This week’s Tech-law round-up

July 17, 2026
UK law

IPO updates guidance on Search and Examination of UK Patent Applications under the Patents Act 1977

The Intellectual Property Office has issued guidance which explains how patent applications should now be examined following the UK Supreme Court’s decision in Emotional Perception AI v Comptroller-General of Patents. The guidance replaces the long-standing Aerotel approach with a new three-step framework aligned more closely with European Patent Office practice. Examiners must first determine whether a claim qualifies as an invention using an “any hardware” test, then identify which claim features contribute to the invention’s technical character, and finally assess novelty and inventive step by considering only those technically contributing features. The guidance is particularly significant for computer-implemented inventions and AI-related technologies, as the Supreme Court confirmed that artificial neural networks (ANNs) can constitute computer programs, while also emphasising that inventions involving computer hardware will generally clear the initial patent eligibility hurdle, with the key scrutiny shifting to whether the claimed technical features provide a non-obvious technical contribution.

ICO consults on corporate strategy

The Data Use and Access Act 2025 confirmed the ICO’s transition from a single Information Commissioner model to a Commission structure with a non-executive Chair, Board and separate CEO. This change modernises the ICO, strengthening resilience and bringing greater diversity to its strategic direction. This strategy aims to provide a bridge from the present Information Commissioner’s Office “ICO25” strategy to its future Information Commission governance model. It provides direction and clarity to ICO stakeholders and staff during an important transition for the organisation. The ICO is gathering views on its draft purpose, strategic outcomes, and regulatory and transformation priorities. The consultation closes on 23 August 2026.

ICO issues guidance on using personal information to prevent crime

The ICO’s guidance explains that businesses can use personal information, including CCTV footage, to prevent, investigate and respond to crime such as theft, violence or abuse, but must comply with data protection law when handling “criminal offence data” (information about actual or suspected criminal activity). Businesses may share relevant information with the police and, where necessary and proportionate, with colleagues or partner stores to manage risks, provided they limit the information shared, ensure accuracy, control access and maintain appropriate documentation such as a data protection impact assessment (DPIA) and appropriate policy document (APD). The ICO makes clear that publicly posting images of suspected offenders on social media will rarely be justifiable, whereas sharing information through formal business crime reduction partnerships may be appropriate. The guidance also highlights the higher compliance threshold for facial recognition technology, which should only be used where it is necessary, proportionate and supported by robust safeguards. Overall, the ICO emphasises balancing crime prevention with individuals’ privacy rights through lawful, fair and secure use of personal information.

Ofcom fines porn company £630,000 for age check failings

Ofcom has fined the operator of pornographic website fapello.com a total of £630,000 under the Online Safety Act: £600,000 for failing to implement legally required age-checking measures to prevent children from accessing pornographic content, and £30,000 for failing to respond to a legally binding information request from the regulator. Ofcom said robust age assurance is a key requirement of the Act and stressed that compliance is no longer optional. Following enforcement action, the website has blocked access from UK IP addresses. Ofcom has also launched a new investigation into another pornography provider, Bit Hive (eporner.com), over concerns that one of its age-verification methods may not be sufficiently effective, and has expanded an existing investigation into kemono.cr.

Ofcom investigates TikTok under Online Safety Act

Ofcom has opened an investigation into TikTok under the Online Safety Act 2023 to assess whether it is meeting its legal duties to protect children from harmful content. The regulator will examine whether TikTok has implemented proportionate systems and processes to prevent children from encountering harmful material and whether its age assurance measures are sufficiently effective at identifying child users. The investigation follows Ofcom’s review of major platforms, concerns raised in its recent report on children’s online experiences, and findings suggesting that age inference tools may have failed to identify a significant proportion of children accurately, potentially exposing them to harmful content. Ofcom stresses that opening the investigation does not mean it has concluded that TikTok has breached the law, but if non-compliance is found it could impose fines of up to £18 million or 10% of global turnover, and in serious cases seek court orders to restrict the platform’s operations in the UK.

UK government announces social media curfew for 16-17 year olds

The UK Government has announced new online safety measures for 16 and 17-year-olds, including default overnight social media curfews from midnight to 6 am and the automatic disabling of potentially addictive features such as autoplay and highly personalised recommendation feeds. The measures are intended to ensure that teenagers do not lose online protections when they turn 16, following the planned ban on social media services for under-16s from spring 2027. The Government says the changes are designed to improve sleep, concentration and wellbeing while still allowing older teenagers to adjust their settings if they choose. The announcement also signals further action on AI safety, including proposals for mandatory breaks for under-18s using chatbots, potential restrictions on AI services providing mental health advice, and enhanced media literacy education in schools to help young people navigate AI, misinformation and harmful online content.

Ofcom announces new rules to thwart text message scammers

Ofcom has announced a package of new rules and guidance aimed at reducing mobile phone scams by requiring telecoms providers to take stronger measures to detect, block and disrupt fraudulent text messages and spoofed calls. The measures target both person-to-person scams and business messaging scams, requiring providers to block known scam numbers, detect and stop malicious messages in transit, impose volume limits on pay-as-you-go SIM cards, and carry out enhanced due diligence on businesses using mass messaging services. Ofcom is also strengthening its guidance on international calls that falsely display UK mobile numbers, a tactic frequently used by overseas fraudsters to gain victims’ trust. The regulator says the changes, alongside wider government and industry anti-fraud initiatives, are intended to provide greater protection for consumers and businesses from a form of crime that accounts for a significant proportion of reported fraud in the UK.

EU law

European Commission accepts X’s action plan to comply with Digital Services Act

The European Commission has accepted X’s action plan to comply with transparency obligations and researchers’ access to data under the Digital Services Act. Following the Commission’s decision that X is in breach of the DSA and a fine in December 2025, X committed to improving its advertising repository with better search features and faster response times. It will also publish more information about advertisements and enable access via an API. X will also give eligible researchers effective access to public data by improving and speeding up the screening process for applications, giving access to data free of charge, and updating its terms to refrain from contractually prohibiting eligible researchers from scraping public data. An independent external audit will assess these changes, and X will submit the results to the Commission. If the audit identifies recommendations, X will need to implement them fully. The Board for Digital Services was consulted on these measures and expressed concerns about X’s audit measures. Consequently, the Commission has clarified several points that X must consider in implementing the action plan. X has six months to implement the measures set out in its action plan and must then issue, and submit to the Commission, an audit of the measures. The Commission will closely monitor progress, in particular on the issues raised by the Board. The Commission will also regularly update the Board and the Digital Services Coordinators on the implementation of the action plan and on its ongoing monitoring activities.

CJEU rules that publication of professional athletes who have infringed anti-doping rules may be compatible with EU law

The Court of Justice of the EU has ruled in Case C-474/24 | NADA Austria and Others that publishing the names of professional athletes who breach anti-doping rules, together with details of their ban and the reasons for it, can be compatible with the GDPR because combating doping is an objective of general public interest and publication can help deter misconduct and reinforce the effectiveness of sanctions. However, the Court stressed that publication is not automatic: the responsible body must carry out a case-by-case balancing exercise to ensure the publication is proportionate and complies with data protection rules, including limiting publication to an appropriate period. The Court also clarified that anti-doping offences and sanctions are generally not equivalent to criminal convictions under the GDPR, and that athletes must have the opportunity to challenge imminent publication before the competent data protection authority. The ruling arose from a challenge by four athletes to Austrian legislation requiring anti-doping sanctions to be published online.

CJEU rules merely placing criminal conviction data online does not in principle constitute processing of personal data for ‘journalistic purposes’

In Legal Newsdesk Sweden (C‑199/24), the Court of Justice of the EU ruled that a commercial database which publishes criminal conviction decisions online in return for payment will not, in principle, qualify as processing of personal data for “journalistic purposes” under the GDPR. The case arose after an individual sought damages when information about a 2011 criminal conviction remained accessible through a Swedish database. The Court held that while Member States may create GDPR exemptions to protect freedom of expression and journalism, they cannot exclude GDPR protections for processing carried out for other purposes or deprive individuals of the GDPR remedies available to them. The Court indicated that processing will only be regarded as journalistic where its purpose is to inform the public and where the material is prepared and presented in accordance with journalistic standards, including verification of facts and editorial oversight. Simply making court decisions available online for payment does not appear to satisfy those requirements, leaving the operator subject to the GDPR and affected individuals entitled to exercise the rights and remedies provided by the Regulation.