<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GDPR Archives - Measured Collective</title>
	<atom:link href="https://measuredcollective.com/category/gdpr/feed/" rel="self" type="application/rss+xml" />
	<link>https://measuredcollective.com/category/gdpr/</link>
	<description></description>
	<lastBuildDate>Thu, 30 Jul 2026 15:58:23 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://measuredcollective.com/wp-content/uploads/2023/05/cropped-mc-icon-1-120x120.png</url>
	<title>GDPR Archives - Measured Collective</title>
	<link>https://measuredcollective.com/category/gdpr/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Agentic AI and GDPR: a practical guide to compliant adoption</title>
		<link>https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 11:42:57 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/agentic-ai-and-gdpr-can-your-dsar-process-see-the-whole-tool-chain/</guid>

					<description><![CDATA[<p>An agent that can read a customer record, call a tool and write the result back into a system changes the compliance job. The question is no longer whether a model can produce useful text. It is whether the organisation can account for each personal-data use, control the agent&#8217;s permissions and explain its decisions when ... </p>
<p class="read-more-container"><a title="Agentic AI and GDPR: a practical guide to compliant adoption" class="read-more button" href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/#more-15006" aria-label="Read more about Agentic AI and GDPR: a practical guide to compliant adoption">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/">Agentic AI and GDPR: a practical guide to compliant adoption</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained</title>
		<link>https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 06:07:19 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14980</guid>

					<description><![CDATA[<p>Your team collected customer data for one stated purpose. Six months later, product wants to mine the same database for analytics, marketing wants to cross-sell, and someone suggests training an AI model on support tickets. UK GDPR&#8217;s purpose limitation principle does not ban reuse outright, but it does require compatibility. The ICO refreshed its purpose ... </p>
<p class="read-more-container"><a title="Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained" class="read-more button" href="https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/#more-14980" aria-label="Read more about Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/">Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>When Do You Need to Conduct a GDPR Risk Assessment/DPIA?</title>
		<link>https://measuredcollective.com/when-do-you-need-to-conduct-a-gdpr-risk-assessment-dpia/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 00:17:09 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://wpstaging.measuredcollective.com/?p=12720</guid>

					<description><![CDATA[<p>In practice, people often say “GDPR risk assessment”, but the legal test under the UK GDPR is whether you need a data protection impact assessment before you start processing. The question is not whether a project feels sensitive. It is whether the processing is likely to create a high risk to people’s rights and freedoms, ... </p>
<p class="read-more-container"><a title="When Do You Need to Conduct a GDPR Risk Assessment/DPIA?" class="read-more button" href="https://measuredcollective.com/when-do-you-need-to-conduct-a-gdpr-risk-assessment-dpia/#more-12720" aria-label="Read more about When Do You Need to Conduct a GDPR Risk Assessment/DPIA?">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/when-do-you-need-to-conduct-a-gdpr-risk-assessment-dpia/">When Do You Need to Conduct a GDPR Risk Assessment/DPIA?</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO fines South Staffordshire £963,900 after phishing-led breach exposed 633,887 people’s data</title>
		<link>https://measuredcollective.com/ico-fines-south-staffordshire-963900-after-phishing-led-breach-exposed-633887-peoples-data/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 22:28:38 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14830</guid>

					<description><![CDATA[<p>The ICO has fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 after a phishing-led cyber attack led to the personal information of 633,887 people being extracted and published on the dark web. For compliance leaders, the point is simple. The ICO says the case exposed familiar gaps in access controls, monitoring, patching, and ... </p>
<p class="read-more-container"><a title="ICO fines South Staffordshire £963,900 after phishing-led breach exposed 633,887 people’s data" class="read-more button" href="https://measuredcollective.com/ico-fines-south-staffordshire-963900-after-phishing-led-breach-exposed-633887-peoples-data/#more-14830" aria-label="Read more about ICO fines South Staffordshire £963,900 after phishing-led breach exposed 633,887 people’s data">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-fines-south-staffordshire-963900-after-phishing-led-breach-exposed-633887-peoples-data/">ICO fines South Staffordshire £963,900 after phishing-led breach exposed 633,887 people’s data</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>NHS data breach disciplinary disparity: why staff rarely face dismissal</title>
		<link>https://measuredcollective.com/nhs-data-breach-disciplinary-disparity/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 14 Jun 2026 03:44:52 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14927</guid>

					<description><![CDATA[<p>NHS staff rarely face dismissal for data breaches. Analysis of the Southport and Nottingham record access scandals and what they mean for data protection compliance.</p>
<p>The post <a href="https://measuredcollective.com/nhs-data-breach-disciplinary-disparity/">NHS data breach disciplinary disparity: why staff rarely face dismissal</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Nottingham dismissed 11 staff. Liverpool reportedly dismissed none. What NHS leaders should learn</title>
		<link>https://measuredcollective.com/nottingham-liverpool-nhs-disciplinary-disparity-record-access/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 08:30:00 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14905</guid>

					<description><![CDATA[<p>Two NHS record-access scandals now sit side by side in the public record. On 21 May 2026, Nottingham University Hospitals NHS Trust said 11 employees had been dismissed after inappropriate access to records connected to the June 2023 Nottingham attacks. In Merseyside, reporting across April and May 2026 says nearly 50 staff at hospitals in ... </p>
<p class="read-more-container"><a title="Nottingham dismissed 11 staff. Liverpool reportedly dismissed none. What NHS leaders should learn" class="read-more button" href="https://measuredcollective.com/nottingham-liverpool-nhs-disciplinary-disparity-record-access/#more-14905" aria-label="Read more about Nottingham dismissed 11 staff. Liverpool reportedly dismissed none. What NHS leaders should learn">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/nottingham-liverpool-nhs-disciplinary-disparity-record-access/">Nottingham dismissed 11 staff. Liverpool reportedly dismissed none. What NHS leaders should learn</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO AI code of practice: what UK organisations should do before the next strategy lands</title>
		<link>https://measuredcollective.com/ico-ai-code-of-practice-what-uk-organisations-should-do-before-the-next-strategy-lands/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 06:38:09 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14907</guid>

					<description><![CDATA[<p>On 29 May 2026, the Information Commissioner’s Office said its 2026/27 AI work will include an AI code of practice, dedicated guidance on agentic AI, and more support for consumers dealing with increasingly personalised AI products. That does not mean the code exists yet. It means the regulator has shown where UK organisations will face ... </p>
<p class="read-more-container"><a title="ICO AI code of practice: what UK organisations should do before the next strategy lands" class="read-more button" href="https://measuredcollective.com/ico-ai-code-of-practice-what-uk-organisations-should-do-before-the-next-strategy-lands/#more-14907" aria-label="Read more about ICO AI code of practice: what UK organisations should do before the next strategy lands">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-ai-code-of-practice-what-uk-organisations-should-do-before-the-next-strategy-lands/">ICO AI code of practice: what UK organisations should do before the next strategy lands</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>UK Government Advances Facial Recognition Rollout — What This Means for Privacy Compliance</title>
		<link>https://measuredcollective.com/uk-facial-recognition-expansion-privacy-compliance-2026/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 08:49:30 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14800</guid>

					<description><![CDATA[<p>UK live facial recognition expansion raises data protection concerns. What managers should watch as police biometrics use widens in 2026.</p>
<p>The post <a href="https://measuredcollective.com/uk-facial-recognition-expansion-privacy-compliance-2026/">UK Government Advances Facial Recognition Rollout — What This Means for Privacy Compliance</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>EDPB Issues New Guidelines on AI Systems and Personal Data — Key Changes for EU Organisations</title>
		<link>https://measuredcollective.com/edpb-ai-models-personal-data-gdpr-guidance/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 08:49:25 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14796</guid>

					<description><![CDATA[<p>EDPB Opinion 28/2024 clarifies GDPR rules for AI models and personal data. What HR, leadership, and marketing teams must do now.</p>
<p>The post <a href="https://measuredcollective.com/edpb-ai-models-personal-data-gdpr-guidance/">EDPB Issues New Guidelines on AI Systems and Personal Data — Key Changes for EU Organisations</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Reddit Fined £14.47m by ICO for Children&#8217;s Privacy Failures — 2026</title>
		<link>https://measuredcollective.com/reddit-ico-fine-childrens-privacy-failures-2026/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 08:49:23 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<category><![CDATA[Fines]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14794</guid>

					<description><![CDATA[<p>Reddit fined £14.47m by ICO for children's privacy failures under GDPR and DPA 2018. What this means for your organisation.</p>
<p>The post <a href="https://measuredcollective.com/reddit-ico-fine-childrens-privacy-failures-2026/">Reddit Fined £14.47m by ICO for Children&#8217;s Privacy Failures — 2026</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>EDPB Launches 2026 Coordinated GDPR Enforcement on Transparency &#8211; What Teams Need to Prepare</title>
		<link>https://measuredcollective.com/edpb-launches-2026-coordinated-gdpr-enforcement-on-transparency-what-teams-need-to-prepare/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 06:41:27 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/edpb-launches-2026-coordinated-gdpr-enforcement-on-transparency-what-teams-need-to-prepare/</guid>

					<description><![CDATA[<p>The EDPB's 2026 coordinated enforcement action targets GDPR transparency. Learn what HR, marketing, and compliance teams should check now.</p>
<p>The post <a href="https://measuredcollective.com/edpb-launches-2026-coordinated-gdpr-enforcement-on-transparency-what-teams-need-to-prepare/">EDPB Launches 2026 Coordinated GDPR Enforcement on Transparency &#8211; What Teams Need to Prepare</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Advanced Computer Software Group Fined £3m by ICO for NHS Ransomware Data Breach — 2025</title>
		<link>https://measuredcollective.com/advanced-computer-software-group-fined-3m-by-ico-for-nhs-ransomware-data-breach-2025/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 06:41:22 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/advanced-computer-software-group-fined-3m-by-ico-for-nhs-ransomware-data-breach-2025/</guid>

					<description><![CDATA[<p>The ICO fined Advanced Computer Software Group £3m for the 2022 NHS ransomware data breach. Learn what this means for your data security compliance.</p>
<p>The post <a href="https://measuredcollective.com/advanced-computer-software-group-fined-3m-by-ico-for-nhs-ransomware-data-breach-2025/">Advanced Computer Software Group Fined £3m by ICO for NHS Ransomware Data Breach — 2025</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>EU AI Act Prohibited Systems Ban Takes Effect — What HR and Compliance Teams Need to Know</title>
		<link>https://measuredcollective.com/eu-ai-act-prohibited-systems-ban-takes-effect-what-hr-and-compliance-teams-need-to-know/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 06:41:20 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/eu-ai-act-prohibited-systems-ban-takes-effect-what-hr-and-compliance-teams-need-to-know/</guid>

					<description><![CDATA[<p>The EU AI Act's prohibited systems ban is now in force. Here's what HR and compliance teams need to know about banned AI tools and next steps.</p>
<p>The post <a href="https://measuredcollective.com/eu-ai-act-prohibited-systems-ban-takes-effect-what-hr-and-compliance-teams-need-to-know/">EU AI Act Prohibited Systems Ban Takes Effect — What HR and Compliance Teams Need to Know</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Cross-Border Data Breach Lawsuits: Courts Are Coming for You</title>
		<link>https://measuredcollective.com/cross-border-data-breach-lawsuits-courts-are-coming-for-you/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Wed, 11 Mar 2026 06:44:46 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/cross-border-data-breach-lawsuits-courts-are-coming-for-you/</guid>

					<description><![CDATA[<p>An Estonian crypto company with no office in the US just got dragged into a California courtroom. A facial recognition firm with no UK presence just lost its appeal against a £7.5m ICO fine. The message from courts on both sides of the Atlantic is the same: if you collect data from a jurisdiction&#8217;s residents, ... </p>
<p class="read-more-container"><a title="Cross-Border Data Breach Lawsuits: Courts Are Coming for You" class="read-more button" href="https://measuredcollective.com/cross-border-data-breach-lawsuits-courts-are-coming-for-you/#more-14741" aria-label="Read more about Cross-Border Data Breach Lawsuits: Courts Are Coming for You">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/cross-border-data-breach-lawsuits-courts-are-coming-for-you/">Cross-Border Data Breach Lawsuits: Courts Are Coming for You</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
