Serious Privacy

A Big 300! Regulating Canada and the World (with Philippe Dufresne)

Paul Breitbarth, Ralph O’Brien & dr. K Royal Season 7 Episode 27

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 40:31

Send us Fan Mail

Welcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal, celebrate 300 episodes. And for this milestone, we invited Philippe Dufresne - Privacy Commissioner of Canada and Chair of the Executive Committee of the Global Privacy Assembly. It is a fascinating discussion and one not to miss!



If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!

From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Tim

You're listening to the award-winning Serious Privacy Podcast sponsored by TrustArc. Please welcome your hosts, Paul Breitbart, Ralph O'Brien, and Dr. Kay Royal.

Paul

What started as a bucket list idea back in January 2020 has grown into a weekly endeavor for four persons. Welcome to episode 300 of Sirious Privacy. After almost 200 hours of conversations, including with some 90 guests and over 225,000 downloads, we are happy to celebrate this milestone with our listeners today. And of course we do so with a very special guest. We are pleased to welcome Commissioner Philippe Dufresne to the podcast. Philippe was appointed Privacy Commissioner of Canada on the 27th of June 2022, a leading legal expert on human rights, administrative, and constitutional law. He previously served as the law clerk and parliamentary counsel of the House of Commons in Ottawa. And in September 2025, he was elected as the new chair of the Global Privacy Assembly. So you could say he is the highest commissioner in the world. We are looking forward to discuss the state of privacy and data protection in Canada and around the world with him. My name is Pal Greitbart.

Ralph

My name is Ralph O'Brien.

K

And I'm Kay Royal and welcome to Sirius Privacy. So I'm gonna warn y'all. May I call you Philip or should I call you Commissioner Defrain?

SPEAKER_03

Oh, whatever you want. Both are fine. Thank you.

K

I love it. You're welcome. You can call me Your Majesty. I'm happy with that as I'm showing up with a crown and everything on for the show. Anyway, we always start with an unexpected question. And Ralph, you did not hear that I vetoed y'all's unexpected question because it's substantive and it will take people 10 minutes to answer. So the unexpected question today is what is your favorite go-to breakfast food?

SPEAKER_03

Oh, thank you for that question, Kay, and thank you for the privilege of being here, especially for your 300th uh anniversary. Uh you know, my favorite breakfast food, I love to have toast in the morning with butter and jam and yogurt and oat bran. So it's a very nice specific thing that I have every day, and it's a bit of a routine and starts me off in a good way. I'm a very early riser, and and I do uh believe that grounding yourself as you start your day, where wherever I may be in the world, uh I don't always have access to those. If it's there you go.

Ralph

So I think in which case, if the wonderful commissioner has established a wonderful routine for their day, I'm gonna be very disappointing and say that I rarely have breakfast. But when I am away, and one of my favorite things, of course, is a full English. Anything with bacon and sausages, normally between two slices of bread, is the breakfast of champions as far as I'm concerned.

Paul

So Kay, I know you get breakfast in bed every time that you are at home, at least, or traveling with Tim. So what is that breakfast?

K

My husband brings me breakfast in bed every day, even when I travel, he brings me breakfast in bed, but I will say is not healthy is the one cup of coffee I'm allowed a day, no more caffeine per day for me, and a rice crispy treat with frosting on it.

Paul

Sounds perfect. So my favorite breakfast would be either a full English or a full Swedish, where you can exchange the bacon for some smoked salmon. That's not the thing I would have every day, so I'll stick to yogurt and homemade granola.

K

So good. All right, y'all go with the great questions. It's gonna be a casual conversation, and I am looking forward to this.

Ralph

Yes, so we put out a little Ask Us Anything on the on the old socials, and we dipped into the mailbag because we got a few questions, but there was one that sort of stood out amongst the rest as a worthy question to for the 300th episode, and it was from our good friend Connor Hogan in Ireland, who sort of said wanted to ask us what our sort of most inspirational thing we've ever seen in data protection, the difference we've most we'll we've made, the thing that we will always look at and say, yes, I was a part of that, or or yes, this is something that's actually moved the needle and sort of meant the most to us in our professional career. So I'm gonna ask that to uh good friend the Commissioner Du Friends first before we we go around the houses.

SPEAKER_03

Great question. And look, there's so many things that I'm proud of in this community, and what we've achieved together. I would say that it is how we have been able to come together all over the world as privacy data protection professionals to speak with a strong voice and to ensure the protection of privacy in a really fast-moving world. When privacy protections came into being at the beginning, we were nowhere near the types of technology and integration and data-fueled economy and innovation space that we're in today. We didn't have the same types of challenges with impacts on everyone in society, and particularly children. And so I think that we have risen to the challenge as a community to make sure that we continue to elevate privacy as a fundamental right, as something that's so key to our freedoms and to our dignity as individual human beings and free societies, but also that we do it in a way that's not a zero-sum game and that does not pit privacy against other important aspects of national security, strong economies, the safety of children online, so that we can achieve all of those things together, and that we do so in a way that generates trusts for citizens. I think that we've seen, we see privacy as a key driver of innovation and trust and engagement. And because data crosses borders all the time, no one country can do this together. So it was critical that as a community, we come together with those messages to realize that while there are so many different legal systems, the fundamental core privacy principles are the same. And we need to work together to continue to protect them and preserve them.

Ralph

Amen. It takes a village, as they say. I think my answer to that question, Connor, would be it's the people I've met. The people I've met, the professionals that I've worked with, and the single thing that means the most to me is the opportunity to be a trainer and a mentor to, you know, I've been doing this since the late 90s now. And so here we are in 2026. And the good commissioner there is correct in that technology has never made more of an impact. Technology is it just increases exponentially the benefits and the harms. And therefore, we have to get the benefits, we have to get the harm and minimize the harms. But yes, the people, it's the opportunity to train and shape and mentor and hope that the next generation of data protection professionals makes, if not a greater impact than we have.

Paul

So I think for me, when you when I look back at at 17 years in privacy, it's also starting to count. There are a few moments that are real highlights for me. One of them is the organization of the Amsterdam Global Privacy Assembly back in 2015, where for the first time we had a single topic, a single paper for discussion across the conference, building bridges. Unfortunately, it came very much at the wrong moment following the Shrams 1 decision. Um so all the grand ideas that my commissioner at the time, Jakob Konstam, had, fell a bit on daff ears because the world was in crisis trying to solve cross-border transfers. But that did lead to the second thing that that I really enjoyed and really made me proud, and that is the drafting of the Working Party 29's opinion on what became the privacy shield, working so closely together. It's again, it's working with the people, but with a lot of people who I call still my friends today, to come up with a response to debate all the different scenarios on how cross-border transfers could continue, what safeguards would be required both on the US and the EU side. That was a uh a really good time for debate, and I'm still very proud of what we did in that period. Philippe, you were appointed just over four years ago as Privacy Commissioner of Canada. What was it like to you had human rights experience, but I don't believe you had any day-to-day experience working in privacy and data protection. What was it like to suddenly become the big man in privacy in Canada?

SPEAKER_03

It was a huge privilege, and it was very much in line with uh central theme in my career. I had been focused on protecting fundamental rights for many years as uh at our human rights commission dealing with discrimination cases and equality, but also privacy. I was dealing with privacy from the inside in terms of how does the government institution meet its privacy obligations. And I had done that at the House of Commons as well, making sure that we how do members of parliament deal with this? How do parliamentary committees protect privacy when they're seeking information from witnesses and try to get to the bottom of their fundamental mandate to hold the government to account? The whole notion of fundamental rights was a theme in my career, the notion of supporting and strengthening institutions, especially institutions dealing with democracy and the protection of fundamental principles and values in our societies. And also the importance of balance, balancing the fundamental rights, but also with the collective rights of individuals, national security, effective criminal laws, strong economies, strong partnerships, and all of those. So the notion of trying to say, let's not force our citizens to choose between those important things, but let's work together so that we can build them. But the private sector privacy side of things was one area where I had less experience. And early on in my mandate, I made it a priority to reach out to leaders in industry, to leaders in stakeholders, civil society, privacy experts, privacy professionals. And there was an incredible welcome and openness. And very quickly, those links have helped me become more effective. And one of the first things I remember saying to the to the chief privacy officers is that they to me, they were privacy champions and privacy ambassadors. And it's not only the regulators or the advocates of privacy or the academics, but those on the inside of organizations championing privacy from the inside have an essential and very critical and very powerful role to play. So I've been fortunate to be able to work very closely with them, particularly in Canada, but around the world, and I've been impressed and encouraged by the caliber of individuals and the and passion in that field. And I've said many times the challenges are great, but we have the people to deal with them.

Paul

Because the legislation in Canada is relatively complex, not as complex as in the United States, but you have both at the provincial level privacy legislation at the national level, but then a commercial law that does not apply in all of the provinces. How does that work on in your day-to-day? Do you encounter any specific challenges there? And not to mention the First Nations as well.

SPEAKER_03

Yes, I think that highlights one of the key aspects of privacy, which is we need to work together. We need to work together internationally, but we also need to work together in countries that like Canada, where it's a federation. And so you'll have the national authority, and then you have provincial or state authorities. And so it's important because data can have both a local aspect, but also then an international or interprovincial aspect if it crosses borders, that collaboration exists. We have a very strong network in Canada of the federal regulator, myself, and the provincial and territorial regulators. We have monthly virtual meetings, which is something that came in, was put in place during the pandemic and is something that stayed on, and which is a good thing. It used to be that it was more of a yearly basis meeting in person. We still have that yearly meeting, but we have regular exchanges. So it allows us to issue joint statements on areas of common interest, also joint investigations. And we've done a number of those in Canada and internationally. So with my colleagues in Canada, we did our investigation of OpenAI, ChatGPT. We've done an investigation of TikTok and internationally as well. We've done some recent investigation with the ICO on 23andMe. And I think that is a fundamental aspect of privacy that is distinct from so many other fields, including my previous field of equality and discrimination, where I could do at that time in that role much of my work focusing on Canada alone and the international exchanges work to inform colleagues and to learn from colleagues. But privacy, you have to work together, which is why we have such a strong and diverse international network, and that needs to continue.

Ralph

I would agree. And as well as that, the law in Canada is looking to change, isn't it? Perhaps for our listeners, you might have any insight as to, and I appreciate things are still going through there, but it's the direction of travel in terms of how the rules are going to change and how Canada's looks to grow and change in line with other laws across the globe, because PyPad has been under review for some time, plus you've got the changes in the various provinces and territories laws as well.

SPEAKER_03

That's right. And so there have been two bills that were introduced in our parliament a few weeks ago at the end of June, just before our parliament rose. And I think it mirrors, in a way, some of the international trends that we see. So we have there's been a bill tabled for a safe social media, and then there's been a bill tabled for the modernization of privacy. And I think it reflects the preoccupation of the government with protecting children online, dealing with things like deep fake, fake images, sexual images, nonconsensual sharing of intimate content, hate messages, the it the impacts of AI in terms of on youth, in terms of problematic uses such as suicide counseling or things like that. So a lot of these questions are not all specifically privacy issues, but there's a link to it. And we need to make sure that we are protecting children in this space and that we're protecting privacy in this space. So a lot of the changes we've been calling for in terms of recognizing privacy as a fundamental right, recognizing the special status of children's, children's personal information, its sensitivity, and the need to have that as a key consideration and making decisions in the privacy space, the need to focus on cross-border transfers. You talked about the privacy shield, and those concerns exist in Canada as well. So one of the things that is not currently a requirement is having privacy impact assessments and these types of safeguard mechanisms before data leave the jurisdiction. So that's now proposed. There's some proposals for greater AI transparency, dealing with algorithmic pricing, stronger deletion processes. So we see a lot of uh commonalities on those issues with international interest. And in particular, the issue of minimum wage for social media. So the legislation would put that in for Canada, like it has been done in Australia and proposed in the UK and other places. I uh we're reviewing those legislation bills very carefully, and I'm looking forward to be in Parliament this fall to give to give recommendations on how to make it the best legislation possible for Canadians.

Paul

And are these bills going to cross the finish line? Because I believe it's not the first time in in recent years that Canada has put modernization of data protection law on the table. Previous laws were not successful. Does do these have a chance to actually become an exit?

SPEAKER_03

It's interesting. With my previous role in Parliament, I had a front row seat at bills and debates and so on. So you never know. And sometimes a bill not get going through doesn't necessarily mean that it was refused. Sometimes parliament runs out of time. Time is one of the very precious commodities of legislatures. And so we've had we've had two bills now that did not make it through. It was in a minority parliament context, so that's always a little bit more challenging for government to get its legislation through in this context and also usually longer. Now we have a majority parliament. And so from that standpoint, I would say that it makes it more likely than if it were in a minority parliament. So we'll we will be following it very carefully. And one one one element of this legislation also is the creation of a new commission to deal with both the social media harms and the private sector privacy rights. And so that is a new development as well that I suspect will gather lots of lots of discussion and lots of commentary in Parliament. And I look forward to participating in those.

K

I have been listening diligently, so I apologize. I think my phone actually froze. Question. My question is gonna come because I'm in the United States, and there's a lot of tension between our countries now. And going back to what do we see about the difference in privacy? I came up through the healthcare arena. So I've been in privacy for more than 20 years, let's just leave it that way. And there's a tension between Canada and the U.S. Now, privacy is probably not one a lot of people feel, but the privacy people feel the tension between. Do you think we're going to be able to get to a position where the US, frankly, honors Canada's privacy protections?

SPEAKER_03

I think that there are lots of exchanges with organizations in Canada and the US and around the world. I'm just back from Paris where we had the G7 Data Protection Authorities roundtable. And I uh chaired that meeting last year, last uh June here in Ottawa. And so as part of that round table, we have the FTC. And we're working very closely with the FTC. We have been for many years, including with respect to one of the key files in terms of privacy and the protection of children and vulnerable individuals involving and the sharing of non-consensual images. So we have a lot of partnerships in that. And I think in terms of the privacy, respect for the privacy decisions, I think the dialogue has to continue with the privacy professionals and the regulators. And my goal is that we we have these common principles so that when we when decisions are issued, we can work together so that companies know that this is not just a one country specific, but that these principles are shared across jurisdictions. So we're going to continue to work.

K

Absolutely. Yeah, my biggest problem is trying to get the US companies to honor any privacy laws. The big ones, let's just be honest there, right? That's the challenge here. But no, thank you very much. I definitely agree with what you're saying. Thank you.

SPEAKER_03

Yeah. And you know what? I'll just I'll just add two things is that I've done a number of investigations with TikTok and OpenAI and even more recently. And in the under the current law, we don't have order-making powers or the ability to issue foreign. So that's a big gap that we've been slagging for many years.

K

But in those cases, but you've been trying to get it filled.

SPEAKER_03

Yeah. But but in but in those cases, we were able to obtain a number of commitments from those organizations. So using our investigation powers, using the bully pulpit. And so I think we need to continue to do that, but also using the strength of the international voice to talk about the Grok case. Before I concluded my investigation in Grok, we had issued an international joint statement that was coordinated with the GPA's work cooperation working group that had 61 countries signing off saying these are our expectations in terms of deep fakes. That's a big problem. And it raises privacy issues. And individuals need to take privacy seriously and to protect individuals in that way. And so that's a great example, I think, of the international voice supporting individual decisions and individual jurisdictions, which in turn can feed the international discourse. Because the G7 statement that was issued in France made reference to our guidance in Canada on age assurance. It made reference to our work in Grok on deepfake. So I think it's a virtuous circle when we can speak as a common voice internationally. Yeah. And then that helps us in individual individual countries. I always say the international work that I do on behalf of Canada, it serves Canadians very much.

Ralph

That's really interesting. And one of the things I've been talking about in my training is company can now be bigger than country. We're now in the world where some of these large technology companies are in every country, and their say legal defense budget could dwarf a national regulator's enforcement budget. Let's put it that way. So it's just occurred to me that some of our listeners might not really understand or know what the GPA even is or does, because we all run our own data protection programs. In our own organizations, and we all talk to our own regulators, and occasionally we might be aware that one of the commissioners swanned off to some sunny island to have a nice holiday in a hotel somewhere. But if you could perhaps educate the listeners on in your position as the chair and the sorts of things that might happen at a GPA or why it is that it does bring that value to the own local regulatory environment.

SPEAKER_03

Yes, absolutely. Thank you for that question. So I mentioned the G7 roundtable, which is a smaller grouping. There's other international groupings like Asia Pacific, of course, the European, the European countries, the Francophone countries. And what the GPA is, to my mind, it's a little bit about the United Nations of privacy. So it's all of the countries from all over the world that are rec who are recognized as members if they have a sufficiently independent and empowered regulator. And so we come together not just once a year. Certainly that there is that yearly conference. And certainly, I'm not sure I would describe it as a vacation because it's an absolutely schedule and lots of great discussions with other commissioners from all over the world, but also with stakeholders, with academics, with industry. So it's a great coming together of the privacy professionals. And what it results in is the adoption of resolutions and key principles that can then be pointed to by countries individually to highlight, okay, here is the common worldview on privacy. So it's not country dependent. These are key principles. So I'll give you a specific example from the last meeting that we had at the J in Korea. We adopted a resolution on human decision making, the role, the necessity of having a human in the loop when dealing with artificial intelligence decision making. And what should that look like? How do you do that? How do you make it effective? And so that's going to be critical in the context of agentic AI, which of course does not have, by definition, a human in that decision. But in many cases, you will want there to be in the process if those decisions are going to have key impacts on individuals' freedoms, on individuals' rights. So that's a start of the conversation. And then I'm looking forward to GPA resolutions going a bit further in agentic AI and in other developing fields. We've done some resolutions on cross-border trade, talking about what are the key principles that we want to see? That's becoming incredibly relevant now with the discussions on digital sovereignty and the concerns that some states and citizens have that what about if our data leaves our jurisdiction, is it at risk either because of the legal regime or either because of a government's approach to certain issues? So, how do we make sure that we don't stop the flow of data because then that harms the economy, but that we have a level playing field and key principles that are adopted. So that we've done a lot of work at the GPA and at the G7 in terms of the rule of law principles and the key privacy principles and some of the frameworks you talk about, you talked about the privacy shield privacy framework, those are specific ones. But there's also the cross-border data transfer and global CBPR, which is another mechanism. So working together to develop those, simplify those. And then during the year, the GPA brings together countries very quickly to issue some more specific statements, as we've done in GROK, but also to share information. So they're big commissioners, they're smaller commissioners in terms of the jurisdiction size and the resources. Also, some commissioners are newer to the field. They've been created more recently. So we share the knowledge and the expertise and we help each other. I've seen smaller jurisdictions have a really big impact by bringing a global statement that they would alone they would not have been able to develop that. But working with everyone, then they can. Or some others might not have a lot of resources to participate at all, but they can still then be informed of here's this working group on this area, here are the key trends, and now you have incredible knowledge that it would have taken you months to develop, but you're benefiting and you're not reinventing the wheel because we're facing so many similar issues that we benefit from the knowledge of others, and that helps us use our resources better. I think one of the key challenges that all regulators are having around the world, probably not just in privacy, is that we're seeing huge increases in the number of complaints. And in the industry, AI-driven complaints. AI-driven complaints. Yes. Industry is seeing that. I've been talking to industry leaders saying, well, we're dealing with that as well. How can you help us with that? So that's a global issue. And we all have different solutions. You know, here at the OPC, we've modernized our online complaints form. We've used different legal tools in our toolbox to make it faster. We've done a whole range of things. And so we need to share that with colleagues to say, well, this worked, this didn't work. That's a lot of what the GPA really does. It helps all the regulators, and then it helps the community by saying this some this is a principle that is held worldwide. And so I know when I go in front of my parliament and I say, this is not just me saying this, this is the world privacy community saying this, or this is the G7 saying this, or Asia Pacific, it has a lot of weight and it helps us be part of the conversation with citizens and with governments.

Paul

So it's not only preaching the gospel of privacy around the world, but also real capacity building that's happening with boots on the ground. Even DODO's may be virtual boots, but it's happening that indeed we've seen privacy and data protection commissioners expand all around the world. There are, I think, twice as many now than there were when I set my first foot inside the doors of the Dutch DPA back in 2009. So the volume of commissioners and also the quality of their work has significantly increased in recent years.

SPEAKER_03

Yeah, and you know, I'll add one thing it's next to the yearly conference of the GPA. One is a what we call a closed session, which is only the commissioners and observers who are allowed in that room so that we have our conversation been private, and then we issue, we we publicize our statements and resolutions. But then there's an open ass open portion of it where stakeholders, academia is there, and industry is there. And so we they benefit from hearing from us on our priorities and our expectations, but we benefit from hearing from them on their perspectives, their realities, their challenges, because they're the ones who have to implement it, industry and governments. The other thing the GPA has done, and Paul, I think you were directly involved in that, is it bring, gives a voice to certain groups who may not have otherwise a voice, particularly vulnerable groups and the impacts on privacy on them, the recessions on the impact of cyber breaches, privacy breaches on vulnerable individuals. How what are the concrete impacts of that? It's not just a theoretical thing, it's not just a business thing. There are real people suffering significant harms to their dignity when these things happen. So it's a big deal. It's of course a lot of money, but beyond the money, it's incredible impacts, harmful impacts on individuals. But you brought together a great panel of youth and privacy at the Jersey GPA closed session. I'll never forget that. And it was inspiring for me. It was inspiring for me personally to hear from these young leaders about their lived reality, their challenges. And that was a big part of what influenced me to create my own youth council here in Canada and to build on those footsteps. So it has ripple effects. And for young people to have such an impact and to be speaking to the world community, hugely impactful for them. And I would argue it's one of our obligations under the Convention on the Rights of the Child is to give youth a voice like that.

Ralph

Yeah, giving people a voice in a platform is what data protection is actually about, you know, self-determination. I I was talking to someone about a DPIA the other day, and they'd done it without consulting people. And I said, How dare we? How dare we make decisions? How dare we decide what the risks are? How dare we say what the controls should be without talking to a range of diverse voices? You do a DPIA as a business, as an organization, of course you're gonna have some level of bias, right? Some level of determination that we're gonna do things where we want to do it because we're a business. And whenever I'm doing a DPIA, I always say, I can't be everybody. I don't understand other people's risks, and different people have different risk appetites, be they of a different race, gender, ability level, background, socioeconomic status, whatever that is. I was really I was there in Jersey and just to see and those young people not uh and you mentioned that they were leaders. I actually I'd I would respectfully disagree with you there. I think they were very typical high school social media users rather than leaders. And sometimes they're the voices that are most important to hear.

SPEAKER_03

Yeah, look, I agree. I agree. And I think you don't have to I th I I think they were leaders from the standpoint of the impact that they had by sharing their experience. And you don't have to be in a leadership position to have a leadership impact. And so to me, they did have that, they did have that impact by sharing things and their perspective that that I may not understand. And it's interesting the fact of hearing different views, so important. In my old life as a human rights anti-discrimination lawyer and champion, I did a lot of work with the community of persons with disabilities and the convention on the rights of persons with disabilities. And one of the key principles there was nothing about us without us, to make sure that people with personal disabilities, their voice be heard when making decisions. And too often that doesn't happen. Society will say, here's the here's this accessibility plan that we're putting in place, or here's this ramp to give access to a building and whatnot. But do you actually understand what the live reality is for persons with disability? And I think that's true for a number of groups in society. So children's perspective. I didn't realize some of the speakers on that panel saying, I have four, five, six different social media accounts and different social preferences, and this is for my close friends, this is for my family, this is for my school networks and all that. I didn't grow up with that. So I didn't have that perspective. It's important for me to have it. If I'm going to try to help kids' privacy, I have to understand their realities. My youth council, some of my members told me that they were worried because their teachers were using AI to create letters of reference for the students when they wanted to get accepted to university, but they didn't feel that the teachers would protect their data and they would use just any random AI. And that's if they were worried that their personal information and their grades and all that stuff was going to be fed to train or wasn't going to be properly safeguarded. So again, I didn't have that experience when I was in those shoes. None of us did, right? Yeah. Yeah. And I've seen cases, we've dealt with cases here at the OPC where, you know, in Canada and as in many places, one of the one of the tests to determine if you have to notify the regulator or notify individuals in case of a privacy breach is if there's a serious risk of significant harm. And so that's often a debate. I remember a case where people were saying, there isn't that much of a harm because we didn't disclose more than X amount of personal information in the breach, but it nonetheless disclosed the fact that individuals had made a claim for financial assistance or something like that. And we found that look, this is going to generate a lot of stress. Not everyone's going to be comfortable with that being known. And so you may be creating embarrassment for people. Sometimes, as the organization, they might not have the level of empathy or just they might not have had that lived experience. So having those perspectives is absolutely critical.

Ralph

I would agree the two things that I would add there. You're talking about the level of data, a couple of ICO penalties. One with just people being BCC'd in an email or weren't BCC'd, they were just CC'd. So everyone could see everyone's email address. Now you might say email address is not that impactful, but if it's about their HIV status and things like that, and the fact they're receiving treatment deaths. Trevor Burrus, Jr.

Paul

Or affiliation to an extreme right political party, which we've had in the Netherlands.

Ralph

And also the Northern Ireland police one for us, which was literally just police officers' addresses. But you might say, oh, your address is not that private when it's coupled with the context that you're a serving police officer in Northern Ireland, you've got threat to life. Sometimes it's not the data itself, but the hazard or the harm in the context, right?

Paul

As I keep telling my students, context matters.

SPEAKER_03

Absolutely. And you're just highlighting, Ralph, I think one of the things we've been championing at the GPA and elsewhere is that privacy is a fundamental right, but it because it's linked to freedom and democracy and dignity, but it's also a condition for other rights. So if you're talking about data breaches, for instance, in the context of vulnerable individuals or minorities or groups that could be victims of discrimination, that breach can put them at risk. That breach could amplify discrimination. If you're talking about breaches in the democratic process, that can have real risk. And we've seen it in Canada. Recently, there was a big breach in the province of Alberta of citizens and voters' information. And that had impacts on the safety of some elected officials and former elected officials, because their information was made public and that exposed them to threats. And so that threatens democracy itself. If you have something that can have a chilling effect on individuals' willingness to run for office, major impacts. If you have impacts on the safety of police officers, of course, that threatens public safety and law and order. Just a reminder, I think, that that privacy is so fundamentally important. And that's why we work so hard to preserve it and to do it in a way that allows innovation, allows the public interest, allows the strong economies, but we always have to remain vigilant because so much of that economy is built on data. We have to stay vigilant and protect that data.

Paul

Amen. And I'm sure we all have tons of additional questions, but we're also coming up to the end of the time that we have available for today's interview. So I want to thank you very much. I'm sure we'll see you in Brussels for the GPA this year. So looking forward to that. If people haven't realized yet, GPA will take place in coordination with the IPP Data Protection Congress in Brussels this year to avoid the security issues that Dubai could have brought, given the instability in the Middle East. So hopefully soon we'll have a conference in Dubai, but this year it will be Brussels. Registration is open. Join there. Thank you very much to you, Commissioner, for joining us today. Thank you even more to all of our listeners for being with us for the past 300 episode. And here's to the next hundred, or maybe just the next 300.

SPEAKER_03

Here, here. Thank you so much for the great conversation and leadership and looking forward to seeing you in Brussels. Thank you. Bye for now.

Ralph

Thank you, sir. And thank you to our listeners. Goodbye for now.

SPEAKER_03

Bye, y'all. Goodbye.

Tim

Now that was serious privacy. Please subscribe on your favorite podcast app and leave us a review. You can find us on LinkedIn, Instagram, and Blue Sky at Sirius Privacy. Feel free to drop us a question or a comment. We'd love to hear from you.