United Kingdom
Prime Minister Kier Starmer to ban social media in the UK for under 16s
- The Prime Minister is expected to ban under 16s in the UK from using major social media platforms such as TikTok, Snapchat and Instagram.
- The ban will also extend to such children livestreaming on “safer” websites and stop them being able to talk to strangers on gaming platforms.
- It is reported that ministers are considering if social media curfews should be launched for children, however the details will not be released until next month.
- Kier Starmer said that “This is a choice about whose side we’re on: families across the country, or a status quo that isn’t working,” and that it is a “call time on a system that’s failing our kids”.
- It is reported that the UK will go one step further than Australia- the world’s first country to introduce an outright ban on children using social media. This ban would not only include the ten platforms already banned in Australia such as TikTok, Snapchat and Instagram, but also YouTube, Reddit, Twitch, X, Threads, Facebook and Kick. Additional measures such as curfews for older teenagers and restrictions on AI chatbots may also be introduced.
- The UK’s information commissioner, John Edwards, has been temporarily stripped of his responsibilities whilst the ICO investigates into a workplace allegation, the details of which have not been disclosed.
- Edwards stepped back from his role towards the end of February 2026, and although the independent probe has found no wrongdoing, there still remains a case to be answered.
- The ICO confirmed that although Edwards had continued to receive updates from his team where required, he can no longer act in fulfilling his role for the duration of the investigation.
- Per the ICO’s Scheme of Delegation, Paul Arnold will temporarily take on responsibility of Edwards’ non-delegable roles, however as the commissioner is accountable to Parliament and not directly employed by the ICO, the next steps will be determined by the Department for Science, Innovation and Technology (DSIT).
New data protection complaints procedure to come into effect from 19th June 2026
- Under the new Data (Use and Access) Act 2025, from 19th June 2026, organisations processing the data of UK data subjects will be legally required to have a formal process in place for handling data protection complaints.
- A data protection complaint can be raised by a data subject where they have concerns about how their data is being processed by the organisation, including how their data subject access right was actioned.
- The key requirement is that organisations where acting as data controllers, must facilitate this new ‘right to complain’ by providing a specific mechanism to data subjects, such as an online complaints form or an email address etc.
- The acknowledgement of these complaints should be sent within 30 days. Please see the new guidance published by the Information Commissioner’s Officer for more details.
United States
The US plans on exchanging health aid for surveillance in seven African states
- According to the Human Rights Watch (HRW) the US entered into bilateral agreements with approximately seven African countries to provide healthcare resources in exchange for access to surveillance data and pathogen specimens.
- A senior health researcher, Julia Bleckner, at the HRW stated that “The agreements show the US intends to condition vital health assistance for millions of people on acquiescence to troubling conditions.”
- This comes after the US’ sudden pullback from assistance in these countries in 2025, the governments of which are now being forced to accept agreements with clauses that are detrimental to human rights.
- Most agreements signed between US and the African nations, except Kenya, commenced on April 1, 2026 and are set to continue for five years until December 31, 2030.
Europe
- The Netherlands has blocked Kyndryl an American IT company from buying Solvinity, the cloud provider which hosts its digital identity system- Dutch life, citing risks of public interest.
- Solvinity operates the platform for DigiD which is a secure login that millions of Dutch citizens use to reach the tax office, pension funds, health insurers and local councils.
- According to US law, that is CLOUD Act, the US government may access the data held by American host providers, regardless of where the data sits in the world.
- This action stems from an EU wide effort to reduce reliance on US Cloud providers, being viewed as a vulnerability rather than convenience of using already established providers.
Meta has removed the facial recognition feature from its smart glasses
- The EU Parliament has observed growing political resistance against the data protection risks presented by Meta’s smart glasses, specifically around how rules such as the GDPR and EU AI Act applies to AI-enabled smart glasses and other wearable recording devices.
- In March 2026, cross-party groups had approached the EU Parliament to investigate Meta based on reports that a third-party provider in Kenya had viewed the recordings of the glasses.
- A big data protection gap emerges from the secret recordings with smart glasses in public spaces having massive consequences for those affected.
- The European Data Protection Board (EDPB) has now also commissioned a report on the “social acceptance” of the devices, which is expected to be published this summer. This report will be extremely significant now that Samsung and Apple are also looking to launch their versions of smart glasses in the coming months.
International
- The NDPC will train secretaries and heads of government backed organisations on data protection, as declared in a three-day technical and organisational drill on data protection measures for information technology administrators across Ministries, Department and Agencies (MDAs).
- The training will be conducted through the Civil Service of the federation- the body which controls the permanent secretaries and all civil servants, using both top down and bottom-up approach.
- The NDPC commissioner has stated that these efforts are a result of the recent cyber security attacks, requiring them to create awareness, and ensuring that the individuals responsible have knowledge of the technical and organisational security measures that can be put in place, to protect their networks from unauthorised access.
Coupang fined $408 million by South Korea over biggest data leak in the country’s history
- The e-commerce giant Coupang has been hit with a record $408m fine over a leak that allegedly exposed the data of more than 30 million customers.
- South Korea’s data protection authority says that the e-commerce giant, Coupang, failed to implement safety measures and delayed reporting breach.
- Song Kyung-hee, the chairperson of the privacy regulator stated that “This accident occurred due to Coupang’s lack of safety measures and systems, not sophisticated hacking.” Furthermore, the delayed breach notifications meant that the data subjects were unaware of the breach and did not have the opportunity to take steps to prevent secondary harm.
- The penalty follows a government-led investigation this year leading to the highest fines in the country’s history- higher than the most recent $88m fine imposed last year on mobile carrier SK Telecom.
For the latest updates on UK social media ban, major privacy investigations, new data protection laws, and global cybersecurity developments, visit our Data Protection News hub.



