Afleveringen

  • In this bite-sized episode, Aakash Suri delivers a sharp warning about the growing role of artificial intelligence in cyber crime — and why the organisations most at risk are the ones still treating it as a future problem. From AI-generated phishing emails to voice cloning and deepfakes, Aakash breaks down how attackers are using the same tools businesses rely on to move faster, strike smarter and exploit the very trust signals we've built our security on.

    KEY TAKEAWAYS

    AI Has Changed the Threat Landscape Forever: Criminals can now generate convincing phishing emails, clone executive voices and create synthetic identities in seconds. The speed and scale of attacks has fundamentally shifted — and defenders are struggling to keep up.

    Trust Signals Are Breaking Down: A familiar voice on a call. A convincing video. An email from a known contact. All of these are becoming less reliable. When your people can't trust what they see or hear, your processes, approvals and controls all become easier to fool.

    Cyber Risk Is Privacy Risk: When attackers break in, they go straight for personal data — employee records, customer information and anything that can be sold, leaked or used for fraud. AI makes that faster. If you manage privacy, cyber can no longer be someone else's problem.

    Awareness Is Not the Same as Readiness: Many leaders know the risk is real, but budgets, talent, tools and response plans aren't moving fast enough. That gap between understanding and preparedness is exactly where attackers thrive.

    BEST MOMENTS

    "The people trying to break in are getting a serious productivity boost."

    "Attackers do not wait for your next board meeting. They do not wait for your next procurement cycle. They just keep going."

    "If attackers are using AI to move faster, your defence has to move faster too. Because in cyber, hesitation is expensive. And with AI, it can be catastrophic."

    TO CONNECT WITH YOUR HOST: https://www.linkedin.com/in/aakashsuri-thoughtleader/ https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/ https://www.instagram.com/letstalkprivacypodcast/ https://www.tiktok.com/@letstalkprivacypodcast

    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

  • A phishing simulation built around Cadbury chocolate failed instantly in the US, but would have caught almost anyone in the UK, and that single detail reveals something most cybersecurity programmes get wrong. Aakash Suri talks with Quadri Omoloju, an IT and cyber security manager at Thousand Heads and co-founder of AfriCyberCore and the Root Access Network, about why cyber attacks are fundamentally psychological rather than technical, and how privacy and security function as two sides of the same coin: one decides who gets the key, the other guards the door. They explore the Cybersecurity ABC framework of awareness, behaviour and culture, why regional context shapes every phishing simulation and awareness campaign, and where organisations should draw the line on feeding personal data into AI tools. Listeners will come away with a practical test for evaluating AI use against privacy risk, a clearer view of how to build genuine security culture rather than just compliance, and concrete examples of designing technology for the people who'll actually use it.

    KEY TAKEAWAYS

    Treat cyber attacks as psychological warfare rather than technical exploits. Quadri Omoloju frames phishing and social engineering as attacks on emotion and distraction, which means awareness training needs to target human behaviour just as much as systems and firewalls.

    Tailor security awareness campaigns to local culture instead of using generic templates. A Cadbury-themed phishing simulation was spotted instantly by staff in the US because the brand isn't part of their everyday life there, while a UK audience wouldn't fall for a fake HMRC email shaped for a different country.

    Build security culture in three deliberate stages: awareness, behaviour, then culture. Quadri describes how giving employees a personal "why" turned reporting phishing emails from something people hid into something shared openly on team channels, eventually leading staff to submit their own simulation ideas.

    Before feeding any data into an AI tool, ask whether you'd be comfortable explaining that use to the person the data belongs to. If the answer is no, that's the signal you've crossed the line on privacy, regardless of how useful the tool seems.

    Design security and privacy products by listening to the people who'll actually use them, not by importing borrowed assumptions. AfriCyberCore's approach to building for African markets, and the pivot to a board game after kids in workshops kept asking for "true gaming," both came from direct conversations with end users before anything was built.

    QUOTES

    "Cyber security, if in the most simplest language, is just protection of people digitally."

    "Our data is the house. Privacy is the key. And cybersecurity is the bodyguard.”

    "People don't know what they don't know."

    "Would you be comfortable explaining to your customer that this is what I'm doing with your data?"

    "Don't overthink. Just start with whatever you have and then just keep building."

    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. ⁠https://disruptivemedia.co.uk⁠/ 

  • Zijn er afleveringen die ontbreken?

    Klik hier om de feed te vernieuwen.

  • FIND EPISODE 2 HERE

    https://open.spotify.com/episode/5tqbtzFvQGeFqtkRb8aGBb?si=fe46ae4692c644f3 

    In this bite-sized episode, Aakash Suri unpacks a monumental moment in technology governance: Pope Leo XIV’s first encyclical, Magnifica Humanitas. Addressed to 1.4 billion Catholics, the encyclical delivers a stark warning against the unchecked power of private tech monopolies and the terrifying prospect of delegating lethal battlefield decisions to artificial intelligence. 

    KEY TAKEAWAYS

    AI is Not Neutral: The systems driving artificial intelligence are built by private organisations whose reach and influence often surpass that of national governments, rendering the idea that the "free market will sort it out" obsolete.

    A Call for Human-Centric Systems: Effective governance must focus on creating strong legal frameworks and independent oversight that protect users and ensure AI serves humanity without overriding human dignity.

    Algorithms Don't Belong on the Battlefield: Lethal decisions must never be delegated to machines. Delegating life-and-death choices to AI crosses a critical moral boundary and fuels a dangerous global arms race.

    BEST MOMENTS

     "Just because AI can help with targeting, surveillance, or battlefield decision-making, does not mean it should be trusted to make life and death calls."

    "AI governance cannot be just about what is possible. It has to be about what is acceptable."

    "Technology should serve humanity, not replace its judgment."

    TO CONNECT WITH YOUR HOST:

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/

    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk

  • FREE GIVEAWAY INFORMATION

    What is up for grabs?

    3 x 45-minute mentoring conversations over a 3-6-month period with Naureen for one person to win! 

    HOW TO:



    Listen to the whole episode, follow on Apple Podcasts.




    DM Aakash a screenshot proof following and listening https://www.linkedin.com/in/aakashsuri-thoughtleader/ 




    All entries must be submitted within the first 24 hours of the episode's release, and a winner will be picked at random




    In this episode, Aakash Suri sits down with privacy, data governance, and responsible AI specialist Naureen Hussain to unpack what true privacy leadership looks like inside modern digital delivery. Naureen shares firsthand insights from leading the pre-merger privacy integration of Virgin Media and O2 during the 2020 lockdown, detailing how the hardest challenges were human, building trust and alignment rather than purely technical. 

    KEY TAKEAWAYS

    Human-Centered Leadership in M&A: During major corporate integrations, the primary obstacle for privacy leaders isn't the technical alignment of systems, but managing cultural differences, easing team anxieties over job security, and establishing mutual trust. 

    Embed Privacy into Product Delivery: In fast-moving, agile environments that ship code every two weeks, traditional, linear Data Protection Impact Assessment checkpoints fail. Privacy outcomes must be deconstructed and natively designed directly into the product lifecycle.

    Lead with Humility across Functions: To bridge the gap between privacy professionals and digital product teams, privacy leaders must step into the developers' world with humility, learn their terminology, and collaborate to adapt tools to suit fast-paced workflows.

    Move Past "Tick-Box" AI Governance: Viewing AI governance strictly as a compliance checklist creates operational drag. Instead, leadership should adopt a harm-led approach, focusing resources on high-risk deployment models while empowering low-risk projects to move forward quickly.

    True Business Ownership of Risk: Governance only succeeds when business and product owners actively feel their accountability rather than treating the Data Protection Officer (DPO) as a rubber stamp. Risk must be owned by those deploying the technology, supported by the data protection team.

    BEST MOMENTS

    "The biggest challenge was actually gaining the trust and confidence of both teams and giving them a sense of direction... You have to be really clear on what your mission is."

    "What I see, and experience, and I can understand it's a natural tendency—is to go to the risk and ignore, or not give as much attention to, the benefits and the value of AI."

    "Let's not try to bolt on our current privacy screening and DPIA process because it doesn't work. Instead, let's deconstruct what outcomes our data protection processes are there to achieve and design them into the way these teams operate."

    "When you lead with humility... it opens so many doors. It's a 'help me to help you' kind of relationship."

    "The accountable owner needs to feel their accountability. So you need to make them feel uncomfortable... I'm not a fan of the language 'DPO signed it off,' because it doesn't leave the accountability of the decision with the person making it."

    TO CONNECT WITH NAUREEN

    linkedin.com/in/naureen-hussain 

    TO CONNECT WITH YOUR HOST:

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/

    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk

  • In this bite-sized episode, Aakash explores a massive shift in the tech landscape: OpenAI's transition from software to hardware. With rumors swirling about the accelerated development of an AI Phone in collaboration with Jony Ive's hardware venture, IO, Aakash breaks down what this means for the future of mobile devices. 

    KEY TAKEAWAYS

    OpenAI is entering the hardware market: The company is reportedly accelerating the development of its first AI phone, aiming for mass production in the first half of 2027 to strengthen its position ahead of a future IPO.

    A shift toward agentic AI: Future AI won't just respond to text prompts; it is being designed to act on users' behalf by looking, listening, and understanding real-world contexts naturally.

    Dual AI processors for seamless interaction: The anticipated device will reportedly use MediaTek as the sole chip supplier, featuring two distinct AI processors, one dedicated to vision tasks and the other for language tasks simultaneously.

    Deep privacy implications: Integrating AI at the hardware level requires massive amounts of sensitive context and data, raising critical questions about default data collection, local versus cloud storage, and what users can actually turn off.

    A strategic move beyond screens: OpenAI's acquisition of Jony Ive's hardware venture, IO, signals a broader vision to redefine how we interact with technology beyond traditional apps and interfaces.

    BEST MOMENTS

    "This is about a phone being built from the ground up for AI agents, not just AI add-ons. And that’s the big shift."

    "If this is real, then OpenAI isn't just trying to build a model, it's trying to build the device that puts the model directly in your hand, your pocket, and more importantly, your life."

    "They're about acting on your behalf, looking, listening, understanding, and maybe eventually doing tasks for you in a much more natural way."

    "If OpenAI can control both the software and the device, then it can shape the way people interact with AI much more deeply than if it was just an app."

    "The more a device sees, hears and understands, the more sensitive the data becomes."

    TO CONNECT WITH YOUR HOST:

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/

    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk

  • GIVEAWAY INFORMATION

    Below you will find Terasa’s Privacy Career Map 

    https://drive.google.com/file/d/1iIo8hAre5oiwe3WYa_Hn4jmffm0l946I/view?usp=sharing



    Terasa is also giving away a 45-minute mentoring session specifically for someone who is looking to make a shift in their privacy career journey. 

    HOW TO:



    Listen to the episode, follow on Apple Podcasts.




    DM Aakash a screenshot proof following and listening https://www.linkedin.com/in/aakashsuri-thoughtleader/ 




    All entries must be submitted within the first 24 hours of the episode's release. 




    In this episode, Aakash sits down with privacy powerhouse Teresa Toester Falk to uncover the messy reality of running a corporate privacy program. Ditching polished compliance platitudes, Teresa explains why certifications only tell half the story and how professionals can truly survive the trenches of privacy and AI governance. From embracing the controversial reality that privacy is a cost center to mastering the art of influencing without authority by mapping an organization's working network.

    KEY TAKEAWAYS

    Certifications Teach the Law, Not Operations: Certifications like the CIPP are excellent for testing foundational knowledge, but they are not designed to teach professionals how to evaluate, create, or execute privacy operations when facing intense corporate deadlines.

    Embrace the Cost Center Reality: Instead of exhausting resources trying to prove that privacy "adds value" to revenue, professionals should be proud to stand as a necessary compliance and overhead function that protects the business.

    Map the Real Working Network: To build influence without authority, privacy leaders must look past the official organizational chart and instead follow the data, track who fixes systems when they break, and identify the informal advisors who actually drive decisions.

    Adopt Agile AI Governance: Traditional governance frameworks take too long to implement in the fast-paced AI environment; professionals should focus on the top immediate risks, apply a "keep, learn, delegate, buy" strategy, and start executing right away.

    Prioritize Documented Execution over Perfect Coverage: When resources and budgets are tight, it is always better to handle a few high-priority compliance tasks with clear evidence and documentation than to poorly attempt full program coverage.

    BEST MOMENTS

    "The certification is, it's not easy to get. But compared to other disciplines, it's a fairly easy gate. You write that exam. If you pass it, you can call yourself a certified professional.”

    "I'm going to say something a little controversial, but I believe 80, 95% of the time. I'm sorry. Privacy doesn't add value. It is a... Overhead. And it's compliance hygiene. I wish that it did... Privacy can be a cost center. And it's okay. It, you can be proud of that..."

    "When we start our roles, we often ask, ' Show me the org chart... But the reality is, the executive level leaders often, you know, are a little bit out of touch with what is happening on the ground.”

    "I hate that we're presenting this as something wildly new, right? AI has been around, and machine learning has been around for 23 years.”

    "When you're under pressure, and you don't have enough people or hours to run a full program, you have to choose between doing everything poorly or doing the most important things with evidence. And I will always choose the second."

    TO CONNECT WITH TERASA 

    https://www.linkedin.com/in/ttfalk/?isSelfProfile=false 



    TO CONNECT WITH YOUR HOST:

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/

    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk

  • Stop treating privacy like a boring legal chore and start looking at the human beings behind the data.

    Chase F joins the show to strip away the corporate buzzwords and share what nearly two decades in law enforcement and cybersecurity actually teaches you about trust. We dive into the "spicy" reality that a thousand state-of-the-art controls won't save an organization if the culture is broken.

    From the cumulative risks of "free" AI accounts to the eerie way your phone tracks who you’re standing next to via Bluetooth, this conversation is a wake-up call for parents and professionals alike.

    Discover why privacy must be a design principle from day one rather than a bolted-on afterthought and hear a powerful take on why the best investment you can ever make is a leap of faith in your own vision.



    KEY TAKEAWAYS

    Privacy is a human-centred game rather than a technical one, meaning your everyday users are the true frontline defenders.

    Digital exposure is cumulative and slow, built through small daily permissions rather than just one-off major breaches.

    AI memory features mean these platforms may eventually know more about your history and habits than you can remember yourself.

    Being proactive means baking privacy and security into every operational conversation from the start to avoid being reactive to regulations.

    Taking the risk to invest in your own skills and vision is the most reliable way to create a meaningful impact in a rapidly shifting world.



    BEST MOMENTS

    "What we lose focus on is that these are all human centered games."

    "You’re really risking these digital systems becoming more about knowing you than you even know yourself."

    "Privacy falls when organizations treat it like paperwork instead of like a design principle."

    "AI does not forget. These systems will remember that about you and the total picture will be more complete than you even know."

    "You learn the most from fear and mistakes anyway and just go towards it."



    TO CONNECT WITH CHASE:

    https://www.linkedin.com/in/chaseprivacy/



    TO CONNECT WITH YOUR HOST:

    ⁠https://www.linkedin.com/in/aakashsuri-thoughtleader/⁠ 



    ⁠https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/⁠



    ⁠Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos⁠

    ⁠https://www.tiktok.com/@letstalkprivacypodcast⁠



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. ⁠https://disruptivemedia.co.uk⁠/  

  • In this episode, Aakash sits down with Feba Rachel, a Senior Privacy Counsel working within the UAE Government, to explore the rapidly evolving landscape of data protection in the GCC. Feba unpacks the stark differences between managing privacy in global corporations versus the public sector, emphasizing how government privacy initiatives must prioritize public trust over mere commercial risk mitigation. 

    KEY TAKEAWAYS

    Public Trust Over Compliance: In the government sector, privacy is a public duty centered around maintaining citizens' trust, unlike the commercial sector, which often focuses on checking boxes and risk mitigation.

    Navigating Multi-Framework Landscapes: The UAE presents a highly complex regulatory environment, requiring organizations to carefully figure out whether they fall under the federal UAE PDPL, free zone laws like DIFC or ADGM, or other specific sectoral laws.

    The Over-Reliance on Consent: While international frameworks like the GDPR allow for "legitimate interest" as a flexible legal basis for data processing, the UAE's federal PDPL leans heavily on explicit consent, which can create significant operational challenges.

    AI Adoption is Outpacing Governance: Organizations are rushing to adopt AI tools at a massive speed, often leaving privacy teams out of the loop until after procurement, which creates severe risks regarding training data rights and automated decision-making.

    Biometrics Require Complex Data Mapping: Implementing massive initiatives like Dubai's contactless hotel check-in demands rigorous data mapping from the outset to establish clear controller and processor roles among the government, tech vendors, and hotels.

    BEST MOMENTS

    "In government, it becomes what is the right thing to do with the trust people have placed in us."

    "When someone cannot walk away, you carry a greater responsibility to be transparent and to be careful with their data. You don't get to hide behind a terms and conditions page."

    "People come into the UAE expecting one privacy law. What they find is more like three rule books sitting next to each other, and your job is figuring out which one applies to you."

    "A condition is not valid consent, right?"

    "The same processing activity can be completely lawful under one framework and then require a completely different legal basis under another."

    TO CONNECT WITH FEBA

    https://www.linkedin.com/in/feba-rachel-914b7889/?isSelfProfile=false 

    TO CONNECT WITH YOUR HOST:

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 



    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/



    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/  

  • Imagine a tool so capable at finding software vulnerabilities that its own creators are hesitant to release it. We’re looking at Mythos, the latest frontier model from Anthropic that has the tech world divided between genuine fear and intense curiosity. While the "hacker's dream" headlines make for great clicks, the reality for privacy and security professionals is much more complex.

    This briefing cuts through the noise to explore why a model's ability to chain exploits and reason through code changes the balance of power in cyber security. We move past the panic to discuss the essential governance questions: Who gets access? What happens when a model does its job too well?. It’s time to stop viewing AI risk as theoretical and start preparing for a future where the battlefield is human plus AI versus human plus AI.

    Key Takeaways

    Capabilities over Hype: Mythos represents a shift toward advanced reasoning and serious cyber security capabilities rather than just simple text generation.

    The Access Dilemma: Anthropik has restricted access to Mythos due to concerns that its power could be misused in a security context.

    Privacy and Cyber are Linked: Any model that simplifies finding vulnerabilities creates a direct risk of data breaches and privacy loss.

    Avoid the Binary Reaction: The danger lies in either overreacting with panic or underreacting by assuming developers have handled all safeguards.

    New Governance Standards: Businesses must implement strict access controls, red teaming, and human oversight to manage high-capability models.

    Quotes

    "The big story here is that Anthropik's latest model appears to be extremely capable at cyber security style tasks."

    "We are no longer just asking, can the model do the job? We are now asking, can it do the job too well?"

    "If a model helps attackers find vulnerabilities faster, that can lead to breaches, data loss, and a whole chain of privacy consequences."

    "The future of cyber is not just human versus human. It's human plus AI versus human plus AI."

    "If a model is powerful enough to be called a hacker's dream, then it's powerful enough to need serious guardrails."



    TO CONNECT WITH YOUR HOST:

    ⁠https://www.linkedin.com/in/aakashsuri-thoughtleader/⁠ 



    ⁠https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/⁠



    ⁠Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos⁠

    ⁠https://www.tiktok.com/@letstalkprivacypodcast⁠



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. ⁠https://disruptivemedia.co.uk⁠/  

  • In this episode, Aakash sits down with Marissa Valerio, a senior data privacy lawyer with extensive experience across UK, EU, and global privacy law. Together, they dive into the realities of translating complex legal requirements into actionable strategies that tech and business teams can actually use. Marissa shares her insights on moving privacy away from a dreaded "tick-box compliance" exercise and repositioning it as a strategic business enabler. 

    KEY TAKEAWAYS

    Speak the Business's Language: To get buy-in from senior leadership, privacy professionals must translate complex legal concepts into clear, risk-based language that aligns with what the stakeholders are actually trying to achieve.

    Privacy is About Human Rights: Effective data protection goes beyond strict academic compliance; it fundamentally requires protecting the rights, freedoms, and psychological well-being of the individuals behind the data.

    Reposition Privacy as an Enabler: The privacy function must shed its reputation as the "Department of No." By adopting a pragmatic, risk-based approach, privacy teams can help businesses innovate safely and responsibly.

    AI Requires Case-by-Case Governance: There is no blanket approach to AI compliance. Organizations must establish clear internal policies to manage how the business uses data within AI tools, and just as importantly, how those AI tools use the business's data.

    Embrace the Unknown in Your Career: Taking calculated risks like moving across the world to restart a career can be daunting, but stepping out of your comfort zone is often the catalyst for the greatest professional and personal growth.

    BEST MOMENTS

    "The way we speak... to a DPO about privacy is not the same way you would speak to a systems engineer or to a contract manager." 

    "It's important to remember that we are talking about human rights and about human beings and their rights and their freedoms... you can't be too rigid or too academical about it either." 

    "We should move away from that and just think about privacy as an enabler. I like to use that phrase when I deliver training." 

    "You can't have a blanket approach for deploying AI. All AI initiatives should be looked at on a case-by-case basis." 

    "The human has to be in the loop in the end. You can't just take the human out." 

    TO CONNECT WITH MARISSA

    linkedin.com/in/marissa-valerio-llm-1909b5119

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 

    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/posts/?feedView=all 

    https://www.tiktok.com/@letstalkprivacypodcast



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/  

  • In this bite-sized episode, Aakash tackles the growing and often invisible threat of Shadow AI, the unauthorized use of artificial intelligence tools within an organization. Aakash explains how AI quietly creeps into daily operations, from developers plugging in unapproved APIs to employees carelessly pasting sensitive data into generative AI tools. 

    KEY TAKEAWAYS

    Assume it's already there: Don't wait for a formal, company-wide AI project launch to start caring about governance. Shadow AI is very likely already operating in the background of your day-to-day business operations.

    Go beyond self-reporting: You cannot rely entirely on employees to disclose their AI use. Organizations need true visibility, which means checking vendor contracts, procurement records, and software usage logs to see what's actually running.

    Audit existing, approved software: Shadow AI often sneaks in through the back door when trusted SaaS platforms, browser extensions, and productivity tools quietly roll out new generative AI features.

    BEST MOMENTS

    "AI is already there, quietly running in the background. And that's exactly what we're talking about in today's bite-size episode: Shadow AI."

    "If people are pasting customer data, employee data, confidential documents, or internal plans into unapproved AI tools, you've got a serious risk on your hands."

    "A lot of organizations still think Shadow AI only exists if someone formally launches a big AI project. But that's not how it usually shows up."

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 



    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/posts/?feedView=all 



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/  

  • FREE GIVEAWAY

    Following is the link for the Podcast listeners: https://bit.ly/4vaXnhw.

    Here are the details about the books:

    In this episode, Aakash sits down with Anuuj Medirattaa, Founder and CTO of Ace Data Devices, to unpack the practical realities of data privacy and protection. They discuss the critical shift in mindset required to view privacy not as a strict legal hurdle, but as a genuine business optimization opportunity. Anuuj brings his extensive background in cloud backup, disaster recovery, and ransomware readiness to the conversation, explaining how organizations must prioritize understanding their data inventory before getting bogged down in policy paperwork. 

    KEY TAKEAWAYS

    Privacy is Business Optimization: Rather than treating data privacy purely as a terrifying legal or compliance issue, organizations should view it as a structural behavioral change that optimizes how personal data is handled and secured.

    Start with a Data Baseline: Before rushing to create complex privacy policies and notices, businesses must first audit their environment to understand exactly what personal data they possess, where it is stored, and who has access to it.

    Education Must Be Relatable: To successfully implement privacy principles across an entire company, training content needs to avoid dense legal jargon and be tailored specifically to the daily tasks of the audience, whether they are in sales, human resources, or IT.

    Backup and Retention Go Hand-in-Hand: While disaster recovery and robust backups are essential for ransomware protection, organizations must balance this with strict data retention policies to ensure they are safely purging old data that is no longer needed.

    Embrace Risk to Keep Growing: Deciding that you know everything about a topic is the exact moment you stop growing; continuous learning, taking calculated risks, and adapting to new regulations are vital for navigating the evolving data privacy landscape.

    BEST MOMENTS

    "I actually feel privacy is a business optimization issue, not a legal issue. In India, when we talk of a law, we get scared that we might have to file returns, we might have to deposit some taxes... No, privacy is not that."

    "Start step-by-step from the rock bottom and you will quickly achieve the top rather than getting scared and looking at the top and making documents."

    "The hardest audience is the people who believe they know everything. I don't know everything. I am still learning whatever is coming."

    "The moment we say 'I am perfect in this', it means I have decided that I don't want to grow."

    "Can I just run away by saying DPDP applies only to digital data? Yes, that way it is fine, but that misuse, if it is known that that happened with my team member, then my reputation, my team's reputation, and my organization's reputation... they are all at stake."

    TO CONNECT WITH ANUUJ

    www.linkedin.com/in/anuujmedirattaa



    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 



    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/posts/?feedView=all 



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/  

    Data Privacy, SimplifiedA practical introduction to data privacy designed for real-world understanding.This book focuses on simplifying core privacy concepts and explaining how they apply inside organisations — beyond legal definitions and theory.It is ideal for professionals, founders, and teams who want to understand privacy in a clear, structured, and usable way, and begin applying it in day-to-day decisions.Data Privacy Simplified: DPDP in PracticeA practical interpretation of India’s Digital Personal Data Protection framework, focused on how organisations can apply it in real scenarios.Instead of legal analysis, this book breaks down key concepts like consent, data handling, retention, and governance into an actionable understanding.While grounded in the Indian context, the insights are relevant for organisations globally looking to align privacy with everyday operations.

  • In this episode, Aakash dives into the evolving landscape of artificial intelligence, focusing on the shift from simple chatbots to sophisticated "working partners." The spotlight is on Claude and Co-work by Anthropic, exploring how these tools assist with complex tasks like drafting policies, analyzing data, and summarizing reports. 

    KEY TAKEAWAYS

    The Evolution of AI Utility: AI is transitioning from a "chat-based" tool used for short tasks to a collaborative assistant capable of supporting long-term, practical workflows.

    The Data Privacy Paradox: As AI becomes more integrated into daily business tasks, there is an increased risk of users inputting sensitive, confidential, or personal data without proper safeguards.

    The Necessity of Governance: To prevent "shadow use," organizations must establish clear rules, human review processes, and staff training rather than letting employees create their own unofficial workflows.

    BEST MOMENTS

    "Think of Claude as the prompt-based tool... on the other hand, think of Co-work as your actual assistant."

    "The danger is simple: people love tools that save time, so they start using them more and more... and then before long, they’re pasting in customer data, employee data, or internal strategy."

    "If your organization doesn’t have clear rules, people will make their own, and that is where the trouble begins."

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 

    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast

    linkedin.com/company/as-privacy-ai-solutions-ltd/

    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/  

  • FREE GIVEAWAY

    Luke is giving away a full day of in-person training using the “What would you do game“. A 6-hour session will include breaks, and lunch will be very interactive in the afternoon. Aimed predominantly at senior management, but happy to undertake a group of 15 persons max. 

    HOW TO ENTER (ONLY 1 WINNER) ENTRIES CLOSE 3 DAYS AFTER THE RELEASE OF THE EPISODE!

    CONNECT WITH AAKASH SURI ON LINKEDIN AND DIRECT MESSAGE HIM OUTLINING WHY YOUR ORGANISATION SHOULD WIN THIS TRAINING? ALL ENTRIES WILL BE PUT IN A RANDOMISER TO DRAW OUT A WINNER AND RECIPIENT OF THIS TRAINING FOR THEIR ORGANISATION. ALSO FOLLOW THE INSTAGRAM AND TIK TOK PAGES OF THE LETS TALK PRIVACY PODCAST - LINKS BELOW:

    Aakash Suri (@letstalkprivacypodcast) • Instagram photos and videos

    https://www.tiktok.com/@letstalkprivacypodcast

    To Connect With Luke

    For data intelligence and protection

    LinkedIn: linkedin.com/in/luke-beckley

    Email: [email protected]

    For Adventure challenges to raise money for charities or undertake Team building and Leadership training

    Email: [email protected]

    Website: www.unchartedsummits.world 

    In this episode, Aakash sits down with data governance expert Luke Beckley. With nearly three decades of experience, Luke dismantles the dangerous misconception that cybersecurity alone equals data protection. Together, they explore the pitfalls of tick-box compliance, the critical importance of continuous, human-led data training, and how mid-sized organizations can safely integrate AI tools without exposing sensitive information. 

    KEY TAKEAWAYS 

    Cybersecurity does not equal data protection: Building a digital fortress is useless if you don't understand what data you are storing, why you collected it, and whether you actually need to keep it.

    Training must go beyond the annual PowerPoint: Generic, once-a-year compliance presentations are ineffective. Organizations must implement consistent, targeted, and engaging human-led training to cultivate a genuine culture of privacy.

    "Tick-box" compliance creates false security: Merely having privacy policies on paper or purchasing security software is insufficient if those policies are not actively understood and practiced by the employees handling the data daily.

    Assess AI risks before deployment: With the rapid adoption of new AI tools, organizations must conduct Data Protection Impact Assessments to fully understand how data is being scraped, stored, and utilized by these platforms.

    Good governance builds business trust: Treating data protection as a core ethical responsibility rather than a regulatory burden builds consumer trust, ultimately turning a compliance necessity into a driver for business growth.

    BEST MOMENTS

    "It's almost like we'll just pour more money at security to protect the data and not worry about actually mitigating the risk in the first place."

    "If you lead with the human, the people in your organization, you will make better decisions around how you process that data, and your customers will see that."

    "We are in a desperate kind of, almost like a race to the bottom to see who can get AI in as quickly as possible... but we've not done the prep."

    "You've got to treat data protection as a driver for more business, as a driver for customer trust, as a driver for a more ethical-based organization."

    "When data is clean and trusted, people stop arguing about the numbers and start making better decisions."

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/  

  • In this bite-sized AI episode, Aakash Suri dives into the trendy new world of vibe coding. Vibe coding allows anyone to build software and applications simply by describing their ideas to an AI in plain English. While tools like Lovable, Replit, and Cursor are democratizing app development and drastically increasing speed, they also introduce significant privacy and security risks if left unchecked.

    KEY TAKEAWAYS

    Vibe coding lowers the barrier to entry: Anyone can now build software by using plain English prompts to tell an AI what they need. This empowers non-technical staff to create tools without waiting weeks for developers.

    Establish strict guardrails: Organizations need clear rules regarding who is authorized to use Vibe coding tools. This prevents the creation of unmonitored shadow IT systems right under your nose.

    Privacy must be proactive, not reactive: Incorporate privacy controls early in the vibe coding process. Do not wait until the end or after launch when the app has already grown legs and become business-critical.

    BEST MOMENTS

    "In the simplest possible terms, it means using AI to help you build software by describing what you want in plain English."

    "Instead of thinking, right, I need to build a database, connect an API, create a front end, fix the errors, you just simply say, build me a simple app to track my podcast guests, store notes, and remind me how to follow up. And the AI gets to work."

    "If people start building tools with real customer data, employee data, or sensitive business information without proper controls, then, in my opinion, you've got a massive issue."

    "You may not even know someone has built a shadow IT system right under your nose."

    "Bring privacy in early. Not at the end, not after launch, but early. Before the thing grows legs and becomes business-critical."

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk

  • FREE GIVEAWAY 

    Jennifer is offering a 1-hour extended discussion and review of your organisation's compliance with ISO standards.

    This could include discussion on:



    Is ISO certification worth it for you?




    Whether to get certified?




    How should we prepare for stage 1 or stage 2 audits before certification?




    How to improve your internal audits?




    What to do if your external audits keep finding non-conformances. 




    How to improve your ISO manual.




    ALSO, Free review of your certificate: 

    Please send Jennifer a copy of your certificate, and she will review it and let you know whether it covers what you are expecting.  If you are sending a copy of a third-party certificate, typically a supplier's, please ensure you can share it. We may need additional information, but we will request it once we have reviewed the certificate.  Certificate reviews are limited to three certificates per company requesting them.



    Please contact Jennifer here, linkedin.com/in/jennifer-hirst-44b3b5b7  

    In this episode, Aakash Suri sits down with Jennifer Hirst, a seasoned compliance and ISO consultant, to demystify the ISO 27001 certification. Moving beyond the idea that ISO is just an IT security badge, Jennifer explains how it serves as a structured framework for organizations of all sizes to implement best practices in data protection. 

    KEY TAKEAWAYS

    ISO 27001 is a Framework, Not Just a Label: It is a structured way of working that focuses on the confidentiality, integrity, and availability of data, regardless of company size.

    Regulatory Alignment is Embedded: ISO 27001 is not separate from laws like GDPR; it requires organizations to be aware of and integrate their legal and regulatory obligations into their security controls.

    The "Human Firewall" is Critical: Technical tools are insufficient without staff awareness. Training employees to recognize simple risks—like leaving a workstation unlocked or working on public transport—is vital to preventing breaches.

    Scope Matters in Certification: A major red flag is a certificate with a limited "scope" that excludes the specific departments or processes where sensitive data is actually handled.

    Continuous Improvement is Mandatory: Certification is not a one-time event. It requires regular internal audits, annual external assessments, and a full recertification every three years to adapt to new risks.

    BEST MOMENTS 

    "It's not a badge, it's a way of working. It's making sure that IT security... is there high on the agenda for that company."

    "While we all live in a very technical world... we don't. You just click on a link because it all looks so perfect."

    "A certificate on the wall means very little if people are still bypassing processes, hoarding data, or ignoring basic hygiene."

    "Top management needs to have the buy-in... if top management hasn't got the buy-in, you're never going to sustain it."

    "Just putting one question into AI uses the amount of water that a town might use in a day... It's a staggering amount."

    TO CONNECT WITH JENNIFER

    linkedin.com/in/jennifer-hirst-44b3b5b7 

    https://qualityexcellence.co.uk

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.

    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk

  • This episode of Let’s Talk AI features Aakash Suri diving into the Black Mirror reality of OpenAI’s latest headlines. The discussion centers on Sam Altman’s radical succession plan to eventually hand the company over to an AI model, his claims that OpenAI has "basically built AGI," and the resulting tension with Microsoft’s Satya Nadella. 

    KEY TAKEAWAYS

    The AI Succession Plan: Sam Altman revealed a plan to eventually replace himself with an AI model, arguing that if OpenAI’s mission is to build AGI, that system should eventually be capable of running the company.

    The AGI Claim & Microsoft Friction: OpenAI reportedly claims to have "basically built AGI," a statement that prompted a restrained pushback from Microsoft CEO Satya Nadella, who described the two companies as "frenemies" with different incentives.

    Governance & Accountability Gaps: Replacing a human CEO with an AI model raises massive legal questions: who is responsible when an AI makes a harmful decision, and can a board truly "override" a system that is also the company's primary tool?.

    BEST MOMENTS

    "If your whole mission is to build AGI... then at some point that system should be able to run a company."

    "Satya Nadella... described the relationship between Microsoft and OpenAI as 'frenemies' but with different incentives, timelines, and levels of hype tolerance."

    "How do you audit the decision-making of a system that is both the tool and the boss?"

    TO CONNECT WITH YOUR HOST

    ⁠https://www.linkedin.com/in/aakashsuri-thoughtleader/⁠ 

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/

    HOST BIOAakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. ⁠https://disruptivemedia.co.uk⁠/ 

  • FREE GIVEAWAY 

    To have access to the 2 FREE books, we have included a link here - https://drive.google.com/drive/folders/1IR6FamA9-XqC5txHBvi5MwkArAPVQBU5 

    ALSO, contact Chetandeep on LinkedIn for a FREE mentorship call HERE - linkedin.com/in/achetansbatra  

    This episode of Let’s Talk Privacy features a deep dive into the evolving landscape of data protection and artificial intelligence in India. Aakash Suri welcomes Chetandeep Batra, a senior security and privacy consultant at EY and IAPP New Delhi Chapter Chair, to discuss the practical challenges organizations face with the Digital Personal Data Protection (DPDP) Act.

    KEY TAKEAWAYS 

    The Execution Gap: The biggest challenge for Indian organizations isn't the text of the DPDP Act, but the disconnect between boardroom policies and real-life data handling practices.

    DPDP vs. GDPR: Unlike the GDPR, India's DPDP Act applies strictly to digital personal data, excluding paper-based records, which requires a specific digital-first maturity.

    Collaborative Governance: Effective privacy management requires an "amalgamation" of legal, security, and management perspectives rather than any single department dominating the conversation.

    AI’s Silent Integration: Regulators often underestimate how "invisibly" GenAI is being embedded into everyday enterprise tools, making auditing and tracing more complex.

    Privacy by Design in AI: Beyond breach prevention, the future of AI compliance lies in "Privacy-Enhanced Technologies" and ensuring data is used only for its original documented purpose.

    BEST MOMENTS

    "Privacy is not implemented in isolation; it is negotiated."

    "The biggest misunderstanding I see... is they underestimate the challenge of security, with terming with privacy all in all. It is not about documentation; it is not about certifications."

    "I look at it as GDPR is the parent and the other legislations are like kids... they still have to follow what the parents are saying, but be bespoke to the country." 

    "Real risk lies in the silent usage of AI... it doesn't just process data; it is how it is interpreted, it creates abstractions, it creates embeddings."

    "People like to be heard here... when the voice is heard, 50% of the things just go very smoothly."

    TO CONNECT WITH CHATENDEEP

    linkedin.com/in/achetansbatra 

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 



    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.





    This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/  

  • In this episode, Aakash Suri moves beyond science fiction to explore the sobering reality of AI on the modern battlefield. Using the current conflict in Iran as a case study, the discussion breaks down how AI is being used to scan satellite imagery, prioritize targets, and assist in cyber operations. 

    KEY TAKEAWAYS

    Active Deployment: AI is no longer theoretical; it is actively used in the Iran war for target identification, threat ranking, and cyber warfare.

    The "Rubber-Stamp" Risk: High-pressure environments lead commanders to reflexively approve AI recommendations, blurring the lines of human accountability.

    Infrastructure as a Target: Tech companies’ data centers and cloud campuses are now considered military assets and potential targets due to their role in running war-fighting AI.

    BEST MOMENTS

    "AI isn’t just in the lab anymore; it’s in the war room."

    "On paper, humans are in the loop. In reality, they’re just approving what the machine has already decided."

    "We speed up the pipeline from a possible target to an explosion on the ground faster than our ethics, our laws, and our investigations can keep up."

    TO CONNECT WITH YOUR HOST

    ⁠https://www.linkedin.com/in/aakashsuri-thoughtleader/⁠ 

    https://www.linkedin.com/company/as-privacy-ai-solutions-ltd/

    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.



    This Podcast has been brought to you by Disruptive Media. ⁠https://disruptivemedia.co.uk⁠/ 

  • FREE GIVEAWAY INFORMATION: Nav has provided a discount for all Let’s Talk Privacy listeners, 50% off the knowledge Blockchain course by using the code: AAKASH50

    In this episode, Aakash is joined by risk expert Nav Sandhu to explore the intersection of blockchain technology and data protection. Nav breaks down complex concepts like Zero-Knowledge Proofs and pseudonymization, illustrating how blockchain can protect personal identity while still proving authenticity. Aakash and Nav also discuss the evolving role of the AI Officer and why boards must move beyond to embrace privacy as a fundamental trust mechanism and business enabler.

    KEY TAKEAWAYS

    Blockchain Terminology vs. Risk Frameworks: Current risk vocabularies often fail to capture the nuances of blockchain, requiring regulators to build new frameworks that define elements like wallet addresses as Personally Identifiable Information.

    The Power of Immutability: Because blockchain data is permanent and unchangeable, it offers a highly reliable "data lineage" for verifying income, transaction history, and consent.

    Zero-Knowledge Proofs (ZKP): This technology allows a user to prove they possess specific knowledge without actually revealing the sensitive information itself.

    Granular Consent: Unlike traditional "on/off" consent switches, blockchain allows individuals to fine-tune what data is visible to third parties, such as allowing a bank to see transaction categories without seeing specific retailers or locations.

    Privacy as a Revenue Driver: When organizations demonstrate a robust commitment to looking after personal information, privacy evolves from a compliance hurdle into a competitive advantage that builds customer trust. 

    BEST MOMENTS

    "If you risk nothing, you risk everything."

    "Blockchain is the internet; industries will be built on top of it."

    "Zero-knowledge proof is where a person can prove knowledge or authenticity without revealing that personal information."

    "Privacy is not seen as a blocker; it's seen as a revenue driver and as a trust mechanism that will win you more customers."

    "We need the right people in the right room; you cannot expect a Data Protection Officer to try and understand everything happening in AI on top of what they're already doing."

    TO CONNECT WITH NAV

    https://www.linkedin.com/in/nav-s-6194468b 

    TO CONNECT WITH YOUR HOST

    https://www.linkedin.com/in/aakashsuri-thoughtleader/ 

    HOST BIO

    Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/