Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Ever since the UK left the EU, data protection has been a hot topic. On the one side government officials on one side argue that current rules are unnecessarily restrictive, while on the other privacy campaigners maintain that any changes to legislation could make it harder for organisations to do business with EU partners.
The solution to this conflict may lie in reinterpreting how we think about GDPR, rather than revising the regulations themselves. The UK’s Data and Marketing Association has suggested that GDPR codes of conduct could be a way to clarify the rules without having to water them down. We’re joined this week by DMA CEO Chris Combemale to discuss this idea, as well as the potential impact the government’s proposed changes to UK data protection laws could have on businesses.
Highlights
“When GDPR came into force, one of the main objectives … was turning the previous data protection legislation from 1998 from a directive, which gave each country the opportunity to have some flexibility, to a regulation, which theoretically means less flexibility nationally ... but in actual fact, every Data Protection Authority across the remaining 27 countries of the EU is interpreting and applying GDPR in a different way. And that is creating huge inconsistency and confusion. So one of the things we're doing [is] trying to create a network of national codes of conduct that harmonise the interpretation in the ways we think are consistent.”
“If you have customers that no longer want to do business with you, for whatever the reason, it's not actually efficient for that company to continue to communicate with you. It's not a productive use of resources, and what companies are trying to do when they're collecting insight about their customers, and understanding what their customers buy, they're trying to find those customers that really do want to have a long term relationship and do want to buy from you frequently and do want to benefit from the things loyalty offers. And that's where companies want to invest their money, because that's what's profitable. So philosophically, then, there is no contradiction between what GDPR asks and what companies are trying to do.”
Read the full transcript here.
Footnotes
- What is GDPR? Everything you need to know, from requirements to fines
- GDPR turns three: The biggest fines so far
- The IT Pro Podcast: Happy birthday GDPR
- DCMS lifts the lid on UK GDPR reforms, including ICO restructure
- Irish data regulator fails to resolve 98% of big tech GDPR cases
- The IT Pro Podcast: Navigating Brexit data transfers
- Footballers seek compensation for "GDPR violating" performance data trading
- Seven steps to GDPR compliance
- Amazon faces £637 million fine over GDPR violations
- Data protection policies and procedures
- Nine top GDPR tips for email marketing strategies
- What are the responsibilities of a data controller?
- Three key steps to delivering data-driven marketing
- How to build an effective marketing strategy with the cloud
- The rise of consent and preference management
Subscribe
- Subscribe to The IT Pro Podcast on Apple Podcasts
- Subscribe to The IT Pro Podcast on Google Podcasts
- Subscribe to The IT Pro Podcast on Spotify
- Subscribe to the IT Pro newsletter
- Subscribe to IT Pro 20/20
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
ITPro is a global business technology website providing the latest news, analysis, and business insight for IT decision-makers. Whether it's cyber security, cloud computing, IT infrastructure, or business strategy, we aim to equip leaders with the data they need to make informed IT investments.
For regular updates delivered to your inbox and social feeds, be sure to sign up to our daily newsletter and follow on us LinkedIn and Twitter.
-
Does your business need cyber insurance?In-depth As the cyber insurance market matures, do firms actually need it and if so, how should they choose a policy?
-
Geekom A5 Pro reviewReviews It's not a mini PC for power users or intense graphics work, but as a productivity machine or media server, it will do very nicely
-
March rundown: RSAC warnings and Arm's AGI CPUITPro Podcast AI agents are complicating the jobs of cyber professionals, with broken permissions and a lack of oversight posing major risks
-
SPECIAL EDITION: How AI is changing educationSponsored Podcast With the right support and communication, educational organizations can use AI to empower teachers and students alike
-
Tomorrow's fraud techniquesITPro Podcast Leaders need to proactive as attackers launch more consistent, sophisticated attacks
-
Redefining risk managementSponsored Podcast With a Risk Operations Center (ROC), leaders can proactively crack down on cyber risks instead of simply reacting to them
-
Are AI cyber threats overhyped?ITPro Podcast As cyber teams turn to the threats posed by AI, rising attacks by state-sponsored groups and ransomware gangs remain the biggest threat
-
The future of threat detectionITPro Podcast To fight sophisticated threats, cybersecurity teams will need to unify data like never before
-
November rundown: CrowdStrike's insider threatITPro Podcast As CrowdStrike grappled with a malicious employee, Cloudflare suffered a major outage
-
Getting a grip on digital identityITPro Podcast As AI agent adoption explodes, security leaders will need better identity controls than ever before
