Insights

Insights

Practical writing on privacy impact assessments and algorithmic bias, drawn from the TrustDPO books.

What Is a Privacy Impact Assessment? The Complete Beginner's Guide

July 24, 2026

A plain-English guide to Privacy Impact Assessments — what a PIA actually is, why it exists, and two real Canadian cases that show what happens when one is skipped or done badly.

Read more →

The Robert Williams Case: What Facial Recognition Bias Really Costs

July 27, 2026

Detroit police arrested Robert Williams in front of his kids over a facial recognition match that was never independently checked. Here is what the case actually teaches about algorithmic bias.

Read more →

When Is a PIA Legally Mandatory? GDPR vs LGPD vs PIPEDA vs Quebec Law 25

July 29, 2026

A side-by-side look at when a Privacy Impact Assessment is legally required under the GDPR, Brazil's LGPD, Canada's PIPEDA, and Quebec's Law 25 — with the real cases that show what happens when it isn't.

Read more →

The Amazon Hiring Algorithm That Learned to Discriminate Against Women

July 31, 2026

Amazon built an AI recruiting tool that penalized résumés containing the word "women's." Here is why removing the offending words didn't fix it, and what that means for any company screening candidates with AI.

Read more →

The PIA Quick Check: A One-Page Framework to Spot High-Risk Projects in Minutes

August 3, 2026

Most organizations don't fail at privacy because they lack reports — they fail because no one paused to ask six simple questions before launching a project. Here is the one-page Quick Check that fixes that.

Read more →

When the System Says No: A Lawyer's Own Encounter with Algorithmic Refusal

August 5, 2026

A bank owed the author a discharge document the law said was automatic. A screen said no instead. Here is what that afternoon reveals about the real meaning of AI governance.

Read more →

Is Your AI Tool High-Risk? Automated Decision-Making and PIA Triggers

August 10, 2026

A credit-scoring algorithm, an AI recruiting tool, and an exam-monitoring system all trip the same PIA trigger — automated decisions or profiling. Here's how to tell if yours does too.

Read more →

Inside COMPAS: How ProPublica Exposed the Algorithm Sentencing America

August 13, 2026

A defendant couldn't see how his own risk score worked. Three years later, ProPublica showed why that mattered — and why explanation is not the same thing as recourse.

Read more →

How to Document PIA Accountability Regulators Actually Respect

August 17, 2026

A Quick Check that stays a private thought is worth nothing to a regulator. Here is the four-step framework for turning it into a record that actually proves you did the work.

Read more →

What the Machine Inherits: The SCHUFA Case and the Myth of Neutral Data

August 20, 2026

A German court forced a credit bureau to answer for its score. But the harder question sits one step earlier — the machine doesn't inherit reality. It inherits whatever institutions wrote down.

Read more →

7 Common PIA Mistakes (and How to Fix Them)

August 24, 2026

Most privacy failures don't happen because a PIA was never done — they happen because it was done poorly. Here are the seven mistakes that sink Privacy Impact Assessments, and the fix for each one.

Read more →

The Decision Not to Build: Lessons from the Netherlands' SyRI Welfare Scandal

August 25, 2026

A Dutch court didn't order the government to fix its fraud-detection system. It ordered the system stopped. What SyRI teaches about the first responsibility of algorithmic governance: selection, not mitigation.

Read more →

PIA vs DPIA: Is There Really a Difference?

August 31, 2026

PIA, DPIA, RIPD, évaluation des facteurs relatifs à la vie privée — same idea, different name in every jurisdiction. A quick reference to what each acronym means and where it comes from.

Read more →

Design for Contestability: What Michigan's MiDAS Disaster Teaches About AI Accountability

September 3, 2026

Michigan let a machine decide unemployment fraud without a single human in the loop. Ninety-three percent of its findings were wrong. The lesson isn't better accuracy — it's a system people can actually contest.

Read more →

PIA Laws, Standards, and Templates: The Practical Index by Country

September 7, 2026

ANPD, CAI, CNIL, EDPB, OPC, ISO/IEC 29134, the NIST Privacy Framework — a curated index of the regulators, standards, and templates that turn PIA theory into practice, jurisdiction by jurisdiction.

Read more →

How Machines Learn Our Worst Habits: The Hidden Bias in Classification Systems

September 10, 2026

A public-school classroom in Teresina, a failed Calculus I exam, and a hard lesson learned in London taught me what overfitting looks like — years before I ever watched a machine make the same mistake.

Read more →

← Back to home