Privacy Laws & Business
banner
privacylaws.com
Privacy Laws & Business
@privacylaws.com
Data Protection and Privacy Information Worldwide
Posting data protection and privacy law updates and news, as well info on our Reports and Events

https://www.privacylaws.com/
Pinned
November UK Report out now:
- DUAA introduces a new complaints-handling requirement
- Navigating the new ‘recognised legitimate interest’ lawful basis
- Beyond cyber – beware of human error & process pitfalls
- UK GDPR certification under Art. 42
+ much more...
www.privacylaws.com/reports-gate...
UK Report November 2025
Includes: <br> <br> - DUAA introduces a new complaints-handling requirement<br> - Navigating the new ‘recognised legitimate interest’ lawful basis<br> - Beyond cyber – beware of human error and proces...
www.privacylaws.com
November UK Report out now:
- DUAA introduces a new complaints-handling requirement
- Navigating the new ‘recognised legitimate interest’ lawful basis
- Beyond cyber – beware of human error & process pitfalls
- UK GDPR certification under Art. 42
+ much more...
www.privacylaws.com/reports-gate...
UK Report November 2025
Includes: <br> <br> - DUAA introduces a new complaints-handling requirement<br> - Navigating the new ‘recognised legitimate interest’ lawful basis<br> - Beyond cyber – beware of human error and proces...
www.privacylaws.com
November 5, 2025 at 12:39 PM
The UK's ICO has issued a consultation to seek organisations’ views on the processes the ICO follows when it suspects a breach of the UK GDPR or the Data Protection Act 2018

www.privacylaws.com/news/ico-con...
ICO consults on its approach to investigations and enforcement
The ICO has issued a consultation to seek organisations’ views on the processes the ICO follows when it suspects a breach of the UK GDPR or the Data Protection Act 2018
www.privacylaws.com
November 3, 2025 at 2:29 PM
We are excited to announce that our Student Essay Competition 2026 is now live!
We invite university students worldwide to submit a 1500-word essay for a chance to win great prizes, such as free access to PL&B’s 39th International Conference in Cambridge
www.privacylaws.com/reports-gate...
Student Essay Competition
www.privacylaws.com
October 30, 2025 at 11:57 AM
Join us next week on 4 Nov and get to grips with the common elements of principle and many differences in practice between US and European privacy laws
Gain practical strategies for managing the fast developing privacy laws and privacy elements in other laws

www.privacylaws.com/events-gatew...
Minding the (US-European) Privacy Gap
Conference<br> <br> Latham & Watkins, London
www.privacylaws.com
October 28, 2025 at 12:14 PM
The EDPB has published mostly positive opinions on the UK’s draft GDPR adequacy decisions published in July 2025, saying that it welcomes the continuing alignment between the UK and EU data protection frameworks

www.privacylaws.com/news/edpb-is...
EDPB issues Opinions on EU Commission’s UK draft adequacy decisions
The EDPB has published mostly positive opinions on the UK’s draft GDPR adequacy decisions published in July 2025, saying that it welcomes the continuing alignment between the UK and EU data protection...
www.privacylaws.com
October 20, 2025 at 5:46 PM
The ICO issued, on 15 October, a fine of £14m to Capita (Capita plc for £8m and Capita Pension Solutions Limited £6m) for a data security breach

www.privacylaws.com/news/ico-fin...
ICO fines Capita £14m for data breach affecting over 6 million people
The ICO issued, on 15 October, a fine of £14m to Capita (Capita plc for £8m and Capita Pension Solutions Limited £6m) for a data security breach
www.privacylaws.com
October 16, 2025 at 10:07 AM
Join us on 4 November for an illuminating panel event where leading voices from academia and industry will discuss how to respond to emerging challenges for age assurance
www.privacylaws.com/events-gatew...
Age Assurance
Addressing Non-compliance, Circumvention, and Unintended Consequences<br> <br> University of Nottingham
www.privacylaws.com
October 16, 2025 at 9:50 AM
The European Data Protection Board’s new coordinated enforcement action will look into organisations’ compliance with the transparency and information obligations under the GDPR
www.privacylaws.com/news/edpb-to...
EDPB to probe into GDPR transparency and information obligations
The European Data Protection Board’s new coordinated enforcement action will look into organisations’ compliance with the transparency and information obligations under the GDPR
www.privacylaws.com
October 16, 2025 at 9:40 AM
October International Report is out now:
- Defending MAGA speech: Trump’s war on global data Privacy
- Australia seeks real-world privacy protections for children
- CNIL’s AI guidance sets practical standards
- GDPR enforcement trends for companies
+ much more
www.privacylaws.com/reports-gate...
International Report October 2025
Includes:<br> <br> - Defending MAGA-speech: Trump’s war on global data privacy<br> - Australia seeks privacy protections for children<br> - EU AI Act and GDPR: CJEU case law on automated processing an...
www.privacylaws.com
October 8, 2025 at 1:16 PM
Join us on 3 December at Stephenson Harwood LLP for an afternoon of informative data protection talks and networking
www.privacylaws.com/events-gatew...
Meet the Correspondents
Conference<br> <br> Stephenson Harwood, London
www.privacylaws.com
October 8, 2025 at 11:44 AM
Join us on 4 November at Latham & Watkins and get to grips with the common elements of principle and many differences in practice between US and European privacy laws.
www.privacylaws.com/events-gatew...
Minding the (US-European) Privacy Gap
Conference<br> <br> Latham & Watkins, London
www.privacylaws.com
October 8, 2025 at 11:44 AM
While it has long been recognised that the ePrivacy Directive is outdated and attempts to adopt a regulation in this field have failed, the Commission recognises cookie consent fatigue, and the need to strengthen users’ digital rights online
www.privacylaws.com/news/eu-laun...
EU launches consultation on simplification in the digital field
While it has long been recognised that the ePrivacy Directive is outdated and attempts to adopt a regulation in this field have failed, the Commission recognises cookie consent fatigue, and the need t...
www.privacylaws.com
September 17, 2025 at 11:52 AM
The European Commission launched the process towards the adoption of a data protection adequacy decision with Brazil declaring that it ensures an adequate level of data protection on a similar basis to that of the EU

www.privacylaws.com/news/eu-puts...
EU puts Brazil on path to mutual adequacy status
On 4 September, the European Commission launched the process towards the adoption of a data protection adequacy decision with Brazil declaring that it ensures an adequate level of data protection
www.privacylaws.com
September 8, 2025 at 9:41 AM
France’s Data Protection Authority, the CNIL, has fined Google €325 million & SHEIN €150 million, in particular for failing to comply with the rules on cookies
www.privacylaws.com/news/cnil-fi...
CNIL fines Google €325 million and Shein €150 million
France’s Data Protection Authority, the CNIL, has fined Google €325 million and SHEIN (e-commerce platform specialising in fast fashion) €150 million
www.privacylaws.com
September 4, 2025 at 3:08 PM
UK Report Sept 2025 is out now, includes:
- DUAA data protection aspects in force by end of 2025
- ICO fines 23andMe £2.31 million
- Half-baked no more: Reheated rules on cookies & consent
- New Act enhances enforcement and investigatory powers
+ much more
www.privacylaws.com/reports-gate...
UK Report September 2025
Includes: <br> <br> - DUAA data protection aspects in force by end of 2025<br> - ICO fines 23andMe £2.31 million<br> - Meeting the demands of overlapping regulatory requirements<br> - Half-baked no mo...
www.privacylaws.com
September 3, 2025 at 12:00 PM
Join us on 1 Oct and hear from DSIT and ICO speakers on how the UK's DUAA 2025 will make it easier for businesses in the UK to develop products and services while ensuring a high standard of rights for individuals regarding their personal data

www.privacylaws.com/events-gatew...
Maximising opportunities from the Data (Use and Access) Act 2025
Half-Day Conference<br> <br> Linklaters, London
www.privacylaws.com
August 7, 2025 at 3:35 PM
August International Report out now, inc:
- Germany: Landmark case on using publicly available data for AI
- Ireland imposes half of all EU GDPR fines in 2024
- GDPR simplification starts with one step at a time
- Malaysia’s complex new guidelines
www.privacylaws.com/reports-gate...
International Report August 2025
Includes:<br> <br> - Germany: Landmark case on using publicly available data for AI<br> - Ireland imposes half of all EU GDPR fines in 2024<br> - GDPR simplification starts with one step at a time<br>...
www.privacylaws.com
August 1, 2025 at 1:31 PM
The UK government has issued the commencement dates for various parts of the Data (Use and Access) Act 2025, starting from 20 August 2025:

www.privacylaws.com/news/data-us...
Data (Use and Access) Act commencement dates published
The government has issued the commencement dates for various parts of the Data (Use and Access) Act 2025 starting from 20 August 2025
www.privacylaws.com
July 28, 2025 at 12:16 PM
The European Commission has indicated in a draft decision that the UK remains adequate for EU-UK data flows under the new Data (Use and Access) Act 2025
www.privacylaws.com/news/eu-show...
EU shows green light to UK’s DUAA adequacy
The European Commission has indicated in a draft decision that the UK remains adequate for EU-UK data flows under the new Data (Use and Access) Act 2025
www.privacylaws.com
July 23, 2025 at 9:42 AM
The European Data Protection Board will be helping organisations to understand their GDPR obligations better by issuing simplified guidance
#dataprotection #privacylaws #gdpr
www.privacylaws.com/news/edpb-to...
EDPB to launch practical resources to simplify GDPR application
EDPB Chair Anu Talus said: “The EDPB is committed to helping organisations in achieving GDPR compliance with greater ease and efficiency
www.privacylaws.com
July 4, 2025 at 12:45 PM
Paul Arnold MBE is the first CEO of the future Information Commission which is created under the Data (Use and Access) Act 2025 (DUAA)
www.privacylaws.com/news/paul-ar...
Paul Arnold appointed as CEO of the future Information Commission
Paul Arnold MBE is the first CEO of the future Information Commission which is created under the Data (Use and Access) Act 2025 (DUAA)
www.privacylaws.com
July 1, 2025 at 12:48 PM
In its review of the economic impact of the GDPR, the CNIL chose to study the benefits of the GDPR. Its analysis focused on cybersecurity reveals that the GDPR has generated benefits between €585 million in identity theft cases and €1.4 billion in cyber damages
www.privacylaws.com/news/cnil-sa...
CNIL says that GDPR contributes to savings in cyber security
In its review of the economic impact of the GDPR, five years after its entry into force, the CNIL chose to study the benefits of the GDPR. Its analysis focused on cybersecurity reveals that
www.privacylaws.com
June 24, 2025 at 4:47 PM
July UK Report includes:
- Data (Use and Access) Act 2025
- Handling complex DSARs, how AI can help
- Mind the gap: Content Moderation in UK vs. EU
- Cyber Security & Resilience Bill
- M&S cyber attack: Lessons for retailers
- ‘Is My Boss a Bot’? AI in recruitment
www.privacylaws.com/reports-gate...
UK Report July 2025
Includes: <br> <br> - Data (Use and Access) Act 2025 becomes law<br> - Getting it right handling complex DSARs and how AI can help<br> - UK lessons from an Italian fine<br> - What will the Cyber Secur...
www.privacylaws.com
June 20, 2025 at 8:01 PM
The UK Data (Use and Access) Bill has today received Royal Assent. The Department of Science and Technology will issue guidance and a commencement schedule in due course

#dataprotection #privacylaws

www.privacylaws.com/news/data-us...
Data (Use and Access) Bill becomes law
The Data (Use and Access) Bill has today received Royal Assent. The Department of Science and Technology will issue guidance and a commencement schedule in due course
www.privacylaws.com
June 19, 2025 at 2:54 PM
The ICO has today issued a fine of £2.31million on 23andMe for failing to implement appropriate data security measures. Highly sensitive data of 155,592 people in the UK was compromised by the incident which affected seven million people globally
www.privacylaws.com/news/ico-fin...
ICO fines DNA testing company 23andMe £2.31 Million
The ICO has today issued a fine of £2.31million on 23andMe for failing to implement appropriate data security measures
www.privacylaws.com
June 17, 2025 at 3:27 PM