dpas bulletin - september 2026
Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.
Is the EU–US Data Privacy Framework about to collapse? Sharing data across health, education, and social care in Wales? Have you seen the brand-new WASPI Code of Conduct? TikTok drops its ICO fine appeal?! Where does the DPC’s latest fine against Google rank on its all-time list?
Read about all this and more in our latest DPAS Data Protection Bulletin.
The Data Privacy Framework loses its Golden Gate luster
A US case concerning the Federal Trade Commission (FTC) has caused ripples in Europe after the independence of the FTC was called into question. The FTC Commissioner was removed from her office without warning by President Trump, leading to the wonderfully named case of Trump v Slaughter, which saw the Supreme Court side with the president. The ruling followed that since the FTC exercises executive authority, its members must be subject to the President’s control.
For the Data Privacy Framework (DPF), a bridge for the US and EU to share data, this is significant as the independence of the FTC was a significant consideration in its implementation. The European Commission bases its assessment on the relevant protections in place, so this loss of independence does not mean that the DPF has yet been invalidated. At this stage, the Commission is reviewing the Framework so the only certainty is that there is no certainty.
Read more about this here.
The ICO becomes the IC(O)
The long-awaited change from the Data Use and Access Act 2025 has come into force, dissolving the Information Commissioner’s Office. In its place emerges the Information Commission. The acronym is expected to remain the same, with ‘ICO’ now referring to the Information Commission’s Office, so rejoice policy reviewers as we won’t have quite as much to change as we thought we might.
The change comes with a new office for the ICO, opening a headquarters in Manchester to “be closer to the people, organisations and communities it serves.” While I prefer Manchester to London, those of us here in the South West may argue that Manchester is actually farther away so this statement rings less true for us than it does for our fellows across the country. Still, I for one shall choose to be optimistic about the ICO’s future and wish the organisation good luck. It has been a tough few months for the regulator, but the Deputy Chair has been appointed and hopefully the Chair shouldn’t be too far behind.
Read more about this here.
Wales feels the sting of a new Code of Conduct
The Wales Accord on the Sharing of Personal Information (WASPI) has launched a Code of Conduct for Information Sharing Protocols. This Code of Conduct is designed to provide organisations with a robust framework to support lawful information sharing across Wales.
The new Code means that organisations will be able to apply data protection requirements consistently when sharing personal information for the purposes of health, education, social care, safeguarding and other public service requirements. Having had the chance to speak with WASPI and the great people behind it at a few different conferences over the years, I am buzzing for them.
Read more about this here.
TikTok agrees to pay up
TikTok has agreed to pay the £12.7m fine imposed by the ICO back in 2023. With the appeal dropped, the penalty notice becomes final and we hope to soon hear that TikTok has paid their fine. They have also dropped their appeal against the accompanying information notice, which was preventing the ICO from investigating their recommendation system.
This was not on my bingo card for 2026. The ICO aims to progress the investigation, started in February 2025, into the recommender system to ensure that it continues to further its work around the protection of our children’s data.
Read more about this here.
.
Ministry of Justice launches urgent investigation
The Ministry of Justice announced an urgent investigation after finding court files around the Southport attack had been accessed. No files are reported to have been shared with third parties, and the Ministry of Justice has reported the breach to the Information Commission.
This follows from July where North-West Ambulance Service launched its own investigation into staff inappropriately accessing patient records of the victims of the attack. Hopefully, the Ministry of Justice’s announcement is the last we hear on this, as the inappropriate access of information continues to be a hot topic across England.
Read more about this here.
NHS to crack down on suspected snoops
A second letter from Sir Jim Mackey has been sent to NHS Trusts across England, ordering Trusts to introduce suspensions for any staff member suspected of looking at patient records without a valid reason. Those suspended will be locked out of NHS computer systems to prevent the risk and impact of data breaches.
The Health Services Journal found that at least 214 NHS staff have been sacked in the wake of snooping investigations, with another 2,000 sanctioned over the last five years. As per the above story, it’s not just the NHS. While they may be the worst offenders, we should all take note of the lesson here and ensure that only the appropriate level of access is given to staff to protect the personal data we look after.
Read more about this here.
Ten suspended at East Suffolk and North Essex NHS Foundation Trust
Unfortunately, Sir Jim’s letter of discouragement was not enough. Following the tragic death of a toddler in Suffolk, ten different members of staff accessed the medical records of the three-year old.
After discovering the access, the Trust immediately secured the records to prevent further access and launched an investigation. Hopefully, this will be the last high-profile data breach involving NHS staff. Trust in our healthcare professionals is of the utmost importance and the actions of these few has risked significantly undermining public trust.
Read more about this here.
The DPC fines Google €403 million
The Irish Data Protection Commission (DPC) has found Google to be infringing the GDPR through its features around location and app activity tracking from 2018 to 2020. Google addressed the case by stating that it had since launched robust tools and evolved its practices since 2019.
It makes the £12.3m levied by the ICO pale in comparison, but this fine by the DPC is only the fourth largest in its history. Google seem unlikely to appeal the fine in its entirety, as their spokesperson stated the changes in 2019 to precise location tracking as evidence of their improvements.
Read more about this here.
GET IN TOUCH WITH US!

If you need any support in ensuring your organisation is complying with the relevant legislation, or require training in the areas of data protection and information security, get in contact with us.
Either call us on 0203 3013384, email us at info@dataprivacyadvisory.com, or fill out our contact form. Our dedicated team will get back to you as soon as possible.




