Chief Data Protection Officer… ‘Nigel Says’…….

Emotional intelligence

Nigel has an instagram account which is used for displaying numerous pictures of cakes, labradors and other such jolly bragging events.

This weekend along with 34 other ‘update your preferences’ emails received, all sent because of 20 years of non compliance,

I spotted the cheekiest, most rubbish attempt at a privacy notice ever, it happen to come from Instagram, owned by no other than Facebook.

It was vague and used every ‘lawful basis’ sat in the GDPR articles in an attempt to justify its rather creepy use of profiling of our pictures.

A privacy notice should be detailed enough for us to make a choice about whether we want to give our data to you, not suggesting that they are able to use the lawful basis of ‘in the vital interests of the data subject’ to process our holiday pictures!

This lawful basis is reserved for ‘life & death’ events, limited to organisations such as hospitals and ambulance services. There is not the remotest chance that they would use this lawful basis to attempt to pull the wool over our eyes and include it in the privacy notice.

I would love to see the justification for that lawful basis. Be GDPR smart, be specific, link a lawful basis with a product and be clear and not vague like the instagram lawyers draft.

#dataprotection #gdpr #dpa #consultancy #training #brexit #DPIA

related posts

Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »
Noah de Wild

How to Assess a Data Breach: A Practical Guide

This blog explains how to assess a data breach by identifying its cause, determining what information was exposed, and evaluating the potential impact on affected individuals and the organisation. It outlines common causes of breaches, the importance of understanding the type and scale of compromised data, and how assessing the timeline of an incident can help businesses respond effectively, meet legal obligations, and reduce long-term risks.

Read More »
Noah de Wild

Don’t Panic: A Pragmatic Guide to the June 2026 Enforcement of the Data (Use and Access) Act Changes

With the June 19, 2026 enforcement of the Data (Use and Access) Act approaching, ensuring your business is compliant doesn’t have to be complicated or expensive. In our latest guide, we break down exactly what the new data protection complaint rules mean for you. Cut through the noise and discover our simple, free six-step checklist to update your protocols, designate handlers, and keep your business confidently compliant.

Read More »

Get a Free Consultation