Data Protection News Update 06 July 2026

iPhone 18 pro

United Kingdom

Sainsbury’s deploys facial recognition cameras

  • Sainsbury’s is rolling out Facewatch facial recognition cameras to 150 more branches before Christmas following a successful trial that stopped 90% of repeat offenders, building on the 55 stores already using the system.
  • The AI technology triggers instant alerts when previously flagged suspects (tagged for offences like shoplifting or violence) enter a participating store.
  • The rapid rollout aims to protect worried staff amid a post-pandemic surge in shoplifting, though it goes ahead despite an incident in February where an innocent shopper was wrongly identified and escorted from a London store.

Apple faces £3bn UK class action over alleged iCloud monopoly

  • The Competition Appeal Tribunal granted a £3 billion class action lawsuit against Apple to proceed to trial, which could see up to 40 million UK iCloud users receive a payout of around £77 each if successful.
  • Consumer group Which? claims Apple abused its dominant position by overcharging users since 2018, using technical restrictions and unfair choice architecture to favour iCloud and block rival storage providers from full-device backups.
  • Apple has rejected the claims as unfounded, stating that customers have plenty of alternative options and are not required to use iCloud; the landmark competition case is not expected to be heard at trial until October 2028.

United States

US Supreme Court FTC ruling threatens collapse of EU-US Data Privacy Framework

  • The US Supreme Court ruled that the Federal Trade Commission’s independence is unconstitutional, directly undermining the legal foundation of the EU-US Data Privacy Framework (DPF), which relies on an independent FTC to oversee data protection.
  • Because EU treaty law mandates that data protection oversight must be conducted by an independent authority, it has been argued the EU-US deal has effectively collapsed and that the adequacy decision shall be repealed by the European Commission.
  • The ruling additionally could have an impact on alternative data transfer mechanisms, such as Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs).
  • Crucially, the privacy advocacy group NOYB, founded by Max Schrems, has already announced plans to challenge the DPF in the CJEU.

AI agent JadePuffer executes first fully automated ransomware attack

  • Security researchers at Sysdig have discovered what is believed to be the first-ever ransomware attack executed from start to finish by an artificial intelligence agent called JadePuffer without any human assistance or oversight.
  • Driven by a large language model (LLM), the AI gained access via an open-source tool, targeted Chinese cloud provider successfully modifying a failed login attempt into a working fix in just 31 seconds.
  • Whilst Sysdig’s findings await independent verification, the incident marks a major milestone suggesting that AI models can fundamentally transform cyber attacks.

Apple investigates massive iPhone 18 Pro data breach

  • A ransomware group called World Leaks has posted sensitive files on the dark web stolen from Apple’s Indian supplier, Tata Electronics, which include component lists, supplier names, and photos of the unreleased iPhone 18 Pro models.
  • The leak of over 200,000 files maps hundreds of parts to specific vendors revealing where the tech giant relies on single or multiple suppliers and exposing its commercial leverage and vulnerabilities.
  • In response, Apple is investigating the matter whilst Tata has restricted internal system access and hired a global consultant to conduct a forensic audit.

Europe

Eurocommerce petitions EU to exempt AI advertising from disclosure

  • Eurocommerce, a major retail association representing brands like Amazon, H&M, and Ikea, has written to EU tech chief requesting that AI-generated advertisements be exempt from strict new disclosure rules.
  • The EU AI Act mandates that companies must clearly label any images, video, or audio generated or modified by AI that could constitute a deepfake.
  • The group argues that benign marketing visuals are not intended to mislead consumers and therefore should not fall under the deepfake definition. Retailers are already heavily reliant on the technology, with Zalando using AI to reduce content production costs by 90%, and H&M and Zara utilising AI-generated model clones.

Estonia announces state-recognised digital identity for AI agents

  • Estonia’s government backed a plan to issue AI ID codes, making it the first country to design state-recognised digital identities for autonomous AI agents so they can perform tasks without borrowing their owner’s credentials.
  • The system introduces controllable, revocable, and limited delegated authority, creating audit trails essential for cybersecurity, data privacy, and compliance teams.
  • This has sparked some critical questions on legal liability, leaving scholars and tech leaders to watch how Estonia intends to assign responsibility when an independent AI agent makes an error.

International

Japan’s telecom provider KDDI suffers mass 14.2m email breach

  • Japanese telecoms provider KDDI Corporation disclosed a breach exposing the email and password combinations of up to 14.22 million current and former customers across six internet service providers after hackers exploited a third-party software vulnerability.
  • The leak includes data from former customers with inactive or closed accounts; these individuals are highly unlikely to receive corporate breach notices or act on password-reset guidance, leaving their credentials exposed to secondary credential-stuffing attacks on other platforms.
  • Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications are investigating the incident.

Australia strengthens powers and fines to prevent bypassing of child social media ban

  • The Australian government has announced it will double the maximum penalty for social media platforms failing to uphold its underage ban, raising the fine for systematic failures to AUD 99 million.
  • To tackle non-compliance, the eSafety Commissioner will be granted strengthened information-gathering powers, allowing the regulator to compel major tech firms and third-party providers to prove what actions they are taking to block under-16s.
  • The legislative crackdown comes in response to evidence that the ban is being easily bypassed, with a study revealing that 85% of young teens remain on social media, often by self-declaring a false age or using easily fooled selfie verification tools.
  • Australia’s policy is being closely watched globally, with the UK planning a similar under-16 ban by spring 2027, though the Australian government faces domestic resistance on free speech grounds.


For the latest updates on iPhone 18 Pro data breach, Sainsbury’s facial recognition rollout, the EU-US Data Privacy Framework, Apple’s £3bn UK lawsuit, and global regulatory developments, visit our Data Protection News hub.

Share:

More Posts

Send Us A Message