Skip to content
PodcastsTechnologyThe Privacy Partnership Podcast with Robert Bateman

The Privacy Partnership Podcast with Robert Bateman

treborjnametab1
The Privacy Partnership Podcast with Robert Bateman
Latest episode

52 episodes

  • The Privacy Partnership Podcast with Robert Bateman

    Is TikTok a patron of the arts? How an appeal under the "special purposes" exemption failed

    06/08/2026 | 4 mins.
    In this episode of the Privacy Partnership Podcast, Robert Bateman dives into a fascinating and highly creative legal defense recently mounted by TikTok. Facing a £12.7 million fine from the UK Information Commissioner's Office (ICO) for processing the data of underage children, TikTok attempted to use a jurisdictional trump card: the "special purposes" exemption under Section 156 of the Data Protection Act 2018.
    Did TikTok’s recommender algorithm process user data for "artistic purposes"? Should the platform be shielded by freedom of expression laws? And how did a philosophy professor from Oxford end up testifying at a data protection tribunal? Robert breaks down the Upper Tribunal's July 2026 ruling, explaining why tech platforms can't retrofit a fundamental rights defense onto an engagement-driven algorithm.
    Key Topics Covered:

    The £12.7m Penalty: The background of the ICO's enforcement action against TikTok for age-gating failures and processing the data of under-13s without parental consent.

    The "Special Purposes" Exemption: A look at Section 156 of the DPA 2018, which provides procedural safeguards (including court approval) before a regulator can penalize processing done for journalistic, academic, literary, or artistic purposes.

    The "What is Art?" Debate: TikTok's argument that its platform facilitates artistic expression, and why the Upper Tribunal decided to sidestep the philosophical debate entirely.

    Algorithm vs. Intent: Why the Upper Tribunal ruled that an engagement-driven recommender system—which is completely indifferent to whether a video is actually "art"—cannot be said to be processing data for an artistic purpose.

    The Underage Contradiction: The fatal flaw in TikTok claiming to facilitate the artistic expression of under-13s while simultaneously banning them in their own Terms of Service.

    Articles 12 & 13 as Procedural Obligations: Why the Tribunal rejected TikTok’s attempt to classify transparency and privacy notice failings as "processing" breaches.
  • The Privacy Partnership Podcast with Robert Bateman

    Web scraping under the GDPR: The EDPB's uncharacteristically pragmatic solution

    29/07/2026 | 7 mins.
    Can you scrape the internet for AI training data without completely running afoul of the GDPR? The European Data Protection Board (EDPB) has finally offered an answer: Yes, but get ready to implement a massive amount of filtering.
    In this episode of the Privacy Partnership Podcast, Robert Bateman breaks down the EDPB’s newly adopted Draft Guidelines 03/2026 on web scraping for generative AI. Robert begins by exploring the political context behind this unexpectedly pragmatic guidance, discussing how the EDPB is effectively front-running the European Commission’s upcoming "Digital Omnibus" proposal to cement its authority over how privacy law applies to AI development.
    Then, Robert walks listeners through a practical, 10-point checklist for developers and privacy teams trying to navigate this regulatory minefield, from mapping out complex controllership arrangements to leveraging a fascinating loophole for the "incidental and residual" scraping of sensitive, special category data.
    Key Topics Discussed:

    The Digital Omnibus Context: Why the EDPB’s new guidance is "deceptively permissive" and how it serves as a strategic maneuver to preempt upcoming EU legislation.

    Controllership in the AI Supply Chain: How to define your role—whether you are dictating instructions to a scraper, co-determining collection criteria, or buying a pre-scraped dataset.

    Establishing a Lawful Basis: Why consent is a non-starter at this scale, how to lean on Legitimate Interests, and why a missing "robots.txt" file does not equal a green light.

    Designing the Collection: The end of indiscriminate web hoovering, the importance of data minimisation, and respecting technical barriers (like CAPTCHAs and ai.txt).

    Transparency at Scale: How to utilize the Article 14 "disproportionate effort" exception while maintaining a highly detailed, searchable public scraping notice.

    Cleaning and Accuracy: Applying syntax-based filters to weed out format-identifiable data on the fly, and utilizing synthetic data where feasible.

    The Article 9 Workaround: How the EDPB is applying the 2019 GC & Others CJEU search engine ruling to allow the incidental scraping of special category data—and the rigorous output filters required to justify it.

    Accountability: The massive documentation burden required to prove your technical measures and filters remain effective against the evolving state of the art.
  • The Privacy Partnership Podcast with Robert Bateman

    The EDPB's new anonymisation framework: 5 things you need to know

    21/07/2026 | 4 mins.
    This week, Robert Bateman breaks down the newly adopted EDPB Guidelines 02/2026 on Anonymisation. Dragging the ancient 2014 Working Party 29 framework into the age of generative AI and EU data spaces, these new rules are dense, highly technical, and will undoubtedly complicate your compliance programmes.
    Robert explores the new concept of "relative anonymity," explains the rebranded technical criteria, and discusses why making your data anonymous might actually trigger a 72-hour data breach notification down the line.
    In this episode, we cover:
    Relative Anonymity: What the EDPS v SRB case means for controllers, and how data can be anonymous to a recipient but still constitute personal data for the sender.

    The Assessment Gauntlet: Navigating the "contextual" vs. "simplified" approaches (and why the EDPB expects you to evaluate the capabilities of cybercriminals and foreign spies).

    The New Technical Criteria: A look at the replacement tests for anonymity: No Record Isolation, No Linkage, and No Inference.

    The AI Threat: How "membership inference" attacks against AI training data are raising the bar for the No Inference test.

    The Processing Trap: Why the sheer act of running an anonymisation algorithm is a processing activity requiring its own Article 6 (and potentially Article 9) legal basis.

    The Expiry Date on Anonymity: How a completely unrelated security incident on the other side of the internet can instantly turn your anonymous dataset back into personal data.
  • The Privacy Partnership Podcast with Robert Bateman

    Rob rambles about Trump v Slaughter from a European perspective

    15/07/2026 | 19 mins.
    A longer edition of the podcast because Rob gets unreasonably animated about EU-US data transfers.
    On 29 June 2026 the US Supreme Court ruled that the Federal Trade Commission's protection from presidential removal is unconstitutional, overruling ninety years of precedent on independent agencies. 
    The ruling says nothing about data protection, but the EU-US Data Privacy Framework is built on the premise that the FTC is an independent supervisory authority, and campaigners are already demanding that the European Commission repeal the adequacy decision.
    In this 20-minute briefing, Rob Bateman of Privacy Partnership explains what has happened on the American side and what it means for anyone moving personal data across the Atlantic.
    Covered in this episode
    A timeline from the adequacy decision in 2023 to the Supreme Court's ruling and noyb's demand for repeal
     The US machinery behind the DPF: Executive Order 14086, the FTC, the PCLOB and the Data Protection Review Court
     What the Supreme Court actually decided, explained without assuming any US constitutional law
     The four routes by which the adequacy decision could be invalidated, and their very different timescales
     Whether the ruling's logic spreads to the DPRC, and why that question matters more than the DPF headline
     The two scenarios for SCCs, including why standard contractual clauses could be a stronger fallback than they were after Schrems II
    The DPF remains in force and transfers under it remain lawful today. Nothing in this episode is legal advice for your specific situation.
  • The Privacy Partnership Podcast with Robert Bateman

    CalPrivacy Director Tom Kemp on how businesses should approach California's robust privacy regulation

    09/07/2026 | 28 mins.
    What happens when a Silicon Valley cybersecurity founder takes the reins at one of the world's most powerful privacy regulators?
    In this special edition of the Privacy Partnership Podcast, Robert Bateman is joined by Tom Kemp, Executive Director of CalPrivacy (the California Privacy Protection Agency). They dive deep into California’s aggressive new enforcement strategies and the technical tools the state is building to make privacy rights frictionless for the average consumer.
    From massive potential fines for data brokers to mandated browser-level opt-outs and algorithmic risk assessments, Tom breaks down exactly what businesses need to know—and why simply relying on your GDPR compliance won’t be enough to keep you safe in the Golden State.
    In this episode, we cover:

    From Founder to Enforcer: How Tom's background in tech shaped his belief that privacy rights need to be scalable, not a "never-ending set of chores" for consumers.

    The DROP System: California's new Delete Request and Opt-Out Platform that allows users to delete their data from roughly 600 data brokers with a single click.

    $40 Million-a-Day Fines: The terrifying math behind California’s enforcement against data brokers. (Hint: the $200 fine is per incident, not per day).

    Data Minimisation in the US: Lessons from the recent General Motors enforcement action and Cal Privacy's focus on eliminating "dark patterns" and consumer friction.

    The Rise of OOPS: Why California is moving away from cookie banners and mandating that all web browsers natively support Opt-Out Preference Signals by 2027.

    The EU-to-California Pipeline: Actionable advice for UK and European businesses on configuring third-party tools, preparing for incoming cybersecurity audits, and handling Automated Decision-Making Technology (ADMT) regulations.
    Timestamps:

    [00:00] Intro: Welcome Tom Kemp, Executive Director of Cal Privacy.

    [01:09] Changing perspectives: Moving from building cybersecurity tech to regulating privacy.

    [04:30] Solving the data broker problem: How the new DROP system actually works.

    [09:34] Enforcement with teeth: Breaking down the massive fines awaiting non-compliant data brokers in August.

    [12:41] Common themes in Cal Privacy enforcement actions: Data minimisation, the GM case, and reducing friction.

    [18:06] Putting privacy "in the box": Mandating browser-level Opt-Out Preference Signals (OOPS) by 2027.

    [22:56] Practical advice for EU/UK companies navigating CCPA, risk assessments, and ADMT.
More Technology podcasts
About The Privacy Partnership Podcast with Robert Bateman
Robert Bateman provides the latest on data protection and privacy, with regular solo news updates and short-form interviews. Brought to you by Privacy Partnership: www.privacypartnership.com
Podcast website

Listen to The Privacy Partnership Podcast with Robert Bateman, All-In with Chamath, Jason, Sacks & Friedberg and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features