Data Protection News Update 20 July 2026

Folded newspapers wooden table, closeup

United Kingdom

New UK Data Regulator structure announced

  • The UK Department for Science, Innovation and Technology (DSIT) and the Information Commissioner’s Office (ICO) have announced the appointment of seven non-executive board members for the new UK Information Commission, which will replace the ICO’s current single-commissioner model.
  • The restructured regulator, introduced under the Data (Use and Access) Act, will adopt a corporate governance model with a chair, CEO, executive directors and a non-executive board focused on accountability, trust and responsible data use.
  • DSIT has launched consultations on key data protection issues, including international data transfers, the interaction between data protection rules and AI development, and the costs of reusing public sector data.
  • The UK Cabinet Office has also proposed a model action plan for managing significant government data breaches, requiring rapid escalation, risk assessment, ICO notification within 72 hours and post-incident remediation.

UK announces social media curfew for teenagers aged 16-17

  • The UK government has announced plans for a default overnight social media curfew for 16 and 17-year-olds, restricting access to platforms such as Instagram, TikTok and YouTube between midnight and 06:00 unless users opt out.
  • The measures would also require addictive platform features, including autoplay and infinite scroll, to be disabled by default in an effort to improve teenagers’ sleep, focus and wellbeing.
  • Concerns that the opt-out approach may be ineffective have been raised, arguing that stronger protections are needed to address harmful platform design and online risks.
  • The government is also considering further online safety measures, including protections for young people using AI chatbots, with proposals expected to be introduced to Parliament by the end of 2026.

United States

US Supreme Court expands privacy protection for location data

  • On 29 June, the US Supreme Court has ruled that historical smartphone location data held by third-party providers is protected under the Fourth Amendment, meaning law enforcement generally requires a warrant to access it.
  • The decision extends previous privacy protections established in Carpenter v. United States, confirming that even short periods of smartphone-generated location data can reveal sensitive insights into an individual’s movements and private life.
  • The ruling has significant implications for technology companies, app developers and other organisations that collect location data, requiring closer scrutiny of government requests for access to such information.
  • While the Court did not rule that geofence warrants are unconstitutional, it raised concerns about reverse-search techniques and indicated that future cases may examine protections for other sensitive smartphone-generated data.

xAI sues Grok user over alleged AI-generated sexual deepfakes

  • Elon Musk’s AI company xAI has filed a lawsuit against a Grok user accused of misusing the AI system to create child sexual abuse material and non-consensual sexualised deepfakes.
  • The user allegedly violated xAI’s terms of service by uploading images of adults and minors and attempting to generate explicit AI-generated content from them.
  • The case is among the first legal actions brought by an AI provider against a user for abusing an AI system to create harmful content, highlighting growing accountability concerns around generative AI tools.
  • xAI stated it uses enforcement measures including account suspensions, terminations and reporting suspected child sexual abuse material to relevant authorities, while seeking damages and a permanent restriction on the user’s access to Grok.

US allows TikTok use on federal devices after data deal

  • The US Department of Justice (DoJ) has determined that federal employees may download TikTok on government devices, reversing a 2022 restriction introduced over national security concerns.
  • The decision follows a January agreement transferring control of TikTok’s US user data and operations to a new joint venture, TikTok USDS, with data and algorithm security managed through US-based infrastructure.
  • The DoJ concluded that TikTok’s Chinese owner ByteDance’s continued minority ownership of the venture does not create a significant security concern, allowing agencies discretion over whether employees can use the app.
  • The move follows ongoing US scrutiny of TikTok’s ownership, data protection practices and potential foreign access risks, with the app continuing to serve around 200 million U.S. users.

Europe

Greece proposes jail penalties for removing AI deepfake labels

  • Greece has proposed legislation implementing the EU AI Act that would introduce criminal penalties, including imprisonment and fines, for removing or tampering with labels and watermarks identifying AI-generated deepfakes.
  • The draft law would make it an offence to remove visible AI labels, delete invisible digital watermarks or interfere with AI systems designed to identify synthetic content.
  • The proposal goes beyond the approach taken by several other EU Member States, which have generally opted for administrative fines rather than criminal sanctions for breaches of the AI Act’s transparency requirements.

Lidl customer data exposed following third-party cyber incident

  • Lidl has notified customers in Germany, Belgium and the Netherlands after a cyber incident at an external IT provider resulted in the theft of customer data from a third-party database.
  • The compromised data includes names, email addresses, telephone numbers, dates of birth and customer identification numbers. Lidl confirmed that passwords, payment details and customer accounts were not affected.
  • While there is currently no evidence of misuse, affected customers have been advised to remain vigilant for phishing attempts and identity fraud.

International

China introduces rules for AI companion services to prevent addictive use

  • China’s new Interim Measures for the Administration of Anthropomorphic AI Interaction Services have come into force, introducing requirements for providers of AI-powered emotional interaction services and companion chatbots.
  • The rules require providers to implement safeguards such as emotional distress detection, crisis intervention measures and controls to prevent excessive or addictive use of AI companions.
  • The framework also introduces data protection obligations, including restrictions on using sensitive personal data collected through AI companion interactions to train AI models.
  • The Cyberspace Administration of China will oversee enforcement, with providers facing fines of up to CNY200,000 for serious violations involving harm to users’ safety and wellbeing. 

Ecopetrol investigates cyberattack affecting 3,300 user accounts

  • Colombian energy company Ecopetrol has disclosed a cyberattack that resulted in the theft of data linked to approximately 3,300 user accounts across its cloud-based file storage environments.
  • The attacker issued extortion demands and threatened to publish the stolen information, although no data had been publicly disclosed at the time of reporting.
  • Ecopetrol stated it successfully prevented an attempted ransomware attack and reported no disruption to operations or production, while continuing to assess the scope of the compromised data. The incident affected Ecopetrol and 15 subsidiaries.


For the latest updates on UK social media curfews for teenagers, AI regulation, cyberattacks, data breaches, global privacy developments, and further data protection news, visit out Data Protection News Hub.

Share:

More Posts

Send Us A Message