United Kingdom: Data Protection

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
EU E-Evidence: What US Tech Providers Need To Prioritize Now
The EU's e-Evidence Package introduces a direct cross-border framework allowing authorities to compel electronic evidence from service providers through binding Production and Preservation Orders. U.S. companies offering cloud, communications, or data-driven services to EU users face immediate operational obligations including appointing EU representatives, meeting shortened response windows, and navigating potential conflicts with U.S. law.
European Union International
ZwillGen PLLC
Article
Covert Recordings In Family Proceedings: What Does The Law Say? (20 August 2026)
The Family Justice Council's May 2025 guidance addresses the increasingly common practice of making covert recordings in family proceedings involving children. While smartphones have made secret recording easier than ever, the legal and welfare implications of using such evidence in court are complex and potentially serious. Understanding when recordings may be admissible, and when they might actually harm your case, is crucial for anyone involved in family proceedings.
United Kingdom Family
DL
Duncan Lewis & Co Solicitors
Article
Government Consultations On UK Data Protection Law – An Opportunity To Create Clearer Rules Whilst Ensuring High Standards Of Protection
The UK government has launched consultations on data protection law in the age of AI, seeking practical examples of what works and where clarity is lacking. With the EU shifting its regulatory approach following the Draghi Report, the UK now has an opportunity to demonstrate how data protection rules can be simplified while maintaining high standards, potentially using the FCA's Consumer Duty as a blueprint for clearer, more intelligible regulations.
United Kingdom Privacy
MC
Marks & Clerk
Article
The UK ICO’s New Statutory Duty To Produce An AI Code Of Practice: What It Means For Businesses That Use AI
The UK's data protection regulator is preparing a formal Code of Practice on AI and automated decision-making, expecting businesses to assess their AI use well before it takes effect. Organizations subject to UK GDPR that develop or use AI tools—including those purchased from third parties—face significant compliance obligations that extend far beyond AI developers to any business making decisions about individuals through automated systems.
United Kingdom Privacy
AP
Arnold & Porter
Article
Virtual And Digital Health Digest – July 2026
European regulators are accelerating AI governance frameworks while balancing innovation with patient safety in digital health. The European Commission has published voluntary codes for AI-generated content marking and appointed expert bodies to enforce the AI Act, while the UK's MHRA launches regulatory sandboxes to test AI tools in medicines development and the ICO establishes comprehensive guidance for AI-powered healthcare technologies.
United Kingdom Healthcare
AP
Arnold & Porter
Article
You Can’t Take Something For Nothing: Court Of Appeal Allows Class Representative To Pursue User Damages In Competition Claims
The Court of Appeal has rejected Meta's challenge to Dr Liza Lovdahl Gormsen's amendment of her pleadings to include a claim for 'user damages' in a competition law case concerning Facebook's collection of personal data. This decision opens up another potential claim against tech companies for alleged misuse of consumer data, with the question of whether such damages will be awarded to be decided at trial in October 2028.
United Kingdom Anti-trust
M
Macfarlanes LLP
Article
Hybrid Or Flexible Working - Both At Home Or Abroad
As hybrid and flexible working arrangements become increasingly common, employees seeking to work remotely from abroad face a complex web of legal requirements that differ significantly from domestic arrangements. This analysis explores the critical distinctions between working from home in the UK versus relocating to work in Spain, examining visa requirements, employment rights, data protection obligations, and the essential policies employers must implement to manage cross-border remote working arrangemen
United Kingdom Immigration
GP
Giambrone & Partners
Article
Giambrone & Partners Identity Fraud Warning: Scammers Impersonating Lawyers To Target Cryptocurrency Victims
Cryptocurrency recovery scams are targeting individuals who have already lost money through fraudulent investments, with criminals impersonating lawyers and legal professionals to extract further payments or gain access to digital wallets. Understanding the warning signs of these sophisticated frauds and knowing how to verify communications can protect victims from falling prey to secondary scams that exploit their desire to recover lost assets.
United Kingdom Criminal
GP
Giambrone & Partners
Article
Schrödinger's Data? A Practical Guide To The EDPB’s New Anonymisation Guidelines
The European Data Protection Board has released its first major update to anonymisation guidance in over a decade, introducing a new framework that determines whether data qualifies as anonymous based on who is accessing it. This contextual approach means the same dataset could be considered anonymous for one organisation while remaining personal data for another, fundamentally changing how companies assess data privacy obligations.
United Kingdom Privacy
LS
Lewis Silkin
Article
EU Court Of Justice Confirms Competition Authorities’ Information-gathering Powers, But Introduces Additional Protection For Data On Personal Devices
The EU Court of Justice has ruled on the extent to which competition authorities can seize business emails during dawn raids without prior court approval, establishing new boundaries for digital evidence gathering while introducing important distinctions for personal versus company devices. This landmark judgment clarifies the balance between fundamental rights protection and competition enforcement powers across EU Member States.
European Union Anti-trust
M
Macfarlanes LLP
Article
The GDPR:  Ambition, Execution, Reform And Future Developments – Where Is EU Data Protection Law Heading?
The General Data Protection Regulation was designed to harmonize EU data protection law and strengthen the single market, but has it achieved these goals? This analysis examines the GDPR's structural challenges, from its complex balancing tests to problematic controller-processor distinctions, and explores whether proposed reforms can address fundamental flaws in an era of artificial intelligence and rapid technological change.
United Kingdom Privacy
MC
Marks & Clerk
Article
After Just 6 Months Of The LHF Ad Ban, Parliamentarians Are Already Asking For More!
Lewis Silkin's website provides essential information about accessibility standards, complaint procedures, contact details, cookie policies, legal and regulatory disclosures, modern slavery statements, payment options through Legl, privacy policies, and terms and conditions. These resources help clients and visitors understand the firm's operational framework and compliance commitments.
United Kingdom Commercial
LS
Lewis Silkin
Article
What Is Shadow AI? The Growing Risk Inside Legal Departments
Shadow AI—the use of unapproved artificial intelligence tools within organizations—poses significant risks for legal departments handling confidential and privileged information. This article examines how legal teams can identify shadow AI usage, understand the regulatory and ethical implications under frameworks like the EU AI Act, and implement governance strategies that balance innovation with compliance and data protection.
United Kingdom Privacy
Axiom
Article
Data And Cyber School – The Latest Cyber Security And Data Protection Updates
The UK's data protection and cyber security landscape is undergoing significant transformation through three major developments: the Cyber Security and Resilience Bill expanding regulatory scope to managed service providers and data centres, the Data (Use and Access) Act 2025 modernising UK GDPR provisions, and the NCSC's voluntary Cyber Governance Code of Practice for boards.
United Kingdom Privacy
GW
Gowling WLG
See more