Hello. I’m Sue Denim, and I’ve spent the month looking at what organisations have been doing with personal data. Some used it to determine people’s livelihoods. Some considered using it to determine prices. Some fed it to artificial intelligence. Others stored it in buildings where the principal records-management system appeared to be “put it over there and hope the mould signs the retention policy”.
It has been a varied month.
The important lesson is that privacy has escaped the compliance department. It is now sitting in recruitment, pricing, marketing, artificial intelligence, workplace management, health systems and that account you created one evening because you wanted to watch somebody play a video game.
Here is what caught my eye, and what it could mean for organisations, employees, customers and ordinary people trying to get through the day without becoming a training dataset.
Personalised pricing is more intimate. Rather than changing the price for everyone according to demand, a business may use information about a particular person, such as browsing behaviour or purchase history, to decide what price that person sees.
The FTC has not proposed banning every form of personalised pricing. Its concern is that businesses could mislead consumers if a price appears to be standard while personal data is quietly helping to determine it. [The FTC’s consultation explains the proposed approach](https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-seeks-comment-enforcement-policy-statement-regarding-personalized-pricing).
Before introducing a personalised offer or price, an organisation should be able to explain:
- Which personal data influences the decision
- Where that information came from
- Whether the customer reasonably expects this use
- Whether different people can receive different prices
- What the customer is told
- Whether the result could unfairly exploit urgency or vulnerability
- How somebody can question or challenge the outcome
Calling the output an “individual value opportunity” will not make those questions disappear. It may, however, earn somebody a very exciting meeting with Legal.
For individuals, comparing prices while signed out or using a private browsing session may reveal differences, although it cannot establish why a price changed. Location, availability, promotions and timing may also influence the result.
According to the regulator, decisions concerning suspected fraud and low ratings were taken without human intervention. Losing access to the platform meant affected drivers could no longer accept rides or earn income. [The CNIL’s account of the cross-border decision explains the findings](https://www.cnil.fr/en/automated-decisions-uber-fined-nearly-eur-825-million).
This matters well beyond the gig economy.
Organisations increasingly use automated tools to shortlist applicants, score performance, detect fraud, prioritise investigations, allocate work and identify supposedly unusual behaviour. There is a natural corporate temptation to describe such tools as “decision support”. Sometimes that is accurate. Sometimes the human contribution consists of staring briefly at a score before clicking the button the system has already selected.
- Understand the factors that influenced the decision
- Have access to relevant contextual information
- Be able to identify inaccurate or incomplete data
- Possess genuine authority to change the result
- Record why the decision was upheld or overturned
- Respond within a useful timeframe
An appeals mailbox monitored every second leap year does not constitute human oversight. Employees should also know when monitoring, scoring or automated decision-making affects them. If a system influences pay, shifts, access, promotion, discipline or continued employment, it deserves considerably more governance than the office coffee-ordering spreadsheet.
The regulator said the setting was enabled by default and advised users who did not want their material used in this way to switch it off. It highlighted that livestreams can include faces, voices, names, conversations and views inside people’s homes. [The Dutch authority’s notice provides details and opt-out instructions](https://autoriteitpersoonsgegevens.nl/actueel/ap-adviseert-twitch-gebruikers-zet-instellingen-uit-voor-delen-van-data-met-amazon-ai).
This is a consumer story with a very obvious workplace sequel. Employees are joining AI assistants, meeting tools, transcription services, design platforms and coding products with both personal and company accounts. The settings governing model training, product improvement and data retention can differ by service, subscription and account type.
A product being approved for corporate use does not necessarily mean every edition of it is approved. The enterprise version may have contractual controls that the free version does not.
- Use prompts, uploads or outputs for model training
- Enable training or product-improvement settings by default
- Treat free, individual and enterprise accounts differently
- Allow administrators to enforce settings centrally
- Retain deleted conversations or uploaded files
- Receive personal information about employees, clients or suppliers
- Provide an appropriate way to honour access, deletion and objection requests
Individuals should periodically inspect the privacy settings of creative, social and AI services. Pay particular attention after a notice announcing “exciting improvements”, a phrase that has occasionally meant exciting improvements for the company’s dataset.
The regulator examined 265 requests made during 2024. More than three quarters had not been handled, or had not been handled satisfactorily. It also found failures to tell people what had happened after they exercised their rights. [The CNIL decision summarises the findings](https://www.cnil.fr/fr/sanction-non-respect-droits-personnes-extia).
Recruitment systems are enthusiastic collectors. A person uploads a CV for one vacancy and may quietly achieve immortality across an applicant-tracking platform, a shared drive, an interviewer’s inbox, a recruiter’s spreadsheet and a folder called `Potential People FINAL v4`.
Deleting the main applicant profile may therefore be only the opening act.
- Applicant-tracking systems
- Recruitment agencies and other processors
- Interview notes and assessment tools
- Email and collaboration platforms
- Talent pools
- Background-check providers
- Recorded interviews
- Artificial-intelligence screening services
- Locally maintained spreadsheets and exports
Automated deletion can help, but it does not remove the need to respond to the person. “The system probably dealt with it” is not a status update. For individuals, a deletion request should identify the account, vacancy or approximate application period. Keep a copy and note when it was sent. Depending on the applicable law and the organisation’s obligations, some information may need to be retained—but the organisation should explain what it is keeping and why.
The investigation followed unauthorised access to records in disused former hospital buildings. During inspections, the regulator found documents affected by mould, water, animal droppings and general deterioration. Records were also found in disused bathrooms and cubicles, and in a shipping container inside a turf shed.
The DPC ordered a complete audit of storage facilities, better tracking of records, safe destruction where retention was no longer necessary, and removal of files from unsuitable locations. [The DPC decision describes the findings and corrective measures](https://dataprotection.ie/en/news-media/latest-news/data-protection-commission-announces-final-decision-following-inquiry-health-service-executive-hse).
This is the monthly reminder that personal data does not stop being personal because it has corners and smells faintly of filing cabinet. Many organisations have invested heavily in cloud security while retaining paper archives, backup media, retired laptops, old access cards and boxes inherited through mergers.
- Off-site and third-party storage
- Closed offices and former premises
- Paper files awaiting scanning
- Archived employee and customer records
- Retired equipment and removable media
- Boxes acquired through mergers or restructuring
- Departmental cupboards that apparently pre-date electricity
Records must remain confidential, available and usable for as long as they are legitimately required. Retention is not achieved by keeping something indefinitely in conditions that make it inaccessible or unsafe.
At home, the same principle applies on a smaller scale. Old payslips, medical correspondence, photocopied identity documents and statements should not live forever in a drawer simply because the shredder is “a weekend job”.
We both know which weekend you mean. It does not exist.
The incident affected 524,867 patients and 202,246 people listed as trusted third parties. Although patients were informed, the trusted contacts were not notified directly. [The CNIL decision explains the security and notification failures](https://www.cnil.fr/en/sanction-fine-hopital-prive-loire).
That last point deserves attention. Organisations often design incident searches around their primary population: customers, employees, patients or account holders. Personal data about other people can be tucked inside those records:
- Emergency contacts
- Dependants and beneficiaries
- Guarantors
- Referees
- Witnesses
- Family members
- Authorised representatives
- Client contacts
- People mentioned in notes or correspondence
This also matters when buying software. A supplier may promise that one compromised user cannot access unrelated records, but that claim should be tested through role design, access reviews, monitoring and realistic security exercises.
“Least privilege” should be an access-control principle, not the number of people invited to read the audit report.
Include prompts, meeting transcripts, uploaded documents, customer messages, source code, screenshots and generated outputs.
Look across recruitment, fraud, workforce management, customer eligibility, pricing and account suspension.
Test the journey across the primary system, exports, suppliers and local copies. Do not accept “there is a button” as proof.
Include archives, warehouses, closed premises, cupboards, shared drives and historic platforms.
Check dependants, emergency contacts, representatives and people mentioned within free-text records.
If so, document the inputs, explain the practice properly and test the outcomes.
- Review training and product-improvement settings in AI and creative services
- Use unique passwords and multifactor authentication
- Close accounts you no longer use
- Check which applications can access your email, files and social accounts
- Keep copies of important privacy or deletion requests
- Compare significant prices without assuming every difference is personalised
- Securely destroy documents you no longer need
- Avoid putting confidential work information into personal AI accounts
You do not need to spend Sunday reading every privacy notice ever written. Nobody should lose a Sunday like that—not even the person who wrote them.
Start with services holding information that could affect your health, money, employment, identity or reputation.
They do reveal a consistent practical problem: organisations frequently lose sight of personal data once it moves outside the process for which governance was originally designed.
A candidate becomes a record in several recruitment tools. A driver becomes a score. A trusted contact becomes a field inside somebody else’s medical file. A livestream becomes training material. A customer becomes a predicted willingness to pay. A paper record becomes part of the building.
Good privacy management keeps the person visible throughout that journey.
Until next month, please remember: if your data strategy requires the sentence “technically, they agreed”, Sue has follow-up questions.
It has been a varied month.
The important lesson is that privacy has escaped the compliance department. It is now sitting in recruitment, pricing, marketing, artificial intelligence, workplace management, health systems and that account you created one evening because you wanted to watch somebody play a video game.
Here is what caught my eye, and what it could mean for organisations, employees, customers and ordinary people trying to get through the day without becoming a training dataset.
The price may now be looking back at you
The US Federal Trade Commission is consulting on a proposed enforcement policy concerning personalised pricing: the use of personal data to estimate what an individual might be willing to pay. Dynamic pricing is familiar. Flights become more expensive, hotel rooms fluctuate and the sandwich at the airport apparently arrives with its own mortgage application.Personalised pricing is more intimate. Rather than changing the price for everyone according to demand, a business may use information about a particular person, such as browsing behaviour or purchase history, to decide what price that person sees.
The FTC has not proposed banning every form of personalised pricing. Its concern is that businesses could mislead consumers if a price appears to be standard while personal data is quietly helping to determine it. [The FTC’s consultation explains the proposed approach](https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-seeks-comment-enforcement-policy-statement-regarding-personalized-pricing).
Sue’s translation: The website may not simply know that you want the shoes. It may be considering how desperately you want the shoes. For businesses, this is not only a pricing question. It involves marketing claims, customer expectations, profiling, transparency and the provenance of every signal entering the pricing model.Before introducing a personalised offer or price, an organisation should be able to explain:
- Which personal data influences the decision
- Where that information came from
- Whether the customer reasonably expects this use
- Whether different people can receive different prices
- What the customer is told
- Whether the result could unfairly exploit urgency or vulnerability
- How somebody can question or challenge the outcome
Calling the output an “individual value opportunity” will not make those questions disappear. It may, however, earn somebody a very exciting meeting with Legal.
For individuals, comparing prices while signed out or using a private browsing session may reveal differences, although it cannot establish why a price changed. Location, availability, promotions and timing may also influence the result.
The robot manager needs an escalation route
The Dutch Data Protection Authority fined Uber nearly €825 million over automated decisions that temporarily or permanently deactivated drivers’ accounts.According to the regulator, decisions concerning suspected fraud and low ratings were taken without human intervention. Losing access to the platform meant affected drivers could no longer accept rides or earn income. [The CNIL’s account of the cross-border decision explains the findings](https://www.cnil.fr/en/automated-decisions-uber-fined-nearly-eur-825-million).
This matters well beyond the gig economy.
Organisations increasingly use automated tools to shortlist applicants, score performance, detect fraud, prioritise investigations, allocate work and identify supposedly unusual behaviour. There is a natural corporate temptation to describe such tools as “decision support”. Sometimes that is accurate. Sometimes the human contribution consists of staring briefly at a score before clicking the button the system has already selected.
Sue’s question for the meeting: If the computer is wrong, who is both willing and authorised to say so? A meaningful human review needs more than a nominal approver. The reviewer should:- Understand the factors that influenced the decision
- Have access to relevant contextual information
- Be able to identify inaccurate or incomplete data
- Possess genuine authority to change the result
- Record why the decision was upheld or overturned
- Respond within a useful timeframe
An appeals mailbox monitored every second leap year does not constitute human oversight. Employees should also know when monitoring, scoring or automated decision-making affects them. If a system influences pay, shifts, access, promotion, discipline or continued employment, it deserves considerably more governance than the office coffee-ordering spreadsheet.
Your hobby would like to become an AI training exercise
In August, the Dutch privacy regulator warned Twitch users about a setting allowing their streams, images, chats and other information to be used for training Amazon’s generative AI.The regulator said the setting was enabled by default and advised users who did not want their material used in this way to switch it off. It highlighted that livestreams can include faces, voices, names, conversations and views inside people’s homes. [The Dutch authority’s notice provides details and opt-out instructions](https://autoriteitpersoonsgegevens.nl/actueel/ap-adviseert-twitch-gebruikers-zet-instellingen-uit-voor-delen-van-data-met-amazon-ai).
This is a consumer story with a very obvious workplace sequel. Employees are joining AI assistants, meeting tools, transcription services, design platforms and coding products with both personal and company accounts. The settings governing model training, product improvement and data retention can differ by service, subscription and account type.
A product being approved for corporate use does not necessarily mean every edition of it is approved. The enterprise version may have contractual controls that the free version does not.
Sue’s rule: “It was already on” is a description of a setting, not a privacy strategy. Businesses should check whether their approved AI services:- Use prompts, uploads or outputs for model training
- Enable training or product-improvement settings by default
- Treat free, individual and enterprise accounts differently
- Allow administrators to enforce settings centrally
- Retain deleted conversations or uploaded files
- Receive personal information about employees, clients or suppliers
- Provide an appropriate way to honour access, deletion and objection requests
Individuals should periodically inspect the privacy settings of creative, social and AI services. Pay particular attention after a notice announcing “exciting improvements”, a phrase that has occasionally meant exciting improvements for the company’s dataset.
The right to be forgotten also applies to people you did not hire
France’s data protection authority fined engineering and IT consultancy Extia €300,000 following complaints from former employees and job candidates about deletion requests.The regulator examined 265 requests made during 2024. More than three quarters had not been handled, or had not been handled satisfactorily. It also found failures to tell people what had happened after they exercised their rights. [The CNIL decision summarises the findings](https://www.cnil.fr/fr/sanction-non-respect-droits-personnes-extia).
Recruitment systems are enthusiastic collectors. A person uploads a CV for one vacancy and may quietly achieve immortality across an applicant-tracking platform, a shared drive, an interviewer’s inbox, a recruiter’s spreadsheet and a folder called `Potential People FINAL v4`.
Deleting the main applicant profile may therefore be only the opening act.
Sue’s recruitment test: Can you remove a candidate’s information from the places where recruitment actually happens, not merely the system shown during the audit? Organisations should map candidate information across:- Applicant-tracking systems
- Recruitment agencies and other processors
- Interview notes and assessment tools
- Email and collaboration platforms
- Talent pools
- Background-check providers
- Recorded interviews
- Artificial-intelligence screening services
- Locally maintained spreadsheets and exports
Automated deletion can help, but it does not remove the need to respond to the person. “The system probably dealt with it” is not a status update. For individuals, a deletion request should identify the account, vacancy or approximate application period. Keep a copy and note when it was sent. Depending on the applicable law and the organisation’s obligations, some information may need to be retained—but the organisation should explain what it is keeping and why.
The cloud was secure. The records were in a bathroom.
Ireland’s Data Protection Commission fined the Health Service Executive €645,000 after investigating the storage and retention of paper medical records.The investigation followed unauthorised access to records in disused former hospital buildings. During inspections, the regulator found documents affected by mould, water, animal droppings and general deterioration. Records were also found in disused bathrooms and cubicles, and in a shipping container inside a turf shed.
The DPC ordered a complete audit of storage facilities, better tracking of records, safe destruction where retention was no longer necessary, and removal of files from unsuitable locations. [The DPC decision describes the findings and corrective measures](https://dataprotection.ie/en/news-media/latest-news/data-protection-commission-announces-final-decision-following-inquiry-health-service-executive-hse).
This is the monthly reminder that personal data does not stop being personal because it has corners and smells faintly of filing cabinet. Many organisations have invested heavily in cloud security while retaining paper archives, backup media, retired laptops, old access cards and boxes inherited through mergers.
Sue’s storage policy: If nobody can explain what is in the room, who owns it or when it can be destroyed, locking the door is only delaying the plot. A proper information audit should include:- Off-site and third-party storage
- Closed offices and former premises
- Paper files awaiting scanning
- Archived employee and customer records
- Retired equipment and removable media
- Boxes acquired through mergers or restructuring
- Departmental cupboards that apparently pre-date electricity
Records must remain confidential, available and usable for as long as they are legitimately required. Retention is not achieved by keeping something indefinitely in conditions that make it inaccessible or unsafe.
At home, the same principle applies on a smaller scale. Old payslips, medical correspondence, photocopied identity documents and statements should not live forever in a drawer simply because the shredder is “a weekend job”.
We both know which weekend you mean. It does not exist.
A breach can affect people outside the customer list
France’s privacy regulator also fined Hôpital Privé de la Loire €500,000 following a health-data breach. The regulator identified weaknesses including insufficient external authentication, inadequate access controls and a lack of prompt detection for suspicious activity. It said credentials for one account allowed access to information concerning all hospital patients.The incident affected 524,867 patients and 202,246 people listed as trusted third parties. Although patients were informed, the trusted contacts were not notified directly. [The CNIL decision explains the security and notification failures](https://www.cnil.fr/en/sanction-fine-hopital-prive-loire).
That last point deserves attention. Organisations often design incident searches around their primary population: customers, employees, patients or account holders. Personal data about other people can be tucked inside those records:
- Emergency contacts
- Dependants and beneficiaries
- Guarantors
- Referees
- Witnesses
- Family members
- Authorised representatives
- Client contacts
- People mentioned in notes or correspondence
Sue’s incident-response question: Whose information was exposed—not merely whose account was involved? A notification assessment should follow the data, not the shape of the customer database. Secondary contacts may face different risks and may need different advice.This also matters when buying software. A supplier may promise that one compromised user cannot access unrelated records, but that claim should be tested through role design, access reviews, monitoring and realistic security exercises.
“Least privilege” should be an access-control principle, not the number of people invited to read the audit report.
Sue’s five-minute workplace privacy review
Before the next meeting acquires a steering group, try these questions:1. What personal data is entering our AI tools?Include prompts, meeting transcripts, uploaded documents, customer messages, source code, screenshots and generated outputs.
2. Which decisions about people are substantially automated?Look across recruitment, fraud, workforce management, customer eligibility, pricing and account suspension.
3. Can we actually complete a deletion request?Test the journey across the primary system, exports, suppliers and local copies. Do not accept “there is a button” as proof.
4. Where is the forgotten information?Include archives, warehouses, closed premises, cupboards, shared drives and historic platforms.
5. Does our incident process identify everyone in the data?Check dependants, emergency contacts, representatives and people mentioned within free-text records.
6. Are we changing prices, offers or treatment using personal profiles?If so, document the inputs, explain the practice properly and test the outcomes.
Sue’s five-minute personal privacy review
For people whose job description does not contain the word “governance”:- Review training and product-improvement settings in AI and creative services
- Use unique passwords and multifactor authentication
- Close accounts you no longer use
- Check which applications can access your email, files and social accounts
- Keep copies of important privacy or deletion requests
- Compare significant prices without assuming every difference is personalised
- Securely destroy documents you no longer need
- Avoid putting confidential work information into personal AI accounts
You do not need to spend Sunday reading every privacy notice ever written. Nobody should lose a Sunday like that—not even the person who wrote them.
Start with services holding information that could affect your health, money, employment, identity or reputation.
Sue’s final word
These developments come from different countries, sectors and legal proceedings. They do not prove that every business is personalising prices, every automated system is unlawful or every archive is being slowly consumed by wildlife.They do reveal a consistent practical problem: organisations frequently lose sight of personal data once it moves outside the process for which governance was originally designed.
A candidate becomes a record in several recruitment tools. A driver becomes a score. A trusted contact becomes a field inside somebody else’s medical file. A livestream becomes training material. A customer becomes a predicted willingness to pay. A paper record becomes part of the building.
Good privacy management keeps the person visible throughout that journey.
Until next month, please remember: if your data strategy requires the sentence “technically, they agreed”, Sue has follow-up questions.