Dutch AP fines Uber €825m: what meaningful human review looks like
The Dutch Data Protection Authority (AP) has fined Uber €825 million over automated driver-account deactivations. The decision, reported on 21…
Practical guidance on UK GDPR, data protection, and privacy compliance. From ICO enforcement updates to implementation guides, we help you stay informed and compliant.
The Dutch Data Protection Authority (AP) has fined Uber €825 million over automated driver-account deactivations. The decision, reported on 21…
Data protection training for staff works best when it is part of an everyday operating routine, rather than a generic…
An ICO enforcement notice and reprimand issued to the Metropolitan Police Service (MPS) offer a practical reminder for any organisation…
An agent that can read a customer record, call a tool and write the result back into a system changes…
A new ICO case is a useful reminder that personal-data risk is not limited to phishing, lost devices or external…
A connected car, van, or scooter generates location data every time it moves. Fleet dashboards, rental recovery tools, and telematics…
On 8 July 2026, the ICO fined Thermotech Wall and Loft Surveys Ltd £240,000 and Jacksons Marketing Ltd £130,000 after…
A B2B platform holds years of customer booking data collected for one operational purpose. A product team wants to mine…
Your team collected customer data for one stated purpose. Six months later, product wants to mine the same database for…
Unsolicited email and SMS to people based in the UK “individual subscribers” normally needs explicit consent under UK ePrivacy/PECR electronic…
Slack is where your team talks. It is not where your GDPR programme lives. Under the UK GDPR Article 28,…
The General Data Protection Regulation (GDPR) gives you the explicit right to request and receive a copy of all personal…
Italy's Garante fined Emirates €180,000 over MEDIF health-data transparency and retention. Practical lessons for accessibility and assisted-travel data.
The ICO has issued a formal caution to a former healthcare professional after concluding a criminal investigation linked to medical…
The Irish Data Protection Commission has fined the Health Service Executive €300,000 after a ransomware attack on the laboratory information…
Yes. Employee data is personal data, so GDPR applies whenever an employer collects, stores, shares, searches, or deletes it. The…
In practice, people often say “GDPR risk assessment”, but the legal test under the UK GDPR is whether you need…
The ICO has fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 after a phishing-led cyber attack led to…
NHS staff rarely face dismissal for data breaches. Analysis of the Southport and Nottingham record access scandals and what they…
California says 23andMe failed to protect genetic data and misled consumers after the 2023 breach. Here is why the lawsuit…