Chief Data Protection Officer… ‘Nigel Says’…….

Emotional intelligence

Nigel has an instagram account which is used for displaying numerous pictures of cakes, labradors and other such jolly bragging events.

This weekend along with 34 other ‘update your preferences’ emails received, all sent because of 20 years of non compliance,

I spotted the cheekiest, most rubbish attempt at a privacy notice ever, it happen to come from Instagram, owned by no other than Facebook.

It was vague and used every ‘lawful basis’ sat in the GDPR articles in an attempt to justify its rather creepy use of profiling of our pictures.

A privacy notice should be detailed enough for us to make a choice about whether we want to give our data to you, not suggesting that they are able to use the lawful basis of ‘in the vital interests of the data subject’ to process our holiday pictures!

This lawful basis is reserved for ‘life & death’ events, limited to organisations such as hospitals and ambulance services. There is not the remotest chance that they would use this lawful basis to attempt to pull the wool over our eyes and include it in the privacy notice.

I would love to see the justification for that lawful basis. Be GDPR smart, be specific, link a lawful basis with a product and be clear and not vague like the instagram lawyers draft.

#dataprotection #gdpr #dpa #consultancy #training #brexit #DPIA

related posts

Sophie Costain

Should All My Employees Be Able to Recognise a Subject Access Request?

Data protection is not just about cybersecurity; it relies on your employees recognising Subject Access Requests. The statutory one-month deadline begins the moment a request is received, even informally. Discover why training your entire workforce to instantly spot and escalate these requests is essential to avoid serious regulatory compliance breaches.

Read More »
Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »

Get a Free Consultation