$ grep -l "tag:data-protection" writing/
tag: data protection.
8 pieces tagged data protection, newest first. The full taxonomy is on the tag index.
2026·10·05
A board, no chair and a new address: the ICO becomes the Information Commission On 30 September the Information Commissioner ceased to exist and a board-led Information Commission took over, two days after the regulator left Wilmslow for Manchester. What changed, what did not, and why the chair is empty. regulation · governance · board · privacy · data protection · policy
13 min
2026·09·30
Half a million faces, one wrong alert: grading the BTP pilot In its first six months, British Transport Police scanned more than half a million faces at London stations and got one alert, which was wrong. Its own deployment register shows why: the watchlist, not the camera. What a pilot should prove before it grows. privacy · data protection · biometrics · governance
7 min
2026·09·27
The 999 lines held: Dyfed-Powys Police and the staff question Dyfed-Powys Police kept 999 and 101 running through a cyber incident and has so far found no evidence the public's data was accessed; staff data is still under investigation. What went right, what "technical difficulties" costs, and why your own people should never hear last. incident response · data protection · social engineering · governance · board
10 min
2026·09·18
Somebody else's problem: the lockbox codes, the reporting tool, and the supplier review A London property manager kept bank details, passwords and key-safe codes where a cloud analytics tool could read them; a vulnerability in that tool did the rest. Why "the cloud" is not a security decision, and a supplier review you can actually run and evidence. supply chain · data protection · governance · board · small business · cloud · plain english
19 min
2026·07·22
Four days, 490 records: the insider breach nobody budgets for A new council worker opened ~490 sensitive safeguarding records and downloaded 94 over four days — then got a suspended sentence. The sentence is the least interesting part. Why insider snooping is the breach nobody budgets for, and why you can't rely on prosecution to stop it. data protection · insider risk · privacy
8 min
2026·07·11
It wasn't a misdirected email: the NHS Forth Valley breach The headlines called it an email blunder. It wasn't — a staff member moved a spreadsheet of 150 maternity patients' data to their own personal inbox. Why that distinction matters, where NHS Scotland keeps going wrong, and the controls that actually stop it. data protection · privacy · insider risk
10 min
2026·07·06
Everyone in the shop is a suspect Sainsbury's is tripling its Facewatch facial recognition, scanning every shopper's face against a private watchlist to catch a few. It's biometric special-category data, the ICO's own guidance calls it the hardest case to justify, and 'it works' is not the same as 'it's lawful.' privacy · surveillance · data protection
11 min
2026·06·21
Least certain exactly where it has to decide: the Home Office age guesser A facial age-estimation system whose error margin is widest at the one line it exists to draw is not a decision aid. Setting the immigration politics aside, it fails on accuracy and privacy alone. ai governance · privacy · data protection · biometrics
6 min
→ all tags · all writing