36

11. The Right Compound for the Conditions

Privacy Culture | July 23, 2026

The Observation

The first ten observations describe what is happening. This final point addresses what to do about it. AI does not remove the need for technical and organisational measures under Articles 25 and 32 of the UK GDPR, it intensifies it. When personal data enters AI workflows, the surface area for processing expands. Data may be used for inference, combined with other datasets retained in model context, or passed through sub-processors that the controller has never assessed.

Privacy-enhancing technologies, including differential privacy, synthetic data generation, federated learning, homomorphic encryption and data minimisation at ingestion, move from nice to have to operationally essential when AI is involved. But tyre compound selection is perhaps the single most consequential technical decision in a race and it only works if you understand the surface you are deploying it on, track temperature, degradation profile and whether rain is coming. A team on the wrong tyre compound is not under equipped, as they may have the best rubber available, it is just not the right choice for this surface, today, at this temperature. The same compound that delivers a dominant strategy in one race destroys itself two stints into the next.

Selecting the right PET for the right processing activity is therefore not a technology decision alone. It is a data architecture decision that depends entirely on understanding what you have, where it flows and what it is being used for. Without that inventory, PET selection is guesswork. Organisations that have completed thorough data inventories can make confident, proportionate decisions about which privacy-enhancing technologies to deploy, where and why. Organisations that have not are left choosing between blocking AI adoption entirely or proceeding on assumptions they cannot evidence.

What This Means for Data Privacy

The practical sequence matters, inventory first, then risk assessment, then proportionate technical measures. Selecting PETs without a current data inventory is choosing your compound before you know the track conditions. You might get lucky but more often, you will be managing graining by lap three. We consistently see organisations attempting to select PETs or design AI governance frameworks without a current, accurate picture of their data landscape. The result is either over-engineering, applying expensive technical controls to low-risk processing, or under-engineering, missing high-risk data flows entirely because they were not mapped.

It may be worth reviewing whether your current approach to technical and organisational measures has been updated to reflect AI-specific processing patterns. Traditional measures were designed for structured databases and defined workflows. AI introduces probabilistic processing, dynamic data combinations and context-dependent risk levels that may not fit neatly into existing frameworks. The DPOs and privacy teams we work with who have adapted most effectively tend to share one characteristic, they started with a thorough, current data inventory and built their AI governance architecture on top of that foundation, rather than attempting to retrofit controls onto processing activities they had not fully mapped.

The inventory-first approach also creates a natural review cycle. As new AI tools are adopted and data flows change, the inventory surfaces processing activities that need reassessment, keeping technical measures proportionate and current rather than static and increasingly disconnected from operational reality. You need to understand your conditions before you choose your kit.

Next Steps

We would welcome the opportunity to explore any of these themes in more depth with your team.

Each of the eleven observations in this briefing can be expanded into a focused workshop, assessment or advisory engagement tailored to your organisation's specific context and maturity.

Related Articles

Loading...