This week’s Tech-law round-up

June 30, 2026
UK law

UK government publishes Media Green Paper

The UK government has published a Media Green Paper setting out proposals to modernise the public service media (PSM) regime, with a particular focus on increasing the prominence of trusted news sources on social media and online platforms to counter misinformation. It is consulting on measures that could require platforms to make content from public service broadcasters, such as the BBC, ITV and Channel 4, and other reliable publishers more visible and discoverable, alongside broader reforms to give PSM providers greater flexibility in an increasingly digital, on-demand viewing environment. The proposals also include extending protections for major sporting events to on-demand services, introducing potential media literacy obligations, and planning for a long-term transition from terrestrial TV to internet-based delivery, potentially by 2034 or 2044, with safeguards to ensure audiences are not excluded.  In addition, Ofcom has issued a series of recommendations on how broadcasters, online platforms and streamers should promote media literacy. 

ICO fines firm £300,000 for sending over 5.5 million unlawful texts

The ICO has fined KRA Consultancy Ltd (KRA) £300,000 after it targeted people who were already in financial difficulty with unlawful spam texts, including fake bailiff messages. KRA sent 5,575,715 unsolicited direct marketing texts between April 2022 and May 2025, promoting debt solutions to people who had already been turned down for loans. This led to more than 60,000 complaints to the ICO and Mobile UK’s 7726 spam reporting service. KRA also sent fabricated bailiff threats designed to frighten recipients into engaging with its debt services. During the investigation, search warrants were executed, but KRA resumed its unlawful marketing activity afterwards, leading to 161 new complaints. The ICO says that KRA deliberately tried to evade detection and contacted a telecoms provider based in China seeking assurances that the mass text messages would be “completely untraceable”. KRA also made no attempt to check whether the loan decline data was accurate or whether recipients had consented to receive marketing messages. Alongside the monetary penalty, the ICO issued an enforcement notice ordering KRA to stop sending marketing messages without consent within 30 days. KRA was also not registered with the Financial Conduct Authority, despite directing people towards debt solutions.

ICO issues report on edtech

The ICO has worked directly with edtech providers to review and improve data protection practices in the sector. It has now issued a report setting out the findings from a programme of audits carried out during 2024 and 2025 with 28 edtech providers whose products are widely used across primary and secondary schools in the UK. In addition to information security issues, common concerns included insufficiently detailed contracts with schools; incomplete data-flow mapping; weak application of data minimisation and storage limitation principles; outdated or inaccessible privacy information; and gaps in data protection impact assessments.

Extending online marketplace liability to combat VAT non-compliance

In 2021, the previous UK government introduced reforms to improve VAT compliance in the online marketplace sector, making marketplaces liable for VAT on certain sales by overseas sellers. These reforms have improved compliance and helped tackle VAT losses. However, non-compliance persists among both overseas and UK-based businesses, distorting competition and disadvantaging compliant firms online and on the high street. The government is now consulting on extending marketplace liability to cover sales by UK businesses via these platforms, including domestic sales of goods such as retail items and takeaway food, to further tackle non-compliance. The consultation seeks views on design features, including how to minimise the impact on businesses not required to register for VAT. It also seeks evidence on the administrative, commercial and operational impact of the proposals on online marketplaces and businesses. The consultation ends on 18 August 2026.

Ofcom publishes statement on changes to illegal harms guidance and regulatory documents

Ofcom has published a statement setting out changes to the Illegal Harms regulatory documents and guidance under the Online Safety Act. In December 2025, the government created two new priority offences under the Act: encouraging or assisting serious-self harm, and cyberflashing. Ofcom’s statement sets out the changes to its regulatory documents and guidance to reflect this change in law. It describes Ofcom’s decisions to combine the offence of encouraging or assisting suicide and the offence of encouraging or assisting serious self-harm into a single kind of illegal harm, ‘suicide and self-harm’, and to include cyberflashing as a new, and separate, kind of illegal harm. As a result, providers of regulated services must review and update their illegal content risk assessments, to assess the risks of the new kinds of illegal harm on their service. Providers need to assess both suicide and self-harm and assign one overall risk level for ‘suicide and self-harm’, and separately risk assess for cyberflashing.  The amendments to the Codes will be implemented separately. Subject to them completing the Parliamentary process, providers will need to take the safety measures set out in the Codes or use other effective measures to protect users from illegal content and activity. Ofcom has published draft consolidated versions of the Codes. Taken together, these updates strengthen protections for users from the risks of harm arising from self-harm and cyberflashing, for example, by extending existing safety measures to apply to services at risk of these harms. The updates are designed to improve how services identify, assess and mitigate risks, and are aimed at facilitating a significant impact on user safety across a range of online services. 

EU law

European Parliament agrees position on digital euro

The European Parliament’s Economic and Monetary Affairs Committee has adopted a position on proposals for a digital euro, emphasising that it should provide a secure, private and free-to-use payment option that complements cash while supporting EU sovereignty and reducing reliance on non-EU providers. The proposed central bank digital currency, issued by the European Central Bank, would work both online and offline, with offline functionality akin to cash; incorporate strong “privacy by design” safeguards, including limited data use and technologies such as zero-knowledge proofs; and be distributed through a wide range of payment service providers, with most businesses required to accept it. To mitigate financial stability risks, holding limits would apply and the digital euro would be non-interest bearing, while basic services for users would be free and merchant fees capped. The Committee also calls for for extensive pilot testing, a phased roll-out and public awareness campaigns ahead of launch, alongside related measures to preserve access to cash and enable participation by non-euro member states. The negotiating mandates will be announced at the start of the European Parliament’s plenary session in July. The final legislation will have to be negotiated with the Council before coming into force.