23andMe fined £2.31 million for failing to protect UK users’ genetic data

The ICO has fined genetic testing company 23andMe £2.31 million for failing to implement appropriate security measures to protect the personal information of UK users, following a large-scale cyber-attack in 2023. The penalty follows a joint investigation conducted by the ICO and the Office of the Privacy Commissioner of Canada. Between April and September 2023,…

Read More… from 23andMe fined £2.31 million for failing to protect UK users’ genetic data

AI Data Leaks & Shadow AI: The Legal Minefield Facing UK Organisations in 2025

Camilo Artiga-Purcell, General Counsel at Kiteworks, identifies some of the ever-increasing risks and potential consequences of rushing to use AI in legal practice Picture a partner at a leading UK law firm, racing to finalise a high-stakes merger. With a deadline looming, they turn to a free online AI tool, uploading sensitive deal documents for…

Read More… from AI Data Leaks & Shadow AI: The Legal Minefield Facing UK Organisations in 2025

ICO consults on guidance for consumer Internet of Things products and services

The ICO is consulting on new guidance for smart products. It points out that from smart speakers and fitness trackers to Wi-Fi fridges and interconnected air fryers, smart products often collect large amounts of personal information from users, including sensitive information, so manufacturers and developers must ensure their products are designed with data protection in…

Read More… from ICO consults on guidance for consumer Internet of Things products and services

Super-complaints regime for online safety due to come into force on 31 December 2025

The Online Safety Act 2023 established the basis for creation of an online safety super-complaints regime. The process will allow for complaints about systemic issues (features or conduct of regulated services) to be raised with the regulator where those issues are, appear to be, or present a material risk of: For the online safety super-complaints…

Read More… from Super-complaints regime for online safety due to come into force on 31 December 2025

This Week’s Techlaw News Round-Up

UK law Data (Use and Access) Bill finally passes through Parliament and heads for Royal of Assent The Data (Use and Access) Bill finally completed its passage through the UK parliament on 11 June 2025. It was the third attemot at data protection reform in the UK and this final attempt was subject to a…

Read More… from This Week’s Techlaw News Round-Up

Ofcom opens nine new investigations under Online Safety Act 2023

Ofcom has opened formal investigations into online discussion board 4chan and seven file-sharing services – Im.ge, Krakenfiles, Nippybox, Nippydrive, Nippyshare, Nippyspace and Yolobit.  Ofcom has not received responses to its statutory information requests, to which services are legally required to respond. It also says that it has received complaints about the potential for illegal content…

Read More… from Ofcom opens nine new investigations under Online Safety Act 2023

Ofcom’s strategic approach to AI

Ofcom has issued a report how it is supporting the safe innovation and use of artificial intelligence across the sectors it regulates, and streamlining the way it works. Smarter communications The industries Ofcom regulates have technology and innovation at their heart. As technologies evolve, new opportunities emerge that have the potential to drive better outcomes…

Read More… from Ofcom’s strategic approach to AI

Amazon gives undertakings to CMA regarding fake online reviews

Under the Digital Markets, Competition and Consumers Act 2024, fake reviews are a blacklisted commercial practice which is always unfair.  The CMA issued guidance on fake reviews in April. Under the DMCC Act, the CMA can now decide independently whether consumer law has been infringed, rather than going through the courts. It can also tackle…

Read More… from Amazon gives undertakings to CMA regarding fake online reviews

EDPB publishes final version of guidelines on data transfers to third country authorities and SPE training material on AI and data protection

During its latest plenary, the European Data Protection Board (EDPB) adopted the final version of its guidelines on Article 48 GDPR about data transfers to third country authorities. The EDPB also discussed the European Commission’s request for a joint EDPB-EDPS opinion on the draft proposal on the simplification of record-keeping obligation under the GDPR. Finally,…

Read More… from EDPB publishes final version of guidelines on data transfers to third country authorities and SPE training material on AI and data protection

Law Commission seeks views about the law on digital assets and (electronic) trade documents in private international law

In recent years, a significant aspect of the Law Commission’s work has focused on emerging technologies, including smart legal contracts, electronic trade documents, decentralised autonomous organisations (DAOs) and digital assets such as crypto tokens. These developments often rely on distributed ledger technology (DLT). It is now consulting on proposals for law reform. It focuses primarily…

Read More… from Law Commission seeks views about the law on digital assets and (electronic) trade documents in private international law