
Finding it difficult to navigate the changing landscape of data protection? In this episode of the DMI podcast, host Will Francis speaks with Steven Roberts, Group Head of Marketing at Griffith College, Chartered Director, certified Data Protection Officer, and long-time marketing leader. Steven demystifies GDPR, AI governance, and the rapidly evolving regulatory environment that marketers must now navigate.
Steven explains how GDPR enforcement has matured, why AI has created a new layer of complexity, and how businesses can balance innovation with compliance. He breaks down the EU AI Act, its risk-based structure, and its implications for organizations inside and outside the EU.
Steven also shares practical guidance for building internal AI policies, tackling “shadow AI,” reducing data breach risks, and supporting teams with training and clear governance.
For an even deeper look into how businesses can ensure data protection compliance, check out Steven’s book, Data Protection for Business: Compliance, Governance, Reputation and Trust.
Steven’s Top 3 Tips
The Ahead of the Game podcast is brought to you by the Digital Marketing Institute and is available on YouTube, Apple Podcasts, Spotify, and all other podcast platforms.
And if you enjoyed this episode please leave a review so others can find us. If you have other feedback for or would like to be a guest on the show, email the podcast team!
Timestamps
01:29 – AI’s impact on GDPR & the explosion of new global privacy laws
03:26 – Is GDPR the global gold standard?
05:04 – GDPR enforcement today: Who gets fined and why
07:09 – Cultural attitudes toward data: EU vs. US
08:51 – The EU AI Act explained: Risk tiers, guardrails & human oversight
10:48 – What businesses must do: DPIAs, fundamental rights assessments & more
13:38 – Shadow AI, risk appetite & internal governance challenges
17:10 – Should you upload company data to ChatGPT?
20:40 – How the AI Act affects countries outside the EU
24:47 – Will privacy improve over time?
28:45 – What teams can do now: Tools, processes & data audits
33:49 – Data enrichment tools: targeting vs. Legality
36:47 – Will anyone actually check your data practices?
40:06 – Steven’s top tips for navigating GDPR & AI