9 min read

Data, privacy and cyber in July 2026: in case you missed it

Read more

By Hans Allnutt, Jade Kowalski, Peter Given and Justin Tivey

|

Published 13 August 2026

Overview

Our 'In Case You Missed It' section of the Data, Privacy and Cyber Bulletin provides readers with a high-level digest of important regulatory and legal developments from July 2026. 

Contents 

1. Case law updates

2. Regulatory developments

3. Data & privacy developments

4. Cyber developments

 

Case law updates 

Dale Vince v Associated Newspapers Limited [2026] EWCA Civ 899 

This action considered the circumstances in which a claim for unfair processing could be made under articles 5 and 82 of the UK GDPR. 

A newspaper group had published newsprint and online articles about the Claimant, which juxtaposed images of the Claimant alongside headlines highlighting inappropriate conduct unrelated to the Claimant. The High Court struck out a libel claim, and a subsequent claim alleging unfair processing on procedural grounds as an abuse of process, and also entering summary judgment for the newspaper group. The Claimant appealed. 

The Court of Appeal provided clarity on how data controllers should consider whether they are processing data fairly, potentially opening up a route for data subjects to challenge how controllers handle their personal data. 

Handing down leading judgment, the Master of the Rolls noted that "this claim is novel in that no such claim has ever, to the parties’ knowledge, succeeded before." The Court held that a claimant could pursue a claim for a breach of the duty to process data 'fairly'.

In terms of what was considered to be fair, he stated that it was “unnecessary and undesirable to lay down any generally applicable test". However, this would involve a consideration of context, the balance of interests between data controller and subject and the reasonable expectations of the data subject. 

The Claimant was granted summary judgment on the unfair processing claim, with damages to be assessed. The full judgment can be accessed here

 

Dr Liza Lovdahl Gormsen v Meta Platforms, Inc. and Others [2026] EWCA Civ 993 

The underlying action is pursued before the Competition Appeal Tribunal on behalf of a class of individuals who had Facebook accounts and accessed that account at least once whilst in the UK between 14 February 2016 and 6 October 2023.

The Class Representative alleges Meta abused a dominant position by imposing "take it or leave it" terms requiring users to hand over "Off-Facebook Data" for advertising monetisation without payment. For the purposes of the action, Off-Facebook Data "comprises data concerning users’ activities off Facebook’s social network platform, including in particular data on user activity from: (i) other Meta products and services (such as Instagram); and (ii) third-party websites and apps visited. 

Meta challenged a decision in the Court of Appeal that 'user damages', which are identified as compensation for the wrongful use of a valuable asset, are available for breaches of section 18 of the Competition Act 1998. Section 18 prohibits the abuse of a dominant position by the imposition of unfair selling and purchasing terms. The CAT had previously granted permission for the pleadings to be amended to add that claim. 

Meta's appeal was dismissed, and the Court of Appeal judgment can be accessed here

 

Regulatory developments 

Cyber Security and Resilience Bill moves to report stage 

The Cyber Security and Resilience (Network and Information Systems) Bill successfully passed second reading on 14 July 2026 in the House of Lords. Report stage is due to commence in early September 2026. 

The debate at second reading indicated that support for the Bill is not universal, with concerns expressed that the legislation does not sufficiently respond to AI-enabled cyber attacks and quantum computing risks. Other concerns related to the focus of the Bill, and that important sectors, including parts of the private sector, and local authorities are not covered. 

The second reading debate can be accessed here.

 

House of Commons Defence Committee publishes report addressing Afghan data breach 

The report sets out a series of conclusions and recommendations (page 68-69) in respect of the data breach, setting out that the data breach was directly caused by undetected hidden data within an Excel file sent to a third party without adequate checks, despite existing Ministry of Defence and central government guidance on this issue. This was considered a foreseeable systemic failure. 

Ownership of the data protection risk was inadequate before the breach. The subsequent injunction meant that ordinary ministerial accountability was paused for nearly two years, this meant that responsible ministers had left office before facts could be scrutinised. 

The report recommends that the government should mandate and enforce minimum standards for skills, process, tools, controls, and independent assurance/testing for datasets where a compromise or breach could plausibly endanger life. 

 

Google fined EUR890 million for breaches of the Digital Markets Act 

At the time of writing, Google has yet to confirm whether it intends to appeal a fine issued by the European Commission for alleged breaches of the Digital Markets Act. 

The Commission found that Google gives preferential treatment to its own services, including shopping, hotels, transport, and sports results, over those of third parties in Google Search. Further, the Commission found that Google failed to comply with its obligations under the DMA by preventing app developers from communicating and promoting offers via alternative channels, including third-party app stores. 

The Commission press release can be found here

 

EDPB adopts draft guidelines on anonymisation 

The European Data Protection Board ("EDPB") has adopted draft guidelines on anonymous data, taking into account the CJEU decision in EDPS v SRB in 2025. The guidelines are open for public consultation until 30 October 2026. 

The guidelines are intended to provide a framework for organisations to determine if anonymisation is successful. The framework uses 3 criteria to determine if data is anonymous, namely no record isolation, no linkage and no inference. 

The guidelines can be accessed here.

 

EDPB adopts draft guidelines on web scraping in the context of generative AI 

The European Data Protection Board ("EDPB") has adopted draft guidelines on web scraping in the context of generative AI. The draft guidelines can be accessed here, and providing clarification on various aspects of the GDPR compliance of web scraping, including the legal basis for such activities and the conditions under which special categories of data can be processed in this context. 

The EDPB guidelines also provide clarifications and examples on the use of the legitimate interest legal basis in the specific context of web scraping for AI training. 

The guidelines are also open for public consultation until 30 October 2026. 

 

Data & privacy developments 

Call for evidence issued on data regulation in the age of AI 

The former Department for Science, Innovation, and Technology announced an open call for evidence considering how personal and non-personal data regulation interacts with AI, and other data-intensive technologies. The call for evidence closes on 9 September 2026. 

The call for evidence seeks practical examples of how organisations access, prepare and use data (both personal and non-personal) in these circumstances, and how organisations approach questions of data quality and accuracy. Finally, the call for evidence seeks insights on how technological progress may change how data is used in the economy, and whether existing governance frameworks may be sufficient. 

The above call for evidence is one of a number forming part of the government's data policy development. Two other calls were simultaneously launched covering data flows you can trust, and the marginal cost restriction on public sector data re-use

 

ICO publishes Annual Report for 2025/26 

The ICO published its Annual Report covering the past year. From a statistical perspective, the report confirms that data protection complaints, FOI complaints and data breaches reported had all increased significantly on the previous years figures.

The report discusses progress made in implementing the Data (Use and Access) Act, including the introduction of the new data protection complaints process for organisations, steps to move towards the new UK Information Commission governance structure, and the introduction of new regulatory powers such as higher PECR fines, and compelling witnesses to attend interviews. 

In anticipation of the change to the board-led governance model, the appointment of seven Non-Executive Directors to the Information Commission was announced.

 

ICO commences consultation on draft corporate strategy  

The ICO announced a consultation on its draft corporate strategy that will provide a bridge between its ICO25 strategy to the future Information Commission governance model. The draft corporate strategy can be found here. The consultation on the contents will close on 23 August 2026. Interested parties can be respond here

The regulatory priorities proposed include building and strengthening cyber resilience, promoting trust and transparency in AI, and ensuring that personal data use helps, not harms, children. 

 

ICO publishes report on evolving regulatory sandboxes 

As part of the ICO's commitments to government, the ICO has worked with the Regulatory Innovation Office to research the viability of establishing a Statutory Regulatory Sandbox (SRS) for data protection. The introduction of the proposed SRS would allow time-limited flexibility from parts of data protection law to test ideas, within ICO oversight and standards. 

The report concludes that the creation of a SRS is feasible, providing a helpful addition to the ICO's regulatory toolkit. However, this would require primary legislation, including ensuring that SRS participants would be protection. The findings report can be accessed here, as well as commentary from the ICO's Executive Director of Regulatory Risk and Innovation. 

 

EDPB issues letter to European Commission on EU-US Data Privacy Framework 

The EDPB has issued a letter to the European Commission seeking clarification on the EU-US Data Privacy Framework ("DPF") in light of the recent US Supreme Court decision in Trump v Slaughter

The letter highlights that the recent decision allows the President to remove officers of supervisory authorities in the United States without previously specific 'for-cause' reasons. The EDPB letter notes that one of the key elements when assessing the adequacy of a third country is the existence and effective functioning of one or more independent supervisory authorities in the third country. 

The letter invites the Commission to "closely assess whether this development affects the functioning of Commission Implementing Decision EU 2023/1795 and would welcome relevant actions, including the continued sharing of information with the EDPB in a timely manner." 

The EDPB letter follows an open letter from the privacy activist group, noyb, encouraging an 'orderly exit' from DPF. The letter from noyb can be accessed here

 

EDPB calls for legal basis for cross-regulatory information sharing 

The EDPB has issued a call to the European Commission to propose a legal basis for cross-border regulatory information sharing. This would allow regulators of different competencies to exchange information and increase cross-border regulatory coherence. 

The EDPB also is seeking an expansion of measures to ensure a consistent application of the GDPR through measures such as cooperation between Data Protection Authorities. 

The EDPB press release can be accessed here

 

UKJT legal statement on liability for AI harms avoids data protection issues 

The UK Jurisdiction Taskforce's Legal Statement on Liability for AI Harms under the private law of England and Wales was published in July.

With reference to data protection and cyber issues, we note that there were a number of areas deemed out of scope of the statement, including data protection, and no references to cyber or related harms. The full Legal Statement can be accessed here.

 

Cyber developments 

AI Safety Institute reports incident involving AI agents 

The AI Safety Institute published an incident report discussing outcomes that occurred during testing in which AI agents were given a task of solving a cyber security challenge. The challenge was run 122 times across several models. The AISI investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. Most of the behaviour resulted from the Mythos 5 model, with 2 involving GPT-5.6-Sol.

In the most serious case, an agent tried to insert malicious code into an open-source project, and engaged in social engineering, namely the creation of a fake online identity and using them to pressure the project's maintainer to approve the code. The AISI report emphasises that a human maintainer caught and refused to approve the malicious code. 

 

NCSC issues statement in response to recent AI incidents 

Following widespread reporting of incidents involving frontier AI models carrying out unsanctioned actions, and as above, in one reported instance, deceptive behaviour, the NCSC issued a statement emphasising that detection after an incident is insufficient, and that following cyber security fundamentals contained within available NCSC guidance remains essential. 

 

European Commission publishes guidance to support Cyber Resilience Act implementation 

The European Commission has published guidance to help manufacturers, developers, and businesses meet their obligations under the Cyber Resilience Act. The guidance can be accessed via this page, and addresses issues such as 'substantial modification', support periods and clarifying when certain products fall within the scope of the CRA. 

The Cyber Resilience Act's main obligations apply from 11 December 2027. 

Authors