Data Bytes 68: Your EMEA Data Privacy Update for September 2026
Welcome to our “back to school” edition of Data Bytes. Whether you've been soaking up the last of the summer sun or buried in DPIAs, the data protection and cyber security world has certainly not taken a holiday.
Our spotlight this issue falls on the EDPB's new draft guidelines on anonymisation, which attempt to bring clarity to one of the GDPR's most debated concepts. With the consultation window open until October, now is the time to get to grips with the two-question test for determining whether data is truly anonymous and to consider what the contextual and simplified assessment approaches mean for your organisation's data strategy. We break down the key points and practical implications.
Closer to home, the ICO has been busy publishing the findings of its facial recognition audits across five police forces, issuing fines for children's privacy failures, and continuing to push platforms on age assurance. Meanwhile, the government's decision to abolish DSIT and elevate AI to Cabinet level signals a new chapter for technology governance in the UK, one that organisations across all sectors will want to watch closely. Over in the EU, the European Commission has published its first detailed implementation guidance on the Cyber Resilience Act just as the September 2026 vulnerability-reporting deadline looms, and the AI Act's enforcement machinery is now fully operational.
As always, we've rounded up the developments you need to know about, distilled the practical takeaways, and flagged the deadlines worth marking in your diary.
On 7 July 2026, the European Data Protection Board published its long-awaited Draft Guidelines 02/2026 on Anonymisation as an update to the Article 29 Working Party's Opinion 05/2014. The backdrop to these draft guidelines, which are open for consultation until October, was the Court of Justice of the European Union's September 2025 ruling in EDPS v SRB. In that decision, the CJEU held that pseudonymized data is not automatically personal data for every recipient and that the same dataset can be personal data in one organization's hands and anonymous in another's. Though helpful, the judgment led to differences in interpretation and practical challenges in implementing meaningful anonymisation across different contexts at a time when the use of personal data is accelerating at an unprecedented pace.
The draft guidelines seek to resolve uncertainty around GDPR anonymisation standards while highlighting ongoing reidentification and compliance considerations.
The draft guidelines set out a two-question test to determine whether data is anonymous under the EU General Data Protection Regulation: Does the data relate to a natural person? If so, is that person identifiable? Identifiability turns on the "means reasonably likely to be used" standard, assessed from the perspective of each "relevant entity."
The European Data Protection Board provides two approaches organizations can use to assess anonymisation. The contextual approach examines each relevant entity's actual capabilities individually, while the simplified approach ignores differences between entities' resources and produces a more conservative result. The EDPB notes that organizations may wish to use the simplified approach in the first instance and switch to the contextual approach where they require a more nuanced answer specific to a relevant entity.
Under both approaches, the EDPB tests against three technical criteria: no record isolation, no linkage and no inference.
The no record isolation criterion is met “if the data does not contain a unique combination of attribute values that relate to a single individual,” and larger, more detailed records carry higher risk.
The no linkage criterion is likely to be met if the information “has not been recorded elsewhere and is not correlated to similar information about the same individual recorded in other contexts.” In short, the criterion is met when the data cannot be connected back to other data relating to the same person.
The no inference criterion is met “if no specific and meaningful inference can be drawn from the given data.” In other words, no one can deduce a specific, individual-level conclusion from either the record itself or the aggregate.
The EDPB clarifies that failing one criterion does not automatically make data personal. Instead, it should trigger further analysis of whether that failure enables identification in context.
In addition, the draft guidelines confirm that data cannot be personal in a controller's hands but anonymous in its processor's hands. The EDPB describes this as a "teleological application" of the GDPR, to stop controllers using processors to escape GDPR protections. They also confirm that a dataset can be considered anonymous only if the anonymisation is effective for every individual whose data is contained within it. If some parts of the dataset cannot be anonymised, the entire dataset should be treated as personal data.
The EDPB's perspective-based approach in the draft guidelines creates more flexibility for organizations sharing data with other entities. Where a data recipient has no reasonable means of reidentifying individuals in a dataset, it can be treated as anonymous for the recipient, even if the disclosing controller still has the ability to reidentify them. This opens practical doors for data sharing in the context of analytics and research in particular.
The draft guidelines emphasize that for information to be anonymous, reidentification risk does not need to reach zero. Instead, the standard is whether the likelihood of the individual being successfully distinguished from others within a given context is "insignificant in reality."
They also confirm that controllers who have already assessed datasets to be anonymous under the approach set out in the Article 29 Working Party's Opinion 05/2014 do not need to reassess them purely in light of this new draft.
Several aspects of the draft guidelines could create additional burdens or complexities for organizations. They expressly exclude a "lack of motivation" as a relevant factor for whether information can be reidentified, meaning the test should be purely capability-based. Even where reidentification serves no commercial interest, the risk still counts.
Also, the draft guidelines’ list of "relevant entities," from whose perspective identifiability should be assessed, is broad and non-exhaustive, encompassing cybercriminals, foreign intelligence agencies, rogue employees, and investigative journalists. The EDPB makes clear that organizations should assess what adversarial actors could do with the information in their possession, not just what cooperative partners would do.
Third, contractual no-reidentification clauses offer limited comfort. The draft guidelines treat such clauses as complementary to technical measures, not as substitutes for them. In practice, this means that a data-sharing agreement that prohibits a recipient from reidentifying individuals is insufficient in itself to render a dataset anonymous in the recipient’s hands.
The guidelines reiterate that anonymisation itself is a type of processing of personal data. Therefore, controllers must comply with their usual obligations under the GDPR, including having a lawful basis under Article 6 GDPR, a special category condition under Article 9 if applicable, and providing transparency about how personal data is processed.
In addition, even when personal data has been anonymised, controllers must reassess reidentification risk over time. The draft guidelines acknowledge that artificial intelligence and agentic AI systems in particular are reducing the cost of reidentification, meaning a dataset that has been anonymised today may not stay anonymous in the future.
Organizations dealing with cookies, location data, or telecommunications traffic should also remember that the Privacy and Electronic Communications Regulations in the U.K. and the ePrivacy Directive in the EU impose separate consent requirements on certain data categories.
The consultation on the draft guidelines is open until 30 Oct. 2026. With the final version likely to evolve in response to consultation input, privacy professionals should monitor developments but nevertheless begin reviewing their current anonymisation processes and identify where gaps or opportunities in relation to the draft guidelines exist.
This article was originally published by IAPP on 30 July 2026. Authors: Arnav Joshi, Partner; Tom Brookes, Senior Associate and; Stacy Young, Associate.
On 18 August 2026, the ICO published a blog post setting out conclusions from its audits of five police forces’ use of facial recognition technology (FRT) in England and Wales. The ICO’s work follows its 2019 Opinion and forms part of its wider AI and biometrics strategy.
The ICO found that there were some good practices amongst the police forces audited; generally, police forces had a lawful basis identified and documented, were careful not to use more data than necessary in live facial recognition (LFR) deployments and had breach reporting procedures in place. However, significant improvements were still considered needed, with the ICO making 107 recommendations (for all police forces using FRT, not just those audited) covering both compliance and best practice.
In particular, the ICO identified several areas requiring urgent attention, such as:
The ICO also highlighted concerns about bias in the algorithm used by police forces for facial recognition searches within the Police National Database. These concerns were raised with the Home Office and the National Police Chiefs’ Council (NPCC), who have implemented mitigations such as staff training, oversight reporting and equality impact assessments and plans to replace the algorithm.
The ICO referred to the government's consultation on a new legislative framework for law enforcement use of biometrics, facial recognition and similar technologies. The ICO published its response to the consultation, ultimately welcoming the government's intent for this area but reinforcing that data protection law should remain the foundation of any new regime.
Although this audit focused on the use of these technologies by law enforcement, the ICO’s audit findings and recommendations are also relevant to organisations operating in adjacent sectors where FRT or other biometric technologies are deployed. The ICO’s clear message is that strong data protection governance, bias testing, staff training and accountability structures are essential to the lawful and proportionate use of FRT.
In August 2026, the ICO published its latest progress update under the Children’s code strategy which was launched in April 2024 to examine behaviour of social media platforms and video sharing platforms when processing children's data. The ICO estimates that improvements made between April 2024 and July 2026 have already affected approximately five million child users across several platforms.
The ICO's update outlines its key achievements since its December 2025 update and these include:
The ICO notes that the government recently announced wide-ranging proposals including a ban on certain social media platforms from offering their services to children under 16, to be brought in by amendments to the Online Safety Act. This is expected to cover platforms such as Snapchat, TikTok, YouTube, Instagram, Facebook and X. The ICO emphasises that data protection obligations apply irrespective of any minimum age or service restriction, and that it will continue to engage with government and other regulators (especially Ofcom) to ensure the proposals deliver robust protection for children online.
Organisations that provide online services likely to be accessed by children should review this update carefully. The ICO’s enforcement activity, its expansion into mobile gaming and the government’s proposed restrictions on social media access for under-16s collectively signal a heightened regulatory focus on children’s online privacy. Organisations should ensure their age assurance mechanisms, DPIAs and privacy-by-design measures are robust and up to date.
On 20 July 2026, new Prime Minister Andy Burnham announced significant changes to Whitehall’s approach to technology and innovation. The Department for Science, Innovation and Technology (DSIT), which was created by the previous Conservative government in 2023, has been abolished. DSIT's responsibilities have been absorbed by: (i) a new Department for Business, Innovation, Science and Trade (DBIST), led by Jonathan Reynolds will take responsibility for science and innovation and emerging technology; and (ii) the Department for Digital, Culture, Media and Sport (DCMS) which will take responsibility for digital identity, cyber resilience and online harms.
AI strategy and policy and public sector AI adoption have moved into the Cabinet Office, with Kanishka Narayan appointed as the Minister of State for AI, jointly across the Cabinet Office and DBIST. Narayan will attend Cabinet meetings, making this the first time a dedicated AI minister has had a seat at the Cabinet table in British history.
The government’s rationale, as set out in a statement to Parliament, is that “the functions of DSIT will be redistributed to align with our core economic and social agenda, embedded as vital engines of growth exactly where they can have the most direct impact....technology and innovation are not separate sectors of our economy — they are the foundation of all future industry, culture, and public service delivery.”
Organisations should monitor these developments closely, particularly as they may affect the policy landscape for AI governance, data protection sponsorship, and digital regulation. The elevation of AI to Cabinet level may signal a more assertive government approach to AI policy, and organisations developing or deploying AI should be prepared for potential changes to the regulatory framework.
On 7 August 2026, the ICO issued a reprimand to ACRO Criminal Records Office (ACRO) following cyber security failings that impacted up to 10,920 people’s personal data, including sensitive data such as National Insurance numbers, passport details, bank account information, biometric data and criminal offence information. As part of its investigation, the ICO found that ACRO failed to: (i) assign clear responsibility for identifying and monitoring critical security updates; (ii) maintain an effective patch management process; and (iii) adequately investigate security alerts. See more details here.
On 5 August 2026, the ICO issued a statement welcoming the Upper Tribunal’s decision to dismiss TikTok’s appeal in TikTok Inc & Anor v The Information Commissioner [2026] UKUT (AAC) 277 and remit the case to the First-tier Tribunal for determination of the substantive issues. The ICO had previously fined TikTok £12.7 million for mishandling children's personal data, and TikTok tried to appeal the fine, arguing that because its platform hosts creative content, the ICO needed special court permission before it could take action, but the Upper Tribunal rejected this. See more details here.
The House of Lords Communications and Digital Committee launched an inquiry on 27 July 2026 to examine the implementation, enforcement and impact of the Online Safety Act (OSA). The Committee will also assess whether there are shortcomings in the OSA itself that limit its effectiveness. The Committee invites written submissions to be submitted by 7 September 2026. See more details here.
The ICO has published a report on the viability of a data protection Statutory Regulatory Sandbox (SRS) which has been researched with the Regulatory Innovation Office’s AI Capability Fund. The proposed SRS is an experimentation regime intended to meet the demands of AI and emerging tech and would offer innovators time-limited flexibility from parts of data protection law, within ICO oversight and safeguards, to test ideas. The implementation of an SRS would need changes to data protection laws so next steps reside with the government. See more details here.
On 15 July 2026, the government published a call for evidence on “Data regulation in the age of AI and other data-intensive technologies.” It closes on 9 September 2026 and the government seeks: (i) practical examples of how personal and non-personal data regulation interacts with AI and other data-intensive technologies; (ii) insights on how technological progress impacts how data is used; and (iii) views on how legal, technical and governance arrangements could enable data use/re-use. Ultimately, responses will be used to evaluate the need for further guidance or targeted changes or even fundamental reform to ensure regulatory frameworks are still fit for purpose. See more details here.
On 5 August 2026, the government published its response to the “Reshaping Cyber Regulation in Downstream Gas and Electricity” - a joint consultation run by the Department for Energy Security and Net Zero (DESNZ) and Ofgem. Respondents broadly supported the need to strengthen cyber oversight across the downstream gas and electricity sector, while emphasising the importance of a risk-based approach. The government intends to: (1) review the applicability of the NIS Regulations 2018 in the downstream gas and electricity sector; and (2) develop baseline cyber resilience requirements for all Ofgem licensees (led by Ofgem in consultation with the NCSC). The government will focus first on implementing baseline requirements and reviewing NIS applicability before considering whether further requirements are needed. See more details here.
On 15 July 2026, the ICO announced that seven new Non-Executive Members were appointed to the Information Commission Board – a milestone in the transition to the UK’s new independent data protection regulator. Additionally, Paul Arnold who is already the ICO’s Accounting Officer and Interim Chief Executive Officer will also join the Board. Separately, DSIT is in the process of a recruitment campaign for the Chair of the Information Commission. See more details here.
On 14 July 2026, the EDPB published its binding decision in relation to a cookie related complaint brought by NOYB on behalf of an individual against Belgian public broadcasting company Vlaamse Radio-en Televisieomroeporganisatie (VRT).
Whilst NOYB lodged the complaint with the Austrian data protection authority, the Belgian DPA, in its role as lead supervisory authority, strove to dismiss the complaint on procedural grounds, alleging that NOYB abused its right to lodge complaints because the initiative for the complaint came from NOYB rather than the individual and NOYB effectively created its own standing to pursue its own policy objectives. The Austrian DPA argued that the Belgian DPA should have issued a decision on the merits but instead the Belgian DPA submitted the case to the EDPB, who ultimately found that the Belgian DPA had to assess the complaint on its merits.
This decision reinforces that DPAs cannot easily dismiss complaints on procedural grounds (such as alleged abuse of rights) without properly assessing the merits. It is particularly relevant for organisations relying on cookie consent mechanisms, as it signals that NOYB-style complaints about cookie banners will continue to be pursued through the EDPB dispute resolution process where lead supervisory authorities attempt procedural dismissals. Organisations should ensure their cookie consent mechanisms are robust and genuinely compliant, as complaints are more likely to be assessed substantively.
On 27 July 2026, the European Commission published its first official implementation guidance on the Cyber Resilience Act (CRA) which is also part of the European Commission's simplification plans. The CRA, which entered into force in December 2024, imposes mandatory cybersecurity standards on products containing digital elements throughout their entire lifecycle — from design through to end-of-life vulnerability management. The guidance is non-binding but represents the Commission's most detailed interpretive document on the regulation to date, running to over 80 pages and is intended to be practical in nature to assist companies in complying with the CRA.
The guidance addresses:
Two compliance deadlines are fast approaching: manufacturers must begin reporting actively exploited vulnerabilities from 11 September 2026, while the full suite of CRA obligations take effect on 11 December 2027.
Organisations that manufacture, import or distribute products with digital elements should pay attention to this guidance — market surveillance authorities across the EU are expected to rely on it when assessing conformity. Priority actions include: mapping your product portfolio against the scope clarifications; confirming readiness for the September 2026 vulnerability-reporting obligation; and reviewing support-period commitments for products already on the market. The worked examples and flowcharts are particularly valuable for smaller organisations assessing whether and how the CRA applies to them.
A CJEU ruling on 14 July 2026 relating to online publication of athletes who infringed anti-doping rules found that anti-doping violation data does not typically constitute: (i) health data (unless specific reference is made to the prohibited substance/method in a way that could reveal physical/mental state, even indirectly); or criminal offences data (as those sanctions are only directed at a particular group i.e. athletes). Although this case concerns anti-doping regulations in sport, the ruling sheds some insight on the scope of special category data and criminal offences data. See more details here.
On 21 August 2026, the Dutch Data Protection Authority publicised its €825 million fine on Uber for automated decision infringements. This is the second-largest GDPR penalty ever imposed, following Ireland’s €1.2 billion Meta fine in 2023. Uber was found to have: (i) used software to track driving behaviour and customer reviews and this was used to automatically suspend or permanently deactivate some drivers’ accounts; and (ii) failed to provide drivers with meaningful information about the logic, significance and consequences of automated processing. This fine is a reminder that organisations operating automated decision-making systems which trigger Article 22 GDPR requirements must provide specific information about the logic and potential impact of the automated processing. See more details here.
On 24 July 2026, the European Commission published its preliminary findings that TikTok had failed to provide adequate safety protections for minors' accounts as required by the Digital Services Act (DSA) — in particular, the "public" account settings which minors can select can share their content to all users and allow it to be surfaced to a global audience via the platform's recommendation algorithm. See more details here.
Following the closure of the EDPB’s consultation on a new data breach notification template (see Data Bytes 67 for more details) on 5 August, there has since been public criticism of it. Insurance Europe, a prominent industry body, published a critique describing the template as excessively lengthy and containing questions that go beyond GDPR notification requirements. Another objection is that the template fails to accommodate a staged notification approach to allow for information gained through technical investigations which typically occur after the 72 hour notification period. Organisations should maintain a watching brief of the finalised template. See more details here.
On 17 July 2026, the EDPB called on the European Commission to propose a legal basis which would enable the sharing of information among different supervisory authorities including information which would be relevant to enforcement. It is unclear to what extent the European Commission will take such action but organisations should prepare for a potentially more coordinated regulatory environment across EU digital regulators. See more details here.
On 20 July 2026, the European Commission published the final version of its guidelines setting out how providers and deployers of certain AI systems should comply with the transparency requirements in Article 50 of the AI Act. In-scope organisations should review the guidelines and assess their compliance with them keeping in mind the enforcement period has officially begun and non-compliance may result in hefty penalties. See more details here.
As of 2 August 2026, the European Commission’s AI Office and national authorities can enforce the AI Act. A range of enforcement tools are now operational, including a dedicated complaints mechanism, a whistleblower channel and a complaints route for downstream providers using general-purpose AI models. Organisations deploying or procuring AI-powered systems — particularly those with user-facing chatbots or content-generation capabilities — should ensure that their labelling, disclosure and marking practices satisfy the new requirements and familiarise themselves with the available enforcement channels.
Authors: Rhiannon Webster, Partner; Alexandre Brazeau, Partner; Alexander Duisberg, Partner; Arnav Joshi, Partner; Nicolas Quoy, Partner Shehana Cameron-Perera, Senior Associate; Tom Brookes, Senior Associate, Stacy Young, Associate and Davide Borelli, Counsel.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.