Chief Data Protection Officer… ‘Nigel Says’…….

Emotional intelligence

Nigel has an instagram account which is used for displaying numerous pictures of cakes, labradors and other such jolly bragging events.

This weekend along with 34 other ‘update your preferences’ emails received, all sent because of 20 years of non compliance,

I spotted the cheekiest, most rubbish attempt at a privacy notice ever, it happen to come from Instagram, owned by no other than Facebook.

It was vague and used every ‘lawful basis’ sat in the GDPR articles in an attempt to justify its rather creepy use of profiling of our pictures.

A privacy notice should be detailed enough for us to make a choice about whether we want to give our data to you, not suggesting that they are able to use the lawful basis of ‘in the vital interests of the data subject’ to process our holiday pictures!

This lawful basis is reserved for ‘life & death’ events, limited to organisations such as hospitals and ambulance services. There is not the remotest chance that they would use this lawful basis to attempt to pull the wool over our eyes and include it in the privacy notice.

I would love to see the justification for that lawful basis. Be GDPR smart, be specific, link a lawful basis with a product and be clear and not vague like the instagram lawyers draft.

#dataprotection #gdpr #dpa #consultancy #training #brexit #DPIA

related posts

Bethany Meredith

Navigating SAR Chaos: Why PDF Conversion and Deduplication Are Your Secret Weapons

When a Subject Access Request lands in your inbox, the one-month clock starts ticking immediately, and the real bottleneck usually isn’t finding the data, it’s wading through duplicate files and endless email threads. Discover why deduplication and PDF conversion aren’t just nice-to-haves but non-negotiable steps in your SAR pipeline: cutting review volume by up to 60%, closing redaction loopholes, and delivering a secure, universally accessible disclosure , all while keeping your compliance team sane and your deadline intact.

Read More »
Alex Haslam

DPAS Data Protection Bulletin – August 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Sophie Costain

Should All My Employees Be Able to Recognise a Subject Access Request?

Data protection is not just about cybersecurity; it relies on your employees recognising Subject Access Requests. The statutory one-month deadline begins the moment a request is received, even informally. Discover why training your entire workforce to instantly spot and escalate these requests is essential to avoid serious regulatory compliance breaches.

Read More »

Get a Free Consultation