Data Protection News Update 03 August 2026

changing landscapes in LLM

United Kingdom

UK Department for Education and police databases hit by cyberattack

  • The UK Department for Education and Police National Legal Database have been targeted in a cyberattack, with hackers claiming to have stolen more than 740,000 records containing personal and professional information.
  • The exposed data reportedly includes names, email addresses, phone numbers and job details of government officials, education staff, police personnel and members of the public who previously contacted related services.
  • A previously unknown hacking group, ExfilSquad, has claimed responsibility and threatened to release further data unless victims pay an unspecified ransom, following a common extortion tactic used by cybercriminal groups.
  • Authorities including the National Cyber Security Centre (NCSC), National Crime Agency and Information Commissioner’s Office, are investigating the incidents, with the Department for Education stating that no wider systems or additional sensitive data have been accessed.

Claude AI chats publicly exposed through search engines

  • Hundreds of Claude AI conversations were temporarily accessible online after users’ shared chat links were indexed by search engines, making some private interactions discoverable through public searches.
  • The exposed conversations included potentially sensitive information such as personal details, CVs, workplace projects, research materials and private discussion transcripts.
  • Anthropic stated that users control whether conversations are shared and that shared links are publicly accessible, but acknowledged that third-party services such as search engines may archive publicly available content.

United States

OpenAI launches health data integration for ChatGPT

  • OpenAI has introduced Health in ChatGPT, allowing eligible users in the US to connect Apple Health data and supported medical records to ChatGPT to provide more personalised health-related responses.
  • OpenAI stated that connected health data will not be used to train its AI models or for advertising, and emphasised that ChatGPT is not intended to replace professional medical advice, diagnosis or treatment.
  • The launch comes shortly after a lawsuit alleging ChatGPT provided unsafe medical advice that contributed to a user’s serious medical condition, which highlights ongoing concerns over AI use in healthcare.

Anthropic’s $1.5bn settlement approved after AI training on copyrighted books

  • A US federal court has approved Anthropic’s US$1.5 billion settlement with authors who alleged the company used copyrighted books without permission to train its Claude AI model.
  • The case follows a landmark ruling that AI training on copyrighted books can constitute fair use, although the court found Anthropic liable for retaining millions of pirated books in a central library beyond what was necessary for model training.
  • More than 91% of eligible authors and publishers have reportedly claimed their share of the settlement, while some rights holders opted out and continue to pursue separate legal action against Anthropic.
  • The settlement comes broader scrutiny of AI companies, with Anthropic facing recent cybersecurity incidents involving AI models autonomously accessing or attempting to breach external systems, intensifying concerns around AI safety, oversight and governance.

FTC sues Hims & Hers over health data and privacy practices

  • The US Federal Trade Commission has filed a lawsuit against telehealth provider Hims & Hers, alleging it shared users’ sensitive health information with advertising platforms, including Meta and Snap, despite assurances that the data would remain private.
  • The complaint also alleges the company engaged in deceptive business practices by charging customers for prescriptions before consultations with healthcare providers and making subscription cancellations unnecessarily difficult.
  • Hims & Hers has denied the allegations, describing the lawsuit as unfounded and maintaining that the action is not based on genuine consumer protection concerns. 

Europe

EU mandates driver monitoring cameras in new vehicles

  • From July 2026, all new cars and vans registered in the EU must include Advanced Driver Distraction Warning (ADDW) systems using interior cameras to monitor driver attention and alertness.
  • The camera-based systems will track indicators such as eye movement, head position and signs of drowsiness, providing visual, audio or haptic warnings when drivers appear distracted.
  • EU rules require driver-monitoring data to be processed within the vehicle, with no third-party transmission, biometric identification or retention after processing, in an effort to address privacy concerns.
  • This has raised wider data protection debates over potential “function creep”, including future uses of vehicle monitoring data by manufacturers, insurers, governments or other third parties beyond road safety purposes.

EU extends online child pornography detection rules

  • EU Member States have approved a temporary extension allowing platforms such as Google and Meta to detect and remove child sexual abuse material (CSAM) without violating existing privacy rules.
  • The interim measure, which had expired in April 2026, will now remain in place until April 2028 while EU institutions continue negotiations on permanent legislation to address online child protection.
  • The extension includes an exemption for end-to-end encrypted messaging services, such as WhatsApp, Telegram and Signal, following concerns over privacy and potential surveillance risks.

International

Australia’s under-16 social media ban faces compliance challenges

  • Australia’s regulator eSafety has found that more than 80% of teenagers continued using social media three months after the country’s under-16 ban came into force, largely due to ineffective age verification measures by platforms.
  • The report found that many young users retained or created accounts because platforms failed to verify ages, incorrectly identified users as older, or allowed accounts to continue without checks.
  • While account ownership declined from 52% to 42%, daily social media use among teenagers showed little change, with around 58% reporting frequent use after the ban.
  • The findings have prompted further scrutiny of major platforms including Meta, Snapchat, TikTok and Google, as regulators consider stronger enforcement measures and penalties for non-compliance. 

China and US escalate AI technology dispute over misuse allegations

  • China has accused the US of “AI hegemonism” and threatened countermeasures after US officials raised the possibility of sanctions and trade restrictions against Chinese AI companies over alleged technology misuse.
  • The dispute is based on claims that Chinese AI company Moonshot AI used large-scale model distillation to replicate capabilities from US AI systems, which the company has denied.
  • US officials have warned that companies accused of intellectual property theft could face sanctions or placement on the Commerce Department’s Entity List, potentially restricting access to US technology and services.


For the latest updates on the Claude AI data leak, UK Department for Education cyberattack, Anthropic’s copyright settlement, Australia’s social media ban, and the biggest cybersecurity and AI developments, visit out Data Protection News Hub.

Share:

More Posts

Send Us A Message