Data Protection News Update 26 May 2026

New patient medical record form and stethoscope medical.

United Kingdom

ICO puts forward recommendation to extend cookie consent exemptions to contextual advert cookies only

  • The Information Commissioner’s Office (ICO) has posted its recommendations to the Government on how the new powers to extend cookie consent exemptions should be used to cover only contextual advertising.
  • Amendments to cookie consent requirements come from the enactment of the new Data (Use and Access) Act 2025.
  • Businesses in the advertising industry expressed their disappointment to the restriction of consent exemption for contextual advertising alone stating that it risks undermining innovation, investment, and the future sustainability of the sector.
  • Ultimately, it is for the Government to decide whether it wants to accept the ICO’s recommendations and to what extent. The Government is also undertaking a consultation with other stakeholders, some who are arguing for personal advertising exemptions.  

11 NHS staff members sacked for inappropriately accesses medical records

  • Eleven NHS staff members have been dismissed for inappropriately accessing medical records of the Nottingham attacks victims.
  • Two Nottingham students and the grandfather were stabbed to death on 13 June 2023 by Valdo Calocane, who was diagnosed with paranoid schizophrenia in 2020.
  • NHS staff including doctors, nurses, registered medical professionals, and administrative and clerical employees, accessed the victims’ record without need in 2025, as found by an investigation concluding last week.
  • Nottingham University Trust confirmed that it had dismissed 11 members of staff, while 12 had received final written warnings and two had first written warnings.

United States

Lawmakers warn that key sites like the White House and CIA are not protected by data protection rules

  • The Biden administration drafted rules over a span of one year with the aim to block U.S. adversaries from buying commercial data gathered from cell phones at the federal government’s most sensitive locations.
  • As found recently, 736 locations were left off the list within the drafted regulations, including the White House, Congress and CIA’s headquarters.
  • The letter by the lawmakers urged the Trump administration to fill the gaps identified in the Biden regulation by creating a “protection zone” which encompasses the entire Washington DC area rather than individual buildings. The letter also asked the administration from considering banning a list of countries from acquiring data of Americans.
  • It is argued that data brokers around the world make such data available which could then be used by Governments and foreign spy agencies to map the patterns and activities of U.S. government personnel.

Europe

Stadiums in the EU are expanding use of biometric data for entry, raising GDPR concerns

  • Clubs and leagues in the EU are expanding facial recognition for ticketing and security while the regulators warn biometric deployments will face stricter standards compared to the U.S.
  • Borussia Moenchengladbach, a German football club, plans to partner with U.S. firm Extreme Networks, which provides AI cloud networking products for the NFL and Major League Baseball, to eliminate queues at it 54,000 capacity stadium.
  • Legal professionals have urged venue operators to first consider regulatory differences between the UK and EU vs the US before enacting any such changes. The main reason being that biometric data is considered special category data under the GDPR.
  • Most recently, regulatory authorities have already fined Spanish club Barcelona €500,000 fine for “failing to carry out appropriate data protection impact assessments when gathering biometric data during its mandatory census of 143,000 club members.”

EU parliament moves to ban non-consensual ‘nudifier apps’

  • Starting 2 December, the European Parliament and Council will outlaw “nudifier apps”. The ban specifically targets companies developing AI systems for sexual deepfakes and users creating false intimate content of real people without consent.
  • The European Parliament Research Service found that about in 2025 there were about 8 million deepfakes, with 90 per cent of online content set to be AI-generated by 2026.
  • These tools use deep-learning models, image recognition, and body reconstruction technology to generate realistic images based on the lighting, pose, and skin tone of the original photo. These tools are often marketed as “AI Art” and are available to download as mobile applications on App Store etc.
  • The ban works by making developers of large-scale AI models directly responsible if their systems are used to create such images. As a result, these companies must now build permanent safety blocks as a core part of their software to stop users from generating such content.

International

Brazil’s President Lula makes big tech companies liable for illegal content generated by its users

  • Brazil’s President has signed two decrees on Wednesday which aim to increase big tech companies’ liability for illegal content shared by its users, thereby paving the way for investigations by regulatory authorities into their responses to such cases.
  • The first decree enables the national agency of data protection to investigate such cases. Whereas the second decree establishes guidelines for the protection of women in the digital environment.
  • These amendments stem from a recent Supreme Court case, which has required big tech companies to monitor their platform for hate speech, racism and incitation to violence and act to remove it.
  • Brazil’s approach to monitor big tech is increasingly mirroring that of the EU.


For the latest updates on ICO cookie consent exemptions, NHS medical record access breaches, GDPR concerns over biometric stadium entry systems, EU plans to ban AI nudifier apps, and global crackdowns on big tech liability, visit our Data Protection News hub.

Share:

More Posts

Send Us A Message