Privacy and Data Protection Summer Snapshot 2026
Wednesday 9th September 2026
Welcome to our Summer Snapshot, which summarises the latest key data protection news and developments.
In this edition we look at:
- the latest developments on TikTok’s ICO fine for the unlawful processing of children’s personal data;
- the Cyber Security and Resilience Bill;
- recent enforcement by the ICO in relation to cyber attacks, and ‘lessons learned’;
- Apple’s challenge to the UK Government’s data surveillance order;
- social media restrictions for under 16s; and
- a summary of the ICO’s regulatory strategy which focuses on AI transparency.
A turning point for children’s privacy? TikTok loses appeal against ICO monetary penalty
In April 2023, the Information Commissioner’s Office (ICO) issued TikTok with a £12.7 million monetary penalty notice for breaches of the UK GDPR, due to concerns around TikTok’s processing of personal data of children under 13. TikTok had appealed, claiming that the penalty notice was ultra vires and that, at high level, its processing activity is for ‘journalistic, academic, artistic or literary purposes’.
The Upper Tribunal dismissed TikTok’s appeal on all grounds, holding (amongst other grounds) that the processing carried out by TikTok’s platform was not carried out “for” artistic purposes. The recommender algorithm distributes content based on predicted user engagement and is therefore incapable of identifying if content is artistic.
This decision clarifies that online platforms hosting third party content cannot rely on “special purposes” on the basis that their services enable artistic expression. To rely on such purposes, processing would need to be deliberately and intentionally for a journalistic, academic, artistic or literary purpose.
For any platform processing children’s personal data, this serves as an important reminder that such data is given special protection under data protection laws. Organisations should ensure they have all appropriate privacy notices and impact assessments and have adopted a privacy by design and default approach in line with the Children’s Code before any data processing takes place.


The Cyber Security and Resilience Bill
The Cyber Security and Resilience (Network and Information Systems) Bill is set to be the most significant update to the UK’s cyber security framework since the NIS Regulations 2018. Expected to receive Royal Assent in late 2026, the Bill expands regulatory oversight to managed service providers, data centres, large load controllers and designated critical suppliers. It also introduces enhanced incident reporting requirements, including notification within 24 hours and a full report within 72 hours, backed by fines of up to £17 million or 4% of global turnover for serious breaches.
While retailers are not currently within the Bill’s direct scope, recent high-profile cyber incidents affecting major UK brands have fueled debate about whether the sector should be brought within the regime. The Bill’s new ‘designated critical supplier’ mechanism and broad ministerial powers to expand its scope mean further sectors, such as retail, could be captured in the future.
Even where businesses are not directly regulated, the impact is likely to be felt across supply chains. Organisations subject to the new regime will be expected to manage cyber risk throughout their supplier networks, increasing due diligence, contractual cyber security requirements and compliance expectations.
Cyber security in the spotlight: The ICO reinforces measures to prevent cyber attacks
The ICO has recently reprimanded the ACRO Criminal Records Office (ACRO) following its investigations which revealed that a hacker gained access to ACRO’s website and content management system between August 2022 and March 2023.
Although ACRO had engaged third parties to provide security services, ACRO had failed to allocate responsibility for identifying and monitoring critical security updates or investigating security alerts and as a result, the personal data of up to ten thousand individuals may have been compromised.
This reprimand serves as a reminder to all organisations to:
- allocate responsibility clearly: designate responsibility for identifying, assessing and implementing security updates across all third-party systems and suppliers;
- proactively act on warning signs: ensure security alerts are frequently monitored and escalated appropriately to avoid major incidents; and
- master the fundamentals: straightforward measures such as effective patch management and regular security testing can provide critical defences against cyber attacks.


Encryption vs access: Apple challenges UK Government’s data surveillance order
Apple is challenging a UK Government order issued under the Investigatory Powers Act 2016, which compels technology companies to provide law enforcement with access to user data. At the heart of the dispute is Apple’s Advanced Data Protection feature, which uses end-to-end encryption for iCloud data, meaning that not even Apple can access its contents.
In February 2025, the UK Government issued a technical capability notice requiring Apple to create a mechanism enabling access to encrypted user data. Apple has publicly refused, arguing that compliance would require building a ‘backdoor’ into its encryption systems, fundamentally weakening security protections for all users worldwide, not just those in the UK.
The case raises fundamental questions about the balance between national security interests and individual privacy rights. While the Government maintains that such access is necessary for detecting serious crime and national security threats, privacy advocates warn that any backdoor, however well-intentioned, creates vulnerabilities that could be exploited by malicious actors.
The outcome of this dispute could have significant implications for organisations that rely on end-to-end encryption or handle sensitive data. It may influence how technology providers design security features, and how organisations assess and communicate the security of their data storage solutions to customers and regulators.
A brave new world? Under-16s face social media ban
Proposals were formally announced by the Government on 15 June 2026 to prohibit those under the age of 16 from accessing social media platforms. The proposed restrictions are expected to come into force in Spring 2027.
The proposals also seek to protect young people from harmful uses of AI, including so-called “AI companion” or “romantic companion” chatbots, which would be required to enforce a minimum age requirement of 18.
A key aspect of the proposals is the enforcement of age restrictions. Organisations operating online platforms will therefore need to ensure they have effective age assurance measures in place to verify users’ ages. The practical implementation of these measures will be particularly important from a data protection perspective. For example, if platforms require users to submit identification documents as part of the verification process, this could involve significant processing of personal data and may necessitate a careful assessment of privacy risks and compliance obligations. To support this work, Ofcom has been tasked with carrying out a rapid review into the effectiveness of age assurance methods for verifying whether users meet the threshold.


The ICO’s AI agenda: trust and transparency
The ICO has reaffirmed that regulating AI will remain a key priority under its new corporate strategy, emphasising that now is the critical moment to build trust, transparency and accountability into the development and use of AI.
In a recent article, William Malcolm, the ICO’s Executive Director of Regulatory Risk and Innovation, highlights the growing role of AI across all sectors and the benefits it can deliver for organisations and consumers. However, he also notes that recent incidents have demonstrated the risks that can arise when appropriate safeguards are not built into AI systems from the outset.
The ICO believes that public trust will be fundamental to the long-term success of AI. The regulator is keen to address concerns around fairness, bias, security and transparency.
To support responsible innovation, the ICO plans to focus on a number of initiatives, including developing a statutory AI and automated decision-making (ADM) code of practice, issuing guidance on agentic AI, helping organisations manage AI-related cyber risks and producing resources to help businesses carry out AI due diligence.
Sign up to our upcoming webinar

Lauren Wills-Dixon and Will Powell from the privacy and data protection team will be covering the subject of DPIAs (data protection impact assessments) in the AI and novel tech era.
Providing legal and practical guidance on identifying high-risk data processing, they will explain common DPIA triggers, and how to build privacy considerations into digital projects from the start.
The session is aimed at all those involved in designing, procuring or deploying AI and digital technologies.
Register for the event here.
If you have any questions, please do not hesitate to get in touch with one of our Privacy experts.