay Pacific Enforcement Action </title>
      <description>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox consider the recently released UK Information Commissioner’s Office (ICO) Cathay Pacific Airways Limited fine of £500,000 for failing to protect the security of its customers’ personal data. This is a pre-GDPR case and the fine represents the maximum fine under the ICO’s pre-GDPR powers. The ICO took into particular account the fact that Cathay Pacific failed to follow its own policies and ignored fundamental best practices.
Some of the highlights in this episode include:

What were the background facts of the enforcement action?

What are the implications of a pre-GDPR enforcement action?

Why was the maximum fine levied?

What were the regulators findings?

What are the lessons learned for the data protection practitioner?

Where listeners can go for more information.

Resources
Cordery Breach Navigator
Cordery Client Alert “Client Alert: ICO Fines Cathay Pacific £500k for Data Security Breach”
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 09 Apr 2020 04:08:00 -0000</pubDate>
      <itunes:title>Cathay Pacific Enforcement Action </itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>40</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/77bbe898-79b8-11ea-9831-4beebacaff08/image/uploads_2F1586364168043-s8b0y8hobgk-9cffeb38835203c265d685bc059d70cc_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox consider the recent Cathay Pacific ICO enforcement action. </itunes:subtitle>
      <itunes:summary>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox consider the recently released UK Information Commissioner’s Office (ICO) Cathay Pacific Airways Limited fine of £500,000 for failing to protect the security of its customers’ personal data. This is a pre-GDPR case and the fine represents the maximum fine under the ICO’s pre-GDPR powers. The ICO took into particular account the fact that Cathay Pacific failed to follow its own policies and ignored fundamental best practices.
Some of the highlights in this episode include:

What were the background facts of the enforcement action?

What are the implications of a pre-GDPR enforcement action?

Why was the maximum fine levied?

What were the regulators findings?

What are the lessons learned for the data protection practitioner?

Where listeners can go for more information.

Resources
Cordery Breach Navigator
Cordery Client Alert “Client Alert: ICO Fines Cathay Pacific £500k for Data Security Breach”
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox consider the recently released UK Information Commissioner’s Office (ICO) Cathay Pacific Airways Limited fine of £500,000 for failing to protect the security of its customers’ personal data. This is a pre-GDPR case and the fine represents the maximum fine under the ICO’s pre-GDPR powers. The ICO took into particular account the fact that Cathay Pacific failed to follow its own policies and ignored fundamental best practices.</p><p>Some of the highlights in this episode include:</p><ol>
<li>What were the background facts of the enforcement action?</li>
<li>What are the implications of a pre-GDPR enforcement action?</li>
<li>Why was the maximum fine levied?</li>
<li>What were the regulators findings?</li>
<li>What are the lessons learned for the data protection practitioner?</li>
<li>Where listeners can go for more information.</li>
</ol><p><strong>Resources</strong></p><p><a href="https://www.corderycompliance.com/solutions/breach-navigator/">Cordery Breach Navigator</a></p><p>Cordery Client Alert “<a href="https://www.corderycompliance.com/ico-fines-cathay-pacific-for-data-security-breach/"><em>Client Alert: ICO Fines Cathay Pacific £500k for Data Security Breach</em></a>”</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>970</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[77bbe898-79b8-11ea-9831-4beebacaff08]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7651135110.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Coronavirus and GDPR</title>
      <description>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox consider the multiple data privacy/data protection risks which have arisen under the coronavirus health crisis.
 Some of the highlights in this episode include:

How does coronavirus impact GDPR compliance?

What issues arise with working from home?

What is consent and why is it so critical now?

What is the role of a DPIA in this process and why is it so critical?

Can you monitor employees working from home?

What about customer communications?

What are some basic best practices to minimize risk at this point?

What does this mean for companies and clients going forward?

Resources
Cordery Breach Navigator
Cordery Client Alert “Coronavirus and Data Protection”
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 Apr 2020 04:11:00 -0000</pubDate>
      <itunes:title>Coronavirus and GDPR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>39</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/c027cfe8-72ce-11ea-90bd-f701164a05ca/image/uploads_2F1585604133978-kpnk7wftepj-32c94ae7933a474c59f4df035aa2a637_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>What will be the implications for GDPR in the coronavirus health crisis? Find out on this episode of Life with GDPR.</itunes:subtitle>
      <itunes:summary>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox consider the multiple data privacy/data protection risks which have arisen under the coronavirus health crisis.
 Some of the highlights in this episode include:

How does coronavirus impact GDPR compliance?

What issues arise with working from home?

What is consent and why is it so critical now?

What is the role of a DPIA in this process and why is it so critical?

Can you monitor employees working from home?

What about customer communications?

What are some basic best practices to minimize risk at this point?

What does this mean for companies and clients going forward?

Resources
Cordery Breach Navigator
Cordery Client Alert “Coronavirus and Data Protection”
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox consider the multiple data privacy/data protection risks which have arisen under the coronavirus health crisis.</p><p> Some of the highlights in this episode include:</p><ol>
<li>How does coronavirus impact GDPR compliance?</li>
<li>What issues arise with working from home?</li>
<li>What is consent and why is it so critical now?</li>
<li>What is the role of a DPIA in this process and why is it so critical?</li>
<li>Can you monitor employees working from home?</li>
<li>What about customer communications?</li>
<li>What are some basic best practices to minimize risk at this point?</li>
<li>What does this mean for companies and clients going forward?</li>
</ol><p><strong>Resources</strong></p><p><a href="https://www.corderycompliance.com/solutions/breach-navigator/">Cordery Breach Navigator</a></p><p>Cordery Client Alert “<a href="https://www.corderycompliance.com/coronavirus-covid19-and-dp/"><em>Coronavirus and Data Protection</em></a>”</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1597</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[c027cfe8-72ce-11ea-90bd-f701164a05ca]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3865986833.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Special Valentine’s Day Edition-Facebook Dawn Raid in Ireland </title>
      <description>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox have their first emergency podcast. Earlier this week, the Irish Data Protection Commission raided Facebook in Ireland over the company’s announced plan to begin a dating service on Valentine’s Day.
Some of the highlights in this episode include:

What is the to-do all about?

Do European data protection authorities have dawn raid powers?

What might the Irish Data Protection Commission have been looking for in this raid?

What is the role of a DPIA in this process and why is it so critical?

When should a DPIA be carried out?

How can a DPIA a mitigating or aggravating factor?

What is the importance of training around DPIAs?

What does this mean for companies and clients going forward?

Resources
Cordery Breach Navigator
Cordery Client Alert “Ireland’s Data Protection Authority Halts Facebook Dating Service”
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Fri, 14 Feb 2020 05:08:00 -0000</pubDate>
      <itunes:title>Special Valentine’s Day Edition-Facebook Dawn Raid in Ireland </itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/1d63c22c-4e8d-11ea-a425-cbed7d22f888/image/uploads_2F1581617489782-rbxdqa6fnf-fcad6cce86755648f377aa5f618899d0_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this special Valentine Day's episode, Jonathan Armstrong and Tom Fox consider the recent dawn raid by the Irish Data Protection Commission at Facebook in Ireland around FB's DPIA for its dating services app.</itunes:subtitle>
      <itunes:summary>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox have their first emergency podcast. Earlier this week, the Irish Data Protection Commission raided Facebook in Ireland over the company’s announced plan to begin a dating service on Valentine’s Day.
Some of the highlights in this episode include:

What is the to-do all about?

Do European data protection authorities have dawn raid powers?

What might the Irish Data Protection Commission have been looking for in this raid?

What is the role of a DPIA in this process and why is it so critical?

When should a DPIA be carried out?

How can a DPIA a mitigating or aggravating factor?

What is the importance of training around DPIAs?

What does this mean for companies and clients going forward?

Resources
Cordery Breach Navigator
Cordery Client Alert “Ireland’s Data Protection Authority Halts Facebook Dating Service”
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox have their first emergency podcast. Earlier this week, the Irish Data Protection Commission raided Facebook in Ireland over the company’s announced plan to begin a dating service on Valentine’s Day.</p><p>Some of the highlights in this episode include:</p><ol>
<li>What is the to-do all about?</li>
<li>Do European data protection authorities have dawn raid powers?</li>
<li>What might the Irish Data Protection Commission have been looking for in this raid?</li>
<li>What is the role of a DPIA in this process and why is it so critical?</li>
<li>When should a DPIA be carried out?</li>
<li>How can a DPIA a mitigating or aggravating factor?</li>
<li>What is the importance of training around DPIAs?</li>
<li>What does this mean for companies and clients going forward?</li>
</ol><p><strong>Resources</strong></p><p><a href="https://www.corderycompliance.com/solutions/breach-navigator/">Cordery Breach Navigator</a></p><p>Cordery Client Alert “<a href="https://www.corderycompliance.com/ireland-dpc-halts-fb-dating-service/"><em>Ireland’s Data Protection Authority Halts Facebook Dating Service</em></a>”</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1525</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[1d63c22c-4e8d-11ea-a425-cbed7d22f888]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7642276974.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Episode 36- Extension of BA Response Time  </title>
      <description>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to discuss the recent ICO announcement that it was extending the time for British Airways and Marriott to respond to its proposed fine and penalty. Some of the highlights in this episode include:

What makes the background of the case so complex?

What did the ICO say and why did they extend the deadline for BA to respond?

What are some of the possible reasons for the delay?

What if anything does Brexit have to do with this?

In view of Brexit, will the EU be watching the ICO in this matter?

What might be the relationship between the ICO and EU on data privacy going forward?

Background of British Airways (BA) enforcement action.

Resources
Is the BA Fine in the Departure Lounge?
Cordery Breach Navigator
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 06 Feb 2020 05:03:00 -0000</pubDate>
      <itunes:title>Episode 36- Extension of BA Response Time  </itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>36</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/37c8d4d0-47ae-11ea-bfde-a3c5b2c6a14c/image/uploads_2F1580862397755-anx9yi28ykj-de8bd07d51b09823d10f1619f0810dff_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to discuss the recent ICO announcement that it was extending the time for British Airways and Marriott to respond to its proposed fine and penalty. </itunes:subtitle>
      <itunes:summary>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to discuss the recent ICO announcement that it was extending the time for British Airways and Marriott to respond to its proposed fine and penalty. Some of the highlights in this episode include:

What makes the background of the case so complex?

What did the ICO say and why did they extend the deadline for BA to respond?

What are some of the possible reasons for the delay?

What if anything does Brexit have to do with this?

In view of Brexit, will the EU be watching the ICO in this matter?

What might be the relationship between the ICO and EU on data privacy going forward?

Background of British Airways (BA) enforcement action.

Resources
Is the BA Fine in the Departure Lounge?
Cordery Breach Navigator
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to discuss the recent ICO announcement that it was extending the time for British Airways and Marriott to respond to its proposed fine and penalty. Some of the highlights in this episode include:</p><ol>
<li>What makes the background of the case so complex?</li>
<li>What did the ICO say and why did they extend the deadline for BA to respond?</li>
<li>What are some of the possible reasons for the delay?</li>
<li>What if anything does Brexit have to do with this?</li>
<li>In view of Brexit, will the EU be watching the ICO in this matter?</li>
<li>What might be the relationship between the ICO and EU on data privacy going forward?</li>
<li>Background of British Airways (BA) enforcement action.</li>
</ol><p><strong>Resources</strong></p><p><a href="https://www.corderycompliance.com/is-ba-fine-in-departure-lounge/">Is the BA Fine in the Departure Lounge?</a></p><p><a href="https://www.corderycompliance.com/solutions/breach-navigator/">Cordery Breach Navigator</a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1028</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[37c8d4d0-47ae-11ea-bfde-a3c5b2c6a14c]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN6332253863.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Episode 35- What does Brexit Mean for GDPR?</title>
      <description>In this episode Jonathan Armstrong and I consider the implications of GDPR enforcement going forward after Brexit. Recognizing the situation is incredibly fluid, there are nevertheless some areas of risk management that you can begin to prepare for in the event of a deal for an orderly Brexit, a no-deal Brexit or an extension of the deadline Some of the highlights in this episode include:

What does Brexit mean for GDPR enforcement?

How will the UK-ICO move forward after Brexit?

What are the implications of a no-deal Brexit? What can a company do to prepare at this point?

How will the Irish regulators react to Brexit?

What will Brexit mean for internal investigations, both in the UK and EU?

What happens if there is an extension?


Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Mon, 21 Oct 2019 10:34:41 -0000</pubDate>
      <itunes:title>What does Brexit Mean for GDPR?</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>35</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/5cfbb106-f37f-11e9-ab5d-43c6e104d123/image/uploads_2F1571606293349-00n4rp1hgu6bh-2bb115d494f1b6f30188e16fc8d7829e_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>In this episode Jonathan Armstrong and I consider the implications of GDPR enforcement going forward after Brexit. Recognizing the situation is incredibly fluid, there are nevertheless some areas of risk management that you can begin to prepare for in the event of a deal for an orderly Brexit, a no-deal Brexit or an extension of the deadline Some of the highlights in this episode include:

What does Brexit mean for GDPR enforcement?

How will the UK-ICO move forward after Brexit?

What are the implications of a no-deal Brexit? What can a company do to prepare at this point?

How will the Irish regulators react to Brexit?

What will Brexit mean for internal investigations, both in the UK and EU?

What happens if there is an extension?


Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode Jonathan Armstrong and I consider the implications of GDPR enforcement going forward after Brexit. Recognizing the situation is incredibly fluid, there are nevertheless some areas of risk management that you can begin to prepare for in the event of a deal for an orderly Brexit, a no-deal Brexit or an extension of the deadline Some of the highlights in this episode include:</p><ol>
<li>What does Brexit mean for GDPR enforcement?</li>
<li>How will the UK-ICO move forward after Brexit?</li>
<li>What are the implications of a no-deal Brexit? What can a company do to prepare at this point?</li>
<li>How will the Irish regulators react to Brexit?</li>
<li>What will Brexit mean for internal investigations, both in the UK and EU?</li>
<li>What happens if there is an extension?</li>
</ol><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1013</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[5cfbb106-f37f-11e9-ab5d-43c6e104d123]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3440934156.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Role of Vendors in Data Breaches</title>
      <description>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to discuss the role of vendors in data breaches and the corporate response thereto. Some of the highlights in this episode include: 
How much due diligence did you perform on your vendors from the data protection risk perspective?How much due diligence did you engage in for any M&amp;A activity or acquisitions?Do you have the full cooperation of your vendors in any data breach?What is the role of a vendor in responding to a data breach?Does your risk management strategy have a fall back if you have to terminate a vendor over a data breach?For more information on vendor data breaches, check out the following resource on the Cordery Compliance website, https://www.corderycompliance.com/dealing-with-a-data-breach/ . Also if you have not done so, check out the Cordery Breach Navigator here,  https://www.corderycompliance.com/solutions/breach-navigator/



Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 10 Oct 2019 04:00:00 -0000</pubDate>
      <itunes:title>Role of Vendors in Data Breaches</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/c0eb55a2-e940-11e9-91fb-0bb1e8a277cc/image/uploads_2F1570479940626-bcsf4bs3k0i-741b765ceed7991babca23903f94fbc4_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>What is the role of vendors in any data breach and response thereto? In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to explore and provide insights going forward. </itunes:subtitle>
      <itunes:summary>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to discuss the role of vendors in data breaches and the corporate response thereto. Some of the highlights in this episode include: 
How much due diligence did you perform on your vendors from the data protection risk perspective?How much due diligence did you engage in for any M&amp;A activity or acquisitions?Do you have the full cooperation of your vendors in any data breach?What is the role of a vendor in responding to a data breach?Does your risk management strategy have a fall back if you have to terminate a vendor over a data breach?For more information on vendor data breaches, check out the following resource on the Cordery Compliance website, https://www.corderycompliance.com/dealing-with-a-data-breach/ . Also if you have not done so, check out the Cordery Breach Navigator here,  https://www.corderycompliance.com/solutions/breach-navigator/



Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Life with GDPR, Jonathan Armstrong and Tom Fox are back to discuss the role of vendors in data breaches and the corporate response thereto. Some of the highlights in this episode include: </p><p>How much due diligence did you perform on your vendors from the data protection risk perspective?How much due diligence did you engage in for any M&amp;A activity or acquisitions?Do you have the full cooperation of your vendors in any data breach?What is the role of a vendor in responding to a data breach?Does your risk management strategy have a fall back if you have to terminate a vendor over a data breach?For more information on vendor data breaches, check out the following resource on the Cordery Compliance website, <a href="https://www.corderycompliance.com/dealing-with-a-data-breach/">https://www.corderycompliance.com/dealing-with-a-data-breach/</a> . Also if you have not done so, check out the Cordery Breach Navigator here,  <a href="https://www.corderycompliance.com/solutions/breach-navigator/">https://www.corderycompliance.com/solutions/breach-navigator/</p><p></a></p><p><a href="https://www.corderycompliance.com/solutions/breach-navigator/"></p><p></a></p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1242</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[c0eb55a2-e940-11e9-91fb-0bb1e8a277cc]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN7011502575.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Episode 33- Lessons Learned in Year 1 of GDPR, Part 3</title>
      <description>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we conclude our three-part series of some of the key lessons learned from the first year of GDPR. Some of the issues and highlights are:
Remediate then report. The remediation of an issue before reporting can be the key issue for regulators on whether they will move forward with a more public spanking. It is important to show that you have learned lessons and applied them to the facts of your data breach. Don’t try and cheat the victims by imposing new contractual terms such as Equifax did in its recent settlement. Think of the simple way for a data breach to occur, a briefcase left on the Tube.
Don’t Diss the DPA. Why would a company take on the regulator? You must respect the regulator even if you disagree with them. You can make a bad situation worse by attacking the regulators. This does not mean you cannot forcefully argue you position or zealously represent you client but calling regulators idiots in public filings will not help you position or your case. 

Keep logs. This is important in case you need to revisit a decision later. Regulators can ask to see these logs at any time, not simply during an investigation or enforcement action. A compliance officer should be involved in the maintenance of the log system. Document Document Document. Unannounced inspections are beginning to occur.
Debrief and Learn. Revisit the facts to see what lessons are to be learned. Continuous improvement. Even on a journey of 1000 miles, it is important to look back. Once again if you make a change due to a breach or other event, document what you have done so you can show the regulators.
For more information on Cordery Compliance, go their website here.
For more information on data breaches, see here.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 19 Sep 2019 04:00:00 -0000</pubDate>
      <itunes:title>Episode 33- Lessons Learned in Year 1 of GDPR, Part 3</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>33</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/bd43dfa0-d955-11e9-8d18-3bee1bcf2d40/image/uploads_2F1568729727853-saop3204x1d-8f08af7532c77e3b78597addbabb694e_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode of Life with GDPR, we conclude our three-part series of some of the key lessons learned from the first year of GDPR. </itunes:subtitle>
      <itunes:summary>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we conclude our three-part series of some of the key lessons learned from the first year of GDPR. Some of the issues and highlights are:
Remediate then report. The remediation of an issue before reporting can be the key issue for regulators on whether they will move forward with a more public spanking. It is important to show that you have learned lessons and applied them to the facts of your data breach. Don’t try and cheat the victims by imposing new contractual terms such as Equifax did in its recent settlement. Think of the simple way for a data breach to occur, a briefcase left on the Tube.
Don’t Diss the DPA. Why would a company take on the regulator? You must respect the regulator even if you disagree with them. You can make a bad situation worse by attacking the regulators. This does not mean you cannot forcefully argue you position or zealously represent you client but calling regulators idiots in public filings will not help you position or your case. 

Keep logs. This is important in case you need to revisit a decision later. Regulators can ask to see these logs at any time, not simply during an investigation or enforcement action. A compliance officer should be involved in the maintenance of the log system. Document Document Document. Unannounced inspections are beginning to occur.
Debrief and Learn. Revisit the facts to see what lessons are to be learned. Continuous improvement. Even on a journey of 1000 miles, it is important to look back. Once again if you make a change due to a breach or other event, document what you have done so you can show the regulators.
For more information on Cordery Compliance, go their website here.
For more information on data breaches, see here.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we conclude our three-part series of some of the key lessons learned from the first year of GDPR. Some of the issues and highlights are:</p><p><strong><em>Remediate then report. </em></strong>The remediation of an issue before reporting can be the key issue for regulators on whether they will move forward with a more public spanking. It is important to show that you have learned lessons and applied them to the facts of your data breach. Don’t try and cheat the victims by imposing new contractual terms such as Equifax did in its recent settlement. Think of the simple way for a data breach to occur, a briefcase left on the Tube.</p><p><strong><em>Don’t Diss the DPA. </em></strong>Why would a company take on the regulator? You must respect the regulator even if you disagree with them. You can make a bad situation worse by attacking the regulators. This does not mean you cannot forcefully argue you position or zealously represent you client but calling regulators idiots in public filings will not help you position or your case.<strong><em> </p><p></em></strong></p><p><strong><em>Keep logs. </em></strong>This is important in case you need to revisit a decision later. Regulators can ask to see these logs at any time, not simply during an investigation or enforcement action. A compliance officer should be involved in the maintenance of the log system. Document Document Document. Unannounced inspections are beginning to occur.</p><p><strong><em>Debrief and Learn. </em></strong>Revisit the facts to see what lessons are to be learned. Continuous improvement. Even on a journey of 1000 miles, it is important to look back. Once again if you make a change due to a breach or other event, document what you have done so you can show the regulators.</p><p>For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>.</p><p>For more information on data breaches, see <a href="https://www.corderycompliance.com/dealing-with-a-data-breach/">here</a>.</p><p>Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1652</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[bd43dfa0-d955-11e9-8d18-3bee1bcf2d40]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3526214596.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Episode 32- Lessons Learned in Year 1 of GDPR, Part 2</title>
      <description>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we continue our three-part series of some of the key lessons learned from the first year of GDPR. Some of the issues and highlights are:
DPIA Everything. It’s mandatory under GDPR. It is a process analysis so you will need Subject Matter Expertise. How often do you revisit DPIA? Regulators are beginning to look at the process of your DPIA. When new process comes into play, you should do a new DPIA. Do you require DPIA when you hire 3rdparty vendor or in the M&amp;A situation? If not you should do so moving forward.
Do SARs and DSRs are real good.How do you deal with these types of request? More importantly do you have a centralized team to understand the reason behind the request. Who could make that analysis? Is it a work in progress for your organization? Robust response to SARs is critical, as they are here to stay as core component of GDPR.
Respect the time. Time limits are much more generous in the US. Some regulators suggest not to be obsessed with time. Will courts allow ‘reasonable delay’? Corporations trying to extend the 72 hour by time zone arguments and other ridiculous argument by US corporations. (Listen for the Thanksgiving Weekend exemption) Regulators can fine you for being late. Are US companies getting the message? It’s a mixed bag, some are not doing so.
For more information on Cordery Compliance, go their website here.
For more information on data breaches, see here.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 05 Sep 2019 04:00:00 -0000</pubDate>
      <itunes:title>Episode 32- Lessons Learned in Year 1 of GDPR, Part 2</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>32</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/b3e9a418-c4f0-11e9-a119-d34ecae96522/image/uploads_2F1566487305217-8aowkjxsal7-d68997a0c7b71c5429df1d0617501cc4_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode of Life with GDPR, we continue our three-part series of some of the key lessons learned from the first year of GDPR.</itunes:subtitle>
      <itunes:summary>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we continue our three-part series of some of the key lessons learned from the first year of GDPR. Some of the issues and highlights are:
DPIA Everything. It’s mandatory under GDPR. It is a process analysis so you will need Subject Matter Expertise. How often do you revisit DPIA? Regulators are beginning to look at the process of your DPIA. When new process comes into play, you should do a new DPIA. Do you require DPIA when you hire 3rdparty vendor or in the M&amp;A situation? If not you should do so moving forward.
Do SARs and DSRs are real good.How do you deal with these types of request? More importantly do you have a centralized team to understand the reason behind the request. Who could make that analysis? Is it a work in progress for your organization? Robust response to SARs is critical, as they are here to stay as core component of GDPR.
Respect the time. Time limits are much more generous in the US. Some regulators suggest not to be obsessed with time. Will courts allow ‘reasonable delay’? Corporations trying to extend the 72 hour by time zone arguments and other ridiculous argument by US corporations. (Listen for the Thanksgiving Weekend exemption) Regulators can fine you for being late. Are US companies getting the message? It’s a mixed bag, some are not doing so.
For more information on Cordery Compliance, go their website here.
For more information on data breaches, see here.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we continue our three-part series of some of the key lessons learned from the first year of GDPR. Some of the issues and highlights are:</p><p><strong><em>DPIA Everything</em></strong>. It’s mandatory under GDPR. It is a process analysis so you will need Subject Matter Expertise. How often do you revisit DPIA? Regulators are beginning to look at the process of your DPIA. When new process comes into play, you should do a new DPIA. Do you require DPIA when you hire 3rdparty vendor or in the M&amp;A situation? If not you should do so moving forward.</p><p><strong><em>Do SARs and DSRs are real good.</em></strong>How do you deal with these types of request? More importantly do you have a centralized team to understand the reason behind the request. Who could make that analysis? Is it a work in progress for your organization? Robust response to SARs is critical, as they are here to stay as core component of GDPR.</p><p><strong><em>Respect the time</em></strong>. Time limits are much more generous in the US. Some regulators suggest not to be obsessed with time. Will courts allow ‘reasonable delay’? Corporations trying to extend the 72 hour by time zone arguments and other ridiculous argument by US corporations. (Listen for the Thanksgiving Weekend exemption) Regulators can fine you for being late. Are US companies getting the message? It’s a mixed bag, some are not doing so.</p><p>For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>.</p><p>For more information on data breaches, see <a href="https://www.corderycompliance.com/dealing-with-a-data-breach/">here</a>.</p><p>Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1557</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[b3e9a418-c4f0-11e9-a119-d34ecae96522]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5956177675.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Episode 31-Lessons Learned in Year 1 of GDPR, Part 1</title>
      <description>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we begin a three-part series of some of the key lessons learned from the first year of GDPR. Some of the highlights in this episode include:
Do you have a plan? You need to have a plan for a data breach because it is not if but when you will be hacked. Armstrong advises you can be two plans; one for all employees which is straight-forward so that all employees will be able to understand it. You should have a second plan, which you rehearse which is for all compliance/IT/data security. It should be process driven so it allows flexibility for those responding.
Know your data and know your third parties. Many companies have disaggregated data because they have so many vendors and platforms where data is stored. You must know who has your data. Do you have visibility into 3rd, 4thand 5thparties from the data perspective? You should also capture where data is going in an organization, particularly customer and employee data. Finally, and sadly overlooked by many US companies is the question of data protection of a US parent when a UK/EU sub is audited?
Assemble your data response team now and practice, practice, practice.You need to look at your data security response. What does the A Team teach you about data response? You should strive for strength in diverse skills and practice your response. Look at PR rapid response, your compliance, your legal response all in addition to your IT/data security response. Regulators looking at share price drop off, this shows the need for a rapid, practiced response.
For more information on Cordery Compliance, go their website here.
For more information on data breaches, see here.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 22 Aug 2019 04:00:00 -0000</pubDate>
      <itunes:title>Lessons Learned in Year 1 of GDPR, Part 1</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>31</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/7c4bb88e-c2bb-11e9-9f92-73516c8a74c2/image/uploads_2F1566244499615-qyes07ebj9-3d884792924fbdddb4fb7d8e2f13886c_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this part 1 of a three-part podcast series, Jonathan Armstrong and I consider 10 lessons learned from the first year of GDPE enforcement. </itunes:subtitle>
      <itunes:summary>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we begin a three-part series of some of the key lessons learned from the first year of GDPR. Some of the highlights in this episode include:
Do you have a plan? You need to have a plan for a data breach because it is not if but when you will be hacked. Armstrong advises you can be two plans; one for all employees which is straight-forward so that all employees will be able to understand it. You should have a second plan, which you rehearse which is for all compliance/IT/data security. It should be process driven so it allows flexibility for those responding.
Know your data and know your third parties. Many companies have disaggregated data because they have so many vendors and platforms where data is stored. You must know who has your data. Do you have visibility into 3rd, 4thand 5thparties from the data perspective? You should also capture where data is going in an organization, particularly customer and employee data. Finally, and sadly overlooked by many US companies is the question of data protection of a US parent when a UK/EU sub is audited?
Assemble your data response team now and practice, practice, practice.You need to look at your data security response. What does the A Team teach you about data response? You should strive for strength in diverse skills and practice your response. Look at PR rapid response, your compliance, your legal response all in addition to your IT/data security response. Regulators looking at share price drop off, this shows the need for a rapid, practiced response.
For more information on Cordery Compliance, go their website here.
For more information on data breaches, see here.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we begin a three-part series of some of the key lessons learned from the first year of GDPR. Some of the highlights in this episode include:</p><p><strong><em>Do you have a plan? </em></strong>You need to have a plan for a data breach because it is not if but when you will be hacked. Armstrong advises you can be two plans; one for all employees which is straight-forward so that all employees will be able to understand it. You should have a second plan, which you rehearse which is for all compliance/IT/data security. It should be process driven so it allows flexibility for those responding.</p><p><strong><em>Know your data and know your third parties. </em></strong>Many companies have disaggregated data because they have so many vendors and platforms where data is stored. You must know who has your data. Do you have visibility into 3rd, 4thand 5thparties from the data perspective? You should also capture where data is going in an organization, particularly customer and employee data. Finally, and sadly overlooked by many US companies is the question of data protection of a US parent when a UK/EU sub is audited?</p><p><strong><em>Assemble your data response team now and practice, practice, practice.</em></strong>You need to look at your data security response. What does the A Team teach you about data response? You should strive for strength in diverse skills and practice your response. Look at PR rapid response, your compliance, your legal response all in addition to your IT/data security response. Regulators looking at share price drop off, this shows the need for a rapid, practiced response.</p><p>For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>.</p><p>For more information on data breaches, see <a href="%20https://www.corderycompliance.com/dealing-with-a-data-breach/">here</a>.</p><p>Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1800</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[7c4bb88e-c2bb-11e9-9f92-73516c8a74c2]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1054251628.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 30- British Airways GDPR Enforcement Action</title>
      <description>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we discuss the recently announced proposed fine by the UK Data Protection Regulator against British Airways (BA) after its data breach. She intends to fine the airline £183.39 million (approximately $230MM).
Some of the highlights in this episode include:This proposed fine represents the largest GDPR fine in the UK.As the fine is now open to comment by BA and other national data protection regulators, the amount of the final fine may change.The BA CEO comes out swinging against this fine.What was the role of the ICO as ‘lead regulator’?Will BA’s tone-deaf posturing hurt or help it with the final penalty?What did BA know and when did they know (yes that is the famous Watergate question) will be a critical analysis.What remedial measures did BA engage in after it became aware of the breach?What are the lessons to be learned by the data privacy officer?For more information on Cordery Compliance, go their website here.
For additional reading see the Cordery Compliance article, “UK Data Protection Regulator Announces Intention to Fine BA after Data Breach”.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 11 Jul 2019 04:00:00 -0000</pubDate>
      <itunes:title>Episode 30- British Airways GDPR Enforcement Action</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>30</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/86b174cc-a1ae-11e9-a364-9323dd931443/image/uploads_2F1562610494990-7q2sxtqvq4q-575ccb4261612f23dda1a102b9373381_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode f Life with GDPR, Jonathan Armstrong and I discuss the proposed UK Data Protection Regulator fine against British Airways for its September 2018 reported data breach. </itunes:subtitle>
      <itunes:summary>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we discuss the recently announced proposed fine by the UK Data Protection Regulator against British Airways (BA) after its data breach. She intends to fine the airline £183.39 million (approximately $230MM).
Some of the highlights in this episode include:This proposed fine represents the largest GDPR fine in the UK.As the fine is now open to comment by BA and other national data protection regulators, the amount of the final fine may change.The BA CEO comes out swinging against this fine.What was the role of the ICO as ‘lead regulator’?Will BA’s tone-deaf posturing hurt or help it with the final penalty?What did BA know and when did they know (yes that is the famous Watergate question) will be a critical analysis.What remedial measures did BA engage in after it became aware of the breach?What are the lessons to be learned by the data privacy officer?For more information on Cordery Compliance, go their website here.
For additional reading see the Cordery Compliance article, “UK Data Protection Regulator Announces Intention to Fine BA after Data Breach”.
Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, we discuss the recently announced proposed fine by the UK Data Protection Regulator against British Airways (BA) after its data breach. She intends to fine the airline £183.39 million (approximately $230MM).</p><p>Some of the highlights in this episode include:This proposed fine represents the largest GDPR fine in the UK.As the fine is now open to comment by BA and other national data protection regulators, the amount of the final fine may change.The BA CEO comes out swinging against this fine.What was the role of the ICO as ‘lead regulator’?Will BA’s tone-deaf posturing hurt or help it with the final penalty?What did BA know and when did they know (yes that is the famous Watergate question) will be a critical analysis.What remedial measures did BA engage in after it became aware of the breach?What are the lessons to be learned by the data privacy officer?For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>.</p><p>For additional reading see the Cordery Compliance article, “<a href="http://www.corderycompliance.com/uk-dpa-to-fine-ba-for-data-breach/"><em>UK Data Protection Regulator Announces Intention to Fine BA after Data Breach</em></a>”.</p><p>Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1526</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[86b174cc-a1ae-11e9-a364-9323dd931443]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1654600688.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 29- GDPR Year 1 Review-Part II, the Issues</title>
      <description>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. This episode is the first of a two-part series where  Jonathan Armstrong and myself consider some of the highlights from the first year of GDPR implementation and enforcement. In this Part I we considered some of the enforcement numbers. In this Part II, we discuss some of the substantive issues. Some of the highlights in this episode include: Security issues-multiple regulators for large breaches and questions of whether TOMs are adequate. 6 Principles of GDPR-highest is around transparency.Data Subject Rights are seen as the biggest corporate pain points.DPIAs have been embraced by many companies and are seen by regulators as the backbone of a corporate compliance program around data security/data privacy. Industry sweeps are beginning to occur. Mixed quality of legal advice is hurting many companies in their compliance efforts. Some significant cases are headed to trial and then appeal. GDPR is here to stay. For more information on Cordery Compliance, go their website here.For additional reading see the Cordery Compliance article, “GDPR One Year On”.Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 06 Jun 2019 04:03:00 -0000</pubDate>
      <itunes:title>Episode 29- GDPR Year 1 Review-Part II, the Issues</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>29</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/f13c7ff4-83f3-11e9-b496-17218f04f840/image/uploads_2F1559341700822-cq9423q9f4p-6c8137060799287b2aa1a5f11ca44b11_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. This episode is the first of a two-part series where  Jonathan Armstrong and myself consider some of the highlights from the first year of GDPR implementation and enforcement. In this Part I we considered some of the enforcement numbers. In this Part II, we discuss some of the substantive issues. Some of the highlights in this episode include: Security issues-multiple regulators for large breaches and questions of whether TOMs are adequate. 6 Principles of GDPR-highest is around transparency.Data Subject Rights are seen as the biggest corporate pain points.DPIAs have been embraced by many companies and are seen by regulators as the backbone of a corporate compliance program around data security/data privacy. Industry sweeps are beginning to occur. Mixed quality of legal advice is hurting many companies in their compliance efforts. Some significant cases are headed to trial and then appeal. GDPR is here to stay. For more information on Cordery Compliance, go their website here.For additional reading see the Cordery Compliance article, “GDPR One Year On”.Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. This episode is the first of a two-part series where  Jonathan Armstrong and myself consider some of the highlights from the first year of GDPR implementation and enforcement. In this Part I we considered some of the enforcement numbers. In this Part II, we discuss some of the substantive issues. Some of the highlights in this episode include: Security issues-multiple regulators for large breaches and questions of whether TOMs are adequate. 6 Principles of GDPR-highest is around transparency.Data Subject Rights are seen as the biggest corporate pain points.DPIAs have been embraced by many companies and are seen by regulators as the backbone of a corporate compliance program around data security/data privacy. Industry sweeps are beginning to occur. Mixed quality of legal advice is hurting many companies in their compliance efforts. Some significant cases are headed to trial and then appeal. GDPR is here to stay. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>.For additional reading see the Cordery Compliance article, “<a href="http://www.corderycompliance.com/gdpr-one-year-on/"><em>GDPR One Year On</em></a>”.Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1973</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[f13c7ff4-83f3-11e9-b496-17218f04f840]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN1194916590.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 28- GDPR Year 1 Review-Part I, the Numbers</title>
      <description>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. This episode is the first of a two-part series where  Jonathan Armstrong and myself consider some of the highlights from the first year of GDPR implementation and enforcement. In this Part I of this two-part series we consider some of the enforcement numbers. In Part II, we will consider some of the substantive issues. Some of the highlights in this episode include: EDPB says just over 150,000 complaints files EU under GDPR. Robust enforcement by both regulators and private bodies/citizens.UK leads with the largest number of complaints filed, followed by Germany then France.Around 950 complaints have reach courts. Italy is the country which has seen the largest number of court cases. Several countries are increasing inspections which could lead to enforcement actions.  For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 30 May 2019 04:10:00 -0000</pubDate>
      <itunes:title>Episode 28- GDPR Year 1 Review-Part I, the Numbers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>28</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/e8383c62-8151-11e9-aa38-db0246888451/image/uploads_2F1559052178492-dzh2kwrwser-26097cd955736eda9b0e1833f95fadec_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode Jonathan Armstrong and myself begin a two-part podcast series where we review the first year of GDPR. In this episode we consider the numbers from Year 1.</itunes:subtitle>
      <itunes:summary>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. This episode is the first of a two-part series where  Jonathan Armstrong and myself consider some of the highlights from the first year of GDPR implementation and enforcement. In this Part I of this two-part series we consider some of the enforcement numbers. In Part II, we will consider some of the substantive issues. Some of the highlights in this episode include: EDPB says just over 150,000 complaints files EU under GDPR. Robust enforcement by both regulators and private bodies/citizens.UK leads with the largest number of complaints filed, followed by Germany then France.Around 950 complaints have reach courts. Italy is the country which has seen the largest number of court cases. Several countries are increasing inspections which could lead to enforcement actions.  For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. This episode is the first of a two-part series where  Jonathan Armstrong and myself consider some of the highlights from the first year of GDPR implementation and enforcement. In this Part I of this two-part series we consider some of the enforcement numbers. In Part II, we will consider some of the substantive issues. Some of the highlights in this episode include: EDPB says just over 150,000 complaints files EU under GDPR. Robust enforcement by both regulators and private bodies/citizens.UK leads with the largest number of complaints filed, followed by Germany then France.Around 950 complaints have reach courts. Italy is the country which has seen the largest number of court cases. Several countries are increasing inspections which could lead to enforcement actions.  For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>686</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[e8383c62-8151-11e9-aa38-db0246888451]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN3869473445.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 27- BountyUK Ltd. Notice of Monetary Penalty</title>
      <description>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, I visit with Jonathan Armstrong about a recent enforcement action against Bounty UK Ltd. by the UK data protection regulator. Some of the issues and highlights are: The enforcement action came out of the Facebook/Cambridge Analytica investigation. Déjà vu all over again?Why did the company receive 80% of the highest possible fine?How does this case mimic the Emma’s Diary enforcement action?What are the lessons to be learned? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 16 May 2019 04:06:00 -0000</pubDate>
      <itunes:title>Episode 27- BountyUK Ltd. Notice of Monetary Penalty</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>27</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/c600cddc-769b-11e9-85b8-4b0e463d0b43/image/uploads_2F1557874412527-rskd2d8b7b-b70a2252d7bf1630becb7a221f077aad_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode Cordery Compliance Partner Jonathan Armstrong and myself break down the recently released BountyUK Ltd. data privacy enforcement action. </itunes:subtitle>
      <itunes:summary>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, I visit with Jonathan Armstrong about a recent enforcement action against Bounty UK Ltd. by the UK data protection regulator. Some of the issues and highlights are: The enforcement action came out of the Facebook/Cambridge Analytica investigation. Déjà vu all over again?Why did the company receive 80% of the highest possible fine?How does this case mimic the Emma’s Diary enforcement action?What are the lessons to be learned? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this podcast, data privacy/data security expert Jonathan Armstrong and Compliance Evangelist Tom Fox use the framework of GDPR to discuss a wide range of issues relating to these topics. They consider what the US compliance and InfoSec security expert needs to know about what is happening in the UK, Europe and beyond. In this episode, I visit with Jonathan Armstrong about a recent enforcement action against Bounty UK Ltd. by the UK data protection regulator. Some of the issues and highlights are: The enforcement action came out of the Facebook/Cambridge Analytica investigation. Déjà vu all over again?Why did the company receive 80% of the highest possible fine?How does this case mimic the Emma’s Diary enforcement action?What are the lessons to be learned? For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1797</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[c600cddc-769b-11e9-85b8-4b0e463d0b43]]></guid>
      <enclosure url="https://traffic.megaphone.fm/CSN5006169486.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 26- The Importance of Passwords</title>
      <description>In this episode, I visit with Jonathan Armstrong a topic which does not seem to garner the attention that it deserves in data protection; that being passwords. Some of the issues and highlights are: What is two-factor authentication? How, when and where should your use it?What are the most common passwords still in use?Why are passwords one of the most basic forms of data security protection?What are the lessons to be learned? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 02 May 2019 05:03:00 -0000</pubDate>
      <itunes:title>Life With GDPR: Episode 26- The Importance of Passwords</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>26</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/88a6776c-69e8-11e9-8c23-0f5ce1ded0b8/image/uploads_2F1556478264851-db7exlwgexo-c32afc36acb0efb6a9c57a2fb85221d9_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Life With GDPR: Episode 26- The Importance of Passwords</itunes:subtitle>
      <itunes:summary>In this episode, I visit with Jonathan Armstrong a topic which does not seem to garner the attention that it deserves in data protection; that being passwords. Some of the issues and highlights are: What is two-factor authentication? How, when and where should your use it?What are the most common passwords still in use?Why are passwords one of the most basic forms of data security protection?What are the lessons to be learned? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, I visit with Jonathan Armstrong a topic which does not seem to garner the attention that it deserves in data protection; that being passwords. Some of the issues and highlights are: What is two-factor authentication? How, when and where should your use it?What are the most common passwords still in use?Why are passwords one of the most basic forms of data security protection?What are the lessons to be learned? For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1137</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[88a6776c-69e8-11e9-8c23-0f5ce1ded0b8]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS9140819275.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 25- Data Breach=Deadly Consequences</title>
      <description>In this episode, I visit with Jonathan Armstrong to consider the recent regulatory fine leveled against London Borough of Newham £145,000 for a data breach involving the data of more than 200 people. It presents a situation where a data breach was literally a matter of life and death. Some of the issues and highlights are: What was the data and why was it so sensitive? How was the data leaked?How did the authorities determine the data breach?What as the basis of the Information Commissioner’s Office (ICO) fine?What are the lessons to be learned? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 18 Apr 2019 05:05:00 -0000</pubDate>
      <itunes:title>Life With GDPR: Episode 25- Data Breach=Deadly Consequences</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>25</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/5232c0b6-6112-11e9-b3a1-0f0be362fde1/image/uploads_2F1555506301065-glzwgp4k0ic-dcedc4bdd32a2b8ff18fa0d7a0adb91a_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Life With GDPR: Episode 25- Data Breach=Deadly Consequences</itunes:subtitle>
      <itunes:summary>In this episode, I visit with Jonathan Armstrong to consider the recent regulatory fine leveled against London Borough of Newham £145,000 for a data breach involving the data of more than 200 people. It presents a situation where a data breach was literally a matter of life and death. Some of the issues and highlights are: What was the data and why was it so sensitive? How was the data leaked?How did the authorities determine the data breach?What as the basis of the Information Commissioner’s Office (ICO) fine?What are the lessons to be learned? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, I visit with Jonathan Armstrong to consider the recent regulatory fine leveled against London Borough of Newham £145,000 for a data breach involving the data of more than 200 people. It presents a situation where a data breach was literally a matter of life and death. Some of the issues and highlights are: What was the data and why was it so sensitive? How was the data leaked?How did the authorities determine the data breach?What as the basis of the Information Commissioner’s Office (ICO) fine?What are the lessons to be learned? For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1043</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[5232c0b6-6112-11e9-b3a1-0f0be362fde1]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS3875045973.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 24- Phishing</title>
      <description>In this episode, I visit with Jonathan Armstrong consider the increasing business risk around phishing. There have recently been some multi-million-dollar losses around phishing so you need to be prepared. Some of the issues and highlights are: What is phishing? The largest number of data breach have come through phishing. Why has it become such a business risk?What are the requirements a company take against phishing under GDPR?What are the three key concepts in data protection?Modern phishing attacks are very sophisticated.What are some of the most intricate frauds seen in this area? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 28 Mar 2019 05:00:00 -0000</pubDate>
      <itunes:title>Life With GDPR: Episode 24- Phishing</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>24</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/eaeef786-4833-11e9-b9b9-5f52d6d03152/image/uploads_2F1552772193954-tklah8538jd-0c1d68bfffeb97ccae4c4290b18fae1a_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Life With GDPR: Episode 24- Phishing</itunes:subtitle>
      <itunes:summary>In this episode, I visit with Jonathan Armstrong consider the increasing business risk around phishing. There have recently been some multi-million-dollar losses around phishing so you need to be prepared. Some of the issues and highlights are: What is phishing? The largest number of data breach have come through phishing. Why has it become such a business risk?What are the requirements a company take against phishing under GDPR?What are the three key concepts in data protection?Modern phishing attacks are very sophisticated.What are some of the most intricate frauds seen in this area? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, I visit with Jonathan Armstrong consider the increasing business risk around phishing. There have recently been some multi-million-dollar losses around phishing so you need to be prepared. Some of the issues and highlights are: What is phishing? The largest number of data breach have come through phishing. Why has it become such a business risk?What are the requirements a company take against phishing under GDPR?What are the three key concepts in data protection?Modern phishing attacks are very sophisticated.What are some of the most intricate frauds seen in this area? For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1027</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[eaeef786-4833-11e9-b9b9-5f52d6d03152]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS1126302915.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 23- Looking into the 2019 Crystal Ball</title>
      <description>In this episode, I visit with Jonathan Armstrong consider some of his predictions for the rest of 2019. Even if these predictions do not become fully formed, you should consider them in light of your data privacy/data protection policies and protocols. Some of the issues and highlights are: Drones-what are the GDPR implications. The number of data breach notifications under GDPR. Through the end of January there were over 42,000 in the EU alone.Will AI and self-driving cars follow the rules on safe driving standards, or will there be new rules for the road? What will be the effects of data, big data and AI in elections going forward? What will be the fallout from Cambridge Analytica going forward?How will businesses respond to the industrialization of internet crime? What happens when there is a Zero-Day exploit?Cybersecurity insurance. Will standard insurance rules and regulations apply, or will new policy language be drafted for such coverage? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 21 Mar 2019 05:00:00 -0000</pubDate>
      <itunes:title>Life With GDPR: Episode 23- Looking into the 2019 Crystal Ball</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>23</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/1eb993b2-4831-11e9-a396-077938cb25fe/image/uploads_2F1552770728311-3ezu36u4bzh-9a2110beeae9134997bc2f52261b12fc_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Life With GDPR: Episode 23- Looking into the 2019 Crystal Ball</itunes:subtitle>
      <itunes:summary>In this episode, I visit with Jonathan Armstrong consider some of his predictions for the rest of 2019. Even if these predictions do not become fully formed, you should consider them in light of your data privacy/data protection policies and protocols. Some of the issues and highlights are: Drones-what are the GDPR implications. The number of data breach notifications under GDPR. Through the end of January there were over 42,000 in the EU alone.Will AI and self-driving cars follow the rules on safe driving standards, or will there be new rules for the road? What will be the effects of data, big data and AI in elections going forward? What will be the fallout from Cambridge Analytica going forward?How will businesses respond to the industrialization of internet crime? What happens when there is a Zero-Day exploit?Cybersecurity insurance. Will standard insurance rules and regulations apply, or will new policy language be drafted for such coverage? For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, I visit with Jonathan Armstrong consider some of his predictions for the rest of 2019. Even if these predictions do not become fully formed, you should consider them in light of your data privacy/data protection policies and protocols. Some of the issues and highlights are: Drones-what are the GDPR implications. The number of data breach notifications under GDPR. Through the end of January there were over 42,000 in the EU alone.Will AI and self-driving cars follow the rules on safe driving standards, or will there be new rules for the road? What will be the effects of data, big data and AI in elections going forward? What will be the fallout from Cambridge Analytica going forward?How will businesses respond to the industrialization of internet crime? What happens when there is a Zero-Day exploit?Cybersecurity insurance. Will standard insurance rules and regulations apply, or will new policy language be drafted for such coverage? For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1710</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[1eb993b2-4831-11e9-a396-077938cb25fe]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS4736928507.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 22- Morrisons’ and vicarious liability</title>
      <description>In this episode, I visit with Jonathan Armstrong on the recent UK court of appeals decision in the Morrisons’ case. This decision stretched the limits of vicarious liability for a corporation to the absolute breaking point and has significant implications in the broader data privacy-data protection space. Jonathan and I go full lawyer-geek to discuss the legal theories, underlying facts and what it all may mean. Some of the issues and highlights are: The case is instructive for how to do (or perhaps not do) regular business under GDPR on data privacy. If a file is too large to email, it presents a higher data protection risk and must be so managed.Should you do risk assessments on individual employees around data privacy-data protection? How can vicarious liability exist for ultra vires conduct by an employee?How do you properly scope an investigation to ascertain an individual’s mindset?A company must require its vendors to exercise appropriate data protection and control. Will Morrisons apply to the UK Supreme Court for relief? For a more detailed reading, see the Cordery Client alert, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 14 Feb 2019 06:00:00 -0000</pubDate>
      <itunes:title>Life With GDPR: Episode 22- Morrisons’ and vicarious liability</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>22</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/68218d58-24d1-11e9-814c-ab8c89ec1cc7/image/uploads_2F1548881658830-0f9h1uj3znsp-f47ec7ca77724f9c7dd1542c6dcee7e8_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Episode 22- Morrisons’ and vicarious liability</itunes:subtitle>
      <itunes:summary>In this episode, I visit with Jonathan Armstrong on the recent UK court of appeals decision in the Morrisons’ case. This decision stretched the limits of vicarious liability for a corporation to the absolute breaking point and has significant implications in the broader data privacy-data protection space. Jonathan and I go full lawyer-geek to discuss the legal theories, underlying facts and what it all may mean. Some of the issues and highlights are: The case is instructive for how to do (or perhaps not do) regular business under GDPR on data privacy. If a file is too large to email, it presents a higher data protection risk and must be so managed.Should you do risk assessments on individual employees around data privacy-data protection? How can vicarious liability exist for ultra vires conduct by an employee?How do you properly scope an investigation to ascertain an individual’s mindset?A company must require its vendors to exercise appropriate data protection and control. Will Morrisons apply to the UK Supreme Court for relief? For a more detailed reading, see the Cordery Client alert, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, I visit with Jonathan Armstrong on the recent UK court of appeals decision in the Morrisons’ case. This decision stretched the limits of vicarious liability for a corporation to the absolute breaking point and has significant implications in the broader data privacy-data protection space. Jonathan and I go full lawyer-geek to discuss the legal theories, underlying facts and what it all may mean. Some of the issues and highlights are: The case is instructive for how to do (or perhaps not do) regular business under GDPR on data privacy. If a file is too large to email, it presents a higher data protection risk and must be so managed.Should you do risk assessments on individual employees around data privacy-data protection? How can vicarious liability exist for ultra vires conduct by an employee?How do you properly scope an investigation to ascertain an individual’s mindset?A company must require its vendors to exercise appropriate data protection and control. Will Morrisons apply to the UK Supreme Court for relief? For a more detailed reading, see the Cordery Client alert, <a href="http://www.corderycompliance.com/client-alert-court-of-appeal-confirms-morrisons-vicarious-liability-for-actions-of-rogue-employees/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1652</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[68218d58-24d1-11e9-814c-ab8c89ec1cc7]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS2506757095.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 21- Cambridge Analytica Subject Access Case</title>
      <description>In this episode I visit with Jonathan Armstrong on the recent fine levied by British regulators against the insolvent institution Cambridge Analytica for violations of the British privacy law which was in place before GDPR went live. The case involved Cambridge Analytica denying aggrieved parties subject access requests and associated rights. Some of the issues and highlights are: The case demonstrates how not to interact with regulators as Cambridge Analytica’s pleadings were unnecessarily demeaning. The settlement with the company left open the possibility of criminal charges against individuals.How wide is the jurisdiction of the ICO? This case tested the limits. Always remember data subjects have rights.What are the key takeaways on the case?A vigorous defense of a civil action can lead to higher regulatory fines. What does a corporate regime change mean for regulatory enforcement? For a more detailed reading, see the Cordery Client alert, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 31 Jan 2019 06:00:00 -0000</pubDate>
      <itunes:title>Life With GDPR: Episode 21- Cambridge Analytica Subject Access Case</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>21</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/8d147c68-24ce-11e9-b45d-c7a8bdc13d2f/image/uploads_2F1548880467313-6dfxnrhxzmy-a0763211a86061c6f7229f0dcba1f771_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle> Cambridge Analytica Subject Access Case</itunes:subtitle>
      <itunes:summary>In this episode I visit with Jonathan Armstrong on the recent fine levied by British regulators against the insolvent institution Cambridge Analytica for violations of the British privacy law which was in place before GDPR went live. The case involved Cambridge Analytica denying aggrieved parties subject access requests and associated rights. Some of the issues and highlights are: The case demonstrates how not to interact with regulators as Cambridge Analytica’s pleadings were unnecessarily demeaning. The settlement with the company left open the possibility of criminal charges against individuals.How wide is the jurisdiction of the ICO? This case tested the limits. Always remember data subjects have rights.What are the key takeaways on the case?A vigorous defense of a civil action can lead to higher regulatory fines. What does a corporate regime change mean for regulatory enforcement? For a more detailed reading, see the Cordery Client alert, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode I visit with Jonathan Armstrong on the recent fine levied by British regulators against the insolvent institution Cambridge Analytica for violations of the British privacy law which was in place before GDPR went live. The case involved Cambridge Analytica denying aggrieved parties subject access requests and associated rights. Some of the issues and highlights are: The case demonstrates how not to interact with regulators as Cambridge Analytica’s pleadings were unnecessarily demeaning. The settlement with the company left open the possibility of criminal charges against individuals.How wide is the jurisdiction of the ICO? This case tested the limits. Always remember data subjects have rights.What are the key takeaways on the case?A vigorous defense of a civil action can lead to higher regulatory fines. What does a corporate regime change mean for regulatory enforcement? For a more detailed reading, see the Cordery Client alert, <a href="http://www.corderycompliance.com/ico-secures-criminal-convictions-against-ca-in-sar-case/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1155</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[8d147c68-24ce-11e9-b45d-c7a8bdc13d2f]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS4413925118.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 20-Google Fined €50 for GDPR Violations</title>
      <description>In this episode I visit with Jonathan Armstrong and André Bywater on the recent fine levied by the French Data Privacy regulator CNIL against Google for violations under GDPR. Some of the highlights are: The case is the first major GDPR fine against a US company.It demonstrates the lack of forum shopping available to US companies which are looking for a softer regulatory approach.How did the regulators investigate, review and assess a fine and penalty so quickly as GDPR only came into effect last May?What were the two basis of legal violations under GDPR?What are the key takeaways on the case?How was the quantum amount determined? Is it reasonable? Will Google appeal to the European Court of Justice?  For a more detailed reading, see the Cordery Client alert, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Fri, 25 Jan 2019 06:00:00 -0000</pubDate>
      <itunes:title>Life With GDPR: Episode 20-Google Fined €50 for GDPR Violations</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>20</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/ee0bd970-1e80-11e9-89e3-2bb29de304f4/image/uploads_2F1548187432724-vzkyl7rbb5-c20a132c1452e9e823f8d5db7787d869_2FLife+after+GDPR-1.0.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Episode 20-Google Fined €50 for GDPR Violations</itunes:subtitle>
      <itunes:summary>In this episode I visit with Jonathan Armstrong and André Bywater on the recent fine levied by the French Data Privacy regulator CNIL against Google for violations under GDPR. Some of the highlights are: The case is the first major GDPR fine against a US company.It demonstrates the lack of forum shopping available to US companies which are looking for a softer regulatory approach.How did the regulators investigate, review and assess a fine and penalty so quickly as GDPR only came into effect last May?What were the two basis of legal violations under GDPR?What are the key takeaways on the case?How was the quantum amount determined? Is it reasonable? Will Google appeal to the European Court of Justice?  For a more detailed reading, see the Cordery Client alert, here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode I visit with Jonathan Armstrong and André Bywater on the recent fine levied by the French Data Privacy regulator CNIL against Google for violations under GDPR. Some of the highlights are: The case is the first major GDPR fine against a US company.It demonstrates the lack of forum shopping available to US companies which are looking for a softer regulatory approach.How did the regulators investigate, review and assess a fine and penalty so quickly as GDPR only came into effect last May?What were the two basis of legal violations under GDPR?What are the key takeaways on the case?How was the quantum amount determined? Is it reasonable? Will Google appeal to the European Court of Justice?  For a more detailed reading, see the Cordery Client alert, <a href="http://www.corderycompliance.com/french-data-protection-authority-fines-google-e50m-for-violations/">here</a>. For more information on Cordery Compliance, go their website <a href="http://www.corderycompliance.com/">here</a>. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking <a href="http://www.corderycompliance.com/solutions/cordery-gdpr-navigator/">here</a>.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1655</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[ee0bd970-1e80-11e9-89e3-2bb29de304f4]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS5236463494.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 15</title>
      <description>The Administration’s attacks on allies, perhaps former allies and other in the area of trade and sanctions has not occurred in vacuum. Many other countries and groups such as the EU have retaliated with counter-sanctions. One area that the current administration does not seem to have considered too well is EU data privacy and data protection. In this episode of Life with GDPR we explore this issue in the age of trade policy as conflict. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 30 Aug 2018 16:00:00 -0000</pubDate>
      <itunes:title>The Weaponization of Data Privacy/Protection Laws</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>15</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/a352b842-c5b9-11e8-ae30-1313de16cef7/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>The Weaponization of Data Privacy/Protection Laws</itunes:subtitle>
      <itunes:summary>The Administration’s attacks on allies, perhaps former allies and other in the area of trade and sanctions has not occurred in vacuum. Many other countries and groups such as the EU have retaliated with counter-sanctions. One area that the current administration does not seem to have considered too well is EU data privacy and data protection. In this episode of Life with GDPR we explore this issue in the age of trade policy as conflict. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>The Administration’s attacks on allies, perhaps former allies and other in the area of trade and sanctions has not occurred in vacuum. Many other countries and groups such as the EU have retaliated with counter-sanctions. One area that the current administration does not seem to have considered too well is EU data privacy and data protection. In this episode of Life with GDPR we explore this issue in the age of trade policy as conflict. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>891</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[197603ed385641e7a0ca150fc6ff0e74]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS6744966345.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life with GDPR-Episode 14</title>
      <description>The recent case involving the Jehovah's Witnesses and data privacy in the UK raised some very interesting legal issues. It also demonstrated just how broad the reach of GDPR could be. In this podcast Jonathan Armstrong and I unpack the case, detailing the underlying facts, the Court's rationale behind its decision and conclude with some of the implications for not only corporations but also individuals and data privacy practitioners. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 23 Aug 2018 16:00:00 -0000</pubDate>
      <itunes:title>The Jehova's Witness Case and data privacy</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>14</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/a9c11c28-c5b9-11e8-ae30-4fa9df4664d0/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>The Jehovah's Witness Case and data privacy</itunes:subtitle>
      <itunes:summary>The recent case involving the Jehovah's Witnesses and data privacy in the UK raised some very interesting legal issues. It also demonstrated just how broad the reach of GDPR could be. In this podcast Jonathan Armstrong and I unpack the case, detailing the underlying facts, the Court's rationale behind its decision and conclude with some of the implications for not only corporations but also individuals and data privacy practitioners. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>The recent case involving the Jehovah's Witnesses and data privacy in the UK raised some very interesting legal issues. It also demonstrated just how broad the reach of GDPR could be. In this podcast Jonathan Armstrong and I unpack the case, detailing the underlying facts, the Court's rationale behind its decision and conclude with some of the implications for not only corporations but also individuals and data privacy practitioners. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1590</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[f568d3e4d07548ea9c74a8c9b958c8d5]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS2110741155.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDPR: Episode 13</title>
      <description>The General Data Protection Regulation (GDPR) which went live on May 25, 2018. What has happened since then in the data privacy and data protection world? In this episode, Jonathan Armstrong, partner at Cordery Compliance and I explore what is going on publicly and what has been going on behind the scenes as well. Armstrong provides his thoughts, reflections and observations on the activity which have and will impact companies and individuals going forward.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 09 Aug 2018 16:00:00 -0000</pubDate>
      <itunes:title> Thoughts, Reflections and Observations at 2 Months</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>13</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/af75c2cc-c5b9-11e8-ae30-73660d5d186f/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle> Thoughts, Reflections and Observations at 2 Months</itunes:subtitle>
      <itunes:summary>The General Data Protection Regulation (GDPR) which went live on May 25, 2018. What has happened since then in the data privacy and data protection world? In this episode, Jonathan Armstrong, partner at Cordery Compliance and I explore what is going on publicly and what has been going on behind the scenes as well. Armstrong provides his thoughts, reflections and observations on the activity which have and will impact companies and individuals going forward.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>The General Data Protection Regulation (GDPR) which went live on May 25, 2018. What has happened since then in the data privacy and data protection world? In this episode, Jonathan Armstrong, partner at Cordery Compliance and I explore what is going on publicly and what has been going on behind the scenes as well. Armstrong provides his thoughts, reflections and observations on the activity which have and will impact companies and individuals going forward.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>1007</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[c62afe462cf64553a8928dfe45078139]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS6687166096.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life After GDPR: Episode 11 </title>
      <description>How does a company transfer data from the European Union (EU) to the US under the General Data Protection Regulation (GDPR) which went live on May 25, 2018? I recently had the opportunity to visit Jonathan Armstrong, partner at Cordery Compliance in London and an internationally renowned data privacy/data protection expert on this topic. Armstrong noted there have been some changes which may significantly impact this issue going forward. There are basically four ways to affect such a transfer. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Wed, 27 Jun 2018 23:00:00 -0000</pubDate>
      <itunes:title>Data Transfers after GDPR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>11</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/b78c39e6-c5b9-11e8-ae30-135cd229212b/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Data Transfers after GDPR</itunes:subtitle>
      <itunes:summary>How does a company transfer data from the European Union (EU) to the US under the General Data Protection Regulation (GDPR) which went live on May 25, 2018? I recently had the opportunity to visit Jonathan Armstrong, partner at Cordery Compliance in London and an internationally renowned data privacy/data protection expert on this topic. Armstrong noted there have been some changes which may significantly impact this issue going forward. There are basically four ways to affect such a transfer. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>How does a company transfer data from the European Union (EU) to the US under the General Data Protection Regulation (GDPR) which went live on May 25, 2018? I recently had the opportunity to visit Jonathan Armstrong, partner at Cordery Compliance in London and an internationally renowned data privacy/data protection expert on this topic. Armstrong noted there have been some changes which may significantly impact this issue going forward. There are basically four ways to affect such a transfer. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>882</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[5792dd6398b34e7b988c36ca0ab8df62]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS1163180918.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Life With GDRP-Epiosde 10</title>
      <description>While most practitioners focused on the heavy fines and penalties available under GDPR of up to 4% of total global revenues or other very large fines, there are other remedies that each EU and UK data regulator can levy or put into place that may require considerable corporate cost and effort. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 21 Jun 2018 16:00:00 -0000</pubDate>
      <itunes:title>Non-Financial Remedies under GDPR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>10</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/b889dbaa-c5b9-11e8-ae30-4f14c2f0962c/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Non-Financial Remedies under GDPR</itunes:subtitle>
      <itunes:summary>While most practitioners focused on the heavy fines and penalties available under GDPR of up to 4% of total global revenues or other very large fines, there are other remedies that each EU and UK data regulator can levy or put into place that may require considerable corporate cost and effort. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>While most practitioners focused on the heavy fines and penalties available under GDPR of up to 4% of total global revenues or other very large fines, there are other remedies that each EU and UK data regulator can levy or put into place that may require considerable corporate cost and effort. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>908</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[392a5552a7484c7b87bb51d4ddca017c]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS5944059386.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Countdown to GDPR-Episode 5</title>
      <description>In this episode of Countdown to GDPR, Jonathan Armstrong, a partner at Cordery Compliance in London and I consider the roles of vendors in GDPR. These roles are both in complying with GDPR and substantively following the regulation itself. The first area is a vendor which is a subject matter expert in the areas of data protection and data privacy. The second is in managing vendor risk under GDPR. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 12 Apr 2018 16:00:00 -0000</pubDate>
      <itunes:title>Vendors in GDPR Compliance</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>5</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/7e33316e-c810-11e8-be13-437724c2349c/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Vendors in GDPR Compliance</itunes:subtitle>
      <itunes:summary>In this episode of Countdown to GDPR, Jonathan Armstrong, a partner at Cordery Compliance in London and I consider the roles of vendors in GDPR. These roles are both in complying with GDPR and substantively following the regulation itself. The first area is a vendor which is a subject matter expert in the areas of data protection and data privacy. The second is in managing vendor risk under GDPR. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode of Countdown to GDPR, Jonathan Armstrong, a partner at Cordery Compliance in London and I consider the roles of vendors in GDPR. These roles are both in complying with GDPR and substantively following the regulation itself. The first area is a vendor which is a subject matter expert in the areas of data protection and data privacy. The second is in managing vendor risk under GDPR. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>796</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[fc05ff7d913c3d10060783096ca1fdb7]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS8430462817.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Countdown to GDPR-Episode 4</title>
      <description>In this episode, we take up a key element in the upcoming General Data Protection Regulation (GDPR), which comes into effect on May 25, 2018, that being the issue of the Data Protection Impact Assessment.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Thu, 29 Mar 2018 16:00:00 -0000</pubDate>
      <itunes:title>Data Protection Impact Assessments</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>4</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/81d1123c-c810-11e8-be13-23e48d5c9183/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Data Protection Impact Assessments</itunes:subtitle>
      <itunes:summary>In this episode, we take up a key element in the upcoming General Data Protection Regulation (GDPR), which comes into effect on May 25, 2018, that being the issue of the Data Protection Impact Assessment.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, we take up a key element in the upcoming General Data Protection Regulation (GDPR), which comes into effect on May 25, 2018, that being the issue of the Data Protection Impact Assessment.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>715</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[0a629d2d5ded0002667e73d1ae7df60d]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS9793220583.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Countdown to GDPR-Episode 3</title>
      <description>In this episode we explore the basic policies and procedures that you need to have in place to comply with the General Data Protection Regulation or GDPR.
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Wed, 07 Mar 2018 17:00:00 -0000</pubDate>
      <itunes:title>Policies and Procedures</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>3</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/85de21b2-c810-11e8-be13-73ba26b44334/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Policies and Procedures</itunes:subtitle>
      <itunes:summary>In this episode we explore the basic policies and procedures that you need to have in place to comply with the General Data Protection Regulation or GDPR.
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode we explore the basic policies and procedures that you need to have in place to comply with the General Data Protection Regulation or GDPR.</p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>879</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[553d12a448b4a3df608fbe8c89930737]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS9937510312.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Countdown to GDPR-Episode 2</title>
      <description>In today’s episode of Countdown to General Data Protection Regulation (GDRP), Jonathan Armstrong, a partner at Cordery Compliance Ltd in London, and myself consider the role of the Data Protection Officer (DPO) in complying with the new regulations which go live on May 25, 2018. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Wed, 28 Feb 2018 17:00:00 -0000</pubDate>
      <itunes:title>The Role of a Data Protection Officer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>2</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/874718c4-c810-11e8-be13-43bb63eba0d1/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>The Role of a Data Protection Officer</itunes:subtitle>
      <itunes:summary>In today’s episode of Countdown to General Data Protection Regulation (GDRP), Jonathan Armstrong, a partner at Cordery Compliance Ltd in London, and myself consider the role of the Data Protection Officer (DPO) in complying with the new regulations which go live on May 25, 2018. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In today’s episode of Countdown to General Data Protection Regulation (GDRP), Jonathan Armstrong, a partner at Cordery Compliance Ltd in London, and myself consider the role of the Data Protection Officer (DPO) in complying with the new regulations which go live on May 25, 2018. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>768</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[8ecf61d398d3094d1171609d16a42d93]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS8336028406.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Countdown to GDPR-Episode 1</title>
      <description>Whether you are ready or not, the EU General Data Protection Regulation (GDPR) goes live on May 25, 2018. It will impact companies doing business in London as much as any other EU legislation. To help US companies prepare, Jonathan Armstrong and myself have started a countdown to GDPR podcast. In this premier episode we discuss what is GDPR and why it is so important that you begin preparing now. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</description>
      <pubDate>Tue, 20 Feb 2018 17:00:00 -0000</pubDate>
      <itunes:title>Introduction to GDPR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>1</itunes:episode>
      <itunes:author>Tom Fox</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/896eb44a-c810-11e8-be13-bbc2f79414ec/image/FCPA_Compliance_and_Ethics_Report.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>Introduction to GDPR</itunes:subtitle>
      <itunes:summary>Whether you are ready or not, the EU General Data Protection Regulation (GDPR) goes live on May 25, 2018. It will impact companies doing business in London as much as any other EU legislation. To help US companies prepare, Jonathan Armstrong and myself have started a countdown to GDPR podcast. In this premier episode we discuss what is GDPR and why it is so important that you begin preparing now. 
Learn more about your ad choices. Visit megaphone.fm/adchoices</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Whether you are ready or not, the EU General Data Protection Regulation (GDPR) goes live on May 25, 2018. It will impact companies doing business in London as much as any other EU legislation. To help US companies prepare, Jonathan Armstrong and myself have started a countdown to GDPR podcast. In this premier episode we discuss what is GDPR and why it is so important that you begin preparing now. </p><p> </p><p>Learn more about your ad choices. Visit <a href="https://megaphone.fm/adchoices">megaphone.fm/adchoices</a></p>]]>
      </content:encoded>
      <itunes:duration>942</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[dce8fad3d693271f3adc732985f905a9]]></guid>
      <enclosure url="https://traffic.megaphone.fm/ACS2170111009.mp3" length="0" type="audio/mpeg"/>
    </item>
  </channel>
</rss>
