Data Protection News Update 13 July 2026

hacker hand stealing data from laptop top down

United Kingdom

Prince Harry’s privacy case against Daily Mail dismissed by High Court

  • The High Court has dismissed the privacy claims brought by Prince Harry, Elton John, and other high-profile figures against Associated Newspapers, ruling there was insufficient evidence that the Daily Mail unlawfully obtained information for its reporting.
  • The claimants alleged journalists used unlawful practices including phone hacking, landline tapping, private investigators and blagging to obtain personal information. The court found that suspicion alone was insufficient and that legitimate methods of obtaining the information remained plausible.
  • Associated Newspapers described the ruling as an overwhelming victory for the publisher and the free press and is seeking to recover legal costs, with the case estimated to have cost more than £50 million.
  • Prince Harry and fellow claimant Doreen Lawrence criticised the judgment as a whitewash, while the ruling is widely seen as bringing an end to Harry’s long-running legal campaign against the British press, following previous cases against other newspaper groups.

ICO fines home improvement firms £370,000 for illegal marketing calls

  • The ICO has fined Thermotech Wall and Loft Surveys Ltd (TWLS) £240,000 and Jacksons Marketing Ltd (JML) £130,000 for making over 800,000 unlawful marketing calls to people registered with the Telephone Preference Service (TPS).
  • Investigations found the companies repeatedly targeted vulnerable individuals, including older and disabled people, using misleading sales tactics and automated robot calls that appeared to come from UK-based callers. Victims reported feeling distressed and afraid to answer their phones.
  • The ICO uncovered evidence that company director Thomas Vickrage encouraged overseas call centres to target TPS-registered numbers and discussed creating ‘phoenix’ companies to continue operations if enforcement action was taken.
  • JML also falsely claimed to represent government-backed schemes and warned homeowners about supposedly hazardous insulation to pressure them into purchasing services. Both companies have been issued with enforcement notices requiring them to stop making unlawful marketing calls.

United States

Meta withdraws Instagram AI image feature following privacy backlash

  • Meta has removed a newly launched Instagram feature that allowed users to generate AI images using content from public Instagram accounts after widespread criticism over privacy and consent.
  • The feature, part of Meta’s new Muse Image AI tool, automatically opted public account holders in by default, enabling others to use their publicly available images and likenesses to create AI-generated content without prior permission.
  • Privacy advocates and industry groups, including SAG-AFTRA and Privacy International, criticised the feature as it arguably failed to adequately protect users’ rights and treated personal images as material for AI training and generation.
  • Meta acknowledged it had ‘missed the mark’ and removed the feature within days of launch, stating it had listened to user feedback. The company however indicated it still plans to expand AI capabilities across WhatsApp, Facebook and Messenger.

Court denies California’s request for damages over 23andMe data breach

  • A U.S. bankruptcy judge has ruled that California cannot pursue monetary damages against the company formerly known as 23andMe over its 2023 data breach, which exposed the genetic and personal information of approximately 6.9 million customers.
  • The judge found that 23andMe’s Chapter 11 reorganisation plan prevents the state from seeking financial penalties, although California may continue to pursue non-monetary remedies. The state has been ordered to amend or dismiss its lawsuit accordingly.
  • California Attorney General Rob Bonta had claimed that 23andMe ignored warnings about security weaknesses and downplayed the severity of the breach while seeking potentially millions of dollars in civil penalties. The court rejected the State’s argument that the bankruptcy process should not shield companies from state enforcement actions.

Europe

EU Commission finds Meta’s Instagram and Facebook design may breach Digital Services Act

  • The European Commission has issued preliminary findings that Meta’s use of addictive design features on Instagram and Facebook, including infinite scroll, autoplay, push notifications and personalised recommender systems, may breach the Digital Services Act (DSA).
  • The Commission found that Meta may have failed to adequately assess risks to users’ mental and physical wellbeing, particularly for minors and vulnerable groups, with engagement-driven design features potentially contributing to compulsive use.
  • Existing safeguards such as screen-time tools, parental controls and awareness measures, were considered insufficient to effectively mitigate the risks associated with addictive platform design.
  • Meta has the opportunity to respond to the findings. If the Commission confirms non-compliance, Meta could face enforcement action, including a fine of up to 6% of its global annual turnover.

Apple’s Gatekeeper status maintained under Digital Markets Act

  • The EU General Court has dismissed Apple’s legal challenge against its designation as a ‘gatekeeper’ under the Digital Markets Act (DMA), confirming that its App Stores and iOS operating system are subject to rules designed to promote competition.
  • The ruling strengthens the European Commission’s ability to enforce the DMA, which requires major technology platforms to open their ecosystems to competitors and carries potential fines of up to 10% of a company’s global annual turnover for non-compliance.
  • Apple argued that the DMA’s requirements threaten user privacy and security by forcing greater interoperability, but the court sided with regulators: Apple retains the right to appeal the decision to the Court of Justice of the European Union.
  • The court also ruled that Apple’s challenge regarding iMessage was inadmissible, noting that the messaging service has not been designated as a core platform service under the DMA and is therefore not currently subject to the Act’s obligations.

International

China warns of alleged security risks in Anthropic’s Claude code AI tool

  • China’s Ministry of Industry and Information Technology warned that some versions of Anthropic’s Claude Code AI coding tool may contain a back-door vulnerability that could expose sensitive user information.
  • The alleged risk involves the tool’s ability to send data, including user identity and location details, to remote servers without explicit user consent, according to Chinese cybersecurity authorities.
  • Anthropic disputed the characterisation of the issue, stating that the feature was an earlier security measure designed to prevent AI model distillation, and advised that its policies restrict use by certain China-based entities. 

Pakistani law enforcement agencies targeted by China and India-linked cyber groups

  • Cybersecurity researchers at SentinelOne have recently identified multiple cyber-espionage campaigns from Chinese and Indian threat groups targeting Pakistani law enforcement agencies between February 2024 and April 2026.
  • The campaigns focused on agencies including Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police and the Punjab Safe Cities Authority, with attackers seeking access to sensitive internal security information.
  • SentinelOne highlighted the targeting of systems such as Balochistan Police’s Complaint Management System, while Khyber Pakhtunkhwa Police confirmed one incident involving compromised user credentials.


For the latest updates on Prince Harry Daily Mail case, Meta’s AI privacy changes, ICO fines, Apple and EU decisions, the 23andMe case, and the latest cybersecurity stories worldwide, visit out Data Protection News Hub.

Share:

More Posts

Send Us A Message