Photo of David Naylor

David Naylor

The EU Artificial Intelligence (AI) Act requires companies to disclose in certain cases whether content has been created or modified by AI. This also applies to companies that make use of AI such as image-generation programs for product advertising.

Given that the new rules are enforceable from 2 August 2026, with fines up to EUR

The UK’s data protection framework continues to evolve following the enactment of the Data (Use and Access) Act 2025 (DUAA). One of the more operationally significant developments for organisations is the introduction of a new statutory right for individuals to complain to controllers regarding infringements of the UK General Data Protection Regulation (GDPR), as well as a framework governing how controllers must handle those complaints.

The relevant provisions will apply from 19 June 2026, pursuant to the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026. On or before that date, organisations subject to the UK GDPR will need to update their privacy notices, and introduce formal data protection complaint handling processes that meet specific legal requirements.

Continue Reading The Data (Use and Access) Act 2025 and the new right for individuals to complain to controllers: What organisations need to do before 19 June 2026

French law requires that where hosting services providers host certain types of health data, they must first obtain certification as “hébergeurs de données de santé” (“HDS”) which translates as “health data hosting service providers”. The relevant HDS certification framework was updated in 2024. This framework notably incorporates the amendments introduced by the law of 21 May 2024 aimed at securing and regulating the digital space, as well the decree of 24 March 2026, which imposes data sovereignty-related obligations that will take effect in September 2026.

Continue Reading V2.0 Certification of French Health Data Hosting Service Providers (HDS) now Fully Effective

In its press release relating to the Court of Justice of the European Union (CJEU) judgment of 10 February 2026 in Case C-97/23 P, the CJEU has confirmed that the action brought by an organization against a Binding Decision of the European Data Protection Board (EDPB) is admissible.

With this decision, the CJEU has clarified that organizations have a right of direct appeal against binding decisions of the EDPB on which a national authority’s decision against them is based.

Continue Reading EDPB Binding Decisions Can Be Challenged Directly by Organizations Before EU Courts

Measures included in the digital package aim to cut red tape through “digital by default” services and applying the “once-only” principle, which will mandate public sector bodies across the EU to reuse citizen and business data instead of requiring it to be provided separately to different agencies.

On 16 September 2025, the European Commission (EC) launched a call for evidence to collect research and information on best practices for its upcoming digital package. This is a new round of feedback and follows earlier consultations on data regulation, cybersecurity rules, and the implementation of the Artificial Intelligence Act (AI Act).

Continue Reading EU Seeks Feedback on Proposed Digital Package To Simplify and Modernise Regulations

The UK’s data protection regime is undergoing its most significant transformation since the adoption of the UK GDPR. With the successful passage through both the House of Lords and the House of Commons on 11 June 2025, the Data (Use and Access) Act 2025 (“DUAA”) received Royal Assent on 19 June 2025. Positioned as introducing incremental change rather than major reform, the DUAA is intended to address the UK government’s aim to recalibrate the balance between privacy, innovation, and regulatory pragmatism with the ultimate goal of promoting economic growth.

Continue Reading The Data (Use and Access) Act 2025: A New Chapter in the UK’s Data Protection Framework

The Data (Use and Access) Bill (“DUA Bill”)[1] had its second reading on 19th November 2024 after being introduced in the House of Lords on 23 October and the Bill is anticipated to enter the Lords’ Committee stage in December. According to the Department for Science, Innovation and Technology, the DUA Bill will harness the power of data to boost the UK economy by an estimated £10 billion, free up thousands of police and NHS staff time and secure the effective use of data for the public interest.[2] The DUA Bill proposes to amend both the UK General Data Protection Regulation (“UK GDPR”) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECRs”), despite little weight being placed on this in the Government’s initial press release.

Continue Reading Unpacking the Proposed Data (Use and Access) Bill

The UK Parliament was dissolved on 30th May 2024 ahead of the upcoming July general election and before the Government’s Data Protection and Digital Information (DPDI) Bill could be passed in the “wash up period”1. Like other proposed laws which were not enacted prior to the dissolution of Parliament, the Bill is considered failed and will not be carried over to the new Parliament (even if the Conservatives are re-elected, it will need to be re-presented).

What was the DPDI Bill?

This Bill was the second version of the DPDI Bill – the first version was presented to Parliament in July 2022. Its stated goal was to revise the UK’s data protection laws post-Brexit and reduce red tape and paperwork for UK businesses2. However, as we observed in a previous post, the creation of a UK data protection regime that diverged further from the regime in the EU would have had the opposite effect for any international UK (and other) businesses already subject to EU GDPR and other data protection laws.

In addition, the DPDI Bill aimed to:

  • Reduce barriers to responsible innovation by, for example, amending the definition of “scientific research” to include commercial activities;
  • Boost trade and reduce barriers to data flows by, for example, keeping the existing EU Standard Contractual Clauses;
  • Deliver better public services by, for example, the facilitation of data sharing between public and private institutions including banks to prevent fraud; and
  • Reform the Information Commissioner’s Office by, for example, replacing the current Commissioner role with a statutory board of members appointed by the Secretary of State.
Continue Reading What Happened to the UK’s Data Protection and Digital Information Bill?

Collaboration is a core value of our firm’s client service. Daily our lawyers with in-depth experience in different practice areas collaborate with each other to find joined-up and multi-faceted solutions to the legal issues facing our clients. This is particularly so in the field of online safety, where several legal regimes overlap. We have already