Purpose & Means Newsletter — Issue 2, September 2026
Welcome to Issue 2.
September always feels like a gear change. Summer holidays are behind us, and attention is turning to the projects that need to land before the year ends - and to planning what comes next. For me, that means scoping work and securing budgets with clients between now and the end of December, and then there’s Data Protection Day on 28 January 2027 which always requires lots of planning.
On top of that, I’m also currently studying a Master’s in Advanced Digital Technologies for Business, and the timing has been useful. Everything I’ve been learning about cloud computing - elasticity, scalability, what happens when demand is unpredictable - has been directly relevant to building the Field Talk infrastructure. I’m self-hosting the whole thing, so the theory and the practice are happening at the same time. Field Talk runs 17-19 November, fifteen speakers, free to attend. Making sure the infrastructure holds up on the day is one of the more interesting problems I’ve worked on this year.
Have a good weekend.
Tim
Data Protection Hero #
High, medium or low - if only it was that simple.

The DPIA everyone writes and no one uses #
Part 2 of a short series. Just joining us? Part 1 is here.
In Part 1, I argued that most DPIAs are written to satisfy a process, not to understand a risk. This time I want to be more specific. I want to name exactly where the conventional DPIA breaks down - because if we can see the failure clearly, we can start to fix it.
Start with what the regulation actually requires. Article 35(7) of the GDPR asks for an assessment of risks to “the rights and freedoms of natural persons.” The old WP29 guidelines on DPIAs - now endorsed and built upon by the European Data Protection Board, which has also published a revised standard DPIA template - are explicit about what that scope means. It reaches the full Charter of Fundamental Rights: freedom of expression, freedom of movement, non-discrimination, human dignity. Not just data protection rights. The ambition is broad, deliberately so.
Now look at a typical completed DPIA. Not a template - a finished one, submitted, signed off, filed.
The subjectivity problem #
Most DPIAs use a risk matrix: likelihood on one axis, severity on the other, a heat map of red, amber and green. The intention is sound. The execution has a persistent problem: who decides what counts as high, medium or low? On what basis? Two experienced practitioners assessing the same processing activity will often score it differently. And if you try to compare DPIAs across a programme - to understand which activities carry the most risk, to prioritise remediation, to report to a board - the scores are essentially incomparable. The calibration is different every time.
A heat map that cannot be compared is not an assessment tool. It is a documentation exercise. What we need instead is a more quantitative approach - one that allows DPIAs to be calibrated consistently, compared meaningfully, and used to prioritise action. That is a bigger topic, and one we will return to in a later issue.
The system versus the activity #
A second problem is more structural. Many DPIAs are written about systems rather than processing activities. A DPIA on “Microsoft Copilot” is assessing a tool. But the GDPR requires assessment of processing activities - what is actually being done with personal data, by whom, for what purpose, affecting which people.
Some organisations recognise this and attempt to identify different use cases within a single system-level DPIA. The intention is right. But in practice, this approach tends to dilute rather than sharpen the assessment. The reason is straightforward: different processing activities will involve different data subjects, and those data subjects may have vastly different risk profiles.
Take employees as a category. It sounds like a coherent group. But employees include permanent staff and contractors, senior managers and frontline workers, people in roles with access to sensitive data and people who have none. When a company uses a tool for drafting internal communications, the affected population looks one way. When the same tool is used to support HR performance reviews, it looks entirely different. Treating both under the same DPIA, even with separate use case sections, makes it very difficult to identify the specific risks to specific people.
This is where segmentation matters. Breaking down a broad category like “employees” into smaller, more precise groups - based on role, exposure, vulnerability, or relationship to the processing activity - is not a bureaucratic exercise. It is the only way to build a risk picture that is actually accurate. And it is one of the things that conventional DPIA practice almost never does well.
The analysis behind the scores #
Look more closely at what supports the risk entries in a typical DPIA. In most cases it is an article citation. “Article 6 - lawfulness of processing - risk: medium - mitigation: consent obtained.” That is not analysis. That is a checklist item with a number attached. The GDPR and the EDPB’s own guidance ask for a genuine assessment - of necessity, proportionality, and the specific risks to specific people. What most DPIAs deliver is a reference to a legal basis and a colour code.
The missing person #
And then there is Article 35(9). It sits quietly near the end of the article, easy to overlook. It says that where appropriate, the controller shall seek the views of data subjects or their representatives.
In the DPIAs I have reviewed, across organisations of every size and sector, I can count on one hand the number that show any evidence of this happening.
The people the DPIA is supposed to protect are almost never in the room. This matters beyond compliance. The data subject is the only person who can tell you what the actual impact of the processing feels like. They know whether a profiling decision felt fair. They know whether an automated output matched their reality. They know what it is like to be on the receiving end of the system you are assessing. Without that, you are making assumptions. Sometimes informed assumptions. But assumptions.
In the next issue, we will look at this in more detail. There are methods outside traditional data protection practice - design thinking, Value Sensitive Design - that give practitioners concrete tools for understanding who is actually affected by a processing activity, how to segment them, and how to bring their perspective into the assessment in a structured way. These approaches are not theoretical. They are practical, they are accessible, and they change what a DPIA can do.
So here is the question Part 3 will try to answer: if the GDPR already asks you to seek the views of data subjects, and most practitioners want to do this properly - why doesn’t it happen? And what would it actually look like if it did?
Tag of the issue — #horizon-scanning #
Each issue I pick one tag from the Purpose & Means blog and dig into the thinking behind it. A way into my archive for new readers, and a reminder for everyone else that the work goes deeper than any single newsletter.

Most change does not arrive without warning. It arrives as weak signals - a shift in enforcement tone, draft legislation quietly progressing through committee, a technology moving from experimental to mainstream, a geopolitical realignment that rewrites data flow assumptions, a social norm that regulators eventually catch up with, an environmental pressure that reshapes how companies think about their infrastructure. The skill of horizon scanning is learning to read those signals before they become obligations or disruptions. Not predicting the future. Just making sure you are not the last person in the room to notice it is changing.
Explore all posts tagged horizon-scanning
Field Talk — November 2026 #
Field Talk is a free, practitioner-led online conference for data protection professionals. No vendor influence, no sales pitches. Just practitioners talking to practitioners. 17-19 November, online, free to attend.
Over the next few issues I’ll be introducing the speakers.

Audrey Barrett is Data Protection Officer at SIPTU, Ireland’s largest trade union, with a decade of experience helping organisations navigate the practical realities of GDPR - from complex subject access requests to AI governance. She is Vice Chair of the Association of Data Protection Officers within the Irish Computer Society and Chair of the ICS Fellows Guild. A strong advocate for peer learning, her core message is simple: no DPO should have to do the job alone.
Audrey speaks on Day 2, Wednesday 18 November, 1600-1640 CET.

Nathan Kinch is a philosopher with nearly fifteen years of experience leading applied philosophical work within major public and private institutions. His AI ethics practice bridges rigorous philosophy with sociotechnical design, behavioural science, and organisational theory - focused on building AI systems that align to benevolent goals, operate with integrity, and deliver real-world good. He has lectured across the Americas, Europe, and Australia, and has held multiple Philosopher in Residence positions and run philosophical programmes for the Royal Society of the Arts.
Nathan speaks on Day 3, Thursday 19 November, 0700-0740 CET / 1700-1740 AEDT.
See the full programme at fieldtalk.eu. Free to participate and free from vendor influence.