Data Protection News Update 01 September 2026

AI robot hand touching wooden blocks

United Kingdom

Doctor’s appointment phone call led to data breach

  • A doctor took a phone call regarding another patient during a consultation, allowing private medical information to be overheard by the attending patient.
  • The incident triggered a formal data protection breach investigation after the attending patient reported hearing confidential clinical details being discussed in their presence.
  • The breach underlines widespread data confidentiality issues across healthcare settings, where physical space constraints, open bay areas, and curtained wards make preventing overheard conversations difficult.
  • Regulators called for mandatory annual data protection refresher training for staff alongside updated onboarding protocols to avoid future confidentiality breaches.

Customer data accessed in Manchester Airports Group incident

  • Manchester Airports Group (MAG) confirmed an unauthorised third party obtained customer data from systems handling car park, lounge, and Fast Track bookings, as well as terminal Wi-Fi sign-ups.
  • The accessed details include customer email addresses, phone numbers, postcodes, and vehicle registration numbers. MAG clarified that payment card, and bank details were not held on the affected systems and were not compromised.
  • Flight operations, airport security, and passenger safety were not impacted, though MAG temporarily suspended its online ‘Manage My Booking’ service as a precautionary measure while managing urgent customer amendments via phone.
  • MAG contained the breach with specialist advisers, alerted relevant authorities, and emailed affected customers directly, advising them to remain vigilant against potential phishing, smishing, and social engineering attempts.

AI-generated complaints overwhelm UK public sector bodies

  • UK public sector bodies, including local councils, are seeing complaints inflate from simple one-page letters into lengthy 20-to-30-page documents generated by generative AI tools.
  • The AI-drafted grievances routinely cite complex acts of law, statutory duties, and legal precedent, forcing local authorities to instruct lawyers and spend vast amounts of time verifying fabricated or irrelevant facts.
  • The surge in automated correspondence threatens to drive up operational expenses and necessitate additional public sector hiring just to process routine complaints, such as missed bin collections.
  • Rather than streamlining public administration, the widespread adoption of AI for formal correspondence is bogging down civil servants and delaying resolutions for ordinary citizens.

United States

Meta settles claims on its platforms being harmful for children

  • Tech giant Meta agreed to a landmark $18 billion settlement resolving legal action over platform safety and child protection.
  • The cases focused heavily on the impact of social media algorithms, screen time, and platform design on young users’ mental health and safety.
  • The massive payout signals that social media companies may no longer be able to operate addictively engaging features without strict regulatory and financial accountability.
  • Technology experts highlight that the resolution marks a major turning point, potentially hastening a broader global reckoning for social media firms over child safety standards.

Carhartt refuses $3.3m extortion demand as millions of records leaked online

  • Hacker group ShinyHunters published a 50GB database containing information from 12.9 million Carhartt accounts on the dark web.
  • The leaked dataset includes names, physical addresses, email addresses, and phone numbers, alongside details belonging to over 15,000 Carhartt employee accounts.
  • Analysis by Have I Been Pwned founder Troy Hunt linked the exfiltrated dataset to an intrusion involving Carhartt’s cloud-based Databricks analytics platform.
  • The hackers released the entire archive after Carhartt management explicitly declined to pay a $3.3 million ransom demand following internal reviews.

Europe

Uber hit with €825m GDPR fine over automated driver bans

  • The Dutch Data Protection Authority fined Uber €825 million for using automated software to suspend driver accounts between 2018 and 2022. It stands as the second-highest GDPR penalty ever issued.
  • Watchdogs ruled that Uber violated Article 22 by imposing account deactivations without adequate notice or human involvement. Depriving drivers of their earnings via fully automated systems breached strict protections against unreviewed algorithmic decisions.
  • Uber called the fine disproportionate, asserting that human staff verified all permanent bans. The company added that the process affected only 126 drivers accused of fraudulent activity (like taking unnecessary detours) and noted the system was fully retired in 2022.
  • The decision signals stricter global oversight of automated workplace algorithms affecting employment, hiring, and finance. Uber’s ongoing appeal will test how strictly tech firms must maintain human oversight in automated decision-making.

Ireland risking fine over delayed EU Cybersecurity Legislation

  • Ireland faces an estimated €2.8m lump-sum penalty alongside daily recurring fines after the European Commission referred the country to the Court of Justice of the European Union (CJEU).
  • The legal referral comes as a direct result of Ireland failing to transpose the EU’s updated NIS2 Cybersecurity Directive into domestic law by the mandatory deadline.
  • The delay persists because Ireland’s National Cyber Security Bill has yet to pass through the Oireachtas, leaving key infrastructure and digital supply chains in a state of regulatory uncertainty.
  • Professional services firm Aon is urging the Irish government to prioritise the legislation, whilst advising businesses to proactively strengthen their cybersecurity posture rather than waiting for domestic law to catch up.

International

Brazil issues historic fine to TikTok over children’s data privacy failures

  • Brazil’s National Data Protection Authority (ANPD) fined ByteDance for improperly processing the data of children and teenagers, marking the agency’s first-ever monetary fine against a social media platform.
  • Regulators identified five violations of Brazil’s General Data Protection Law (LGPD), ruling that TikTok lacked adequate age verification and processed data belonging to an estimated 8 million minors without a valid legal basis across both signed-in accounts and guest browsing.
  • Alongside an order to delete all unlawfully collected data, ByteDance must enforce restrictive privacy settings for users under 16, disable ads and social features for guest users, and implement stricter content filters and parental controls.


For the latest updates on Uber automated driver ban, Manchester Airports Group data breach, AI-generated complaints, legal action over Meta safety and child protection, and other privacy, AI security breaches, visit out Data Protection News Hub.

Share:

More Posts

Send Us A Message