Purpose & Means Newsletter — Issue 3, September 2026
This issue lands on the same week I published something I’d been putting off writing for a while - a post about why Field Talk has no sponsors.
The short version: sponsors often want something in return. Usually your contact details, passed to a sales team, disguised as a community benefit. In a data protection conference, that is a particular kind of irony. You attract practitioners in good faith and hand their data to companies whose compliance record they are there to scrutinise.
I am under no illusion that Field Talk is entirely selfless. I organise it under the Purpose and Means name. People who attend may go on to read this newsletter, hire me for consultancy, or take my courses. I am the sponsor, and I benefit. The difference is scale and transparency, and I think that distinction matters.
It relates, I think, to the main piece in this issue. Who benefits from a decision, and who bears the risk of it, are often different people. That gap is exactly what a properly conducted DPIA is supposed to surface.
More on that below.
Tim
Data Protection Hero #

Some data subjects have more to lose. That’s exactly why they matter most.
The DPIA everyone writes and no one uses #
Part 3 of a short series. Just joining us? Part 1 and Part 2 are here.
Article 35(9) of the GDPR says controllers shall, where appropriate, seek the views of data subjects on the intended processing. The DPIAs I’ve read either treat this as a box to tick or skip it entirely. This instalment asks what happens when you take it seriously.
The answer draws on two frameworks that data protection has largely ignored. Design thinking - which starts with the person experiencing the problem, not the organisation solving it - introduces the concept of extreme users: the people at the edges of your user population whose stakes are highest and whose experience of a system is most unforgiving. The GDPR already gestures toward this in Recital 75, which explicitly identifies vulnerable groups requiring heightened attention. R. Jason Cronk’s work on privacy by design maps “at-risk individuals” as a core analytical step, alongside threat actors. These are not edge cases. They are the test of whether a DPIA actually works.
The second framework is Value Sensitive Design, developed by Batya Friedman at the University of Washington - a structured methodology for identifying not just direct stakeholders, but the indirect ones too: the people never touched by a system who are nonetheless shaped by its decisions.
Who counts as a data subject? #
Most DPIAs open with a box labelled “data subjects” and list two or three categories: customers, employees, third parties. That list does real harm. It flattens an enormously varied population into a handful of labels, and those labels invite the assessor to think in terms of the median representative of each group - the typical employee, the average customer. The DPIA is then calibrated to protect that imagined median person.
The median customer, in most processing contexts, is not at particular risk. They have resources, choices, and resilience. The teenager using a mental health app is not the median customer. The migrant worker whose employment contract is bound to a biometric attendance system is not the median employee. The elderly person who does not understand that their smart home device is sharing data with their insurer is not the typical third party.
This is where design thinking’s extreme user concept becomes directly useful. The practice of deliberately identifying the people at the edges of your user population - those with the most to lose, the least power to push back, or the most unusual circumstances - is not a marginal exercise. It is how you find out whether the processing is safe at all.
Recital 75 already told us this #
The GDPR is not silent on this. Recital 75 lists the kinds of harm that should trigger heightened attention: discrimination, identity theft, financial loss, damage to reputation, loss of confidentiality, reversal of pseudonymisation, and more. It specifically identifies processing that could “lead to the exclusion or marginalisation of natural persons, such as vulnerable persons including children or elderly persons.”
This language is not decoration. It is an instruction to think carefully about who is actually in your data subject population and what harm looks like for the people at the riskier end of that population - not the people in the middle.
R. Jason Cronk’s privacy by design methodology formalises this with the concept of “at-risk individuals” - a structured analytical step that sits alongside the identification of threat actors. The question is not only “who could misuse this data?” but “who is most exposed to harm if something goes wrong?” These are different questions, and they often point to different answers.
Value Sensitive Design and indirect stakeholders #
Batya Friedman’s Value Sensitive Design methodology adds another dimension that DPIAs routinely miss: indirect stakeholders. These are the people who are never directly in contact with a system but who are affected by its outputs.
A predictive policing system has obvious direct stakeholders - the people whose data feeds the model, the officers who use its outputs. Its indirect stakeholders include the communities in areas the model flags as high-risk, who will experience increased police presence whether or not any individual resident is in the dataset. A credit scoring algorithm directly affects the people it scores. It indirectly affects their families, their landlords, their employers - anyone who makes decisions based on a score they did not generate and cannot contest.
Standard DPIA templates do not ask about indirect stakeholders. They ask about the processing, the data, the risks to the people whose data is processed. That framing excludes a significant category of people who are affected by a decision without being represented in it.
Three cases that asked the wrong question #
The Dutch childcare benefits scandal
The Dutch childcare benefits scandal centred on an algorithm used by the Dutch Tax Authority to detect fraud in childcare benefit claims. The system assigned risk scores to claimants and flagged them for investigation. Thousands of families - disproportionately those with dual nationality or lower incomes - were incorrectly accused of fraud and had their benefits clawed back. Many were left in severe financial hardship.
The DPIA question that was not asked: what happens to the people this system gets wrong, and are those people disproportionately concentrated in already-vulnerable groups? An extreme user analysis would have identified low-income families with complex household arrangements as the people most exposed to a false positive. A Value Sensitive Design approach would have asked about the indirect stakeholders - the children in those families, whose stability and welfare depended entirely on a benefit claim they had no part in.
SCHUFA and automated credit scoring
The CJEU ruled in 2023 that SCHUFA’s automated credit scoring system constitutes automated decision-making within the meaning of Article 22 GDPR - a ruling that came after decades in which opaque scores had determined access to housing, loans, and basic services for millions of people.
The question that was never seriously asked: who are the people for whom a bad SCHUFA score is most consequential? Not the established professional with savings and an alternative route to credit. The newly arrived migrant. The person recovering from a period of illness who fell behind on payments. The young person with no credit history. Each of these groups experiences the system very differently from the median scored individual - and the consequences of an error are vastly more serious for them.
Workplace monitoring during the pandemic
The wave of employee monitoring software deployed during 2020 and 2021 - activity trackers, keystroke loggers, webcam monitoring - was built almost entirely from the employer’s perspective. The DPIA question it answered was: is this proportionate to the employer’s legitimate interest in productivity? The question it did not answer: who in this workforce is most harmed by constant surveillance?
The answer, had anyone asked, would have included workers with mental health conditions for whom surveillance adds significant anxiety load; workers in smaller homes with no quiet space, now visible to their employer through a webcam; workers with caring responsibilities whose working patterns are irregular by necessity; and workers in precarious employment whose fear of dismissal made them unable to raise concerns about the monitoring at all. None of these people are the median remote employee. All of them are in every large workforce.
What a DPIA that takes this seriously looks like #
It starts before the template. Before you open the standard form, you map your actual data subject population - not the categories, but the range. Within employees: who has the least power? Who has the most to lose from an error? Who has circumstances that make standard assumptions invalid? Within customers: who is most dependent on this service? Who would be most harmed by a data breach? Who is least able to seek redress?
You then ask Article 35(9) seriously: seek the views of data subjects where appropriate. This does not mean a survey of your most engaged customers. It means identifying the people whose views are hardest to obtain and whose stakes are highest, and finding ways to hear them - user research, community consultation, advocacy group input, pilot testing with edge populations.
Value Sensitive Design’s structured stakeholder analysis gives you a method: list the direct stakeholders, then list the indirect ones, then ask what harms are possible for each group and which values are implicated. This is not a different question from the standard DPIA. It is the same question asked more carefully.
None of this is quick. But the Dutch childcare benefits scandal was not quick either. The families it harmed are still living with the consequences. The DPIA that might have caught it would have taken a few more hours. It was not written.
Tag of the issue — #employee-engagement #
Each issue I pick one tag from the Purpose & Means blog and dig into the thinking behind it. A way into my archive for new readers, and a reminder for everyone else that the work goes deeper than any single newsletter.
The main piece in this issue is about granularity - recognising that “data subjects” in a DPIA are never just a handful of broad categories. Many assessments list employees, customers, and third parties, and stop there. But within each of those categories sits an enormous range of people with different vulnerabilities, different levels of power, and very different experiences of the same processing. A DPIA that treats “employees” as a single, uniform group is making the same mistake as one that imagines a single, median data subject. The category is not the person.
That granularity matters in another direction too. Some employees are entrusted with high-risk processing. Some have privileged access to sensitive data. Some, by virtue of their role, pose a greater risk to the organisation if they misunderstand their responsibilities, choose to ignore them or take advantage of them as we saw in the Morrisons supermarket case some years ago.
The receptionist handling a subject access request has a very different risk profile to the CFO approving a new HR analytics platform, or the IT administrator with access to the entire employee dataset. Engaging all three with the same annual e-learning module and calling it done is not a training strategy. It is a completion rate.
The same logic applies across the organisation more broadly. Meeting employees where they are - rather than expecting them to find their way to the legal department’s understanding of the world - requires the same kind of stakeholder thinking the DPIA series is arguing for. There are many tools and techniques for doing this well: scenario-based training, peer-to-peer learning, role-specific content, visual communication, workshop formats that invite questions rather than transmit answers.
Explore all posts tagged #employee-engagement
Field Talk — November 2026 #
Field Talk is a free, practitioner-led online conference for data protection professionals. No vendor influence, no sales pitches. Just practitioners talking to practitioners. 17-19 November, online, free to attend.
Two more speakers to introduce.

Tea Mustać is COO of SafePorter and a legal advisor on AI governance, data protection, and technology regulation. A Harvard Law School LL.M. graduate, she co-authored The AI Act Compact and co-hosts RegInt: Decoding AI Regulation. Her session - Building Your AI Governance Stack - is on Wednesday 18 November, 15:00-15:40 CET.

Corné Purcell is Associate Director and DPO at Abbott, with previous DPO roles at McKesson and Exact Sciences spanning finance, healthcare, and technology. His session - Persecution to Protection: The Origins of European Privacy Law and the Road to the GDPR - is on Thursday 19 November, 10:00-10:40 CET.
See the full programme at fieldtalk.eu. Free to participate and free from vendor influence.
What caught my eye #
Five things from the past two weeks worth your time.
Switzerland’s federal government is replacing Microsoft on 3,000 computers - A pilot migration to open source software, driven by sovereignty concerns. Worth watching: when governments start voting with their infrastructure, it signals something is shifting. (It’s FOSS, 7 September)
I refused to train the AI that could replace me - Workers declining to participate in AI training programmes explicitly designed to automate their own roles. The piece asks a question most organisations haven’t thought through: what does it mean to ask someone to cooperate in their own redundancy? (Rest of World, 3 September)
The proposed EU Biotech Act - Customer screening duties keep arriving in laws that never mention data protection. The proposed EU Biotech Act is the latest. Operators would have to vet identity, affiliation, stated end use and cumulative order history, retain that profile for five years, and report suspect transactions within 24 hours. Worth reading if you are the one who ends up drafting the lawful basis, the retention rule and - given the draft offers customers no route to contest a refusal - the answer to the inevitable access request. (Global Policy Watch, 9 September)
Google Earth’s AI experiment lasted 24 hours. The damage to trust will linger - Here we go again. Something goes wrong, harm occurs, and then the guardrails get promised afterwards. (Rest of World, 11 September)
Who’s buying your personal data? Disney, GM, your insurer and your bank - GDPR Article 15 gives people a right to know the recipients of their personal data, yet most DSAR responses I receive contain a vague category list rather than named buyers - if I get anything at all. This piece shows what happens when data brokers actually disclose. Acxiom’s reports name insurers, banks, lenders and pharmaceutical companies, alongside inferences across more than 3,000 categories about people’s finances and behaviour. (The Markup, 16 September)
Hire Me #
I work with organisations and practitioners on a project basis. No long-term lock-in. We discuss your needs, we agree the scope, we get it done. You can also book me for ad hoc consultancy - from a single hour to a block of time you can use as you need it. Hours can be booked and paid for online by credit card or bank transfer.