United Kingdom
ICO fines debt marketing firm £300,000 for illegal spam campaign
- The UK ICO has fined Manchester-based KRA Consultancy Ltd £300,000 for sending more than 5.5 million unlawful marketing text messages to people in financial difficulty without valid consent, in breach of PECR.
- The company used personal data relating to individuals whose loan applications had previously been rejected and failed to verify whether recipients had consented to receive marketing, resulting in more than 60,000 complaints.
- KRA also sent fake enforcement messages to intimidate recipients into engaging with its debt services, while internal communications revealed deliberate attempts to avoid detection and continue unlawful marketing activity despite the ICO’s investigation.
- Alongside the financial penalty, the ICO issued an enforcement notice requiring KRA to stop sending unsolicited marketing messages to vulnerable individuals.
ICO calls for stronger data protection training across the NHS
- The ICO encouraged NHS organisations to strengthen role-specific data protection training following several cases of healthcare staff accessing patient records without authorisation during high-profile incidents.
- Information Commissioner Paul Arnold said healthcare providers should take a more proactive approach to preventing unauthorised access, warning that data protection is a cultural issue, not just a compliance requirement.
- The ICO stressed that annual compliance training alone is insufficient, calling for practical, role-relevant education, regular reinforcement, and stronger accountability through managers.
- The warning highlights the need for organisations handling sensitive health data to strengthen internal governance and reduce the risk of privacy breaches caused by employee curiosity or poor data handling practices.
New UK data protection complaints rules take effect
- New legal requirements under the Data (Use and Access) Act 2025 now require all organisations handling personal data to provide a clear process for data protection complaints, acknowledge complaints within 30 days, investigate them appropriately and communicate the outcome.
- The ICO has published updated guidance to help organisations comply, including practical examples covering common issues such as subject access requests, inaccurate personal data and direct marketing complaints.
- The ICO warned that many businesses remain unaware the new requirements apply to them, but has emphasised a supportive approach to implementation, encouraging organisations to implement effective complaints handling into day-to-day operations to improve compliance, transparency and customer trust.
United States
Microsoft Teams introduces Wi-Fi-based workplace check-in
- Microsoft has begun rolling out a new Microsoft Teams feature that automatically updates employees’ workplace location when they connect to their organisation’s Wi-Fi, allowing colleagues to see whether they are working from a specific office without requiring manual check-ins.
- The feature has been designed with privacy and user control in mind. It is disabled by default, must be enabled by tenant administrators, and employees can independently opt in or out of sharing their workplace location at any time.
- By relying on recognised corporate Wi-Fi networks rather than GPS or badge tracking, Microsoft aims to provide a less intrusive way of supporting hybrid working while ensuring location information remains within the organisation’s Microsoft 365 tenant.
- Organisations adopting the feature are encouraged to clearly communicate how location data will be collected, processed and shared, ensuring employees understand the consent mechanisms and privacy implications before enabling the capability.
Vermont enacts comprehensive Consumer Privacy Law
- Vermont has become the 23rd US state to enact a comprehensive consumer privacy law, with the Data Privacy and Online Surveillance Act coming into force on 1 January 2028. The legislation introduces obligations for organisations processing personal data, including requirements to conduct data protection impact assessments, respect users’ opt-out preference signals and disclosing whether personal data is collected, used or sold to train large language models.
- This law applies to any business handling data of at least 35,000 consumers, a low bar that represents 5.4% of the state’s 645,000 residents, making this law the most far-reaching of any state’s proportionally speaking.
- Additionally, Vermont introduced new data broker registration requirements, creating a public registry of data brokers and launching work on a statewide data deletion mechanism and Cybersecurity Advisory Council to strengthen oversight of personal data processing.
- The state also passed a new Genetic Information Privacy Act, requiring explicit consent before genetic data can be sold to third parties, prohibiting consent obtained through dark patterns, and giving individuals the right to have their DNA samples and associated genetic data permanently deleted.
Klue supply chain attack exposes Salesforce customer data
- Klue is investigating a supply chain cyberattack in which attackers compromised its Battlecards application to steal OAuth tokens used for third-party integrations, enabling unauthorised access to Salesforce CRM data belonging to hundreds of organisations.
- The incident exposed customer information held in Salesforce environments, including names, email addresses, business contact details, physical addresses, support case information and sales records. Several cybersecurity companies, including LastPass, Recorded Future, Tanium and Huntress, confirmed that customer data was affected, although none reported compromises to their core products or internal infrastructure.
- Salesforce stated there is no evidence of a vulnerability in its own platform and has disabled connections via the Klue Battlecards application. Affected organisations have revoked compromised OAuth integrations and rotated credentials to prevent further unauthorised access.
Europe
EU proposal to replace cookie banners faces opposition
- The European Commission’s proposal to replace cookie banners with an automated browser-based consent signal under the Digital Omnibus has been dropped from the latest EU Council position following opposition from several Member States and industry lobbying.
- The proposed system would have enabled users to manage tracking preferences through their browser rather than repeatedly interacting with cookie banners.
- Noyb argues that the withdrawal of the proposal reflects pressure from the online advertising and tracking industry, particularly Google, which opposed the measure on the basis that it could reduce personalised advertising and consent rates.
- The European Parliament has yet to adopt its position on the proposal, but this highlights ongoing tensions between simplifying the online user experience, protecting individuals’ privacy and consent rights, and preserving advertising-driven business models that rely on large-scale collection and processing of personal data.
Italian DPA fines Emirates over passenger health data practices
- Italy’s data protection authority has fined Emirates €180,000 after finding shortcomings in how the airline handled the health data of passengers requiring mobility assistance.
- Although the regulator found the processing of health data was lawful for providing safe travel and assistance, it ruled that Emirates failed to provide clear and transparent privacy information to passengers about how their data would be used.
- The authority also found that Emirates retained passengers’ health data collected through medical forms for seven years, considering the retention period excessive and disproportionate under the GDPR.
- The investigation was triggered by a passenger complaint alleging she was unnecessarily required to submit a medical form despite not falling within the categories that required one.
International
Five Eyes warn AI will rapidly accelerate cyber threats
- The Five Eyes intelligence alliance (US, UK, Canada, Australia and New Zealand) has issued a joint warning that advances in AI are expected to significantly accelerate offensive cyber capabilities, reducing the time between vulnerability discovery and exploitation from years to months.
- Organisations are to treat cyber resilience as a board-level business risk, with leaders encouraged to strengthen core cybersecurity controls, reduce attack surfaces, improve identity and access management, address legacy systems and accelerate patching.
- The guidance warns that AI is lowering the barriers for cybercriminals while increasing the scale and sophistication of attacks, making incident response planning and defence strategies more critical than ever.
- The Five Eyes also encouraged organisations to use AI to strengthen cyber defences, including improving vulnerability detection, monitoring, software security and incident response, while emphasising that strong cybersecurity fundamentals remain essential.
For the latest updates on the NHS data protection training, the ICO’s spam marketing fine, new UK data protection complaints rules, Microsoft Teams’ Wi-Fi workplace check-in,nand global privacy regulations, visit our Data Protection News hub.



