Data Protection News Update 08 June 2026

What is new word abstract in wood type

United Kingdom

OpenAI expands bank access to AI cybersecurity tool

  • OpenAI has offered major UK banks access to GPT-5.5 Cyber, an advanced AI cybersecurity model designed to identify vulnerabilities in digital systems, while rival Anthropic continues to restrict access to its more powerful Claude Mythos model.
  • The tools can analyse large amounts of code and uncover hidden security weaknesses, raising both cybersecurity opportunities and concerns about the potential misuse of highly capable AI-powered hacking technologies.
  • UK financial institutions, including Lloyds, HSBC and Nationwide, will be able to use GPT-5.5 Cyber to strengthen cyber resilience.
  • This leads to growing questions around the governance, controlled access and responsible deployment of advanced AI models that could significantly influence the security of critical financial infrastructure.

NHS Trust reveals patient data exposed in ransomware attack

  • Bedfordshire Hospitals NHS Foundation Trust has disclosed that personal data relating to 32,927 patients was stolen during a ransomware attack on a third-party supplier in June 2024 and subsequently published online.
  • The compromised information may include names, dates of birth, NHS numbers, patient identifiers, postcodes and laboratory or diagnostic test results relating to patients treated between 2011 and 2020.
  • The incident highlights the risks associated with third-party suppliers, with the Trust stating that it took nearly two years to analyse the fragmented dataset and identify affected individuals.
  • The Trust has notified the ICO and NHS England, and while there is currently no evidence of misuse, patients have been advised to remain alert to phishing attempts or other suspicious communications referencing their personal information.

ICO secures £118,000 from former RAC employees following data theft convictions

  • The ICO has secured confiscation orders totalling £118,852 against two former RAC employees who unlawfully copied and sold nearly 30,000 records containing personal information.
  • The individuals had previously pleaded guilty to offences under the Computer Misuse Act 1990 and Data Protection Act 2018, receiving suspended prison sentences and community service orders in 2024.
  • Using powers under the Proceeds of Crime Act (POCA), the ICO successfully recovered assets linked to the financial benefit gained from the illegal sale of personal data. This highlights the ICO’s willingness to pursue both criminal sanctions and financial recovery measures against individuals who misuse or unlawfully disclose personal information.

United States

US executive order to obtain early access to AI unreleased models

  • President Trump has signed an executive order establishing a framework for voluntary government testing of advanced AI models before public release, with a focus on identifying cybersecurity, safety and national security risks associated with increasingly powerful AI systems.
  • The order directs federal agencies, including the Department of Homeland Security, Treasury and CISA, to strengthen critical infrastructure cyber defences and create an AI cybersecurity clearinghouse to share information on software vulnerabilities, threats and remediation measures.
  • AI developers such as Anthropic, OpenAI and Google may voluntarily provide frontier AI models to the government up to 30 days before release for security evaluation. The order explicitly rejects mandatory licensing or pre-approval requirements.
  • The initiative follows growing concern about AI systems capable of identifying software vulnerabilities at exceptional speed, with policymakers seeking to balance innovation with safeguards against misuse, cybercrime, unauthorised data access and threats to national security.

Meta scales back employee monitoring for AI training

  • Meta has softened plans to monitor employees’ computer activity for AI training purposes following internal backlash over a tool designed to record keystrokes, mouse clicks and workplace interactions.
  • New controls will allow employees to pause monitoring for up to 30 minutes at a time and request exemptions, addressing concerns about privacy, autonomy and the collection of personal data on work devices.
  • Staff criticised the initiative as overly intrusive, with more than 1,500 employees reportedly supporting a petition against the programme and raising concerns about workplace surveillance.
  • The changes also respond to reports that the monitoring tool negatively affected device performance and internet usage, while Meta maintains that the data is used solely to improve AI systems and includes safeguards for sensitive information.

Europe

Hotel data breach exposes guest reservation information across European countries

  • A large-scale cyber incident has affected at least 100 hotels in the Netherlands, exposing guest reservation data including contact details, arrival dates and departure dates, with reports also emerging from Belgium and Ireland.
  • Attackers are reportedly using the stolen booking information to send phishing messages and fraudulent payment requests, exploiting access to genuine reservation details to target guests with active bookings.
  • The breach likely stemmed from a shared software provider used across multiple hotels rather than individual hotel systems, highlighting third-party cybersecurity risks.
  • The incident follows a series of similar attacks on travel and hospitality organisations, raising concerns about the protection of customer data and organisations’ obligations to investigate and report personal data breaches.

CNIL fines IQVIA €5 million over health data governance failures

  • France’s data protection authority (CNIL) fined IQVIA €5 million after finding serious breaches in the management of two large health data warehouses containing information from pharmacies and doctors covering tens of millions of individuals.
  • The regulator concluded that the datasets were pseudonymised rather than anonymous, meaning GDPR protections still applied. The data included detailed health information, patient identifiers and demographic data that could potentially enable re-identification.
  • CNIL found multiple compliance failures, and IQVIA has been ordered to implement corrective measures within six months or face daily penalties.

International

Canada launches ‘AI for All’ strategy to boost AI adoption by 2034

  • The Canadian government has revealed its AI for All strategy, aiming to increase AI adoption from 12% to 60% by 2034, create more than 250,000 jobs and boost economic growth through greater AI deployment across sectors including healthcare, transport, energy and public services.
  • The strategy places significant emphasis on responsible AI governance and data protection, with plans to update privacy legislation to address AI-related risks such as deepfakes, surveillance-based pricing practices and other harmful uses of personal data.
  • Canada will invest in domestic AI infrastructure, including a public AI supercomputer powered by clean energy. The initiative also includes a national AI literacy programme, free AI training for Canadians, education support for teachers and students, and measures to ensure AI adoption is aligned with Canadian values, public trust and the protection of individuals’ rights. 

Hong Kong regulator warns of AI-driven cyber threats

  • Hong Kong’s Securities and Futures Commission (SFC) has warned licensed financial firms, particularly online brokers and virtual asset trading platforms, to strengthen their cybersecurity controls given the rise in increasingly sophisticated AI-enabled cyberattacks. The warning follows a 27% increase in reported cyber incidents in Hong Kong during 2025.
  • The regulator highlighted the growing risk to client data and digital assets, warning that AI is enabling threat actors to identify vulnerabilities more quickly, automate phishing and social engineering campaigns, and conduct large-scale attacks with greater efficiency.
  • Firms have been advised to enhance core cybersecurity measures, including vulnerability management, security monitoring, incident detection, response planning and recovery capabilities to prevent unauthorised access to sensitive customer information.


For the latest updates OpenAI’s GPT-5.5 Cyber rollout, NHS ransomware breaches, ICO enforcement action, AI regulation and global cybersecurity news, visit our Data Protection News hub.

Share:

More Posts

Send Us A Message