8 min read

Data, privacy and cyber in August and September 2026: in case you missed it

Read more

By Hans Allnutt, Jade Kowalski, Peter Given and Justin Tivey

|

Published 09 October 2026

Overview

Our 'In Case You Missed It' section of the Data, Privacy, and Cyber Bulletin provides readers with a high-level digest of important regulatory and legal developments from the end of summer 2026.

Contents

  1. Regulatory developments
  2. Data and privacy developments
  3. Cyber developments

 

Regulatory developments

Information Commissioner's Office transitions to the Information Commission

The Information Commissioner’s Office formally transitioned to the Information Commission on 30 September 2026 under reforms introduced by the Data (Use and Access) Act 2025 (DUAA). The change represents a significant institutional development in UK data protection regulation, establishing a new governance structure for the UK’s privacy regulator.

The regulator is now overseen by a new Information Commission Board, including seven non-executive directors announced in July. The permanent Chair is expected to be in place in spring 2027. Importantly, the organisation will continue to be known as the ICO. The ICO's existing regulatory responsibilities and day-to-day activities will continue unchanged.

For practitioners and organisations, section 119 of the DUAA confirms that references in documents or contracts to the Information Commissioner, regardless of when they were made, are treated as references to the Information Commission. Going forward, however, documents and templates, including communications with data subjects and privacy notices, should be updated to reflect the organisational change.

 

TikTok accepts children’s privacy fine

The ICO announced that TikTok had withdrawn its appeal against a fine imposed for breaches of UK data protection law relating to children's personal data. TikTok also withdrew a separate appeal, which will allow the ICO’s recommender-system investigation to proceed.

 

Irish Data Protection Commission fines Google EUR403 million

The Irish Data Protection Commission announced a final decision following an investigation into Google's processing of location data. The DPC imposed administrative fines totalling EUR403 million. It is expected that Google will appeal the fine.

 

Cyber Security and Resilience Bill moves to report stage

The Cyber Security and Resilience (Network and Information Systems) Bill proceeded through committee stage in early September, with minor changes made to the legislation. Report stage will commence on 26 October 2026.

The debates at committee stage focused on a package of amendments proposed by the government addressing vendor-related cyber security risks. The key amendments would have allowed the Secretary of State to direct operators to restrict, remove or modify the use of specified high-risk vendor technologies and establish a voluntary referral process for high-risk procurements. A reserve power to introduce mandatory screening in future would also have been introduced, should this be considered necessary to protect national security.

Opposition and cross-party peers expressed concerns about the scope and timing of the package and the capacity for parliamentary scrutiny. Lord Clement-Jones noted that it would "completely change the architecture of the Bill" after its passage through the Commons. It was also suggested that the package would have the effect of regulating advanced AI systems through the designation of AI developers as high-risk. The proposed amendments were withdrawn but are likely to be subject to further debate at report stage.

The Bill, as amended at committee stage, can be accessed here.

 

Metropolitan Police Service receives enforcement notice and reprimand over data protection failures

The Information Commissioner's Office (ICO) has issued the Metropolitan Police Service (MPS) with both an enforcement notice and a reprimand following two separate incidents involving the unlawful disclosure of highly sensitive personal information. The ICO concluded that the MPS had failed to implement appropriate technical and organisational measures to protect personal data and identified wider weaknesses in data protection training, monitoring and governance.

One incident involved the disclosure of a stalking victim's new address and telephone number, together with witness details, to the alleged stalker following the service of unredacted court documents. The second concerned a bulk email sent to individuals connected to a so-called "Honeytrap" investigation involving individuals linked to the UK Parliament. In this instance, recipients' identities were inadvertently disclosed to one another via email.

The ICO found that these incidents reflected broader compliance failures rather than isolated mistakes. It noted a low completion rate for mandatory data protection training among MPS personnel. The MPS had taken remedial steps, including additional specialist training, enhanced quality assurance processes and the introduction of email safeguards. However, the ICO still considered that further action was necessary and required the force to improve its data protection training, monitoring and governance arrangements.

The full ICO announcement, as well as the reprimand and enforcement notice, can be accessed online.

 

ICO issues reprimand to criminal records office following cyber security failings

The Information Commissioner's Office has published the outcome of its investigation into ACRO Criminal Records Office. Between August 2022 and March 2023, a hacker accessed ACRO's website and content management systems, potentially exposing the sensitive data of up to 10,000 people.

The ICO issued a reprimand, noting that ACRO had taken remedial steps including decommissioning compromised infrastructure, introducing security monitoring and strengthening network segmentation.

The full reprimand can be accessed here.

 

EDPB harmonises fining methodology

The European Data Protection Board (EDPB) adopted guidelines addressing the use of administrative fines together with other GDPR corrective powers. The guidance sets out a harmonised methodology for supervisory authorities when assessing whether a fine should be imposed. It also explains how fines interact with alternative enforcement measures such as warnings, reprimands and processing restrictions.

The EDPB also adopted the final version of its guidelines on the interaction between the Digital Services Act and the GDPR following public consultation. Both developments are intended to promote greater consistency in regulatory enforcement across the EU.

 

Data and privacy developments

ICO considers privacy implications of AI-enabled smart glasses

The ICO published a blog examining the growing use of smart glasses and other AI-enabled wearable devices. The blog discusses the privacy, transparency and public trust issues already arising from devices capable of collecting and processing personal information in public spaces, and how these should be balanced against the benefits offered by emerging technologies.

The publication forms part of the ICO’s broader engagement with AI-enabled technologies and will be of interest to organisations developing, deploying, or using such devices.

 

ICO highlights governance shortcomings in police use of facial recognition technology

The ICO has published a blog summarising the findings of an audit of the use of facial recognition technology (FRT) across England and Wales by five police forces.

The ICO concluded that while forces generally had lawful bases for using the technology and appropriate breach-reporting procedures, there were significant inconsistencies in compliance and governance arrangements. Several areas require improvement, including senior oversight and accountability, staff training, record-keeping, data retention practices, and measures to address accuracy, fairness, and bias in facial recognition systems.

The ICO stressed that, despite the benefits of FRT, its use must remain lawful, proportionate and subject to effective oversight and safeguards. A final audit of the Metropolitan Police Service is set to take place later this year. The full blog can be accessed here.

 

WASPI information-sharing code published by the ICO

The ICO announced the publication of a new UK GDPR Code of Conduct developed by the Wales Accord on the Sharing of Personal Information (WASPI) to support information sharing across Wales. The code is intended to provide organisations with a clearer and more consistent framework for sharing personal information lawfully and responsibly.

The code of conduct introduces six key requirements covering governance, the use of approved templates, quality assurance, accountability, reviews of information-sharing arrangements, and compliance with ongoing monitoring.

 

EDPS warns against weakening data protection in proposed Europol reforms

The European Data Protection Supervisor (EDPS) has published Opinion 18/2026 on the European Commission's proposal for a new Europol Regulation. The proposal would significantly expand Europol's role as an EU information, operational and technology hub in response to evolving cross-border crime and security threats.

The EDPS supports strengthening Europol's ability to support Member States' law enforcement authorities, but warns that the proposed expansion of Europol's powers would significantly increase the volume and scope of personal data processing. The Opinion calls for stricter purpose and storage limitations, clearer criteria governing when Europol may process personal data, and stronger mechanisms for oversight, accountability and enforcement of EU data protection rules.

The full EDPS press release can be accessed here.

 

EDPS calls for stronger safeguards in proposed Eurojust reforms

The EDPS has issued Opinion 19/2026 on the European Commission's proposal for a new Eurojust Regulation.

The EDPS supports maintaining key protections, including strict data retention limits, use of Eurojust's Case Management System, and secure information exchange through e-CODEX. However, it also recommends further safeguards regarding data sharing, database cross-checking, international transfers of personal data, and accountability for processing activities.

The full EDPS press release can be accessed here.

 

Cyber developments

Reporting requirements under the EU Cyber Resilience Act take effect

As of 11 September 2026, manufacturers placing products with digital elements into the EU must report actively exploited vulnerabilities and severe incidents to the relevant authorities within 24 hours of becoming aware of them. This is in line with the incident and vulnerability reporting requirements established in Article 14 of the Cyber Resilience Act. Failure to comply could result in fines of up to €15 million or 2.5% of worldwide annual turnover.

The majority of obligations under the EU Cyber Resilience Act 2024 will not apply until 11 December 2027, but the Act's incident and vulnerability reporting requirements have now taken effect. Importantly, the reporting obligations apply to all products already placed on the market prior to 11 December 2027.

Manufacturers will be required to notify authorities, and in certain cases affected users, of any actively exploited vulnerabilities or severe cyber security incidents affecting their products within 24 hours of detection.

 

NCSC warns of risks to internet-facing systems and edge devices

The National Cyber Security Centre (NCSC) has reported increased targeting of operational technology by a range of threat actors, resulting in limited real-world disruption.

Against a backdrop of growing cyber capability and geopolitical instability, the NCSC has recommended practical steps for organisations to take while emphasising the need to build longer-term cyber resilience.

 

NCSC warns of risks from 'shadow AI'

The NCSC has published an overview of shadow AI: the use of AI tools outside an organisation's approved systems and processes. It highlights cyber security risks including exposure of sensitive information, reduced visibility, and control over data, and new opportunities for attackers.

The NCSC recommends that organisations reduce the risks associated with shadow AI by fostering a positive cyber security culture through open communication with employees and by integrating AI systems into workplace processes. The NCSC blog can be accessed here.

 

NCSC warns of actively exploited Citrix vulnerabilities

The NCSC urged organisations to take immediate action to address vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products. The agency stated that two of the vulnerabilities were being actively exploited and encouraged organisations to apply available mitigations without delay. The NCSC recommended following vendor best practice and taking the priority actions set out in the link above.

Authors