UK law Investigatory Powers Act 2016 codes of practice published Various codes of practice under the Investigatory Powers Act 2016 have been published. The codes of practice set out processes and safeguards for several investigatory powers. CMA consults on releasing Google from Privacy Sandbox commitments The Competition and Markets Authority is consulting on releasing Google…
23andMe fined £2.31 million for failing to protect UK users’ genetic data
The ICO has fined genetic testing company 23andMe £2.31 million for failing to implement appropriate security measures to protect the personal information of UK users, following a large-scale cyber-attack in 2023. The penalty follows a joint investigation conducted by the ICO and the Office of the Privacy Commissioner of Canada. Between April and September 2023,…
Read More… from 23andMe fined £2.31 million for failing to protect UK users’ genetic data
AI Data Leaks & Shadow AI: The Legal Minefield Facing UK Organisations in 2025

Camilo Artiga-Purcell, General Counsel at Kiteworks, identifies some of the ever-increasing risks and potential consequences of rushing to use AI in legal practice Picture a partner at a leading UK law firm, racing to finalise a high-stakes merger. With a deadline looming, they turn to a free online AI tool, uploading sensitive deal documents for…
Read More… from AI Data Leaks & Shadow AI: The Legal Minefield Facing UK Organisations in 2025
ICO consults on guidance for consumer Internet of Things products and services
The ICO is consulting on new guidance for smart products. It points out that from smart speakers and fitness trackers to Wi-Fi fridges and interconnected air fryers, smart products often collect large amounts of personal information from users, including sensitive information, so manufacturers and developers must ensure their products are designed with data protection in…
Read More… from ICO consults on guidance for consumer Internet of Things products and services
Super-complaints regime for online safety due to come into force on 31 December 2025
The Online Safety Act 2023 established the basis for creation of an online safety super-complaints regime. The process will allow for complaints about systemic issues (features or conduct of regulated services) to be raised with the regulator where those issues are, appear to be, or present a material risk of: For the online safety super-complaints…
Read More… from Super-complaints regime for online safety due to come into force on 31 December 2025
This Week’s Techlaw News Round-Up
UK law Data (Use and Access) Bill finally passes through Parliament and heads for Royal of Assent The Data (Use and Access) Bill finally completed its passage through the UK parliament on 11 June 2025. It was the third attemot at data protection reform in the UK and this final attempt was subject to a…
Ofcom opens nine new investigations under Online Safety Act 2023
Ofcom has opened formal investigations into online discussion board 4chan and seven file-sharing services – Im.ge, Krakenfiles, Nippybox, Nippydrive, Nippyshare, Nippyspace and Yolobit. Ofcom has not received responses to its statutory information requests, to which services are legally required to respond. It also says that it has received complaints about the potential for illegal content…
Read More… from Ofcom opens nine new investigations under Online Safety Act 2023
Ofcom’s strategic approach to AI
Ofcom has issued a report how it is supporting the safe innovation and use of artificial intelligence across the sectors it regulates, and streamlining the way it works. Smarter communications The industries Ofcom regulates have technology and innovation at their heart. As technologies evolve, new opportunities emerge that have the potential to drive better outcomes…
Amazon gives undertakings to CMA regarding fake online reviews
Under the Digital Markets, Competition and Consumers Act 2024, fake reviews are a blacklisted commercial practice which is always unfair. The CMA issued guidance on fake reviews in April. Under the DMCC Act, the CMA can now decide independently whether consumer law has been infringed, rather than going through the courts. It can also tackle…
Read More… from Amazon gives undertakings to CMA regarding fake online reviews
EDPB publishes final version of guidelines on data transfers to third country authorities and SPE training material on AI and data protection
During its latest plenary, the European Data Protection Board (EDPB) adopted the final version of its guidelines on Article 48 GDPR about data transfers to third country authorities. The EDPB also discussed the European Commission’s request for a joint EDPB-EDPS opinion on the draft proposal on the simplification of record-keeping obligation under the GDPR. Finally,…