4/14 ยท AI in the Workplace: Cryptographic Accountability

A response to Professor Nazrul Islam's Guardian column. The cryptographic answer to opaque AI surveillance. 20 pages.

https://mickai.co.uk/ebooks/ai-in-the-workplace-cryptographic-accountability

#WorkplaceAI #UKGDPR #ICO

AI in the Workplace: From Opaque Surveillance to Cryptographic Accountability

Professor Nazrul Islam used his Guardian column to name AI's real workplace threat: opaque AI-powered systems of surveillance and control of lower-autonomy workers. The framing is editorial. The engineering framing underneath it is that the opacity is structural. This ebook is the cryptographic accountability answer to the surveillance question.

Mickai

The Guardian named opaque AI workplace surveillance as the real threat (Prof Nazrul Islam, 11 May 2026).

The opacity is structural. The fix is structural.

The Mickai audit substrate is hash-linked, FIPS 204 ML-DSA-65 signed, browser-verifiable offline. The worker, the union, the employer, and the regulator can all replay the same chain.

https://mickai.co.uk/articles/opaque-ai-surveillance-the-substrate-makes-it-verifiable-for-every-party

#WorkplaceAI #AIsurveillance #UKGDPR #Mickai

The Guardian named opaque AI surveillance as the real workplace threat. The substrate makes it verifiable for every party at once.

Professor Nazrul Islam used his Guardian column on 11 May 2026 to put a name to AI's real workplace threat: opaque AI-powered surveillance and control of lower-autonomy workers. The threat is not the AI; the threat is the opacity. The Mickai audit substrate removes the opacity at the cryptographic primitive layer. Every action the AI took is signed under the operator's key, hash-linked in CBOR, and verifiable offline by the worker, the union, the regulator, and the employer at the same time.

๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ฎ๐—ฐ๐˜† ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—”๐—œ ๐—˜๐—ฟ๐—ฎ: ๐—จ๐—ž ๐—š๐——๐—ฃ๐—ฅ & ๐—ง๐—ต๐—ฒ ๐—ก๐—ฒ๐˜„ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ผ๐—ณ ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฒ

#ArtificialIntelligence #UKGDPR #DataProtection #PrivacyLaw #AutomatedDecisionMaking #DataRights #TechLaw #AICodeOfPractice #MachineLearning #DigitalRights

https://youtu.be/qTiqqX2YukU

How to Protect Your Privacy in the AI Era: UK GDPR & The New Code of Practice

YouTube

I missed a chunk of the #ICO #DPPC yesterday due to dental surgery, will be catching up on the videos today. A colleague who attended learned a lot!
https://ico.org.uk/about-the-ico/data-protection-practitioners-conference/

#DataProtection #InformationSecurity #InfoSec #GDPR #UKGDPR

Data Protection Practitioners' Conference

This yearโ€™s DPPC will take place online on Tuesday 14 October 2025.

The #cat has a microchip registered with #Identibase. After moving home I tried to update my address on Identibase, but they said that I needed to pay an annual subscription fee to do so...

My address is my personal data, and therefore comes under the #UKGDPR, so I submitted a Article 16 "right to rectification" request asking them to update the out of date personal data. Per Article 12(5) they have to do this for free.

And it worked! Identibase have updated my address for free.

#GDPR

New blogpost: A first look at the ICO's new (beta) tool for creating UK GDPR privacy notices

tl;dr: I like it. Sure, it doesn't do away with the need to know what personal data you process and why (the most time-consuming element of the process) but it does make creating a privacy notice pretty straightforward. The output notice is clear enough, free from legal jargon and - best of all? - it's free.

https://decoded.legal/blog/2024/08/a-first-look-at-the-icos-new-beta-tool-for-creating-uk-gdpr-privacy-notices/

#DataProtection #Privacy #GDPR #UKGDPR

A first look at the ICO's new (beta) tool for creating UK GDPR privacy notices

The UKโ€™s Information Commissionerโ€™s Office has launched a beta of a new free tool to create privacy notices.

@tdp_org Why are third-party analytics cookies considered "strictly necessary" on the BBC website?

https://www.bbc.com/usingthebbc/cookies/strictly-necessary-cookies/

Strict necessity is defined as those required for the site's basic functionality to work, such as remembering which shopping cart is yours, or saving your cookie preferences so you are not asked on every page (which could be seen as coercing the user to accept more cookies).

@noybeu, what do you think?

#gdpr #gdprcompliance #UKGDPR #cookies

What strictly necessary cookies does the BBC use?

ICO guidance on workplace monitoring

The UK's Information Commissioner's Office has issued new guidance on workplace surveillance and monitoring, so here's a short blogpost breaking it down.

If you're in the UK and you are monitoring employees - or you are an employee being monitored - this is worth a quick look.

#DataProtection #UKGDPR #surveillance

ICO guidance on workplace monitoring - decoded.legal/blog

A comment on the ICO's new guidance on workplace monitoring

decoded.legal blog

ICO fines TikTok ยฃ12.7m. Looks like the contraventions were around allowing access to under 13s and failing to provide adequate transparency information

#UKGDPR #dataprotection

https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2023/04/ico-fines-tiktok-127-million-for-misusing-children-s-data/

ICO fines TikTok ยฃ12.7 million for misusing childrenโ€™s data

The Information Commissionerโ€™s Office (ICO) has issued a ยฃ12,700,000 fine to TikTok Information Technologies UK Limited and TikTok Inc (TikTok) for a number of breaches of data protection law, including failing to use childrenโ€™s personal data lawfully.

December has flown by with lots of fun festive extra activities on the mind, presents to buy and events to go to. ๐ŸŽ„
 
This means it's been easy to lose track of important developments in data protection - an area of law which continues to be busy all year round! ๐Ÿง
 
So whilst lots of us are winding down for a nice long holiday weekend, here are five significant events in December from a GDPR and UK GDPR perspective in case you missed them:
 
1๏ธโƒฃ The EU Commission has proposed a draft EU - US Data Privacy Framework (the new 'privacy shield' ). However, whilst the draft is significant, the decision has not been finalized. The process which expected to take another 6 months.

2๏ธโƒฃ The UK Information Commissioner published various important pieces including its Direct Marketing Guidance which has long been anticipated by the industry. The ICO also released a forward thinking piece called 'Tech Horizons' which examines the implications of some of the most significant technological developments for privacy in the next two to five years.

3๏ธโƒฃ The EU has signed a declaration on EU digital rights and principles that highlights "the EU's commitment to a secure, safe and sustainable digital transformation." The declaration is wider than just protecting personal data including #ESG themes around sustainability and digital inclusion.

4๏ธโƒฃ Microsoft plans to roll out a 'data boundary' for its EU customers from 1 January to help their customers comply with their commitments under the GDPR.

5๏ธโƒฃ New draft texts has been released for significant EU legislation in the data space, including the upcoming #AI Act, and the EU Data Act.
 
And of course, there were many more developments. Would anything else make your top 5?

#dataprotectionlaw #dataprivacylaw #dataprotection #GDPR #UKGDPR #data #Privacyshield #internationalbusiness