<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>That Privacy Guy! Blog</title>
    <link>https://www.thatprivacyguy.com/blog</link>
    <description>Expert insights on privacy, data protection, GDPR, AI governance, and cyber security.</description>
    <language>en-gb</language>
    <lastBuildDate>Fri, 22 May 2026 19:52:00 GMT</lastBuildDate>
    <atom:link href="https://www.thatprivacyguy.com/blog/feed.xml" rel="self" type="application/rss+xml" />

    <item>
      <title><![CDATA[CIPA and the Environmental Crimes Directive: why forensic web evidence just became the most contested thing in privacy litigation]]></title>
      <link>https://www.thatprivacyguy.com/blog/cipa-environmental-crimes-directive-forensic-evidence</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/cipa-environmental-crimes-directive-forensic-evidence</guid>
      <description><![CDATA[CIPA wiretapping claims and the new EU Environmental Crimes Directive have one thing in common: they are won and lost on forensic evidence of what a website actually does at runtime. Inbound demand for that evidence has outrun us, so WebSentinel orders are now queued. Here is why both regimes turn on evidence, what that evidence has to prove, and why cookie-banner tooling cannot produce it.]]></description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>CIPA</category>
      <category>ePrivacy</category>
      <category>GDPR</category>
      <category>WebSentinel</category>
      <category>litigation</category>
      <category>evidence</category>
      <category>law</category>
      <category>SessionReplay</category>
      <category>EnvironmentalCrimesDirective</category>
      <category>Environment</category>
    </item>

    <item>
      <title><![CDATA[Malta is in breach of the EU Treaties — the IDPC has confirmed in writing that no Maltese citizen is protected under the ePrivacy Directive against any tech company not established in Malta]]></title>
      <link>https://www.thatprivacyguy.com/blog/malta-eprivacy-treaty-breach</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/malta-eprivacy-treaty-breach</guid>
      <description><![CDATA[On 27 April 2026 I lodged a formal complaint with Malta's Information and Data Protection Commissioner against Anthropic.  The IDPC has now confirmed in writing that no Maltese citizen has any protection under the ePrivacy Directive against any tech company not established in Malta.  That is a direct breach of Articles 7 and 47 of the EU Charter, of Article 19(1) TEU, and of Malta's obligations under Directive 2002/58/EC.  This piece walks through the IDPC's correspondence in full, the 2009 Phorm precedent in which the European Commission opened infringement proceedings against the United Kingdom for an analogous failure, and why Malta has now made an Article 258 TFEU complaint to the Commission unavoidable.]]></description>
      <pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>ePrivacy</category>
      <category>GDPR</category>
      <category>Charter</category>
      <category>Malta</category>
      <category>IDPC</category>
      <category>Anthropic</category>
      <category>Phorm</category>
      <category>law</category>
      <category>Compliance</category>
    </item>

    <item>
      <title><![CDATA[Google quietly removes the on-device AI privacy assurance from Chrome's Settings UI]]></title>
      <link>https://www.thatprivacyguy.com/blog/google-quietly-removes-on-device-ai-privacy-claim</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/google-quietly-removes-on-device-ai-privacy-claim</guid>
      <description><![CDATA[Google has quietly removed the privacy assurance from Chrome's on-device AI Settings UI.  The sentence promising that the model runs locally without sending data to Google's servers has been deleted, and the toggle moved out of the System block to reduce the chance the change is noticed.  There are three plausible reasons for that, and each is a serious problem for users.  This piece walks through the legal exposure under the EU Unfair Commercial Practices Directive, Section 5 of the FTC Act, and Articles 13(4) and 5(2) of the Digital Markets Act, and asks Parisa Tabriz directly why the assurance was withdrawn.]]></description>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>AI</category>
      <category>Chrome</category>
      <category>Consent</category>
      <category>Compliance</category>
      <category>ePrivacy</category>
      <category>GDPR</category>
      <category>Google</category>
    </item>

    <item>
      <title><![CDATA[The problem with Consent Management Platforms is they are unlawful by design]]></title>
      <link>https://www.thatprivacyguy.com/blog/cmps-unlawful-by-design</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/cmps-unlawful-by-design</guid>
      <description><![CDATA[Every CMP I have looked at in fifteen years sets a cookie before the user has consented to anything. That is a direct breach of Article 5(3) of the ePrivacy Directive, restated by the CJEU in Planet49 (C-673/17), and reinforced by the Belgian decision against the IAB TCF. This piece explains, step by step, what a lawful consent flow actually looks like and why every cookie banner you have ever seen is wrong.]]></description>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>privacy</category>
      <category>ePrivacy</category>
      <category>GDPR</category>
      <category>Compliance</category>
      <category>Consent</category>
      <category>CMP</category>
      <category>Cookies</category>
      <category>law</category>
    </item>

    <item>
      <title><![CDATA[Google's "Boss" of Chrome gaslights on unlawful Nano push]]></title>
      <link>https://www.thatprivacyguy.com/blog/google-gaslights-despite-evidence</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/google-gaslights-despite-evidence</guid>
      <description><![CDATA[Google's Chrome boss Parisa Tabriz tells the press that users can simply opt out of the unsolicited Gemini Nano install. Google's own Chrome manifest proves the opposite. Chrome reached into the device, flipped the flag, downloaded the 4 GB model and only then surfaced the settings UI after the fact. Opt-out is not the legal standard here — opt-in is. This piece walks through why the public PR statements are demonstrably false against Google's own logs, and why a half-truth response to evidence is its own kind of harm.]]></description>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>AI</category>
      <category>Chrome</category>
      <category>Consent</category>
      <category>Compliance</category>
      <category>ePrivacy</category>
      <category>Google</category>
    </item>

    <item>
      <title><![CDATA[Google Chrome silently installs a 4 GB AI model on your device without consent. At a billion-device scale the climate costs are insane.]]></title>
      <link>https://www.thatprivacyguy.com/blog/chrome-silent-nano-install</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/chrome-silent-nano-install</guid>
      <description><![CDATA[Google Chrome is downloading a 4 GB Gemini Nano model onto users' machines without consent, with no opt-in, no opt-out short of enterprise tooling, and an automatic re-download every time the user deletes it. The pattern is identical to the Anthropic Claude Desktop case I wrote about last month, but the scale is between two and three orders of magnitude larger. This article does the legal analysis and, for the first time, the environmental analysis. The numbers are not small.]]></description>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>AI</category>
      <category>privacy</category>
      <category>ePrivacy</category>
      <category>Compliance</category>
      <category>GDPR</category>
      <category>Google</category>
      <category>Chrome</category>
      <category>Gemini</category>
      <category>ESG</category>
      <category>Environment</category>
      <category>Sustainability</category>
      <category>Climate</category>
      <category>law</category>
    </item>

    <item>
      <title><![CDATA[Bolt's ChatBot Runs Amok]]></title>
      <link>https://www.thatprivacyguy.com/blog/bolts-chatbot-runs-amok</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/bolts-chatbot-runs-amok</guid>
      <description><![CDATA[Bolt's customer support chatbot acknowledged a missing food item and twice refused a refund, swapping personas to dress automated denial as human review.  A GDPR Article 22 case waiting to happen.]]></description>
      <pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>AI</category>
      <category>Compliance</category>
      <category>Technology</category>
      <category>ChatBots</category>
      <category>Customer-Services</category>
      <category>GDPR</category>
      <category>Consumer-Rights</category>
      <category>AI-Act</category>
    </item>

    <item>
      <title><![CDATA[Anthropic issued with a Cease and Desist]]></title>
      <link>https://www.thatprivacyguy.com/blog/anthropic-cease-and-desist</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/anthropic-cease-and-desist</guid>
      <description><![CDATA[Anthropic ignored the Claude Desktop spyware findings.  A formal Cease and Desist has now been issued, with 72 hours before criminal and civil complaints follow.]]></description>
      <pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>AI</category>
      <category>Anthropic</category>
      <category>Claude</category>
      <category>Compliance</category>
      <category>ePrivacy</category>
      <category>InfoSec</category>
      <category>law</category>
      <category>GDPR</category>
      <category>privacy</category>
      <category>forensics</category>
    </item>

    <item>
      <title><![CDATA[Anthropic secretly installs spyware when you install Claude Desktop]]></title>
      <link>https://www.thatprivacyguy.com/blog/anthropic-spyware</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/anthropic-spyware</guid>
      <description><![CDATA[Anthropic's Claude Desktop silently installs a Native Messaging bridge into seven Chromium browsers, including browsers Anthropic's own documentation says it does not support, and browsers the user has not even installed.]]></description>
      <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>AI</category>
      <category>privacy</category>
      <category>ePrivacy</category>
      <category>Compliance</category>
      <category>InfoSec</category>
      <category>GDPR</category>
      <category>law</category>
      <category>Cyber</category>
      <category>Security</category>
      <category>Anthropic</category>
      <category>Claude</category>
    </item>

    <item>
      <title><![CDATA[The Beast behind the Browser: Every Privacy Vulnerability in Chrome and How to Catch It]]></title>
      <link>https://www.thatprivacyguy.com/blog/the-beast-behind-the-browser</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/the-beast-behind-the-browser</guid>
      <description><![CDATA[A forensic reference to every client-side privacy vulnerability in Google Chrome — fingerprinting, storage tracking, header leaks — and how to detect each.]]></description>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>surveillance-capitalism</category>
      <category>AdTech</category>
      <category>MarTech</category>
      <category>Cookies</category>
      <category>privacy</category>
      <category>ePrivacy</category>
      <category>law</category>
      <category>forensics</category>
    </item>

    <item>
      <title><![CDATA[Data Sovereignty in light of US uncertainty]]></title>
      <link>https://www.thatprivacyguy.com/blog/data-sovereignty-in-light-of-us-uncertainty</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/data-sovereignty-in-light-of-us-uncertainty</guid>
      <description><![CDATA[EU and businesses are abandoning US tech giants for open source and self-hosted alternatives. Why data sovereignty matters now more than ever.]]></description>
      <pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>Data-Sovereignty</category>
      <category>Technology</category>
      <category>Self-Hosted</category>
      <category>FOSS</category>
      <category>GDPR</category>
      <category>Compliance</category>
      <category>privacy</category>
      <category>surveillance-capitalism</category>
      <category>InfoSec</category>
      <category>Cyber</category>
      <category>Security</category>
    </item>

    <item>
      <title><![CDATA[Welcome to my Blog]]></title>
      <link>https://www.thatprivacyguy.com/blog/welcome</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/welcome</guid>
      <description><![CDATA[Introducing the That Privacy Guy! blog — expert insights on privacy, data protection, GDPR, AI governance, and cyber security from Alexander Hanff.]]></description>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>privacy</category>
      <category>announcement</category>
    </item>

    <item>
      <title><![CDATA[Digital Psychology: Why Privacy is so important for Self Determination]]></title>
      <link>https://www.thatprivacyguy.com/blog/why-privacy-is-so-important-for-self-determination</link>
      <guid isPermaLink="true">https://www.thatprivacyguy.com/blog/why-privacy-is-so-important-for-self-determination</guid>
      <description><![CDATA[Psychographic profiling and surveillance capitalism erode our autonomy. Why privacy is fundamental to self-determination, free thought, and democracy.]]></description>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <author>Alexander Hanff</author>
      <category>privacy</category>
      <category>surveillance-capitalism</category>
      <category>psychology</category>
      <category>manipulation</category>
      <category>psychographics</category>
    </item>
  </channel>
</rss>