Seven Years of GDPR: Balancing Power Between Organizations and Data Subjects Through Trust

Seven Years of GDPR: Balancing Power Between Organizations and Data Subjects Through Trust

Author: Punit Bhatia | Data Privacy, Sourcing & EU AI Act Specialist | ISO Standards October 2, 2025 Duration: 9:34

In this milestone episode of the FIT4Privacy podcast, host Punit Bhatia is joined by three distinguished privacy experts — Dr. Kerry Miller (AI Governance Expert, U.S.), Heidi Waem (Partner, DLA Piper, Brussels), and Dr. Valerie Lyons (COO, BH Consulting; Academic & Author) — to reflect on 7 years of GDPR and explore what lies ahead. 

Whether you’re a privacy professional, business leader, or just curious about how data protection shapes our digital lives, this conversation offers both a critical reflection on GDPR’s first seven years and foresight into its future role in AI and trust.


 KEY CONVERSATIONS 

00:03:25 Panelist Introductions and Initial Thoughts on GDPR 

00:09:06 Significant challenge that remains in up to 7-9 years of GDPR 

00:18:10 Has there been a fair amount of reporting on compliance failures over the years? 

00:21:11 EU Compliance Gaps and How Companies Can Avoid Them  

00:29:56 Has the GDPR has been successful in balancing the power equilibrium of organization and data subjects?  

00:35:35 Role of trust after 7 years of GDPR  

00:41:39 From GDPR compliance in AI World, what can be done additionally?

 

ABOUT GUEST 

Heidi Waem is the head of the data protection practice at DLA Piper Belgium and specialized in data protection and privacy. She assists clients with all aspects of EU Regulatory Data Protection compliance including the ‘structuring’ of data processing and sharing activities to achieve an optimal use of data, advising on data transfers and the processing of personal data by means of new technologies (AI, facial recognition,…).


Dr. Cari Miller is the Principal and Lead Researcher for the Center for Inclusive Change. She is a subject matter expert in AI risk management and governance practices, an experienced corporate strategist, and a certified change manager. Dr. Miller creates and delivers AI literacy training, AI procurement guidance, AI policy coaching, and AI audit and assessment advisory services.


Dr. Valerie Lyons is a globally recognized authority in privacy, cybersecurity, data protection, and AI governance. Holding a PhD in Information Privacy along with CDPSE, CISSP, and CIPP/E certifications, she serves as a trusted strategic advisor to regulatory bodies and organizations across both public and private sectors. Valerie has played an influential role in shaping EU-wide data protection frameworks and enforcement strategies, and is an active member of the European Data Protection Board’s pool of experts.


ABOUT HOST

Punit Bhatia is one of the leading privacy experts who works independently and has worked with professionals in over 30 countries. Punit works with business and privacy leaders to create an organization culture with high privacy awareness and compliance as a business priority. Selectively, Punit is open to mentor and coach professionals.

 

Punit is the author of books “Be Ready for GDPR' which was rated as the best GDPR Book, “AI & Privacy – How to Find Balance”, “Intro To GDPR”, and “Be an Effective DPO”. Punit is a global speaker who has spoken at over 30 global events. Punit is the creator and host of the FIT4PRIVACY Podcast. This podcast has been featured amongst top GDPR and privacy podcasts.

As a person, Punit is an avid thinker and believes in thinking, believing, and acting in line with one’s value to have joy in life. He has developed the philosophy named ‘ABC for joy of life’ which passionately shares. Punit is based out of Belgium, the heart of Europe.

 

RESOURCES

Websites ⁠⁠www.fit4privacy.com⁠⁠,⁠⁠www.punitbhatia.com⁠⁠, ⁠⁠https://www.linkedin.com/in/heidiwaem/⁠⁠, ⁠⁠https://www.linkedin.com/in/cari-miller/⁠⁠, ⁠⁠https://www.linkedin.com/in/valerielyons-privsec/⁠⁠ , https://growskills.store/

Podcast⁠⁠ ⁠⁠⁠⁠https://www.fit4privacy.com/podcast⁠⁠ 

Blog ⁠⁠https://www.fit4privacy.com/blog⁠⁠ 

YouTube ⁠⁠http://youtube.com/fit4privacy⁠⁠

Insights ⁠⁠⁠https://growskills.store/insights/⁠⁠⁠

ISO Standard Courses at ⁠⁠⁠https://growskills.store/courses⁠⁠ 


Punit Bhatia, an expert in artificial intelligence, privacy, and sourcing, hosts The FIT4Privacy Podcast-AI and Privacy insights in collaboration with Grow Skills Store. Here, the often complex and rapidly changing worlds of data protection and AI are broken down into clear, practical conversations. Each episode delves into specific frameworks like GDPR and ISO standards, while also examining the broader ethical implications and the critical need for digital trust in modern business. The discussions go beyond theory, focusing on actionable insights that professionals can apply directly to their own management and operational challenges. This podcast serves as a vital resource for business leaders and managers navigating this landscape, featuring regular conversations with a variety of industry experts. The dialogue is grounded in real-world application, whether discussing evolving EU regulations or the practical intersection of AI and privacy law. Recognised for its quality, the series consistently ranks highly in its categories. For anyone looking to deepen their understanding of these crucial topics, this podcast offers a reliable and insightful guide through the complexities of compliance, ethics, and technology.
Author: Language: en-gb Episodes: 100

The FIT4Privacy Podcast | Exploring ISO Standards AI Privacy | Grow Skills Store
Podcast Episodes
How to Protect Identity & Eliminate Threats [not-audio_url] [/not-audio_url]

Duration: 8:03
🔐 Identity protection has always been at the heart of security and privacy — but in today’s AI-driven world, the threats are evolving faster than ever. In this episode of the Fit4Privacy Podcast, host Punit Bhatia speaks…
Class Action Litigation [not-audio_url] [/not-audio_url]

Duration: 7:04
What happens when your personal data is misused or stolen — can you really take a company to court? 🤔 Can you really take on a big tech company through a class action lawsuit? And if you win, what do you actually get—com…
Future of privacy in 2045 or 2050 [not-audio_url] [/not-audio_url]

Duration: 9:56
In this episode, we explore the intriguing balance between innovation and data privacy as we approach the AI Age. How will future technologies like AI, digital neural networks, and large language models reshape our world…
Why does EU AI Act matter in your business? [not-audio_url] [/not-audio_url]

Duration: 1:59
In this episode of the FIT4Privacy Podcast, host Punit Bhatia explores the EU AI Act— why it matters, what it requires, and how it impacts your business, even outside the EU.You will also hear about the Act’s risk-based…
Governance, Management & Frameworks in the Age of AI [not-audio_url] [/not-audio_url]

Duration: 7:44
What’s the difference between governance and management—and why do both matter in the world of AI?In this episode of the FIT4PRIVACY Podcast, Mark Thomas joins Punit Bhatia to unpack the core ideas behind governance, man…