peter bassill · operator
$ grep -l "tag:data-protection" writing/

tag: data protection.

8 pieces tagged data protection, newest first. The full taxonomy is on the tag index.

2026·10·05 A board, no chair and a new address: the ICO becomes the Information Commission On 30 September the Information Commissioner ceased to exist and a board-led Information Commission took over, two days after the regulator left Wilmslow for Manchester. What changed, what did not, and why the chair is empty. regulation · governance · board · privacy · data protection · policy 13 min 2026·09·30 Half a million faces, one wrong alert: grading the BTP pilot In its first six months, British Transport Police scanned more than half a million faces at London stations and got one alert, which was wrong. Its own deployment register shows why: the watchlist, not the camera. What a pilot should prove before it grows. privacy · data protection · biometrics · governance 7 min 2026·09·27 The 999 lines held: Dyfed-Powys Police and the staff question Dyfed-Powys Police kept 999 and 101 running through a cyber incident and has so far found no evidence the public's data was accessed; staff data is still under investigation. What went right, what "technical difficulties" costs, and why your own people should never hear last. incident response · data protection · social engineering · governance · board 10 min 2026·09·18 Somebody else's problem: the lockbox codes, the reporting tool, and the supplier review A London property manager kept bank details, passwords and key-safe codes where a cloud analytics tool could read them; a vulnerability in that tool did the rest. Why "the cloud" is not a security decision, and a supplier review you can actually run and evidence. supply chain · data protection · governance · board · small business · cloud · plain english 19 min 2026·07·22 Four days, 490 records: the insider breach nobody budgets for A new council worker opened ~490 sensitive safeguarding records and downloaded 94 over four days — then got a suspended sentence. The sentence is the least interesting part. Why insider snooping is the breach nobody budgets for, and why you can't rely on prosecution to stop it. data protection · insider risk · privacy 8 min 2026·07·11 It wasn't a misdirected email: the NHS Forth Valley breach The headlines called it an email blunder. It wasn't — a staff member moved a spreadsheet of 150 maternity patients' data to their own personal inbox. Why that distinction matters, where NHS Scotland keeps going wrong, and the controls that actually stop it. data protection · privacy · insider risk 10 min 2026·07·06 Everyone in the shop is a suspect Sainsbury's is tripling its Facewatch facial recognition, scanning every shopper's face against a private watchlist to catch a few. It's biometric special-category data, the ICO's own guidance calls it the hardest case to justify, and 'it works' is not the same as 'it's lawful.' privacy · surveillance · data protection 11 min 2026·06·21 Least certain exactly where it has to decide: the Home Office age guesser A facial age-estimation system whose error margin is widest at the one line it exists to draw is not a decision aid. Setting the immigration politics aside, it fails on accuracy and privacy alone. ai governance · privacy · data protection · biometrics 6 min

→ all tags  ·  all writing