<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Measured Collective</title>
	<atom:link href="https://measuredcollective.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://measuredcollective.com/</link>
	<description></description>
	<lastBuildDate>Thu, 10 Sep 2026 15:46:23 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://measuredcollective.com/wp-content/uploads/2023/05/cropped-mc-icon-1-120x120.png</url>
	<title>Measured Collective</title>
	<link>https://measuredcollective.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests</title>
		<link>https://measuredcollective.com/cnil-fines-extia-300000-hr-erasure-requests/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 15:46:23 +0000</pubDate>
				<category><![CDATA[EU Data Protection Enforcement]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15099</guid>

					<description><![CDATA[<p>On 9 September 2026, the CNIL published a decision fining EXTIA €300,000 after the IT and engineering company failed to handle candidates’ and former employees’ erasure requests reliably. The underlying decision was made on 21 July 2026. The case is a useful warning for HR and recruitment teams: deleting a record is only one part ... </p>
<p class="read-more-container"><a title="CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests" class="read-more button" href="https://measuredcollective.com/cnil-fines-extia-300000-hr-erasure-requests/#more-15099" aria-label="Read more about CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/cnil-fines-extia-300000-hr-erasure-requests/">CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach</title>
		<link>https://measuredcollective.com/cnil-fines-hopital-prive-loire-500000-health-data-breach/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 15:37:00 +0000</pubDate>
				<category><![CDATA[EU Data Protection Enforcement]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15103</guid>

					<description><![CDATA[<p>A €500,000 CNIL fine against Hôpital Privé de la Loire is a reminder that healthcare security has to be designed around the sensitivity and scale of the data being processed. The decision concerns both the controls protecting a computerised patient record and the organisation’s communication with people affected by the breach. For healthcare managers, the ... </p>
<p class="read-more-container"><a title="CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach" class="read-more button" href="https://measuredcollective.com/cnil-fines-hopital-prive-loire-500000-health-data-breach/#more-15103" aria-label="Read more about CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/cnil-fines-hopital-prive-loire-500000-health-data-breach/">CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>P&#038;O Ferries data breach: lessons for customer communications</title>
		<link>https://measuredcollective.com/po-ferries-data-breach-customer-communications/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 21:27:49 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15073</guid>

					<description><![CDATA[<p>P&#038;O Ferries reportedly exposed passenger details through a text message. What can organisations learn about safe sharing, staff training and breach response?</p>
<p>The post <a href="https://measuredcollective.com/po-ferries-data-breach-customer-communications/">P&#038;O Ferries data breach: lessons for customer communications</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>AliExpress and silent audio fingerprinting: what the finding means for online tracking</title>
		<link>https://measuredcollective.com/aliexpress-and-silent-audio-fingerprinting-what-the-finding-means-for-online-tracking/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 10:13:56 +0000</pubDate>
				<category><![CDATA[PECR, Cookies & Electronic Marketing]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15070</guid>

					<description><![CDATA[<p>A recent investigation into AliExpress is a useful reminder that online tracking is not limited to cookies or visible consent banners. The marketplace was found running a silent Web Audio routine that could help identify a visitor’s device. It did not record through the microphone. Instead, it generated an inaudible signal and measured small, repeatable ... </p>
<p class="read-more-container"><a title="AliExpress and silent audio fingerprinting: what the finding means for online tracking" class="read-more button" href="https://measuredcollective.com/aliexpress-and-silent-audio-fingerprinting-what-the-finding-means-for-online-tracking/#more-15070" aria-label="Read more about AliExpress and silent audio fingerprinting: what the finding means for online tracking">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/aliexpress-and-silent-audio-fingerprinting-what-the-finding-means-for-online-tracking/">AliExpress and silent audio fingerprinting: what the finding means for online tracking</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Data Protection Training Matrix: How UK Employers Can Map Training by Role</title>
		<link>https://measuredcollective.com/data-protection-training-matrix-how-uk-employers-can-map-training-by-role/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 06:10:20 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15065</guid>

					<description><![CDATA[<p>A completion spreadsheet can show who finished a course. It cannot, by itself, show that people received training suited to the personal data and decisions in their job. A data protection training matrix closes that gap: it maps role groups to the risks they actually face, the learning they need and the evidence an employer ... </p>
<p class="read-more-container"><a title="Data Protection Training Matrix: How UK Employers Can Map Training by Role" class="read-more button" href="https://measuredcollective.com/data-protection-training-matrix-how-uk-employers-can-map-training-by-role/#more-15065" aria-label="Read more about Data Protection Training Matrix: How UK Employers Can Map Training by Role">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/data-protection-training-matrix-how-uk-employers-can-map-training-by-role/">Data Protection Training Matrix: How UK Employers Can Map Training by Role</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Dutch AP fines Uber €825m: what meaningful human review looks like</title>
		<link>https://measuredcollective.com/dutch-ap-fines-uber-e825m-what-meaningful-human-review-looks-like/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sat, 22 Aug 2026 07:05:49 +0000</pubDate>
				<category><![CDATA[EU Data Protection Enforcement]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15061</guid>

					<description><![CDATA[<p>The Dutch Data Protection Authority (AP) has fined Uber €825 million over automated driver-account deactivations. The decision, reported on 21 August and confirmed to Reuters by the regulator, concerns European incidents from 2018 to 2022. Uber says it will appeal, so the penalty is not final. The amount is eye-catching. The operational lesson is more ... </p>
<p class="read-more-container"><a title="Dutch AP fines Uber €825m: what meaningful human review looks like" class="read-more button" href="https://measuredcollective.com/dutch-ap-fines-uber-e825m-what-meaningful-human-review-looks-like/#more-15061" aria-label="Read more about Dutch AP fines Uber €825m: what meaningful human review looks like">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/dutch-ap-fines-uber-e825m-what-meaningful-human-review-looks-like/">Dutch AP fines Uber €825m: what meaningful human review looks like</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Data protection training for staff: a practical UK employer checklist</title>
		<link>https://measuredcollective.com/data-protection-training-for-staff-a-practical-uk-employer-checklist/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 06:10:35 +0000</pubDate>
				<category><![CDATA[Practical Data Protection Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15035</guid>

					<description><![CDATA[<p>Data protection training for staff works best when it is part of an everyday operating routine, rather than a generic course completed once and forgotten. A practical programme gives each person a clear answer to the questions they face in their role: what counts as personal data, what to do before sharing it, and where ... </p>
<p class="read-more-container"><a title="Data protection training for staff: a practical UK employer checklist" class="read-more button" href="https://measuredcollective.com/data-protection-training-for-staff-a-practical-uk-employer-checklist/#more-15035" aria-label="Read more about Data protection training for staff: a practical UK employer checklist">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/data-protection-training-for-staff-a-practical-uk-employer-checklist/">Data protection training for staff: a practical UK employer checklist</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO action against the Metropolitan Police: why training and assurance must be demonstrable</title>
		<link>https://measuredcollective.com/ico-action-against-the-metropolitan-police-why-training-and-assurance-must-be-demonstrable/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 09 Aug 2026 07:09:07 +0000</pubDate>
				<category><![CDATA[Data Protection Authorities]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15025</guid>

					<description><![CDATA[<p>An ICO enforcement notice and reprimand issued to the Metropolitan Police Service (MPS) offer a practical reminder for any organisation that handles sensitive personal information: training, monitoring and assurance must work together—and be capable of being demonstrated. A policy or annual reminder is not evidence that people have the knowledge, supervision and checks required for ... </p>
<p class="read-more-container"><a title="ICO action against the Metropolitan Police: why training and assurance must be demonstrable" class="read-more button" href="https://measuredcollective.com/ico-action-against-the-metropolitan-police-why-training-and-assurance-must-be-demonstrable/#more-15025" aria-label="Read more about ICO action against the Metropolitan Police: why training and assurance must be demonstrable">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-action-against-the-metropolitan-police-why-training-and-assurance-must-be-demonstrable/">ICO action against the Metropolitan Police: why training and assurance must be demonstrable</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Agentic AI and GDPR: a practical guide to compliant adoption</title>
		<link>https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 11:42:57 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/agentic-ai-and-gdpr-can-your-dsar-process-see-the-whole-tool-chain/</guid>

					<description><![CDATA[<p>An agent that can read a customer record, call a tool and write the result back into a system changes the compliance job. The question is no longer whether a model can produce useful text. It is whether the organisation can account for each personal-data use, control the agent&#8217;s permissions and explain its decisions when ... </p>
<p class="read-more-container"><a title="Agentic AI and GDPR: a practical guide to compliant adoption" class="read-more button" href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/#more-15006" aria-label="Read more about Agentic AI and GDPR: a practical guide to compliant adoption">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/">Agentic AI and GDPR: a practical guide to compliant adoption</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO investigation leads to sentence for unlawful council-record access: what employers should do</title>
		<link>https://measuredcollective.com/ico-investigation-leads-to-sentence-for-unlawful-council-record-access-what-employers-should-do/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 07:12:04 +0000</pubDate>
				<category><![CDATA[Data Protection Authorities]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14998</guid>

					<description><![CDATA[<p>A new ICO case is a useful reminder that personal-data risk is not limited to phishing, lost devices or external attackers. On 21 July 2026, the ICO announcement reported that a former Herefordshire Council employee received a suspended prison sentence after unlawfully accessing sensitive records. For employers, the practical lesson is to make sure staff ... </p>
<p class="read-more-container"><a title="ICO investigation leads to sentence for unlawful council-record access: what employers should do" class="read-more button" href="https://measuredcollective.com/ico-investigation-leads-to-sentence-for-unlawful-council-record-access-what-employers-should-do/#more-14998" aria-label="Read more about ICO investigation leads to sentence for unlawful council-record access: what employers should do">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-investigation-leads-to-sentence-for-unlawful-council-record-access-what-employers-should-do/">ICO investigation leads to sentence for unlawful council-record access: what employers should do</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CNIL connected-vehicle location rules: what fleet managers and telematics providers should check</title>
		<link>https://measuredcollective.com/cnil-connected-vehicle-location-rules-what-fleet-managers-and-telematics-providers-should-check/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 06:08:53 +0000</pubDate>
				<category><![CDATA[Practical Data Protection Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14992</guid>

					<description><![CDATA[<p>A connected car, van, or scooter generates location data every time it moves. Fleet dashboards, rental recovery tools, and telematics boxes make that data easy to collect, and easy to over-collect. In June 2026, France&#8217;s CNIL published updated recommendations on how professionals may use connected-vehicle location data, following a public consultation and recent press coverage ... </p>
<p class="read-more-container"><a title="CNIL connected-vehicle location rules: what fleet managers and telematics providers should check" class="read-more button" href="https://measuredcollective.com/cnil-connected-vehicle-location-rules-what-fleet-managers-and-telematics-providers-should-check/#more-14992" aria-label="Read more about CNIL connected-vehicle location rules: what fleet managers and telematics providers should check">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/cnil-connected-vehicle-location-rules-what-fleet-managers-and-telematics-providers-should-check/">CNIL connected-vehicle location rules: what fleet managers and telematics providers should check</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers</title>
		<link>https://measuredcollective.com/ico-fines-thermotech-and-jacksons-marketing-370000-for-nuisance-calls-to-tps-numbers/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 08:06:36 +0000</pubDate>
				<category><![CDATA[PECR, Cookies & Electronic Marketing]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14989</guid>

					<description><![CDATA[<p>On 8 July 2026, the ICO fined Thermotech Wall and Loft Surveys Ltd £240,000 and Jacksons Marketing Ltd £130,000 after both companies made hundreds of thousands of unlawful live marketing calls to numbers registered with the Telephone Preference Service. The linked director Thomas Vickrage, from Bournemouth, was a director of TWLS and suspected of directing ... </p>
<p class="read-more-container"><a title="ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers" class="read-more button" href="https://measuredcollective.com/ico-fines-thermotech-and-jacksons-marketing-370000-for-nuisance-calls-to-tps-numbers/#more-14989" aria-label="Read more about ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-fines-thermotech-and-jacksons-marketing-370000-for-nuisance-calls-to-tps-numbers/">ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects</title>
		<link>https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 06 Jul 2026 06:14:47 +0000</pubDate>
				<category><![CDATA[Data Protection Enforcement & Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14983</guid>

					<description><![CDATA[<p>A B2B platform holds years of customer booking data collected for one operational purpose. A product team wants to mine it for a new analytics pilot. No breach, no hacker. Just reuse. In May 2026, Spain&#8217;s data protection authority closed a cross-border GDPR case against Amadeus with a €14.4 million fine, reduced from €18 million ... </p>
<p class="read-more-container"><a title="AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects" class="read-more button" href="https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/#more-14983" aria-label="Read more about AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/">AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained</title>
		<link>https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 06:07:19 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14980</guid>

					<description><![CDATA[<p>Your team collected customer data for one stated purpose. Six months later, product wants to mine the same database for analytics, marketing wants to cross-sell, and someone suggests training an AI model on support tickets. UK GDPR&#8217;s purpose limitation principle does not ban reuse outright, but it does require compatibility. The ICO refreshed its purpose ... </p>
<p class="read-more-container"><a title="Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained" class="read-more button" href="https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/#more-14980" aria-label="Read more about Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/">Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
