UK law
Reorganisation of government tech and digital departments announced
The UK government has announced a significant reorganisation of Whitehall aimed at strengthening economic growth, devolution and the strategic centre of government. Among other things, a new AI Taskforce is being created to oversee AI strategy and adoption across the public sector. The Department for Science, Innovation and Technology will be dissolved, with its functions redistributed, with responsibility for AI strategy, public sector AI adoption and the AI Security Institute moving to the Cabinet Office and science and innovation functions transferring to the renamed Department for Business, Innovation, Science and Trade (DBIST). Meanwhile, DCMS will take on expanded digital, online safety and digital inclusion responsibilities. A new AI minister will attend Cabinet.
UK government calls for evidence on data regulation in the age of AI
The UK government has issued a call for evidence which seeks practical examples of how personal and non-personal data regulation interacts with AI and other data-intensive technologies, and insights on how technological progress may change how data is used in the economy. The government is interested in where legal, technical, and governance arrangements could enable data use and re-use and manage potential harms. It wants to understand what is working well, where uncertainty remains, and where there is perceived friction or challenge now and in future. This will help the government to assess whether further guidance, targeted changes or more fundamental reform is needed. The call for evidence ends on 9 September 2026.
Ofcom updates on online suicide forum investigation and review of enforcement powers
Ofcom has announced that its enforcement action against an overseas suicide forum has achieved the maximum outcome currently possible under the Online Safety Act: the forum has now implemented a geoblock that prevents the vast majority of UK users from accessing the site without a VPN. The regulator had previously found the forum, which has reportedly been linked to more than 130 UK deaths, in breach of its duties to protect users from illegal suicide content and imposed a £950,000 fine. However, Ofcom concluded that there are no further legal grounds to seek a court order requiring UK internet providers to block the site because the forum is now considered compliant for UK users and any additional changes would affect users outside the UK’s jurisdiction. Ofcom will continue to monitor the geoblock, pursue recovery of the unpaid fine, and work with the UK government to consider whether its enforcement and business disruption powers under the Online Safety Act should be strengthened.
Herefordshire employee handed suspended sentence for illegally accessing personal information
A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence after an investigation by the ICO. The unlawful conduct was discovered after concerns were raised within the council about potential unauthorised access to a referral case, prompting an investigation into other records he had accessed. That investigation revealed that, over a four-day period, Smith unlawfully accessed approximately 490 records and downloaded 94 documents. The records related to his family members and families known to him and included children and adults. The records accessed involved highly sensitive material such as medical records, social worker reports and child and family assessments. On 27 May 2026, Smith pleaded guilty to an offence under Section 1 of the Computer Misuse Act 1990, relating to the unlawful accessing of personal data held on computers. Smith was sentenced at Worcester Magistrates’ Court following a hearing on Friday 17 July to two months imprisonment suspended for 12 months, 120 hours unpaid work, £2000 costs plus a victim surcharge of £154.
EU law
European Commission provides guidance to Google for AI interoperability on Android and sharing of Google Search data under the Digital Markets Act
The European Commission has issued two sets of binding specification measures to Google under the Digital Markets Act. Commission provides guidance to Google for AI interoperability on Android and sharing of Google Search data under the Digital Markets Act. The aim of the first specification measures is to ensure that competitors’ Artificial Intelligence (AI) services can compete with Google’s own AI services, such as Gemini, by having equal access to features on Google’s Android devices. The aim of the second specification measures is to rebalance the playing field by giving third-party search engines access to search data that only Google Search can collect at scale.
European Commission launches second-phase consultation of social partners on Quality Jobs Act
The European Commission has launched the second-phase consultation of European social partners on its upcoming Quality Jobs Act. Among other things, the consultation focuses on algorithmic management and artificial intelligence at work to ensure transparency, human centricity in automated decision-making and protecting employees from excessive monitoring. The consultation ends on 28 September.
European Commission finds that Republic of Korea continues to provide an adequate level of protection of personal data
The Commission has concluded its first review of the 2021 adequacy decision for the Republic of Korea, which allows the free flow of personal data from the EU to this country. The review confirms that the Republic of Korea continues to provide an adequate level of protection for personal data transferred from the EU. The EU and Korean data protection frameworks have converged further, notably following amendments to South Korean law that strengthened the rights of data subject. The report also lays out recommendations to further reinforce some of the safeguards provided by the South Korean framework, with respect to data transfers to third countries and enforcement.#
Council of the EU reinstates interim measures protecting children
The Council of the EU has given its final green light to a regulation allowing online service providers to resume voluntary detection and removal of child sexual abuse material on their platforms. The measure is temporary and aims to protect children while a long-term legislative framework is under negotiation. The measure constitutes a derogation from data protection rules in the electronic communications sector. This derogation allows online service providers to detect online child sexual abuse on their services, as well as to report and remove it. The Council’s decision to support the rules as amended by the European Parliament follows from the need to act swiftly and to fill the legal gap after the previous interim measure expired on 3 April 2026. The measure will be reinstated until 3 April 2028.