This week’s Tech-law round-up

UK law ICO fines South Staffordshire plc and South Staffordshire Water plc £963,900 following cyberattack and data breach The Information Commissioner’s Office (ICO) has fined South Staffordshire plc and South Staffordshire Water plc £963,900. This follows a cyberattack and data breach which led to the personal information of 633,887 customers and employees being extracted and published…

Read More… from This week’s Tech-law round-up

ICO publishes final storage and access technologies guidance

The ICO has published its finalised guidance on Storage and Access Technologies. The guidance, which covers how the Privacy and Electronic Communications Regulations 2002 (PECR) (and where relevant, the UK GDPR) apply to cookies, tracking pixels, device fingerprinting and similar technologies (‘storage and access technologies’), incorporates updates following two consultations and changes introduced by the…

Read More… from ICO publishes final storage and access technologies guidance

This week’s Tech-law round-up

UK law Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 made The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 SI 2016/425 have been made. They require the Information Commissioner to prepare a code of practice on the processing of personal…

Read More… from This week’s Tech-law round-up

Court of Appeal clarifies consent standard in gambling advertising case

In RTM -v- Bonne Terre Limited and another [2026] EWCA Civ 488, the Court of Appeal has clarified that the test for whether consent has been lawfully given under data protection law is objective, not subjective, overturning a High Court decision concerning targeted gambling advertising. In other words, the focus is on what the data…

Read More… from Court of Appeal clarifies consent standard in gambling advertising case

TABLE: Enforcement action & publicity for not using BCC

BCC errors still cause a good deal of regulatory intervention. Dr W Kuan Hon has catalogued some below. This table supplements an article on the data protection risks of not using BCC available here. Below, in reverse chronological order of decision publication date, are selected (non-exhaustive) examples, as at March 2026, of incidents where emails…

Read More… from TABLE: Enforcement action & publicity for not using BCC