Insights
Where Is My Privacy?
Our publication on data privacy, written for founders, operators, and privacy professionals who want to understand what's actually happening, not just what the regulators say.
Articles
Long-form analysis, twice a week
Deep dives on enforcement, regulation, and privacy practice across the EU, India, US, and beyond. Free to read, free to subscribe.
Browse the archiveDaily notes
One privacy story, every day
Short takes on the privacy, security, and AI stories that matter, posted daily on Substack Notes with the source alongside.
Read the daily notesLatest daily notes
All notes1 Sept 2026
Australia put out a draft privacy law on 31 August. The centrepiece is a test that a company can only collect or use personal data when doing that is fair an...
Read on Substack28 Aug 2026
Google is moving its 90-person AI responsibility team out of DeepMind and into global affairs, the arm that runs lobbying and public policy, from 1 September...
Read on Substack26 Aug 2026
Privacy reviews are close to worthless once the product is already built.
Read on SubstackLatest articles

21 Aug 2026
Why is your price your price?
The FTC moves on personalised pricing, the ICO hands five police forces 107 fixes, and somebody is selling the staff directories of nine large companies.
Read on Substack
19 Aug 2026
The flag that switched off the lock and the alarm
Anthropic says 133 million contractor conversations ran for eleven months without its biological safeguards, and the switch that disabled them disabled the logging too.
Read on Substack
6 Aug 2026
Chat Control is back, and the encryption carve-out is the whole story
314 MEPs voted to kill the EU's message-scanning derogation and that was not enough. Regulation (EU) 2026/1881 has been in force since 31 July. Here is what it actually permits.
Read on Substack
31 Jul 2026
A brake pedal with nothing attached to it
1,293 people at the frontier AI labs asked Washington to build a way to slow AI down. Europe already wrote one into law, and the fines switch on 2 August.
Read on Substack
23 Jul 2026
BritCard was voluntary, except when it wasn't
A national digital ID collapsed under nearly three million signatures. The data-protection lesson underneath it will outlast the politics.
Read on Substack
17 Jul 2026
Same scam, opposite verdicts
Two companies lost customer data to someone pretending to be IT support. One was cleared, the other was fined €1.7m. The attack wasn't the difference.
Read on Substack
10 Jul 2026
The model too good to ship
A frontier model held back for its hacking skills, a cyber law its own members ignored, and 7 million driver's licences lost to one phishing email.
Read on Substack
9 Jul 2026
The EDPB just turned "it's anonymous" into a test you have to pass
New draft guidelines on anonymisation and web scraping for generative AI tell AI builders to show their working, not just their labels.
Read on Substack
7 Jul 2026
France built a GDPR fining machine, and it runs on complaints
The CNIL issued 23 sanctions in six months without naming a single company. The headline fines were never the real risk.
Read on SubstackSubscribe, it's free
Written by Abhishek Bansiwal, founder of the practice. CIPP/E certified, LL.M. Trinity College Dublin, statutory DPO at a multi-jurisdiction B2B SaaS platform, ex-Deloitte. Writing about what actually matters in data privacy.
Start here
Tell us what you're dealing with.
Pick the service that sounds closest, or just describe the situation. You'll get an honest reply within 24 hours: where you stand, what actually needs doing, and whether we're the right fit for it.
Prefer to talk? Book a free 30-min callEmail: abhishek.adv@yahoo.com
LinkedIn: linkedin.com/in/abhishekbansiwal
Working with clients across the EU, UK, US, India, and beyond. See the privacy notice for how enquiries are handled.