Sign in

Robert Bateman

@robertjbateman.bsky.social
3.5K followers 571 following 304 posts

• I post about privacy, data protection, security, AI • Regular updates on big tech shenanigans • Views absolutely represent those of my employer (me) • Consultancy and training services •

PostsRepliesMedia
Robert Bateman @robertjbateman.bsky.social · 17/07/2025
Even OpenAI's best models still suck at quoting their training data or external sources. GPT 4o can be useful to help interpret legal provisions pasted into the chat Ask it to draw upon anything outside of the chat and it breaks down. The first quote is wrong and the latter two are just made up.
031
Robert Bateman @robertjbateman.bsky.social · 23/05/2025
Google plans to offer Gemini to US children under 13 without verifiable parental consent (parents can opt out if they use Family Link). As @epicprivacy.bsky.social notes, this seems like a blatant COPPA violation. I don't think Google would have had the gall to do this when Khan headed the FTC.
130
Robert Bateman @robertjbateman.bsky.social · 22/05/2025
Confirmed. My (MANUAL) dash-measurement process reveals that this is an en-dash.
010
Robert Bateman @robertjbateman.bsky.social · 09/05/2025
There was an error in the original, here's a corrected version. I left a stray "facilitate" in (e)(1) which has been updated to "replace".
000
Robert Bateman @robertjbateman.bsky.social · 09/05/2025
California's once pithy (and strict) definition of "automated decisionmaking technology" is on its way to becoming War and Peace. "Replace or substantially facilitate [humans]" becomes "replace or substantially replace" (?)—and the billable hours will rack up when figuring out all those exemptions.
432
Robert Bateman @robertjbateman.bsky.social · 02/05/2025
Here's a post I wrote back when GPT could barely strong a limerick together. Note that it is positively *littered* with em-dashes. Have people forgotten that Large Language Models are trained on stuff *we wrote*?
020
Robert Bateman @robertjbateman.bsky.social · 01/05/2025
This is not what I would call a "tightening"... www.theverge.com/news/658602/...
1377
Robert Bateman @robertjbateman.bsky.social · 14/04/2025
Surely these functions should be nowhere near each other, rather than combined into a single field...
2151
Robert Bateman @robertjbateman.bsky.social · 11/04/2025
The UK government has more plans for the ICO. From its recent paper "New approach to ensure regulators and regulation support growth" www.gov.uk/government/p...
3102
Robert Bateman @robertjbateman.bsky.social · 03/03/2025
EVERY ICO press release says something like, "My message is simple: Comply with the law" You can ALWAYS extract a simple message from a complex one. "Comply with the law" means nothing HOW you comply with the law—eg verifying people's ages, segregating children's data—is very fucking complicated.
130
Robert Bateman @robertjbateman.bsky.social · 28/02/2025
You're right it was this one
Good News For People Who Love Bad News by Modest Mouse album cover (2004)
010
Robert Bateman @robertjbateman.bsky.social · 21/02/2025
Apple pulls end-to-end encryption from UK users following the government's order under the Investigatory Powers Act 2016. I have seen some bragging about how Meta launched threads here earlier than in the EU (etc) due to our less rigourous regulatory environment. Here's the other side of the coin
132
Robert Bateman @robertjbateman.bsky.social · 13/02/2025
Writing about the state privacy laws that take/took effect JUST THIS YEAR I realised there's really no need for a federal US privacy law. Don't worry about it.
Application
Each of the eight privacy laws taking effect in 2025 applies slightly differently, providing various exemptions and thresholds. 

The laws apply to an entity that conducts business in the relevant state and fulfills one of two thresholds:

It controls or processes the personal data of at least 100,000 consumers per year (30,000 consumers per year in Delaware and Maryland), or
It controls or processes the personal data of at least 25,000 consumers (10,000 consumers in Delaware and Maryland) and derives a specified percentage of revenue from selling personal data:
Delaware: 20%
Iowa: 50%
Maryland: 20%
New Hampshire: 25%
New Jersey: Any amount
Tennessee: 50%

The exceptions are Minnesota and Nebraska’s laws, which apply generally to all businesses processing personal data in each state, except small businesses as defined by the US Small Businesses Association (SBA).
130
Robert Bateman @robertjbateman.bsky.social · 08/02/2025
I'm fascinated by this story about the UK government demanding access to Apple e2ee iCloud accounts. This was reportedly a warrant under the Investigatory Powers Act 2016. Neither the content nor the *existence* of such warrants can be made public. I wonder how many such warrants go unreported.
040
Robert Bateman @robertjbateman.bsky.social · 30/01/2025
A new proposed amendment to the UK Data (Use and Access) Bill that I cleaned up. Baroness Kidron proposes "sovereign data assets"—a licensing system for data held by public bodies (I guess primarily the NHS), with preferential access for UK organisations.
254
Robert Bateman @robertjbateman.bsky.social · 29/01/2025
It's Data Protection Boxing Day and the UK's ICO registration fees have officially gone up. Not likely to break the bank but I doubt there is much support for this among businesses.
000
Robert Bateman @robertjbateman.bsky.social · 27/01/2025
Last week's deep and nuanced judgment RTM v Bonne Terre is a fantastic read. A gambling firm used data about a person's vulnerabilities to target them with marketing—with his "consent". Here the judge explains how to balance respect for individual autonomy with the commercial benefits of data use.
161
Robert Bateman @robertjbateman.bsky.social · 13/01/2025
An AI-"turbocharged" Plan for Change. He's ruined my day by saying that. Terrible.
040
Robert Bateman @robertjbateman.bsky.social · 08/01/2025
The General Court has an individual €400 after he used the "Log In With Facebook" button on the Commission's website The court was satisfied that the claimant experienced non-material damages because "he found himself in a position of some uncertainty as regards the processing of his... IP address"
101
Robert Bateman @robertjbateman.bsky.social · 21/12/2024
Grammarly's new "Authorship Report" shows "a full replay of your typing and editing process" to share with clients, tutors, editors etc I understand the need for scrutiny but I would not be comfortable with this I second-guess myself constantly while writing. I feel the drafting process is private
2142
Robert Bateman @robertjbateman.bsky.social · 20/12/2024
Deployers trying to satisfy Article 4 of the AI Act by generating AI literacy training via ChatGPT
092
Robert Bateman @robertjbateman.bsky.social · 19/12/2024
In the latest episode of Google's absurdly convoluted ad privacy saga, the internet Elder God will let its customers to employ fingerprinting from next February The ICO has penned a heavily caveated but supposedly "clear" response: Businesses do not have "free rein" to fingerprint "as they please".
263
Robert Bateman @robertjbateman.bsky.social · 18/12/2024
In case you don't have time to read the EDPB opinion on AI training, here's a summary of pretty much every paragraph.
it depends
0122
Robert Bateman @robertjbateman.bsky.social · 18/12/2024
Dutch DPA to Netflix: "Your privacy notice doesn't say how long you'll retain data, only that you'll retain it 'as required or permitted by legislation and regulations.'" Netflix: "Your privacy notice says exactly the same thing." Dutch DPA: "That's not the point!"
0177
Robert Bateman @robertjbateman.bsky.social · 18/12/2024
The GDPR says controllers must name "the recipients or categories of recipients" of personal data, both in privacy notices (Art 13-14) and on request (Art 15). So which is it? We have case law on Art 15 (must name specific recipients). The Dutch DPA's Netflix fine says this covers Arts 13-14, too.
Article 13, opening words and first paragraph, point e, GDPR indicates that as and when applicable,  the 
controller provides information to data subjects about what the recipients or the categories of personal 
data are. It has been stated in the GDPR (recital 58) that it is difficult to understand for a data subject by 
whom and for what purposes their personal data are collected when it concerns information such as that of 
online advertising services. In accordance with the principle of fairness, Netflix has to provide information 
about the recipients that is most meaningful to the data subjects. In view of this, the Dutch DPA cannot see 
why Netflix has not stated the names of recipients – who,  by the way, are limited in number – in its 
privacy statement. The Dutch DPA is of the opinion that Netflix should have done this and should have 
provided this information in the event of a request for information. Netflix has wrongly omitted to do so, 
and in this way violated the GDPR (Article 13, first paragraph, point e, and Article 15, first paragraph, point 
c). On this point, the complaint of NOYB is, therefore, well-founded.
194
Robert Bateman @robertjbateman.bsky.social · 13/12/2024
The ICO has reported on its generative AI consultation. No huge surprises at first glance. I rather liked this bit though: 7 myths about AI and data protection. Full report as a PDF: ico.org.uk/media/about-...
1) The “incidental” or “agnostic” processing of personal data still constitutes processing of personal data. Many generative AI developers claimed they did not intend to process personal data and that their processing of that data was purely incidental. Our view is clear: data protection law applies to processing of personal data (which includes special category data), regardless of whether this is ‘incidental’ or unintentional. 

2) Common practice does not equate to meeting people’s reasonable expectations. Organisations should not assume that a certain way of processing will be within people’s reasonable expectations, just because it is seen as “common practice”. This applies particularly when it comes to the novel use of personal data to train generative AI in an invisible way or years after someone provided it for a different purpose (when their expectations were, by default, different).

3) “Personally identifiable information” (PII) is different to the legal definition of “personal data”. Many organisations focus their generative AI compliance efforts around PII. However, to ensure compliance in the UK they should be considering processing of any “personal data” (which is a broader and legally defined concept in the UK). Organisations must not undertake compliance based on a fundamental misunderstanding or miscommunicate their processing operations.  

4) Organisations should not assume that they can rely on the outcome of case law about search engine data protection compliance when considering generative AI compliance. A few respondents sought to rely on these case outcomes, arguing that as the initial collection of data was substantively the same (ie crawling the web), the decisions should also apply to the generative AI context. However, while we can see there are similarities in terms of data collection, there are key differences which means that the logic of these decisions may not be applicable. For example, while a search engine intends to index, rank …
4155
Robert Bateman @robertjbateman.bsky.social · 06/12/2024
I made some slides for the LinkedIn crew about the proposed reforms to the the UK GDPR's automated decision-making rules Bluesky doesn't allow .pdf uploads. So as a little experiment I converted the slides into a .gif These changes are very important but you only have 7 seconds to read each slide.
130
Robert Bateman @robertjbateman.bsky.social · 05/12/2024
The UK hopes to open up AI-driven decision-making. The current prohibition (Art 22 UK GDPR) covers "automated decisions" based on all types of personal data. The Data (Use and Access) Bill would narrow it to "special category" data only. Safeguards would still be required for all personal data.
Under the current law, significant solely automated decision-making based on personal data is prohibited unless one of the following three conditions applies:

The data subject gives explicit consent, or
The decision is necessary for a contract between the data subject and a controller, or
The decision is required or authorised by a UK law that provides safeguards for rights and freedoms.

Under the new Article 22B, this prohibition would only apply where special category data is involved. The exceptions are also slightly different:

The data subject gives explicit consent, or
The processing is based on Article 9(2)(g) (“substantial public interest”), and either:
The decision is necessary for a contract between the data subject and a controller, or
The decision is required or authorised by law.

Controllers cannot rely on the new legal basis of “recognised legitimate interests” for automated decisions.

This would mean automated decision-making that only involves “non-special category data” is generally permitted, subject to certain safeguards.
243
Robert Bateman @robertjbateman.bsky.social · 28/11/2024
Some pretty alarming findings about AI recruitment tools from the ICO's report on this sector. The report was based on a consensual audit, so perhaps non-enforcement was part of the deal. Highlights: • Many providers lacked accuracy testing (the ICO says accuracy should be "better than random"!)🧵
Many providers monitored the accuracy and bias of their AI tools and took 
action to improve them. However we did witness instances where there 
was a lack of accuracy testing. Additionally, features in some tools could 
lead to discrimination by having a search functionality that allowed 
recruiters to filter out candidates with certain protected characteristics. 
Others estimated or inferred people’s gender, ethnicity, and other 
characteristics from their job application or even just their name, rather 
than asking candidates directly. This inferred information is not accurate 
enough to monitor bias effectively. It was often processed without a 
lawful basis and without the candidate’s knowledge. 
We were concerned to find tools that collected far more personal 
information than was needed. In some cases, personal information was
scraped and combined with other information from millions of peoples’
profiles on job networking sites and social media. This was then used to 
build databases that recruiters could use to market their vacancies to
potential candidates. Recruiters and candidates were rarely aware that 
information was being repurposed in this way.
We found several instances where AI providers incorrectly defined 
themselves as processors rather than controllers, and subsequently had 
not complied with the data protection principles. Some had attempted to 
pass all responsibility for compliance to recruiters using their tool. In 
these cases the arrangements were usually subject to vague or unclear 
contracts, that appeared to be deliberately broad or left recruiters in the 
dark
1137
Robert Bateman @robertjbateman.bsky.social · 28/11/2024
★ UK Data (Use and Access) Bill update ★ The running list of amendments includes this from Lord Clement-Jones (who is deeply involved in data protection legislation): Public authorities must undertake a (Canada-inspired?) Algorithmic Impact Assessment before conducting automated decision-making.
LORD CLEMENT-JONES
After Clause 80, insert the following new Clause—

“Algorithmic Impact Assessments
(1) Prior to deployment of an algorithmic or automated decision-making system,
public authorities are responsible for completing an Algorithmic Impact
Assessment prescribed in regulations made under this Act.
(2) Subsection (1) does not apply when the algorithmic or automated decision-making system is—
(a) used solely forthe formulation of policy in relation to that public authority,
and
(b) is not expected to, in practice, fully or predominantly determine the content of the policy.
(3) The Algorithmic Impact Assessment must be updated when the functionality, or the scope, of the algorithmic or automated decision-making system changes.
(4) The final Algorithmic Impact Assessment must be published in accessible format within 30 days of the results being known.
(5) The Secretary of State must by regulations prescribe the form of an Algorithmic Impact Assessment framework with the aims of ensuring public authorities—
(a) procure, develop, and implement algorithmic and automated
decision-making systems such that the decisions made in and by a public authority are responsible and comply with procedural fairness and due process requirements, and its duties underthe Equality Act and the Human Rights Act 1998...
1105
Robert Bateman @robertjbateman.bsky.social · 20/11/2024
The Business Secretary: "If you have the technology to understand somebody's personality to a degree where you can target advertising and connect people with similar views, likes and dislikes... You have the technology to understand someone's age with some precision." My Facebook ads:
391
Robert Bateman @robertjbateman.bsky.social · 19/11/2024
Me in like 2008 with more hair standing near some tents
010
Robert Bateman @robertjbateman.bsky.social · 18/11/2024
From @noaasm.bsky.social: German Federal Court finds that temporary loss of control of personal data can constitute "damage" giving rise to a GDPR claim. Very similar facts to the EW case Lloyd v Google, but with the opposite conclusion. www.bundesgerichtshof.de/SharedDocs/P...
2185
Robert Bateman @robertjbateman.bsky.social · 18/11/2024
The EDPS has issued an opinion on the "Proposal for a Regulation on the welfare of dogs and cats and their traceability." I wanted to make light of this with some animal jokes but actually there are some important implications. Plus I can't think of any puns. www.edps.europa.eu/system/files...
Executive Summary
On 26 July 2024, the Council consulted the EDPS on the Council mandate for negotiations with
the European Parliament regarding the proposal for a Regulation of the European Parliament and
of the Council on the welfare of dogs and cats and their traceability (‘the Proposal’).
The objectives of the Proposal are to ensure a smooth functioning of the market of dogs and cats
and a rational development of the sector, as well as a high level of animal welfare. In order to
achieve these objectives, both national competent authorities and the Commission must be able
to process certain personal data. Against this background, the EDPS welcomes the inclusion of a
specific provision regarding data protection in the Proposal and the aim of ensuring a high level of
data protection.
With this Opinion, the EDPS provides a number of recommendations regarding the categories of
personal data to be processed by either national competent authorities or the Commission. In
particular, the EDPS recommends providing further clarifications regarding personal data
processed in the context of (1) the notification and registration of establishments; (2) the national
database of the identification and registration of dogs and cats (and their owners); (3) the online
system performing automated checks of the authenticity of the identification and registration
information; (4) the Union pet travellers’ database and (5) the list of approved breeding
establishments.
The EDPS also recommends explicitly designating the Commission as the controller responsible
for processing personal data through the online system performing automated checks of the
authenticity of the identification and registration of dogs and cats placed on the market.
Finally, the EDPS welcomes that the Proposal provides for maximum storage periods and explains
why these storage periods are considered necessary. However, he recommends re-evaluating
whether a shorter maximum storage period of personal data relating to…
065
Robert Bateman @robertjbateman.bsky.social · 18/11/2024
This beauty came out when I was 7 years old and I think I got Quake running on it at around 2fps.
Amiga 600
020
Robert Bateman @robertjbateman.bsky.social · 14/11/2024
That was fast! Just over two weeks after it promised a Delete Act enforcement sweep, the CPPA has settled with data brokers Growbots ($35,400) and UpLead ($34,400). The penalty for failing to register as a data broker is a truly piffling $200 per day—but the CPPA is clearly willing to enforce it.
Screenshot from the CCPA's website, headline: "CPPA’s Enforcement Division to Review Data Broker Compliance with the Delete Act. News: October 30, 2024"Screenshot from the CCPA's website, headline: "CPPA Settles With First Set of Data Brokers. News: November 14, 2024"
050
Robert Bateman @robertjbateman.bsky.social · 13/11/2024
The EDPB put this statement out on LinkedIn about Meta's new consent-or-pay implementation. It's non-committal but quite supportive and praises Ireland's cooperation. I've said it before, but I think the DPC's new commissioners are attempting a relationship reset with their fellow EU regulators.
2102
Robert Bateman @robertjbateman.bsky.social · 12/11/2024
Meta introducing unskippable ads as part of its "equivalent (free and less data-intensive) alternative", per the Bundeskartellamt CJEU case and subsequent EDPB Opinion. Unskippable ads are pretty normal. But is this "equivalent"? A hardline interpretation (as favoured by the EDPB) might say "no".
100
Robert Bateman @robertjbateman.bsky.social · 12/11/2024
Lina Khan's short but highly significant tenure as FTC Chair will likely end soon. Ted Cruz has urged her not to engage in any ambitious rulemaking before the end of her term. There have been many significant privacy developments under Khan. I imagine her successor will take a less robust approach.
041
Robert Bateman @robertjbateman.bsky.social · 30/05/2023
Yesterday, Elon Musk tweeted: "Incompetence, in the limit, is indistinguishable from sabotage" I agree. Incompetent people will often make a mistake and get in too deep. It can get so bad that it seems like they must be self-sabotaging. But in fact, they are just incompetent. Anyway read this
030