Serious Privacy

one HOT week in Privacy

Dr. K Royal, Paul Breitbarth & Ralph O'Brien Season 7 Episode 29

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 35:57

Send us Fan Mail

Welcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal, discuss a week in privacy in the midst of hot temperatures in Europe and multiple fires arund the world. This week, we bring you some enforcement activities, regulator inquiries, old laws for new purposes, and guidance from various regulators on child safety.

If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!

From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.

Tim

You're listening to the award-winning Serious Privacy Podcast sponsored by Trust Ark. Please welcome your hosts, Paul Breitbart, Ralph O'Brien, and Dr. Kay Royal.

Paul

Welcome to another weekend privacy episode. Because, hey, it's summer, things are happening, or actually no, they're not. This will be probably a relatively short episode because not a lot of major things have been happening. But this is still privacy and data protection, so you don't know anything. For all what we know, next week a massive data breach could occur, a major court case could be handed down. You never know what's going to happen next. But my name is still Pal Breitbart. My name is still Ralph O'Brien.

K

And I bet people wish I wasn't still K. Royal. And welcome to Serious Privacy. So thank you. I think this is gonna be one hot week in privacy because I understand the EU is still on fire or having a heat wave. It depends on which area you're at.

Paul

Yeah. For now, The Hague is not on fire, but we are uh well above the 30s in in temperature. That's Celsius. So that's what, getting up to 100?

K

Yeah, it should be, yeah.

Ralph

Our environment agency today said that at least half the UK is in drought and affords go out to the people near Bordeaux who have had to be relocated because as I understand it, France is on fire at the moment.

K

Good Lord have mercy. So this is gonna be one hot week in privacy. Privacy is on fire.

Paul

Exactly. But these these temperatures are what you are used to, right? From the south.

K

From Arizona, yes. In the south, yeah. We're we run here 90s, but with 100% humidity. So it feels like 110 or something, which is getting up into what the high 30s, low forties Fahrenheit?

SPEAKER_04

Yeah.

K

I'd have to look that up and see. But here we go. Unexpected question of the week. Y'all gonna love this one. Would you rather fight a mouse the size of a lion or a hundred lions the size of mice?

Ralph

A mouse the size of a lion, or no, I'd I'd I think I'd go for a mouse the size of a lion. I'd actually think that would be cute, actually, to be fair.

K

Sounds like a rodent of unusual size.

Paul

Can you imagine how long the tail would be? Exactly, yeah.

K

They'd use it like uh what is it, the long lizards or whatever, and they whip their tails around. Yeah.

Paul

The gallows.

K

Oh, there you go.

Paul

Use the tail of the mouse as their gallows.

Ralph

Plus a s a swarm of anything is always sinister, right? Like a a hundred small things is always sinister.

Paul

Yeah, plus imagine the teeth of lion, even if they're small, they're still pretty sharp. And then there's a hundred lions running around with those sharp teeth and sharp claws, then no, probably I'll take the mouse as well.

K

Yeah.

Paul

Lions can be small. They're they don't always need to be massive. I've seen lions in Kenya that were actually not that massive.

K

I keep thinking of kitten claws. Because kitten claws are like sharper than any other claws on earth. And would miniature lions have kitten claws? They're adults. Probably. Maybe. I don't like a hundred. I did a a thing in a museum one time about old European torture methods. And only one of them really made me sick, and that was when they would lock someone in a box and they would put mice in there, and then they'd put a heater on top of the box or set a fire. Okay, I think we're all gonna go with a mouse the size of a lion.

Paul

Yes, I would say so.

K

Yes. I I think we're all gonna go. So rodent of unusual size. Rodent of unusual size. So I have a few things to talk about this week as well. Nothing that's really earth shattering. Nothing that we would go, wow, never saw that coming, but just some things that have happened. So who wants to start off?

Ralph

I'll jump in with a new Prime Minister. We have new tech policy over here in the UK with the new Prime Minister Andy Burnham. One of the first things he actually did when he came in, as well as a pledge to end street homelessness, which is admirable, but I also think don't be a difficult challenge. And opening number 10 north and social care and all this kind of thing. One of the things he has done that perhaps hasn't received the media attention is to drop the digital ID scheme. So that's an interesting one. We'd actually seen some walking back here already because the previous Prime Minister Keir Starmer had changed it from mandatory to voluntary, and now the unified digital ID is going to be scrapped, and the funds is going to be used to cut a tax on electricity bills. I don't I don't disagree with that decision, to be honest.

Paul

You need some form of digital identification. That was the whole idea. And now the money that was supposedly going to pay for that whole scheme is going to be repurposed for something completely different.

Ralph

Yes. Yeah, definitely. It's really interesting. The tech policy's kind of changing here. For those people that usually load a sponsoring department of the ICO here was the Department of Science, Innovation, Technology. That that has disappeared. That department that was run by Liz Kendall has disappeared and its functions are being redistributed amongst other departments. We think the ICO is now going to be sponsored by the actually the Department of Culture, Media and Sport that it was before, instead of DB sit that we all thought it was going to be for a second. So it'll be interesting to work out where a regulator ends up. But one of the other interesting things he's done is promoted a junior minister to a cabinet position on AI policy.

K

Only the junior members know AI, right?

Ralph

Exactly. So that perhaps signals the uh new sort of AI strategic priority of the new administration, even if the actual previous way that things have been pulled together into the departments of science, innovation, technology has now been moved back out to culture, media, and sport and the government digital service as well. So it's including Ofcom and the Online Safety Act. It's all changed here, perhaps same faces, different organizational chart. I don't know. But I guess we'll see what that means.

K

Did you see John Edwards' post on LinkedIn the last couple of days about his deep friendship with Sinee O'Connor?

Ralph

I saw people talking about it. He has me blocked, but but I have the I've been trying not to give him air time, to be honest. So it I actually think trying to keep himself relevant is one thing, but I think personally it's time to he's trying to draw a line and move on, perhaps. And focus on the future rather than the past, unless it's going to be the results of the ongoing investigation, all right? So who's going to be in charge of that? Again, that's up in the air. Because it was going to be Liz Kendall who appointed the that investigation.

Paul

So we'll see what happens with that in the future as well. It seems that in the end DCMS will be responsible now. Yes. Yeah. There has been some back and forth between UK government departments on who actually owns the ICO. Yep.

K

Who owns the ICO?

Ralph

And it's got to be DC the Department of Culture, Media and Sports. People that don't know, the ICO is supposed to be an independent supervisory authority, technically. But whilst it receives money from the fee, from the registration fee, it also does things like FOI and it does get granting aid from a government department to do that. And I guess it's got to fit somewhere within the infrastructure, and somebody's got to oversee the appointments on to all the committees and etc. etc. So it is supposed to be an independent supervisor authority, but it does have to produce an annual report that gets laid before Parliament and does have to be owned somewhere within government. And uh I do have questions on how independent it is with the new the new structure, and especially how much we've seen it parroting former government policy around innovation and its new statutory mission, of course, which is set by the government. So we will see what happens in the future. But yeah, certainly if I was the European Commission and I was reviewing things like adequacy, having an independent regulator, as we know from Trump versus Slaughter, is probably one of the more fundamental elements, and therefore that's certainly something that I would be looking at. Let's put it definitely. Talking of the ICO, I I the other thing that I've got to talk about today is they've produced some more guidance on how they deal with complaints. And again, as I wish I could say something positive today, but it does seem to me that their approach there does seem to be, again, the fact that we're looking at perhaps a really high threshold for that for them to look at complaints. It says the issue has caused or likely to cause a high level of harm. The issue has caused or is likely to cause a significant effect on individuals. The issue has or likes to have a significant adverse impact on a large number of people. Looking into the issue in more detail will help the ICO to improve data protection rights. People have to provide their personal data to the organization. The issue relates to the ICO's strategic priorities. Making inquiries would be in the public interest, and the ICO doesn't already know about the issue. So to me, that does sound like a pretty high threshold for the ICO to get involved and look at complaints from individuals. Allegedly, the new complaints process in the UK means that the organization, you've got to go to the controller or processor first, and also the current ICO wait period is 40 weeks. So you've got to go to the regulator first. Sorry, the controller or processor first. That's after they've probably spent two or three months not answering, say, a subject access request. They can then respond to you within another month. Then you have to complain to the regulator, then they'll look at it within 40 weeks, and then decide if it looks at that particular threshold, which is quite high, to decide whether to action it or not.

K

So eventually, once a decision is finally made, they could be a senior, elderly senior, not like senior in high school, senior.

Ralph

What do the ICO authorities think of the children? So the question is, would they still be a child by the end of the day?

K

Right. Will they still be a child?

Paul

To be honest, if they are, if it's a children's data complaint, then likely it would fall within the priorities and therefore be eligible for investigation. That is very true. I'm maybe not as concerned as you are on this guideline because it sounds very much like the guideline that the Dutch DPA had before the GDPR went into effect. And it's also very much in line with the a dash from the former ICO commissioner, Richard Thomas, who always preached, be selective to be effective. And I do agree with that to a certain extent.

unknown

Yeah.

K

Be selective to be effective.

Paul

Yeah, this does not mean, in my view, at least, that they will not look at cases, that they will not pick up the phone and call a data controller and say, hey, what the hell do you think you're doing, or send a stern letter to the data controller. This is about full-fledged investigations, where you also need to be mindful of your resources and need to have some sort of assessment criteria to determine whether or not you are going to spend all those resources and set up a full team for a nine to fifteen month investigation.

Ralph

I agree. I'm being somewhat flippant when I say that. But we said on the last episode that complaints, the ICO in their annual report had gone up like 181%, right? They're looking at double the amount of complaints that they've had previously. And I do agree that they've got to prioritize and put limited resource where it has the most effect. Flippancy aside, and my ongoing concerns about how easy it is for individuals to get some sort of satisfaction when their rights and freedoms have been compromised. At the same time, you've got to put your resources where you make most effects. There is a balance there, of course. Exactly.

Paul

Talking about resources and lengthy investigations, Sweden, the Swedish DPA, this week announced that they have wrapped up their investigation into Klarna Bank. And that is something that was started somewhere in 2022. Yeah, 16th of May 2022. But by now they have wrapped up the investigation. This was following a number of complaints related to Klarna's checkout service, where apparently, if you started typing some information, they would already auto-fill your information on the site of the web shop in order to facilitate faster checkout.

K

Yeah, I remember when that happened.

Paul

A lot of people complained about it and said, hey, how the hell are they doing this and why are they doing this? And where is this data coming from? So the IMI has IMY has investigated and they have indeed concluded that there were issues, that Klarna lacked a legal basis for the processing, that they did not provide sufficiently clear information to customers about how the function worked, and that they also did not take sufficient security measures to protect the personal data, and they have decided on a reprimand, which obviously has also been published. And while I was on the website of the Swedish TPA, I also saw that their head of legal has been requested by the Swedish government to investigate whether or not government authorities need improved legal possibilities to process personal data and also to propose the changes to data protection rules that should enable that. So actually, very similar to what we discussed last week on the request from the European Data Protection Board to create better legal basis for authorities to exchange personal information as part of their official work. The Swedish government would like a similar review at a national level. So David Tunngren, who is the head of Beagle at the Data Protection Authority, is now drafting that report to be conclude to be completed no later than the first of March 2028.

K

Okay. Nice. I have some fun stories that have popped up. Scrolling through them to see which ones fit in with the one hot week in privacy. So here's an eBay lawsuit. I was unaware of this, but I think this is fascinating. There is a settlement now. eBay and their former top executives have agreed to pay $55.7 million to resolve a lawsuit by a Massachusetts couple who fell victim to a bizarre stalking and harassment campaign carried out by eBay employees because this couple did some coverage of the e-commerce company in a newsletter that they published. One would assume the coverage was negative. So the eBay employees stalked them and harassed them, and now there's a $55.7 million lawsuit.

Paul

That's a lot of money.

K

I thought that was pretty interesting. Let's see. There was another one that was really good. This is was it Next Era? And it's not as hot as I was saying it, but we'll go we'll go here. Next Era Energy and Brookfield, a location, have developed a plan for a $100 billion data center campus at a former federally owned uranium enrichment site in Kentucky. Data centers making the news lately because AI requires a lot more energy from data centers, and there you go. So a former uranium site. So that's interesting. There is an effort by some US lawmakers to ask the SEC, the U.S. Securities and Exchange Commission, to research into Trump media's feed because they plan to sell early access to social media posts. And these regulators, not regulators, these legislators are saying that breaks law because you can't have disparate interesting. So that's going to be an interesting one to look at. There is China released a draft cyberbullying law covering AI-enabled abuse. So it was their cyberspace regulator. So this just happened today. I would have been much earlier today that they're looking at reducing cyberbullying, including AI-enabled bullying, as Beijing is looking into more online bullying accusations in the world's largest internet community. So I'm glad that they're looking into that. Robin Hood, CN CEO, said that there was a hacker who posted fake content about a meme coin on his ex account last week and said they used social engineering to bypass the ex security guardrails. The one that I'm looking for is a woman who is suing Grok.

Paul

Is this the AI from Elon Musk, right?

K

Yeah. So she apparently Grok is has done some fake nudity pictures on her, and she's looking for lawmakers to block Grok's ability to create more nude pictures of her based on the information they have. I don't think she is submitting her actual nude pictures to bypass it, but it's an interesting thing, right? How do you get this information out of AI?

Ralph

This is true. Yeah. Once one once Pandora's box is open, it can never be closed again. Once something's been learned by the AI model, how is it unlearned? This is the this is an interesting question. Talking of transatlantic, actually, I was at IAPP, I was looking on IAPP's daily dashboard, and their lead story is quite an interesting one, talking about hot and heat. It's about love and a love story.

K

A love story, a privacy-era love story.

Ralph

And they're comparing the marriage of America's most famous couple, Taylor Swift and Travis Kelsey, to Prince William and Kate Middleton. And they're what's quite just saying that because one is a public figure, we had they had a public holiday and publicity and a public broadcast of the wedding. Whereas actually what was quite interesting is even though Taylor Swift and Travis Kelsey are people of public interest and very famous, even though they booked out Madison Square Gardens and did it right in the middle of New York, it was a private event with private guests and no windows. No windows, yeah.

K

I'm rolling my eyes so hard at this one.

Ralph

This is not to suggest that the Swift Kelsey wedding is a loveless commercial enterprise, which is the quote I took from from from the ethical. But it was really interesting that this idea of people who are in the public eye and public focus, whose ability to try and have still private events or still private areas of their life, even if they've given over large amounts to the public.

K

Yeah.

Ralph

I think that's a really interesting question about the fundamental right to privacy where we make ourselves public.

K

That was interesting. I like this story. So looking at, I'm just going to continue your trend of looking at IAPP things, the note from Canada that privacy needs more success stories. They say enforcement plays an important role. Everybody talks about what goes wrong, but we really need to celebrate excellence and innovation. And as a Picasso Award-winning content creator, we definitely support celebrating excellence. Which brings us to are we allowed to say, Ralph, that you're a finalist in a privacy champion for Picasso Europe right now? Because that's a celebration.

Paul

Oops, you've now already said it, right?

K

Oh, damn.

Ralph

A surprise, but a welcome one. Today is Wednesday, the 29th of July, and Picasso has posted all of their short lists for this year.

K

There you go. We can say it.

Ralph

So they've all gone on LinkedIn, and yeah, I'm up for Privacy Champion of the Year somehow. Congrats. Along with many others. Along along along with many others. And yeah, so congratulations to anyone who's been nominated.

K

And I guess I'll have to You have to dress up and wear your bow tie and your socks.

Ralph

I will do that again. Yes. Thank you very much, Kat.

K

You're well- I still have my bow tie. It's just still in the wrapper, right?

Ralph

So yeah, a surprise, but a welcome one. And yeah, it'll be an honor to see. It's an honor to do this job daily and work with such good people anyway. Whatever happens. At the wards, I think on the 2nd of December, there's lots and lots of good people who'll be there. And whatever happens on the night, uh a good opportunity to catch up with our colleagues.

K

Even if I make it over to Brussels, I don't think I can hang out in Europe for three weeks.

Paul

Probably not.

K

I would like to. I don't think I could. I might have to beg a couch from you, Ralph, and I'll just hang out in Europe for a few weeks and do my own work, right? Nobody cares. Nobody cares.

Paul

There's room here.

K

Exactly.

Paul

So on more on a more serious note, the European Commission is set up with Poland. Just in general. Just in well, not in general, in data protection context, obviously. They have actually opened an infringement proceeding against Poland for its inadequate implementation of the law enforcement directive. That's the directive that accompanies the GDPR, but then for all police and justice matters. Poland has not implemented it properly, especially when it relates to the criminal justice part of the data processing with insufficient oversight. So the Polish DPA would not be allowed to supervise criminal proceedings and criminal Justice data processing. So, what this means is that the Polish government will now get the chance to give a formal response or to file a legislative change in the country's parliament. But in the end, this could be a case that is brought before the Court of Justice and could also lead to financial penalties for the country for lack of compliance with European law. Financial penalties are also due for Lucia Systems Incorporated, a US-based data broker. They have just received a 2 million euro fine from the Italian Garante. So the Italian DPA, Lucia provides paid access to enriched information on individuals, job titles, email addresses, phone numbers. And I know that I've received a lot of spam from them in recent years. Ralph, you may have too. There are others like Apollo.io and some more, but I'm really happy that the data protection authorities have now started enforcement against these data brokers because they scrape information from all over the internet. They sell it, but they don't even take the opportunity to tell you, hey, we have your data, and they don't comply with individual rights requests or at least insufficiently. And the Italian DPA says that there are in any case concerns about the lawfulness of the processing. This is not a legitimate interest that can be used. And they have also an issue because they do not have a proper representative in the European Union. So two million euros that will need to be paid.

K

There was something about a TikTok penalty from Europe, right? About another thing that they're doing wrong. TikTok EU finds TikTok violates its digital rule book by failing to protect the privacy of miners. So I don't see what the amount is.

Paul

This was not a data protection fine. This was a digital services fine. So imposed by the European Commission. Top of mind, it was 150 million.

K

Yeah, I was trying. That's the number I had in mind. I'm clicking on it to see if I can find it again. While I'm looking for that one, I will say, yeah, hold on. It is how much? 170. No, 170 million users. Yeah, I don't see the amount. Used to be TikTok being fined actually made the news. Now it's an afterthought. I don't even remember how much they fined them for.

Paul

The fine is not imposed. The fine amount is not known yet because this is is not finalized.

K

Okay.

Paul

This is not finalized. So this is the initial findings of the investigation. TikTok can now defend itself, reply to the findings, and only if the commission is not satisfied with the response, a non-compliance decision and fine, possibly up to six percent of annual revenue can be imposed.

K

And at this point, TikTok ought to have its responses to regulators for violating laws pretty well honed.

Paul

You would think so.

K

Yeah, this one caught my attention. So the U.S. administration is using the Department of Education and the Department of Justice to crack down on schools who have LGBTQ and inclusion initiatives. They are going to some very old laws. Because there are typically surveys or questions around inclusion and diversity, and they're saying that violates student privacy.

Ralph

Interesting.

K

Indicate our kids are being subjected to inappropriate material surveys and events in schools, and parents' fundamental right to review such materials and opt their children out of these suggestive activities appear to be disregarded in the process. Okay. Using now it's a little bit flip of the coin to use a privacy law to hold someone accountable for doing or not doing something that you don't like, as opposed to using old laws like Wiretapping Act to investigate AI chatbots. But I guess what's good for the goose is good for the gander. Use whatever laws are on the books, right?

Paul

I have one more. The Dutch CPA today put out guidance on the childcare sector.

K

Oh yes.

Paul

And especially about employees in the childcare sector. We've had some incidents in the past. I think all countries have had similar incidents where people were employed that were abusing children while they should have been taking care of them. And obviously, there are concerns with employers in the childcare sector how to do the screening in a proper manner, but also do so in a manner that's legal. So the Dutch CPA has given now some initial guidance. For example, providing a list of questions that you are allowed to ask to job applicants and also to referees. How did you function in your in your previous job? Has anything ever happened in your previous job or even before was your previous contract terminated or did it just expire? Have you ever been sent away? Have you ever been dismissed? So those kind of questions can be asked. They also say that it would be possible to use an internal blacklist. That would only be for a single organization. It is prohibited to share the blacklist across organization organizations, but a single organization with multiple locations for childcare that would be allowed to have one single blacklist so that one applicant cannot go to location A and then to location B and then to location C. So that kind of blacklist would be allowed as long as it meets all the basic requirements of the GDPR. A legitimate interest would be allowed here.

K

I would think so.

Paul

As long as the blacklist is demonstrably necessary. And of course, there needs to be the clear ground and the clear interest needs to be demonstrated. There also needs to be a clear retention period and all the basic requirements of the GDPR, such as fairness, but also transparency, purpose limitation, data minimalization, all those kinds of things need to be guaranteed, as do the individual rights and of course proper data security. Dutch CPA finally writes that they understand that there is interest to have a national blacklist and maybe even more measures at a national level. There is currently a task force for running from the Ministry of Welfare and Employment, in which the Dutch CPA is also participating, which will look into that, and then also the possibility to have a national blacklist for people who would not be allowed to function in these kind of sensitive roles. But obviously that also feels very much an employment prohibition. You are not allowed to have a certain job. And even though you can understand context, that is a very far-reaching measure to propose, to implement. So that's a conversation that probably will be ongoing for a long time.

K

We have something similar here, but it's based on if someone's convicted and so they have to become a federally registered child abuser or whatever. Trevor Burrus, Jr.

Paul

Yeah, but the thing is if you are convicted, you will never get your good behavior certificate, which is required for these kinds of So this has nothing to do, this really isn't about convictions.

K

This is about other things, which we would not have here, believe it or not.

Ralph

Aaron Powell We had that when we were years ago when we were looking at the Rehabilitation of Offenders Act and setting up the Criminal Records Bureau that's now the disclosure and barring service. It depends what job you go for. If you've got if you're working with children, elderly and the vulnerable, and then you then have to disclose even what we call spent convictions, ones that have done their time. But if you've got unsupervised access to children, elderly and the vulnerable, the individual police constabories can release what they consider to be an inverted commas relevant intelligence about you, even though you haven't been convicted. So that's a police officer saying nothing's ever gone to trial and nothing's ever been proven, but this one you probably should watch, right? And that's really interesting because that's perhaps denying someone employment without conviction in a court law.

K

And here we're very interested interesting here because they used to have employers would ask for your social media username and logins. That way they could look at your private social media accounts so they could find out information. Not that I think it, but they might. And it became a law that employers couldn't ask for that information, which you're sitting there scratching your head going, Really? Why would anyone think that was legal to begin with, right?

Ralph

But people do it. People do it informally. When someone invites on your for job energy, you reckon they don't look you up on social media?

unknown

Right.

Paul

But this is not just looking you up. This is asking you for your credentials so that they can look at the back end.

K

That way you can look at your messaging, they can look at whatever you have that's private, different things like that. Would you be surprised how many idiots post criminal activities on social media? No, you probably wouldn't be.

Ralph

No, no, not at all. Okay. It was the predicting one that I remember. It was the babysitters in America, wasn't it, where people were looking at their social media to see whether they smoked drugs or spoke disrespectfully. Yeah, it was the predicting case. I remember that.

K

And then you also have your balance of people that are in trusted positions. And there's a split approach here in the United States, especially when it comes to teachers. There's the famous case of the teacher that was fired because there was a social media picture of her holding a red solo cup. Nobody knows what was in the red solo cup, but they said that was enough of a question for questionable morals and ethical behavior in front of our most vulnerable youngest population. She's terminated. So about half the states in the U.S. go from the you're in a trusted position, therefore, yes, these rules apply. And the other half go with no, what you do on the job and what you do off the job are two separate issues. Now, of course, if you're abusing, that's a different matter. But for an adult to drink alcohol off the job and it not impair them on the job, that that shouldn't be anyone's business. So it's a split way of approach here in the U.S., whether someone's in a trusted position or not. And then, of course, you have a lot of your sports stars that in their contracts they have the good behavior appearance kind of thing, that they can't be seen doing things.

Ralph

Yeah, be careful. I've got one more question for Paul before we end. We know that the AI digital omnibus has gone live now. Yes. There was that we're also waiting for omnibus four, which is the one that changes, as I understand it, the own the really small derogation of ropers from 250 to 1000. Do we know when that's going to come in over the summer was the last thing I heard. That's also the last thing that I have heard.

Paul

Okay. So no, I have not seen it. Not seen it come by. I have not seen it adopted. I Are you watching for it? We will need to wait. And so will you for next week.

K

There we go.

Paul

Exactly. Thank you for listening. Until next week. Goodbye. Goodbye.

K

Nayelle.

Tim

Now that was serious privacy. Please subscribe on your favorite podcast app and leave us a review. You can find us on LinkedIn, Instagram, and Blue Sky as Sirius Privacy. Feel free to drop us a question or a comment. We'd love to hear from you.