Data Bytes 67: Your EMEA Data Privacy Update for July 2026
Welcome back to this month's Data Bytes, covering data law updates from across EMEA.
This month we are delighted to introduce our new UAE privacy team who have contributed this month's spotlight focusing on the changing regulatory landscape in the UAE. The creation of a national AI and data authority could prove to be a real turning point for the onshore PDPL, which has so far lacked an active regulator and the long-awaited executive regulations needed to bring it fully to life. Add to that the new child digital safety regime, plus recent DIFC and ADGM developments, and the UAE is beginning to look much more like a mature, multi-layered privacy market rather than an emerging one.
In the UK, children’s online safety continues to dominate the agenda, with proposals to restrict under-16s’ access to social media and impose default protections for older teenagers. The ICO has also been busy on the practical side, publishing detailed IoT guidance and reminding organisations that the new DUAA complaints-handling rules are now in force.
The big news from the EU has been the publication of the much awaited update to the 2014 Article 29 Working Party’s Opinion on anonymisation. They follow the direction of travel of CJEU case law in Breyer and SRB and bring the EU position closer to the ICO draft guidelines.
The Data Bytes team are heading back to the podcast studio this summer with both the UAE data regulatory landscape and the EDPB's anonymisation guidelines to be put under discussion to accompany you on your morning commute (or however else you like to listen to your podcasts)! Watch this space for publication dates.
Over the past twelve months, there has been a series of regulatory developments across onshore UAE, the Dubai International Financial Centre ("DIFC") and Abu Dhabi Global Market ("ADGM"). From the creation of an entirely new national data and AI authority, to landmark online safety legislation for children, to important amendments to the privacy legislation of the DIFC and ADGM, the UAE's data protection regime is rapidly evolving.
Here's what you need to know:
On 14 June 2026, the UAE Artificial Intelligence and Data Authority (“Authority”) was formally established.
The Authority consolidates three entities: (1) the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, (2) the Information and Digital Government Sector within the Telecommunications and Digital Government Regulatory Authority and (3) the UAE Data Office (nominally responsible for enforcing the on-shore data protection law ("PDPL")).
Why does this matter? Until now, the UAE has not had an active data protection regulator on-shore, as the UAE Data Office established under the PDPL never became fully operational. This consolidation is the UAE's effort to resolve that fragmentation. This is a big step forward for the UAE privacy landscape, but what it means in practice remains to be seen. Among the things to watch: the long-awaited Executive Regulations needed to operationalise the PDPL remain pending, and the new Authority may finally be the catalyst that moves them forward. Businesses collecting and processing personal data of on-shore citizens should monitor how the Authority engages with industry early on, as its formative approach will likely set the tone for the year ahead.
The UAE has taken a significant step in protecting children online – introducing some of the most prescriptive child digital safety rules in the region.
The new Child Digital Safety Law places specific obligations on digital platforms, including prohibiting the collection of personal data from under-13s without verified parental consent, and prohibiting advertising using children's data.
The Cabinet Resolution Regarding the Regulation of Children's Access to Social Media Platforms goes further, setting minimum age requirements for creating accounts on social media platforms (15+ years), and adding extra protections for 15- to 16-year-olds.
The July 2025 amendments to the DIFC Data Protection Law introduced a private right of action – meaning data subjects can now pursue claims directly, without relying on the regulator to act on their behalf. This is a meaningful shift, as it gives individuals more control over enforcement and creates real litigation risk for businesses that fall short on compliance. Additional amendments clarified the extra-territorial scope of the law, and updated the adequacy framework for cross-border transfers.
In September 2025, the ADGM introduced the Substantial Public Interest Conditions Rules, clarifying lawful bases for processing special category data (including for insurance and educational purposes), and permitting processing without consent where necessary to protect children or individuals at risk.
These developments signal a clear direction of travel: regulators in the UAE are moving towards more prescriptive and developed privacy regulation. Businesses should ensure their governance frameworks evolve accordingly. Taking proactive steps now will put organisations in a stronger position than waiting for enforcement to catch up.
Please contact Alexandre Brazeau for further information on our data legal services in the region.
On 15 June 2026, the UK government announced that social media platforms will be banned from offering services to under-16s, following a public consultation that received more than 116,000 responses. The ban is intended to model the approach in Australia, covering user-to-user platforms such as Snapchat, TikTok, YouTube, Instagram, Facebook and X. However, the government does not plan to include messaging services such as WhatsApp and Signal in the ban.
Beyond the blanket ban, the government also intends to restrict harmful functions for under-16s (including livestreaming and communication with strangers) across a wider array of online services, such as gaming sites. These restrictions will be “on by default” for 16 and 17 year-olds to avoid a cliff-edge at 16. Under-18s are also expected to be barred from using AI "romantic companion" services.
On 15 July 2026, the government stated that these protections for 16 and 17 year-olds would include overnight curfews from midnight to 6am on social media apps and the disabling of addictive design features — such as autoplay functions and endless personalised feeds — by default. Older teens, however, would be able to change these default settings themselves. The government also aims to put forward measures for use of AI chatbots by children, including regular breaks for under-18s, and addressing the risk of misleading or unverified mental health advice (with a possible ban for chatbots posing serious threats to children). The government intends to bring regulations to Parliament before the end of 2026, with protections expected to come into force in spring 2027. A narrowly defined list of exemptions is planned to exclude educational, e-commerce and music-streaming services. Ofcom will be the enforcing authority, and further statements on age assurance options and VPNs are expected in the coming months.
Organisations operating consumer-facing digital services, particularly social media, gaming and livestreaming platforms, should begin assessing age-assurance capability and monitor the government’s further policy updates expected this year.
On 11 June 2026, the ICO published final guidance on consumer IoT products and services, following a consultation on the draft guidance published in June 2025. The guidance sets out clear expectations for manufacturers, app developers, operating system developers, cloud providers and others across the IoT supply chain on the lawful and fair use of personal data in IoT products provided on the consumer market. Examples of products include smart speakers, connected TVs, fitness trackers, smart doorbells, home hubs and smart domestic appliances. The guidance, however, does not cover smart meters, connected and autonomous vehicles, or enterprise/industrial IoT products.
Key expectations include:
Organisations across the IoT supply chain should review their consent flows, DPIAs, privacy notices and security lifecycle management against this guidance.
On 19 June 2026, the ICO published a statement confirming that former Information Commissioner John Edwards had resigned. Mr Edwards had stepped back from his duties at the end of February 2026 to allow an independent workplace investigation to take place.
The investigation determined that Mr Edwards's conduct had fallen short of the standards expected of a public official.
The board and executive team remain in charge of the ICO to ensure continuity of leadership and regulatory activity, pending appointment of a successor.
For organisations, this represents a period of institutional transition at the UK’s data protection regulator particularly when coupled with the creation of the new Information Commission, under the Data Use and Access Act, though the ICO has emphasised continuity of its regulatory work in the interim.
1. On 19 June 2026, new legal requirements on how organisations handle data protection complaints came into force under the Data (Use and Access) Act 2025 (DUAA), marking the 12-month commencement of the DUAA and bringing the remaining provisions into force. Organisations that process personal data are now required to establish a clear route for individuals lodging a data protection complaint, and must acknowledge it within 30 days, carry out an appropriate investigation and inform the individual of the outcome. The ICO’s focus is on helping organisations embed good practice. See more details here.
2. On 8 June 2026, the Department for Science, Innovation and Technology (DSIT) launched a consultation on empowering people through data intermediaries, focused on personal data intermediaries that help individuals exercise data subject rights, particularly the right to data portability. The consultation seeks views on removing barriers identified in a 2025 call for evidence — including legal ambiguity over the delegation of data subject rights to third parties, controller uncertainty in responding to delegated requests and low public awareness — and explores legislative options to resolve these issues. The consultation closes on 31 August 2026. See more details here.
3. On 24 June 2026, the ICO published its 'Edtech examined' report, detailing findings from consensual audits of 28 edtech providers carried out during 2024 and 2025 across products used in UK primary and secondary schools. The ICO identified compliance gaps including providers incorrectly identifying their controller/processor status, insufficiently detailed contracts with schools, incomplete data flow mapping, weak data minimisation, outdated privacy information and gaps in data protection impact assessments. Providers reportedly accepted and implemented 98% of the 596 recommendations made. See more details here.
4. On 3 July 2026, the ICO published advice aimed at small retail businesses on lawfully using personal information — including CCTV footage and, where justified, facial recognition technology — to help tackle theft and violence against staff. The guidance includes practical checklists, examples and template documents, and emphasises that data protection law enables lawful crime prevention measures. See more details here.
On 8 July 2026, the EDPB launched public consultations on new adopted guidelines on anonymisation, and on web scraping in the context of generative AI.
The guidelines provide a practical framework for organisations to assess whether anonymisation has been achieved, presenting a two-question test for anonymity: (1) does the information “relate” to a natural person?; and (2) if so, is that natural person “identified or identifiable”? If the answer to either question is no, then according to the guidelines, the data should be considered anonymous.
The web scraping guidelines address the GDPR compliance of scraping personal data from publicly available internet sources for generative AI training and fine-tuning, covering scenarios where an organisation scrapes data itself or via a contractor, or reuses a dataset scraped by another organisation (data broker). Key areas addressed include:
Organisations developing or procuring generative AI trained on scraped data, and those relying on anonymisation as a basis for reduced GDPR obligations, should review their legal basis analysis and anonymisation testing methodologies against these guidelines and consider responding to the consultations. Both consultations end on 30 October 2026.
On 10 June 2026, the EDPB launched a public consultation on a new template for personal data breach notifications. The template is intended to be used by data protection authorities (DPAs) through an IT tool and incorporates rules on the necessity of data collection. It also contains predefined values and recommendations to help organisations complete notifications.
Organisations with EU breach-notification obligations should review their incident response templates against the EDPB's proposed structure — including data breach timelines, risk assessment and remediation — and consider responding to the consultation. The consultation ends on 5 August 2026.
On 29 June 2026, the Council of the EU approved the Digital Omnibus on AI, formally adopting the text agreed with the European Parliament. This is the first substantive set of amendments to the EU AI Act since its 2024 adoption. Key elements include:
The legislative act will be published in the Official Journal shortly and will enter into force three days after publication. Organisations subject to the AI Act should update compliance calendars to reflect the revised high-risk deadlines, assess exposure to the new NCII/CSAM prohibition and monitor forthcoming Commission guidance for operators of high-risk AI systems that are subject to sectoral harmonised legislation.
1. On 8 July 2026, alongside its new anonymisation and web scraping guidelines, the EDPB adopted guidelines on the processing of personal data through blockchain technologies, following public consultation. The guidance explains how different blockchain architectures operate and their implications for GDPR compliance. See more details here.
2. On 29 June 2026, privacy NGO noyb warned that the US Supreme Court's decision in Trump v. Slaughter — finding that the independence of the Federal Trade Commission (FTC) is unconstitutional under the "unitary executive" theory — undermines the legal foundation of the EU-US Data Privacy Framework (DPF). The European Commission's adequacy decision underpinning the DPF relies on the independence of the FTC, and noyb has indicated it will file a lawsuit seeking annulment of the DPF by the CJEU. Organisations relying on the DPF for transatlantic transfers should monitor developments closely and consider the resilience of their transfer mechanisms. See more details here.
3. On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence, setting out a coordinated approach across three objectives: (1) promoting the safe and responsible use of advanced AI, by strengthening the EU AI evaluation capacity; (2) reinforcing the EU's cybersecurity and resilience, by promoting implementation of the NIS2 Directive, Cyber Resilience Act, and other EU cybersecurity legislation; and (3) scaling up Europe's AI capabilities for cybersecurity, by launching an "EU Grand Challenge on AI for Cybersecurity" and continued investment in sovereign AI infrastructure. See more details here.
4. The CJEU ruled in Case C-199/24 (Legal Newsdesk Sweden) that Member States cannot exclude GDPR protection for processing that is not genuinely journalistic, academic, artistic or literary in nature. The paid publication of criminal convictions does not qualify as journalism where it does not aim to inform the public through verification of the facts, with appropriate editing or adapting, and adherence to ethical rules and codes of conduct. Individuals affected by such publications must be able to rely on GDPR remedies rather than being confined to defamation actions. See more details here.
5. On 8 July 2026, the European Commission referred Ireland, Spain, France and the Netherlands to the CJEU after their failure to notify measures transposing the NIS2 Directive into national law. Member States were given until 17 October 2024 to transpose the Directive, which sets cybersecurity standards for entities across 18 critical sectors. The Commission has asked the CJEU to impose financial sanctions, including a lump sum and daily penalties, until full transposition is notified by those Member States. See more details here.
6. On 2 July 2026, the European Data Protection Supervisor (EDPS) published a checklist on human intervention on automated decision-making (ADM) intended as a self-assessment tool for EU institutions. The checklist stresses that human oversight does not eliminate the inherent risks of ADM systems entirely, and its effectiveness depends heavily on design and implementation — it covers factors such as whether users receive plain-language summaries of ADM logic and confidence scores, whether operators have authority to override ADM systems, and regular internal and external auditing of overrides. See more details here.
7. On 9 June 2026, the Council presidency and European Parliament negotiators reached a provisional agreement on the 'Omnibus IV' package, covering new legislation on small mid-cap enterprises (SMCs), digitalisation, and common specifications. The agreement raises the Commission's originally proposed SMC thresholds to enterprises with fewer than 1,000 employees and either up to EUR 200 million turnover or up to EUR 172 million balance sheet total. It also advances the "digital by default" principle, aiming to cut unnecessary paperwork and costs for businesses, while ensuring safety information remains available in paper form where there is a risk of serious harm to consumers. See more details here.
8. On 8 May 2026, the European Commission published draft guidelines on implementing the transparency obligations for certain AI systems under Article 50 of the AI Act, intended to help competent authorities, providers and deployers apply the obligations consistently. The guidelines were prepared in parallel with the Code of Practice on marking and labelling of AI-generated content. See more details here.
9. On 18 June 2026, the CJEU ruled in Case C-484/24 (NTH Haustechnik GmbH v EM) that the GDPR does not preclude national courts from considering evidence where it was obtained through unlawful processing of personal data; admissibility of evidence remains governed by national law. However, the court must satisfy its GDPR requirements where it processes personal data of parties (and third parties) in proceedings. See more details here.
10. On 4 June 2026, the CJEU ruled in Case C-312/24 (Darashev) that public authorities were not permitted to retain data from criminal investigations in personnel files indefinitely where no wrongdoing is found. This ruling signifies that organisations that retain records following investigations without adverse findings should ensure that their retention policy is consistent with GDPR obligations. See more details here.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.