<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Measured Collective</title>
	<atom:link href="https://measuredcollective.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://measuredcollective.com/</link>
	<description></description>
	<lastBuildDate>Thu, 30 Jul 2026 15:58:23 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://measuredcollective.com/wp-content/uploads/2023/05/cropped-mc-icon-1-120x120.png</url>
	<title>Measured Collective</title>
	<link>https://measuredcollective.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Agentic AI and GDPR: a practical guide to compliant adoption</title>
		<link>https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 11:42:57 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/agentic-ai-and-gdpr-can-your-dsar-process-see-the-whole-tool-chain/</guid>

					<description><![CDATA[<p>An agent that can read a customer record, call a tool and write the result back into a system changes the compliance job. The question is no longer whether a model can produce useful text. It is whether the organisation can account for each personal-data use, control the agent&#8217;s permissions and explain its decisions when ... </p>
<p class="read-more-container"><a title="Agentic AI and GDPR: a practical guide to compliant adoption" class="read-more button" href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/#more-15006" aria-label="Read more about Agentic AI and GDPR: a practical guide to compliant adoption">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/">Agentic AI and GDPR: a practical guide to compliant adoption</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO investigation leads to sentence for unlawful council-record access: what employers should do</title>
		<link>https://measuredcollective.com/ico-investigation-leads-to-sentence-for-unlawful-council-record-access-what-employers-should-do/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 07:12:04 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14998</guid>

					<description><![CDATA[<p>A new ICO case is a useful reminder that personal-data risk is not limited to phishing, lost devices or external attackers. On 21 July 2026, the ICO announcement reported that a former Herefordshire Council employee received a suspended prison sentence after unlawfully accessing sensitive records. For employers, the practical lesson is to make sure staff ... </p>
<p class="read-more-container"><a title="ICO investigation leads to sentence for unlawful council-record access: what employers should do" class="read-more button" href="https://measuredcollective.com/ico-investigation-leads-to-sentence-for-unlawful-council-record-access-what-employers-should-do/#more-14998" aria-label="Read more about ICO investigation leads to sentence for unlawful council-record access: what employers should do">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-investigation-leads-to-sentence-for-unlawful-council-record-access-what-employers-should-do/">ICO investigation leads to sentence for unlawful council-record access: what employers should do</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CNIL connected-vehicle location rules: what fleet managers and telematics providers should check</title>
		<link>https://measuredcollective.com/cnil-connected-vehicle-location-rules-what-fleet-managers-and-telematics-providers-should-check/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 06:08:53 +0000</pubDate>
				<category><![CDATA[Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14992</guid>

					<description><![CDATA[<p>A connected car, van, or scooter generates location data every time it moves. Fleet dashboards, rental recovery tools, and telematics boxes make that data easy to collect, and easy to over-collect. In June 2026, France&#8217;s CNIL published updated recommendations on how professionals may use connected-vehicle location data, following a public consultation and recent press coverage ... </p>
<p class="read-more-container"><a title="CNIL connected-vehicle location rules: what fleet managers and telematics providers should check" class="read-more button" href="https://measuredcollective.com/cnil-connected-vehicle-location-rules-what-fleet-managers-and-telematics-providers-should-check/#more-14992" aria-label="Read more about CNIL connected-vehicle location rules: what fleet managers and telematics providers should check">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/cnil-connected-vehicle-location-rules-what-fleet-managers-and-telematics-providers-should-check/">CNIL connected-vehicle location rules: what fleet managers and telematics providers should check</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers</title>
		<link>https://measuredcollective.com/ico-fines-thermotech-and-jacksons-marketing-370000-for-nuisance-calls-to-tps-numbers/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 08:06:36 +0000</pubDate>
				<category><![CDATA[PECR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14989</guid>

					<description><![CDATA[<p>On 8 July 2026, the ICO fined Thermotech Wall and Loft Surveys Ltd £240,000 and Jacksons Marketing Ltd £130,000 after both companies made hundreds of thousands of unlawful live marketing calls to numbers registered with the Telephone Preference Service. The linked director Thomas Vickrage, from Bournemouth, was a director of TWLS and suspected of directing ... </p>
<p class="read-more-container"><a title="ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers" class="read-more button" href="https://measuredcollective.com/ico-fines-thermotech-and-jacksons-marketing-370000-for-nuisance-calls-to-tps-numbers/#more-14989" aria-label="Read more about ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-fines-thermotech-and-jacksons-marketing-370000-for-nuisance-calls-to-tps-numbers/">ICO fines Thermotech and Jacksons Marketing £370,000 for nuisance calls to TPS numbers</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects</title>
		<link>https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 06 Jul 2026 06:14:47 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14983</guid>

					<description><![CDATA[<p>A B2B platform holds years of customer booking data collected for one operational purpose. A product team wants to mine it for a new analytics pilot. No breach, no hacker. Just reuse. In May 2026, Spain&#8217;s data protection authority closed a cross-border GDPR case against Amadeus with a €14.4 million fine, reduced from €18 million ... </p>
<p class="read-more-container"><a title="AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects" class="read-more button" href="https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/#more-14983" aria-label="Read more about AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/">AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained</title>
		<link>https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 06:07:19 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14980</guid>

					<description><![CDATA[<p>Your team collected customer data for one stated purpose. Six months later, product wants to mine the same database for analytics, marketing wants to cross-sell, and someone suggests training an AI model on support tickets. UK GDPR&#8217;s purpose limitation principle does not ban reuse outright, but it does require compatibility. The ICO refreshed its purpose ... </p>
<p class="read-more-container"><a title="Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained" class="read-more button" href="https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/#more-14980" aria-label="Read more about Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/can-you-reuse-customer-data-for-a-new-purpose-icos-2026-compatibility-rules-explained/">Can you reuse customer data for a new purpose? ICO&#8217;s 2026 compatibility rules explained</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>When exactly can UK marketers use the soft opt-in?</title>
		<link>https://measuredcollective.com/when-can-uk-marketers-use-the-soft-opt-in/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 06:18:35 +0000</pubDate>
				<category><![CDATA[PECR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14969</guid>

					<description><![CDATA[<p>Unsolicited email and SMS to people based in the UK &#8220;individual subscribers&#8221; normally needs explicit consent under UK ePrivacy/PECR electronic mail marketing rules. Broadly speaking these rules define the need for consent, and UK GDPR then defines the quality of &#8220;consent&#8221; required. The rules can feel restrctives especially when compared to the freedoms enjoyed by ... </p>
<p class="read-more-container"><a title="When exactly can UK marketers use the soft opt-in?" class="read-more button" href="https://measuredcollective.com/when-can-uk-marketers-use-the-soft-opt-in/#more-14969" aria-label="Read more about When exactly can UK marketers use the soft opt-in?">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/when-can-uk-marketers-use-the-soft-opt-in/">When exactly can UK marketers use the soft opt-in?</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>GDPR &#038; Slack: How to stay compliant with GDPR</title>
		<link>https://measuredcollective.com/gdpr-slack-how-to-stay-compliant-with-gdpr/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 21 Jun 2026 08:18:22 +0000</pubDate>
				<category><![CDATA[Guides]]></category>
		<guid isPermaLink="false">https://wpstaging.measuredcollective.com/?p=12547</guid>

					<description><![CDATA[<p>Slack is where your team talks. It is not where your GDPR programme lives. Under the UK GDPR Article 28, your organisation is the controller when you decide what personal data goes into Slack, who can see it, and how long it stays. Slack processes that data on your instructions. That split is the starting ... </p>
<p class="read-more-container"><a title="GDPR &#038; Slack: How to stay compliant with GDPR" class="read-more button" href="https://measuredcollective.com/gdpr-slack-how-to-stay-compliant-with-gdpr/#more-12547" aria-label="Read more about GDPR &#038; Slack: How to stay compliant with GDPR">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/gdpr-slack-how-to-stay-compliant-with-gdpr/">GDPR &#038; Slack: How to stay compliant with GDPR</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Can I Request a Copy of All My Employment Data from My Employer Under GDPR?</title>
		<link>https://measuredcollective.com/can-i-request-a-copy-of-all-my-employment-data-from-my-employer-under-gdpr/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 21 Jun 2026 08:15:06 +0000</pubDate>
				<category><![CDATA[Guides]]></category>
		<guid isPermaLink="false">https://wpstaging.measuredcollective.com/?p=12713</guid>

					<description><![CDATA[<p>The General Data Protection Regulation (GDPR) gives you the explicit right to request and receive a copy of all personal data your employer holds about you.</p>
<p>The post <a href="https://measuredcollective.com/can-i-request-a-copy-of-all-my-employment-data-from-my-employer-under-gdpr/">Can I Request a Copy of All My Employment Data from My Employer Under GDPR?</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Garante fines Emirates €180,000 over assisted-travel health data</title>
		<link>https://measuredcollective.com/garante-fines-emirates-e180000-over-assisted-travel-health-data/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Fri, 19 Jun 2026 08:11:26 +0000</pubDate>
				<category><![CDATA[EU Enforcement Cases]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14957</guid>

					<description><![CDATA[<p>Italy's Garante fined Emirates €180,000 over MEDIF health-data transparency and retention. Practical lessons for accessibility and assisted-travel data.</p>
<p>The post <a href="https://measuredcollective.com/garante-fines-emirates-e180000-over-assisted-travel-health-data/">Garante fines Emirates €180,000 over assisted-travel health data</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>London Clinic ICO caution: what staff medical-record misuse teaches employers</title>
		<link>https://measuredcollective.com/london-clinic-ico-caution-what-staff-medical-record-misuse-teaches-employers/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 18 Jun 2026 07:20:18 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14951</guid>

					<description><![CDATA[<p>The ICO has issued a formal caution to a former healthcare professional after concluding a criminal investigation linked to medical information reported by the London Clinic in March 2024. For employers, the point is direct: insider misuse of personal data can become a criminal data protection matter even when the organisation itself is not fined. ... </p>
<p class="read-more-container"><a title="London Clinic ICO caution: what staff medical-record misuse teaches employers" class="read-more button" href="https://measuredcollective.com/london-clinic-ico-caution-what-staff-medical-record-misuse-teaches-employers/#more-14951" aria-label="Read more about London Clinic ICO caution: what staff medical-record misuse teaches employers">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/london-clinic-ico-caution-what-staff-medical-record-misuse-teaches-employers/">London Clinic ICO caution: what staff medical-record misuse teaches employers</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Irish DPC fines HSE €300,000 after Tullamore ransomware breach</title>
		<link>https://measuredcollective.com/irish-dpc-fines-hse-e300000-after-tullamore-ransomware-breach/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 18 Jun 2026 07:16:30 +0000</pubDate>
				<category><![CDATA[EU Enforcement Cases]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14948</guid>

					<description><![CDATA[<p>The Irish Data Protection Commission has fined the Health Service Executive €300,000 after a ransomware attack on the laboratory information system at Midlands Regional Hospital Tullamore. The DPC notice, published on 15 June 2026, says the breach was detected on 14 November 2018 and affected systems used to store and process patients&#8217; diagnostic-test results. The ... </p>
<p class="read-more-container"><a title="Irish DPC fines HSE €300,000 after Tullamore ransomware breach" class="read-more button" href="https://measuredcollective.com/irish-dpc-fines-hse-e300000-after-tullamore-ransomware-breach/#more-14948" aria-label="Read more about Irish DPC fines HSE €300,000 after Tullamore ransomware breach">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/irish-dpc-fines-hse-e300000-after-tullamore-ransomware-breach/">Irish DPC fines HSE €300,000 after Tullamore ransomware breach</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Is Employee Data Subject to GDPR? How must it be protected?</title>
		<link>https://measuredcollective.com/is-employee-data-subject-to-gdpr-how-must-it-be-protected/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 10:28:46 +0000</pubDate>
				<category><![CDATA[Guides]]></category>
		<guid isPermaLink="false">https://wpstaging.measuredcollective.com/?p=12716</guid>

					<description><![CDATA[<p>Yes. Employee data is personal data, so GDPR applies whenever an employer collects, stores, shares, searches, or deletes it. The more useful question is not whether the law applies, but which rules and controls fit the data you actually hold. The ICO’s employment guidance is aimed at employers handling workers’ information under UK GDPR and ... </p>
<p class="read-more-container"><a title="Is Employee Data Subject to GDPR? How must it be protected?" class="read-more button" href="https://measuredcollective.com/is-employee-data-subject-to-gdpr-how-must-it-be-protected/#more-12716" aria-label="Read more about Is Employee Data Subject to GDPR? How must it be protected?">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/is-employee-data-subject-to-gdpr-how-must-it-be-protected/">Is Employee Data Subject to GDPR? How must it be protected?</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>When Do You Need to Conduct a GDPR Risk Assessment/DPIA?</title>
		<link>https://measuredcollective.com/when-do-you-need-to-conduct-a-gdpr-risk-assessment-dpia/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 00:17:09 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://wpstaging.measuredcollective.com/?p=12720</guid>

					<description><![CDATA[<p>In practice, people often say “GDPR risk assessment”, but the legal test under the UK GDPR is whether you need a data protection impact assessment before you start processing. The question is not whether a project feels sensitive. It is whether the processing is likely to create a high risk to people’s rights and freedoms, ... </p>
<p class="read-more-container"><a title="When Do You Need to Conduct a GDPR Risk Assessment/DPIA?" class="read-more button" href="https://measuredcollective.com/when-do-you-need-to-conduct-a-gdpr-risk-assessment-dpia/#more-12720" aria-label="Read more about When Do You Need to Conduct a GDPR Risk Assessment/DPIA?">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/when-do-you-need-to-conduct-a-gdpr-risk-assessment-dpia/">When Do You Need to Conduct a GDPR Risk Assessment/DPIA?</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
