Tarun Samtani's Avatar

Tarun Samtani

@tsamtani

Data Protection & Privacy Leader | DPO | AI Governance | IAPP Advisory Board Member | Mentor | CIPM | Trainer & Speaker www.linkedin.com/in/tsamtani

292
Followers
51
Following
8
Posts
12.11.2024
Joined
Posts Following

Latest posts by Tarun Samtani @tsamtani

Preview
Responsible AI Use in Attorney Well-Being: Legal and Ethical Considerations AI-powered stress management tools are designed to help legal professionals maintain their composure in high-pressure situations.

“ .. convergence of AI-driven mental health apps, attorney well-being .. data privacy .. important legal & ethical considerations, especially in relation to .. HIPAA .. various state-specific privacy regulations.” www.americanbar.org/groups/law_p...

20.05.2025 11:12 👍 2 🔁 1 💬 0 📌 0
Post image

🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read.

He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords

Media's coverage wasn't detailed enough so I dug into his testimony:

18.04.2025 00:10 👍 14016 🔁 7369 💬 329 📌 1008
Post image

In an article for IAPP, MoFo’s Carrie H. Cohen, Boris Segalis, Katherine Wang, and Darcy Black review the New York attorney general's robust #privacy and #cybersecurity enforcement actions in 2024: bit.ly/4h9pllz

07.03.2025 15:12 👍 1 🔁 1 💬 0 📌 0
Preview
We found a DOGE guy at NASA because his Google Calendar was public DOGE staffer Riley Sennott's Google Calendar wasn't private, exposing his interactions with DOGE and firms like Tesla and Palantir.

We can learn so much about good opsec through the many negative examples brought to us by this carload of clowns: www.businessinsider.com/doge-nasa-go...

07.03.2025 21:04 👍 346 🔁 98 💬 6 📌 4
Preview
87% of Firms Hit By AI Cyber-attacks 87% of security professionals report that their organisation has encountered an AI-driven cyber-attack in the last year.

“87% of security professionals report that their organisation has encountered an AI-driven cyber-attack in the last year, according to a new study by SoSafe, Europe’s largest security awareness and human risk management solution.” www.digit.fyi/87-of-firms-...

08.03.2025 00:08 👍 2 🔁 2 💬 0 📌 0
Preview
The State of Personal Online Security and Confidentiality | SXSW LIVE YouTube video by SXSW

Watch the #sxsw keynote on personal online security and tell me you are not a fan of @meredithmeredith.bsky.social – I won't believe you.

www.youtube.com/live/AyH7zoP...

07.03.2025 20:40 👍 90 🔁 28 💬 2 📌 2
Preview
Signal President Meredith Whittaker calls out agentic AI as having 'profound' security and privacy issues | TechCrunch Signal President Meredith Whittaker warned Friday that agentic AI could come with a risk to user privacy. Speaking onstage at the SXSW conference in

I did. Because it does.

techcrunch.com/2025/03/07/s...

08.03.2025 03:56 👍 953 🔁 304 💬 21 📌 32
Post image Post image

Wow!
If you're still uncertain why you should start using @signal.org (and @ProtonPrivacy.bsky.social btw.),

You must see this @GuyKawasaki.bsky.social @sxsw.com interview with @meredithmeredith.bsky.social

www.youtube.com/live/AyH7zoP...

08.03.2025 22:45 👍 39 🔁 10 💬 1 📌 0
Preview
Signal president warns the hyped agentic AI bots threaten user privacy At SXSW, Signal President Meredith Whittaker warned about the 'profound' security risks to user privacy posed by agentic AI.

At SXSW, Signal President Meredith Whittaker warned about the 'profound' security risks to user privacy posed by agentic AI.

08.03.2025 21:36 👍 100 🔁 39 💬 3 📌 2

"The Salt Typhoon hack was a catastrophic national security breach!" -Meredith Whittaker

fyi for those that weren't aware of the breach:
www.politico.com/news/2024/12...

08.03.2025 21:09 👍 73 🔁 28 💬 2 📌 0
Preview
Deep Impact Soundtrack: The Hives — Hate To Say I Told You So In the last week or so, but especially over the weekend, the entire generative AI industry has been thrown into chaos. This won’t be a lengthy, tech...

Newsletter: The DeepSeek situation is a moment that should fill Silicon Valley with shame, a monument to the lack of vision and herd mentality of the American tech industry. OpenAI and Anthropic have no moat, no business, no innovation, and I believe no future.

www.wheresyoured.at/deep-impact/

29.01.2025 16:41 👍 3026 🔁 609 💬 87 📌 106

Copyright and Artificial Intelligence
Part 2: Copyrightability
January 2025

www.copyright.gov/ai/Copyright...

30.01.2025 12:36 👍 1 🔁 2 💬 0 📌 0
Preview
Decyzje Prezesa UODO- Urząd Ochrony Danych Osobowych.

The Polish DPA announced that it has fined a bank for failing to ensure the independence of the data protection officer (DPO) and failing to register "profiling" as a processing activity under the ROPA. See uodo.gov.pl/decyzje/DKN.....

20.01.2025 13:32 👍 0 🔁 1 💬 0 📌 0
Post image

News from Association of Southeast Asian Nations, or ASEAN,

ASEAN Guide on Data Anonymization. See

lnkd.in/dfrf7cYV

Joint Guide to ASEAN Model Contractual Clauses and LATAM Model Contractual Clauses. See

lnkd.in/dVAxSgcD

20.01.2025 13:47 👍 1 🔁 1 💬 0 📌 0
Post image

Key principles related to the processing of personal
data in FTC's decision in the Matter of General Motors LLC, General Motors and OnStar: (i) Lawfulness, fairness, and transparency; (ii) Purpose limitation; (iii) Data minimization; (iv) Storage limitation; and (v) Accountability.

18.01.2025 22:10 👍 3 🔁 4 💬 0 📌 0
Webinar - Privacy Litigation
Webinar - Privacy Litigation YouTube video by TeachPrivacy

ICYMI - Webinar: Privacy Litigation [Video (free] – Daniel Solove + Katherine Heaton (Beazley) + Melissa Siebert (Cozen) youtu.be/krjtQEic3ig

18.01.2025 22:54 👍 3 🔁 2 💬 0 📌 0
Why ‘open’ AI systems are actually closed, and why this matters - Nature A review of the literature on artificial intelligence systems to examine openness reveals that open AI systems are actually closed, as they are highly dependent on the resources of a few large corpora...

Great paper from @davidthewid.bsky.social, @meredithmeredith.bsky.social and @smw.bsky.social outlines the real obstacle to diversity and accountability in the AI sector: concentration of power in the hands of a few corporations. www.nature.com/articles/s41...

06.12.2024 14:11 👍 8 🔁 6 💬 0 📌 0
Under the current law, significant solely automated decision-making based on personal data is prohibited unless one of the following three conditions applies:

The data subject gives explicit consent, or
The decision is necessary for a contract between the data subject and a controller, or
The decision is required or authorised by a UK law that provides safeguards for rights and freedoms.

Under the new Article 22B, this prohibition would only apply where special category data is involved. The exceptions are also slightly different:

The data subject gives explicit consent, or
The processing is based on Article 9(2)(g) (“substantial public interest”), and either:
The decision is necessary for a contract between the data subject and a controller, or
The decision is required or authorised by law.

Controllers cannot rely on the new legal basis of “recognised legitimate interests” for automated decisions.

This would mean automated decision-making that only involves “non-special category data” is generally permitted, subject to certain safeguards.

Under the current law, significant solely automated decision-making based on personal data is prohibited unless one of the following three conditions applies: The data subject gives explicit consent, or The decision is necessary for a contract between the data subject and a controller, or The decision is required or authorised by a UK law that provides safeguards for rights and freedoms. Under the new Article 22B, this prohibition would only apply where special category data is involved. The exceptions are also slightly different: The data subject gives explicit consent, or The processing is based on Article 9(2)(g) (“substantial public interest”), and either: The decision is necessary for a contract between the data subject and a controller, or The decision is required or authorised by law. Controllers cannot rely on the new legal basis of “recognised legitimate interests” for automated decisions. This would mean automated decision-making that only involves “non-special category data” is generally permitted, subject to certain safeguards.

The UK hopes to open up AI-driven decision-making.

The current prohibition (Art 22 UK GDPR) covers "automated decisions" based on all types of personal data.

The Data (Use and Access) Bill would narrow it to "special category" data only.

Safeguards would still be required for all personal data.

05.12.2024 14:24 👍 3 🔁 3 💬 2 📌 0

🥳 As of yesterday, noyb is approved as a qualified entity to bring collective redress actions in EU courts!

This allows us to bring a European version of a "Class Action", where thousands or millions of users could be represented by noyb.

More Info 👇

03.12.2024 10:30 👍 59 🔁 25 💬 0 📌 6

Looks like a perfect list to be part of.. could I be on it as well? Thank you

30.11.2024 14:13 👍 1 🔁 0 💬 0 📌 0

I created a starter pack for researchers who work at the nexus of HCI & cybersecurity / privacy here.

Please do let me know if you would like to be added to the list!I'm sure I've missed many folks.

go.bsky.app/RGsu5jn

20.11.2024 16:22 👍 29 🔁 22 💬 10 📌 0

My “Privacy, Data Protection, & Ethical Tech” Starter Pack

#PrivacySky #EthicalAI #DataProtection

go.bsky.app/HSRZtb8

30.11.2024 10:06 👍 43 🔁 15 💬 3 📌 2
Webinar exploring the Architecture of the AI Act
Webinar exploring the Architecture of the AI Act YouTube video by DigitalEU

Missed the latest AI Pact webinar on the AI Act? Dive into insightful discussions, expert opinions, and practical takeaways by watching the full session on YouTube.

m.youtube.com/watch?v=eLlS...

30.11.2024 12:50 👍 3 🔁 3 💬 0 📌 0
Post image

But what about transparency under Article 14 of GDPR where the personal data is derived by the controller? See eur-lex.europa.eu/legal-content/…

Derived personal data is personal data that is created from other personal data by an organization in the course of business.

30.11.2024 13:38 👍 3 🔁 1 💬 0 📌 1
Post image

Here’s the Supreme Decree N° 016- 2024-JUS-Regulation of Peru's Personal Data Protection Law. The Decree aims to align the Peruvian data protection rules to the GDPR:

30.11.2024 13:56 👍 1 🔁 2 💬 1 📌 1
Preview
Tech companies put on notice as Australia passes world-first social media ban for under-16s | CNN Australia’s parliament has passed a law banning social media for children under 16, putting tech companies on notice to tighten security before a cut-off date that’s yet to be set.

Australia passes world-first social media ban for under-16s with massive fines for tech giants. Critics warn it'll make the problem worse.

28.11.2024 12:36 👍 699 🔁 95 💬 51 📌 39
Post image

It seems that LinkedIn is doing its homework after getting fined by the Irish DPC

27.11.2024 07:03 👍 8 🔁 1 💬 0 📌 0
Preview
X's Objection to the Onion Buying InfoWars Is a Reminder You Do Not Own Your Social Media Accounts "X CORP. OWNS THE X ACCOUNTS."

Elon Musk's legal filing in the InfoWars bankruptcy case is both batshit crazy and also what you'd expect. It asserts that X owns every account, can do whatever it wants with them, and can inject itself into legal proceedings that have nothing to do with Twitter

www.404media.co/xs-objection...

26.11.2024 19:42 👍 2640 🔁 857 💬 105 📌 178