United Kingdom
ICO calls for stronger oversight of police facial recognition
- The ICO has warned police forces to strengthen accountability and governance around facial recognition, following audits that found a “mixed picture” across the forces reviewed.
- It issued 107 recommendations covering data protection compliance, senior oversight, staff responsibilities and the accurate recording of how personal data is sourced, processed and retained.
- Police forces were also encouraged to introduce stronger safeguards against bias, unfair treatment and inaccurate identification, particularly around retrospective facial recognition searches and the use of police watchlists.
- The findings come as UK police forces expand their use of facial recognition. The ICO said public support is conditional on transparency, accuracy, fairness and clear justification, while the government considers whether the current legal framework provides sufficient safeguards.
Research highlights gap between parental controls and children’s digital lives
- New UK Information Commissioner’s Office (ICO) research involving more than 4,000 children aged 8-17 and their parents found that 36% of children interact online with people they only know digitally or do not know at all, rising to 40% among 14-16-year-olds.
- Although 91% of parents use monitoring or parental-control tools, 41% of children said they had tried to circumvent them, with almost half of those children finding it easy to do so. More than half of children also said they would try to bypass age checks if they wanted to access a service.
- The research highlights concerns around children’s understanding of privacy and consent, including the extensive collection and sharing of location and other personal data, while parents reported finding it increasingly difficult to maintain effective controls as children become more independent.
United States
Disclosure rules considered by FTC for personalised pricing
- The US Federal Trade Commission (FTC) is considering requiring businesses to disclose when personal data is used to set individualised prices, following growing scrutiny of “surveillance pricing”.
- The practice involves using data such as browsing history, location, shopping habits and household information to determine what an individual consumer may be willing to pay.
- The FTC’s proposed enforcement policy would indicate that undisclosed use of personal data for pricing may constitute a deceptive practice under US law. The proposal will be open for public comment for 30 days.
US agencies warn of AI-assisted attacks targeting Siemens PLCs
- US agencies including the NSA, CISA, FBI, EPA and DOE have warned of targeted reconnaissance against Siemens programmable logic controllers (PLCs) used across critical infrastructure sectors.
- Threat actors are reportedly using AI-generated exploitation scripts, alongside known vulnerabilities and open-source industrial automation libraries, to gain access and manipulate PLC memory, configuration data and ladder logic.
- Targeted sectors include energy, water and wastewater, critical manufacturing, food and agriculture, chemical and commercial facilities, with potential consequences ranging from data compromise and equipment damage to safety incidents and supply-chain disruption.
- The agencies recommend patching PLCs, removing unnecessary internet exposure, strengthening access controls and monitoring OT environments. While no major disruptive attacks have been confirmed, the activity is considered preparation for potentially disruptive or destructive operations.
Europe
French tax authority confirms data breach affecting 678,000 users
- France’s Ministry of Finance has confirmed a cyberattack on the General Directorate of Public Finances, following claims that a malicious actor accessed the tax agency in late June.
- The attack involved the consultation and extraction of taxpayer data, with the Ministry later confirming that approximately 678,000 users were affected.
- Authorities are investigating which specific categories of personal and professional data were accessed and the full scope of the incident.
- Affected individuals will receive individual notifications detailing the data that may have been compromised and any precautionary measures they should take.
German privacy group files criminal complaint over Meta smart glasses
- German non-profit HateAid has filed a criminal complaint against Meta, Ray-Ban and Oakley, arguing that the sale of Meta’s smart glasses in Germany breaches the country’s strict privacy and data protection rules.
- The complaint focuses on the risk of covert recording, with concerns that people can be filmed without their knowledge or consent, including in sensitive or intimate situations.
- Meta maintains that the glasses comply with German requirements and include privacy safeguards such as an LED recording indicator and anti-tampering technology.
Hacker group claims major breach of French Ministry of Education
- The hacker group ZeroBytes has claimed an attack on France’s Ministry of Education, alleging that it accessed personal data relating to students and teachers.
- The group claims the breach could involve approximately 346 million lines of data, although this does not necessarily correspond to the number of individuals affected.
- Compromised information could include addresses, telephone numbers, school preferences and personal data relating to teaching staff, with some records potentially more than 20 years old.
- The incident is under investigation, while ZeroBytes has also previously claimed responsibility for the attack on France’s General Directorate of Public Finances, raising broader concerns about the security of French public-sector databases.
International
Brazilian regulator to stop facial recognition in Paraná schools
- Brazil’s National Data Protection Authority (ANPD) has ordered Paraná’s public school system to stop collecting and processing children’s and adolescents’ biometric data through facial recognition for attendance purposes.
- The regulator found that the state had not demonstrated an adequate legal basis for processing sensitive biometric data, nor provided sufficient safeguards around security, governance and the best interests of children.
- The pilot reportedly covered 2,136 schools, around 1 million students and more than 100,000 employees, with facial images processed through systems operated by state technology company Celepar and private vendors.
- The ANPD also found the technology unnecessary and disproportionate, noting that less intrusive alternatives such as traditional roll calls were available. Paraná has been given 10 days to confirm that biometric processing has stopped across all systems, schools and companies involved.
Australia’s eSafety regulator tightens child safety requirements for Roblox
- Australia’s eSafety Commissioner has secured a court-enforceable undertaking from Roblox after testing found that adults could still contact children without parental consent and access children’s profiles and connections.
- Roblox has been given three months to strengthen safeguards, including preventing adults from contacting unknown children, making children’s accounts private by default, and improving complaint reporting and user notifications.
- Roblox must also appoint an independent third-party auditor to assess its safety measures, including its age-estimation technology. It is the first time that eSafety has required an external safety audit by a technology firm.
For the latest updates on UK police facial recognition, parental-control tools, AI-assisted cyberattacks, France’s Ministry of Finance data breach, and other privacy, AI security breaches, visit out Data Protection News Hub.



