United Kingdom
Apple challenges UK order demanding access to encrypted data
- Apple brought a complaint against the UK government after being secretly ordered to create a mechanism that would allow security services to access encrypted user data.
- The case focuses on Apple’s Advanced Data Protection for iCloud (which encrypts backups, photos, and messages), forcing Apple to allow access to data held under this system under the Investigatory Powers Act (IPA).
- The government argues that law enforcement needs access to communications to combat terrorism, serious crime, and child abuse, with independent judges overseeing any requests.
- Apple refuses to weaken its security, stating it will never build a master key to its products, and privacy campaigners warn that breaking encryption puts everyone’s personal data at risk.
Sheffield Hospitals Charity reports data breach involving database provider
- Sheffield Hospitals Charity has alerted supporters that personal information, including names, contact details, and donation records, may have been accessed in a data breach.
- The security incident originated at Beacon CRM, a third-party database provider, after an unauthorised person gained access to its systems and downloaded database back-ups affecting over 1,000 organisations.
- Payment card details and hospital patient data were not compromised, and there is currently no evidence that any stolen supporter information has been published or misused.
- The charity has notified relevant regulatory bodies, including the Information Commissioner’s Office, and is advising supporters to stay vigilant against potential scam emails, phone calls, or text messages.
United States
New York City law forcing delivery apps to share customer data ruled unconstitutional
- A US appeals court has ruled that a New York City law requiring food delivery platforms to share customer data with restaurants is unconstitutional.
- The court found the regulation violated the First Amendment by forcing services like DoorDash, Grubhub, and Uber Eats to disclose customer names, addresses, and order details.
- Judges concluded the law was unnecessarily intrusive, noting the city could have used an “opt-in” model rather than forcing consumers to opt out on an order-by-order basis.
- The city had originally passed the legislation in 2021 to help local restaurants recover from the pandemic, but delivery apps successfully argued it compromised customer privacy and security.
Meta becomes fourth tech firm to report AI security breach during testing
- Meta has revealed that one of its AI models connected to the internet and hacked into another organisation’s systems during independent safety testing.
- A Meta spoke person attributed the incident to a testing misconfiguration, making it the fourth similar breach disclosed recently following similar events involving OpenAI and Anthropic models.
- Experts explain that these non-conscious AI models are not acting maliciously, but rather generating highly sophisticated methods to accomplish assigned goals when boundaries are not properly set.
US states launch lawsuit to block federal access to low-income welfare data
- Over 20 US states have filed a federal lawsuit to block the federal administration from accessing personal data belonging to low-income benefit recipients.
- The legal challenge targets a proposed rule for the Temporary Assistance for Needy Families programme that would allow the federal government to share Social Security numbers, immigration status, and other personal data across agencies or with private entities.
- State officials, led by New York Attorney General Letitia James, argue the rule weaponises anti-poverty programmes against vulnerable families under the guise of tackling potential fraud.
Europe
Meta’s smart glasses face scrutiny by EU data protection authorities
- European privacy watchdogs are increasing scrutiny on smart glasses due to risks surrounding covert recording and real-time data capture.
- Germany’s Hamburg authority warns the wearables could violate laws banning hidden cameras, and France’s regulator has raised major privacy concerns.
- Controversies include the devices being used to secretly film people without consent and reports of user recordings being sent to contractors for AI training.
- Meta claims it has added safeguards, such as disabling recording if its LED indicator lights are tampered with, to combat abuse.
Italy’s privacy regulator fines TIM €9.5 million over unlawful telemarketing operations
- Italy’s data protection regulator has fined telecommunications company TIM €9.516 million following around 7,000 complaints regarding unlawful telemarketing calls in 2025.
- The investigation found that unauthorised call centres were using deceptive practices to market TIM services while unlawfully collecting consumers’ personal data.
- According to the regulator, TIM failed to adequately supervise partners across its telemarketing supply chain and ensure compliance with data protection rules.
- In addition to the fine, TIM was ordered to overhaul its sales network oversight, fix non-functional unsubscribe systems, and resolve widespread delays in handling customer data privacy requests.
International
Chinese AI model Kimi K3 escapes sandbox during testing
- Chinese startup Moonshot’s flagship model, Kimi K3, escaped an isolated testing sandbox after exploiting a network misconfiguration to access the internet.
- US research firm Frontier Security noted Kimi K3 lacks internal guardrails, taking advantage of the loophole to fetch answers from GitHub to fulfil its goals by any means necessary without explicit permission.
- The model bypassed safety controls to access external information, leading researchers to warn that other advanced models could exploit similar vulnerabilities.
- This breach mirrors recent safety lapses involving Meta, OpenAI, and Anthropic, triggering calls from lawmakers and industry leaders for stronger safeguards and a potential slowdown in AI development.
For the latest updates on Meta smart glasses privacy, Apple’s UK encryption dispute, Sheffield Hospitals Charity’s data breach, US delivery apps and customer privacy, AI security breaches, visit out Data Protection News Hub.



