Insights
Where Is My Privacy?
Our publication on data privacy, written for founders, operators, and privacy professionals who want to understand what's actually happening, not just what the regulators say.
Articles
Long-form analysis, twice a week
Deep dives on enforcement, regulation, and privacy practice across the EU, India, US, and beyond. Free to read, free to subscribe.
Browse the archiveDaily notes
One privacy story, every day
Short takes on the privacy, security, and AI stories that matter, posted daily on Substack Notes with the source alongside.
Read the daily notesLatest daily notes
All notes29 Sept 2026
A developer found a 313MB encrypted file in ZCode's folder: their whole workspace, source code and every commit, packed up and uploaded. ZCode is the Chinese...
Read on Substack22 Sept 2026
A leaked EU Council text (the member states' side of EU lawmaking), dated 3 September and published by the privacy group noyb yesterday, would add a new arti...
Read on Substack21 Sept 2026
"Sir, mobile number?"
Read on SubstackLatest articles

11 Sept 2026
Your prompt went to a different model, and somebody kept the transcript
Plus Anthropic's fourth incident and the monitor that believed the model, South Korea's 10% fine cap from today, a €300,000 lesson in ignoring delete requests, and 220 million passport records on an open server
Read on Substack
4 Sept 2026
A perfect score on breaking software, and a worse view inside
OpenAI shipped a model it says can find unknown security holes on its own, and said in the same announcement that its reasoning got harder to monitor. Both statements come from the same company.
Read on Substack
2 Sept 2026
$150,000 a song, and two founders named personally
Sony and Warner built their Anthropic complaint around where the files came from, which is the part of AI copyright law that has already cost money.
Read on Substack
21 Aug 2026
Why is your price your price?
The FTC moves on personalised pricing, the ICO hands five police forces 107 fixes, and somebody is selling the staff directories of nine large companies.
Read on Substack
19 Aug 2026
The flag that switched off the lock and the alarm
Anthropic says 133 million contractor conversations ran for eleven months without its biological safeguards, and the switch that disabled them disabled the logging too.
Read on Substack
6 Aug 2026
Chat Control is back, and the encryption carve-out is the whole story
314 MEPs voted to kill the EU's message-scanning derogation and that was not enough. Regulation (EU) 2026/1881 has been in force since 31 July. Here is what it actually permits.
Read on Substack
31 Jul 2026
A brake pedal with nothing attached to it
1,293 people at the frontier AI labs asked Washington to build a way to slow AI down. Europe already wrote one into law, and the fines switch on 2 August.
Read on Substack
23 Jul 2026
BritCard was voluntary, except when it wasn't
A national digital ID collapsed under nearly three million signatures. The data-protection lesson underneath it will outlast the politics.
Read on Substack
17 Jul 2026
Same scam, opposite verdicts
Two companies lost customer data to someone pretending to be IT support. One was cleared, the other was fined €1.7m. The attack wasn't the difference.
Read on SubstackSubscribe, it's free
Written by Abhishek Bansiwal, founder of the practice. CIPP/E certified, LL.M. Trinity College Dublin, statutory DPO at a multi-jurisdiction B2B SaaS platform, ex-Deloitte. Writing about what actually matters in data privacy.
Start here
Tell us what you're dealing with.
Pick the service that sounds closest, or just describe the situation. You'll get an honest reply within 24 hours: where you stand, what actually needs doing, and whether we're the right fit for it.
Prefer to talk? Book a free 30-min callEmail: abhishek.adv@yahoo.com
LinkedIn: linkedin.com/in/abhishekbansiwal
Working with clients across the EU, UK, US, India, and beyond. See the privacy notice for how enquiries are handled.