<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Measured Collective</title>
	<atom:link href="https://measuredcollective.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://measuredcollective.com/</link>
	<description></description>
	<lastBuildDate>Wed, 30 Sep 2026 16:19:35 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://measuredcollective.com/wp-content/uploads/2023/05/cropped-mc-icon-1-120x120.png</url>
	<title>Measured Collective</title>
	<link>https://measuredcollective.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Bye bye ICO, hello IC: What&#8217;s changed beyond the name</title>
		<link>https://measuredcollective.com/ico-becomes-information-commission-what-has-changed/</link>
		
		<dc:creator><![CDATA[Measured Collective]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 16:17:22 +0000</pubDate>
				<category><![CDATA[Data Protection Authorities]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/ico-becomes-information-commission-what-has-changed/</guid>

					<description><![CDATA[<p>On 30 September 2026 the ICO formally became the Information Commission. What the new board changes, who sits on it, and what organisations need to do.</p>
<p>The post <a href="https://measuredcollective.com/ico-becomes-information-commission-what-has-changed/">Bye bye ICO, hello IC: What&#8217;s changed beyond the name</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO confirms TikTok £12.7m children’s privacy fine is final: what online-service teams should learn</title>
		<link>https://measuredcollective.com/tiktok-127m-childrens-privacy-fine-final-online-service-teams/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 08:06:30 +0000</pubDate>
				<category><![CDATA[Data Protection Enforcement & Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15160</guid>

					<description><![CDATA[<p>The ICO says TikTok’s £12.7m children’s privacy fine is final. Here are the practical controls online-service teams should test.</p>
<p>The post <a href="https://measuredcollective.com/tiktok-127m-childrens-privacy-fine-final-online-service-teams/">ICO confirms TikTok £12.7m children’s privacy fine is final: what online-service teams should learn</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>EU withdrawal pages: what you need to know</title>
		<link>https://measuredcollective.com/eu-withdrawal-pages-what-you-need-to-know/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 10:07:59 +0000</pubDate>
				<category><![CDATA[Practical Data Protection Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15137</guid>

					<description><![CDATA[<p>A practical guide to EU online contract-withdrawal functions from 19 June 2026, with a clear distinction from GDPR cookie-consent withdrawal.</p>
<p>The post <a href="https://measuredcollective.com/eu-withdrawal-pages-what-you-need-to-know/">EU withdrawal pages: what you need to know</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Securitas Direct fined €100,000: why data-subject rights must be genuinely free</title>
		<link>https://measuredcollective.com/securitas-direct-fined-100000-data-subject-rights-free/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 07:10:30 +0000</pubDate>
				<category><![CDATA[EU Data Protection Enforcement]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15128</guid>

					<description><![CDATA[<p>The Spanish DPA fined Securitas Direct €100,000 after a chargeable phone number made data-subject rights harder to exercise. Here is how managers can audit rights-exercise routes.</p>
<p>The post <a href="https://measuredcollective.com/securitas-direct-fined-100000-data-subject-rights-free/">Securitas Direct fined €100,000: why data-subject rights must be genuinely free</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Irish DPC fines HSE €645,000 over insecure paper medical-record storage</title>
		<link>https://measuredcollective.com/irish-dpc-fines-hse-645000-insecure-paper-medical-record-storage/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 08:12:37 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15118</guid>

					<description><![CDATA[<p>In late 2023, people got into two disused psychiatric hospitals in Ireland and filmed what they found: boxes of patient medical records, left in buildings the Health Service Executive (HSE) no longer used for care but still used for storage. The videos were posted on social media. On 2 September 2026, the Irish Data Protection ... </p>
<p class="read-more-container"><a title="Irish DPC fines HSE €645,000 over insecure paper medical-record storage" class="read-more button" href="https://measuredcollective.com/irish-dpc-fines-hse-645000-insecure-paper-medical-record-storage/#more-15118" aria-label="Read more about Irish DPC fines HSE €645,000 over insecure paper medical-record storage">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/irish-dpc-fines-hse-645000-insecure-paper-medical-record-storage/">Irish DPC fines HSE €645,000 over insecure paper medical-record storage</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests</title>
		<link>https://measuredcollective.com/cnil-fines-extia-300000-hr-erasure-requests/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 15:46:23 +0000</pubDate>
				<category><![CDATA[EU Data Protection Enforcement]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15099</guid>

					<description><![CDATA[<p>On 9 September 2026, the CNIL published a decision fining EXTIA €300,000 after the IT and engineering company failed to handle candidates’ and former employees’ erasure requests reliably. The underlying decision was made on 21 July 2026. The case is a useful warning for HR and recruitment teams: deleting a record is only one part ... </p>
<p class="read-more-container"><a title="CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests" class="read-more button" href="https://measuredcollective.com/cnil-fines-extia-300000-hr-erasure-requests/#more-15099" aria-label="Read more about CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/cnil-fines-extia-300000-hr-erasure-requests/">CNIL fines EXTIA €300,000: what HR teams should learn about erasure requests</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach</title>
		<link>https://measuredcollective.com/cnil-fines-hopital-prive-loire-500000-health-data-breach/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 15:37:00 +0000</pubDate>
				<category><![CDATA[EU Data Protection Enforcement]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15103</guid>

					<description><![CDATA[<p>A €500,000 CNIL fine against Hôpital Privé de la Loire is a reminder that healthcare security has to be designed around the sensitivity and scale of the data being processed. The decision concerns both the controls protecting a computerised patient record and the organisation’s communication with people affected by the breach. For healthcare managers, the ... </p>
<p class="read-more-container"><a title="CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach" class="read-more button" href="https://measuredcollective.com/cnil-fines-hopital-prive-loire-500000-health-data-breach/#more-15103" aria-label="Read more about CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/cnil-fines-hopital-prive-loire-500000-health-data-breach/">CNIL fines Hôpital Privé de la Loire €500,000 after health-data breach</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>P&#038;O Ferries data breach: lessons for customer communications</title>
		<link>https://measuredcollective.com/po-ferries-data-breach-customer-communications/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 21:27:49 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15073</guid>

					<description><![CDATA[<p>P&#038;O Ferries reportedly exposed passenger details through a text message. What can organisations learn about safe sharing, staff training and breach response?</p>
<p>The post <a href="https://measuredcollective.com/po-ferries-data-breach-customer-communications/">P&#038;O Ferries data breach: lessons for customer communications</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>AliExpress and silent audio fingerprinting: what the finding means for online tracking</title>
		<link>https://measuredcollective.com/aliexpress-and-silent-audio-fingerprinting-what-the-finding-means-for-online-tracking/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 10:13:56 +0000</pubDate>
				<category><![CDATA[PECR, Cookies & Electronic Marketing]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15070</guid>

					<description><![CDATA[<p>A recent investigation into AliExpress is a useful reminder that online tracking is not limited to cookies or visible consent banners. The marketplace was found running a silent Web Audio routine that could help identify a visitor’s device. It did not record through the microphone. Instead, it generated an inaudible signal and measured small, repeatable ... </p>
<p class="read-more-container"><a title="AliExpress and silent audio fingerprinting: what the finding means for online tracking" class="read-more button" href="https://measuredcollective.com/aliexpress-and-silent-audio-fingerprinting-what-the-finding-means-for-online-tracking/#more-15070" aria-label="Read more about AliExpress and silent audio fingerprinting: what the finding means for online tracking">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/aliexpress-and-silent-audio-fingerprinting-what-the-finding-means-for-online-tracking/">AliExpress and silent audio fingerprinting: what the finding means for online tracking</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Data Protection Training Matrix: How UK Employers Can Map Training by Role</title>
		<link>https://measuredcollective.com/data-protection-training-matrix-how-uk-employers-can-map-training-by-role/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 06:10:20 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15065</guid>

					<description><![CDATA[<p>A completion spreadsheet can show who finished a course. It cannot, by itself, show that people received training suited to the personal data and decisions in their job. A data protection training matrix closes that gap: it maps role groups to the risks they actually face, the learning they need and the evidence an employer ... </p>
<p class="read-more-container"><a title="Data Protection Training Matrix: How UK Employers Can Map Training by Role" class="read-more button" href="https://measuredcollective.com/data-protection-training-matrix-how-uk-employers-can-map-training-by-role/#more-15065" aria-label="Read more about Data Protection Training Matrix: How UK Employers Can Map Training by Role">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/data-protection-training-matrix-how-uk-employers-can-map-training-by-role/">Data Protection Training Matrix: How UK Employers Can Map Training by Role</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Dutch AP fines Uber €825m: what meaningful human review looks like</title>
		<link>https://measuredcollective.com/dutch-ap-fines-uber-e825m-what-meaningful-human-review-looks-like/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sat, 22 Aug 2026 07:05:49 +0000</pubDate>
				<category><![CDATA[EU Data Protection Enforcement]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15061</guid>

					<description><![CDATA[<p>The Dutch Data Protection Authority (AP) has fined Uber €825 million over automated driver-account deactivations. The decision, reported on 21 August and confirmed to Reuters by the regulator, concerns European incidents from 2018 to 2022. Uber says it will appeal, so the penalty is not final. The amount is eye-catching. The operational lesson is more ... </p>
<p class="read-more-container"><a title="Dutch AP fines Uber €825m: what meaningful human review looks like" class="read-more button" href="https://measuredcollective.com/dutch-ap-fines-uber-e825m-what-meaningful-human-review-looks-like/#more-15061" aria-label="Read more about Dutch AP fines Uber €825m: what meaningful human review looks like">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/dutch-ap-fines-uber-e825m-what-meaningful-human-review-looks-like/">Dutch AP fines Uber €825m: what meaningful human review looks like</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Data protection training for staff: a practical UK employer checklist</title>
		<link>https://measuredcollective.com/data-protection-training-for-staff-a-practical-uk-employer-checklist/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 06:10:35 +0000</pubDate>
				<category><![CDATA[Practical Data Protection Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15035</guid>

					<description><![CDATA[<p>Data protection training for staff works best when it is part of an everyday operating routine, rather than a generic course completed once and forgotten. A practical programme gives each person a clear answer to the questions they face in their role: what counts as personal data, what to do before sharing it, and where ... </p>
<p class="read-more-container"><a title="Data protection training for staff: a practical UK employer checklist" class="read-more button" href="https://measuredcollective.com/data-protection-training-for-staff-a-practical-uk-employer-checklist/#more-15035" aria-label="Read more about Data protection training for staff: a practical UK employer checklist">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/data-protection-training-for-staff-a-practical-uk-employer-checklist/">Data protection training for staff: a practical UK employer checklist</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO action against the Metropolitan Police: why training and assurance must be demonstrable</title>
		<link>https://measuredcollective.com/ico-action-against-the-metropolitan-police-why-training-and-assurance-must-be-demonstrable/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 09 Aug 2026 07:09:07 +0000</pubDate>
				<category><![CDATA[Data Protection Authorities]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=15025</guid>

					<description><![CDATA[<p>An ICO enforcement notice and reprimand issued to the Metropolitan Police Service (MPS) offer a practical reminder for any organisation that handles sensitive personal information: training, monitoring and assurance must work together—and be capable of being demonstrated. A policy or annual reminder is not evidence that people have the knowledge, supervision and checks required for ... </p>
<p class="read-more-container"><a title="ICO action against the Metropolitan Police: why training and assurance must be demonstrable" class="read-more button" href="https://measuredcollective.com/ico-action-against-the-metropolitan-police-why-training-and-assurance-must-be-demonstrable/#more-15025" aria-label="Read more about ICO action against the Metropolitan Police: why training and assurance must be demonstrable">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-action-against-the-metropolitan-police-why-training-and-assurance-must-be-demonstrable/">ICO action against the Metropolitan Police: why training and assurance must be demonstrable</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Agentic AI &#038; GDPR: a practical guide to GDPR compliant adoption of AI</title>
		<link>https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 11:42:57 +0000</pubDate>
				<category><![CDATA[GDPR Guidance]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/agentic-ai-and-gdpr-can-your-dsar-process-see-the-whole-tool-chain/</guid>

					<description><![CDATA[<p>AI agents such as a support bot that can read customer records, update customer orders and provide customers with the information they need from your internal systems in seconds, can be a very powerful business tool. It can lead to improved operating margins, and also when deployed properly can improve customer satisfaction &#8211; customers don&#8217;t ... </p>
<p class="read-more-container"><a title="Agentic AI &#38; GDPR: a practical guide to GDPR compliant adoption of AI" class="read-more button" href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/#more-15006" aria-label="Read more about Agentic AI &#38; GDPR: a practical guide to GDPR compliant adoption of AI">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/agentic-ai-gdpr-compliant-adoption/">Agentic AI &amp; GDPR: a practical guide to GDPR compliant adoption of AI</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
