Manage episode 521595812 series 3241001
Finding it difficult to navigate the changing landscape of data protection? In this episode of the DMI podcast, host Will Francis speaks with Steven Roberts, Group Head of Marketing at Griffith College, Chartered Director, certified Data Protection Officer, and long-time marketing leader. Steven demystifies GDPR, AI governance, and the rapidly evolving regulatory environment that marketers must now navigate.
Steven explains how GDPR enforcement has matured, why AI has created a new layer of complexity, and how businesses can balance innovation with compliance. He breaks down the EU AI Act, its risk-based structure, and its implications for organizations inside and outside the EU.
Steven also shares practical guidance for building internal AI policies, tackling “shadow AI,” reducing data breach risks, and supporting teams with training and clear governance.
For an even deeper look into how businesses can ensure data protection compliance, check out Steven’s book, Data Protection for Business: Compliance, Governance, Reputation and Trust.
Steven’s Top 3 Tips
- Build data protection into projects from the start, using tools like Data Protection Impact Assessments to uncover risks early.
- Invest in regular staff training to avoid common mistakes caused by human error.
- Balance compliance with business performance by setting clear policies, understanding your risk appetite, and iterating your AI governance over time.
The Ahead of the Game podcast is brought to you by the Digital Marketing Institute and is available on YouTube, Apple Podcasts, Spotify, and all other podcast platforms.
And if you enjoyed this episode please leave a review so others can find us. If you have other feedback for or would like to be a guest on the show, email the podcast team!
Timestamps
01:29 – AI’s impact on GDPR & the explosion of new global privacy laws
03:26 – Is GDPR the global gold standard?
05:04 – GDPR enforcement today: Who gets fined and why
07:09 – Cultural attitudes toward data: EU vs. US
08:51 – The EU AI Act explained: Risk tiers, guardrails & human oversight
10:48 – What businesses must do: DPIAs, fundamental rights assessments & more
13:38 – Shadow AI, risk appetite & internal governance challenges
17:10 – Should you upload company data to ChatGPT?
20:40 – How the AI Act affects countries outside the EU
24:47 – Will privacy improve over time?
28:45 – What teams can do now: Tools, processes & data audits
33:49 – Data enrichment tools: targeting vs. Legality
36:47 – Will anyone actually check your data practices?
40:06 – Steven’s top tips for navigating GDPR & AI
129 episodes