dpas bulletin - AUGUST 2026
Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.
Will Meta finally pay a big fine? Will Uber treat the people that work for them fairly? Will I be able to resist making apple puns with a story about Apple? Have OpenAI spooked themselves with their frontier development? Why won’t American companies stop developing AI systems that try to use all the data ever?
Read about all this and more in our latest DPAS Data Protection Bulletin.
Meta settles addictive design trial
A landmark federal trial in California ended abruptly after Meta agreed to an $18 billion settlement with 29 US states over allegations that it deliberately designed its platforms to addict young users. The agreement halted court proceedings after just four days of testimony, sparing senior executives, including chief executive Mark Zuckerberg, from facing further cross-examination regarding internal safety warnings and child data collection practices. While state officials heralded the outcome as a major victory for youth mental health and corporate accountability, Meta (shockingly) denied all legal wrongdoing throughout the trial.
Under the terms of the settlement, Meta is mandated to implement sweeping platform overhauls for Facebook and Instagram within months. The core operational changes require mandatory daily usage limits for teenage accounts, automatic app restrictions during school hours, overnight hours, and a total ban on plastic surgery filters. While the financial penalty will be distributed among the participating states over a ten-year period, Meta has called on industry rivals to adopt identical framework protections across their own services.
Read more about this here.
Dutch Data Protection Authority takes Uber for a ride
The Autoriteit Persoonsgegevens has levied a massive €825 million fine against Uber for utilising automated algorithms to deactivate driver accounts without adequate human intervention or explanation. Originating from a complaint by French drivers cut off from their primary source of income between 2018 and 2022, the investigation revealed that automated systems routinely suspended accounts following flags for low ratings or suspected fraud, such as route detours. Regulators ruled that the practice violated EU GDPR; these were fully automated decisions that carry severe real-world consequences.
In response to the second-largest ever enforcement action, Uber has disputed the findings and announced plans to appeal. According to them, the multi-million-dollar penalty is disproportionate to the number of impacted drivers. The ride-hailing company maintains that temporary suspensions were brief and that permanent account bans were never executed without human review and appeal procedures.
Read more about this here.
Brazil takes a Byte(Dance) out of unlawful processing
Brazil’s Data Protection Authority (ANPD) has issued a substantial 153.7 million reais (c. €25 million) fine against ByteDance following an investigation into TikTok’s handling of underage user data. Regulators determined that the social video platform unlawfully collected and processed personal information from an estimated eight million minors without establishing adequate age verification or obtaining explicit parental consent. The watchdog highlighted that features like logged-out feed access exposed children to data harvesting before any age checks occurred.
Beyond the financial penalty, the ANPD ordered ByteDance to immediately delete all unlawfully gathered datasets and overhaul its operational practices within the country. Under the mandatory compliance directive, TikTok must implement robust age-verification mechanisms and automatically enforce strict privacy defaults for users under 16, which can only be adjusted with verified guardian approval.
Read more about this here.
The Home Office tries to worm its way to Apple’s core (again)
Apple has launched a new legal action at the Investigatory Powers Tribunal against the UK government, who have once again demanded Apple to construct a backdoor into its encrypted iCloud storage service. The dispute follows a Technical Capability Notice issued by the Home Office under the Investigatory Powers Act, compelling the tech giant to provide law enforcement and intelligence agencies access to personal backups. After the UK upset the apple cart with its previous attempt, the new request refined the scope to specifically target British citizens, prompting Apple to reiterate its firm refusal to compromise end-to-end encryption or develop master keys for any government entity.
The renewed legal battle has drawn intense pushback from privacy organisations, with civil liberties groups Liberty and Privacy International filing joint complaints. Opponents argue that enforcing localised access mechanisms inherently undermines system-wide security, creating vulnerabilities that compromise user data globally. A fairly convincing argument, looking at the track record.
Read more about this here.
OpenAI pausing frontier model training
OpenAI has initiated a two-week pause on frontier model training after internal evaluations revealed its upcoming model, Astra, crossed critical cybersecurity capability thresholds. The company conceded that its existing “Preparedness Framework” is inadequate to mitigate emergent autonomous risks. To prevent unauthorised capabilities or escape vectors during research phases, OpenAI is hardening sandbox environments, restricting local code execution paths, and implementing automated continuous log monitoring to detect jailbreak attempts.
To enforce real-time oversight, the company is deploying automated containment protocols designed to flag suspicious token generation patterns. This will mandate a human investigator review within 30 minutes or requiring an immediate execution shutdown. The voluntary pause comes amid mounting regulatory pressure.
Have a break, have a KitKat, except it’s for AI that’s getting out of hand.
Read more about this here.
Reform takes on the UK GDPR
Reform UK has unveiled a sweeping business proposal aimed at replacing the UK’s GDPR with a “light-touch” privacy framework. The party pledges to scrap UK GDPR entirely and adopt a streamlined model based on New Zealand’s data laws, arguing that existing EU-derived rules impose excessive compliance burdens on small enterprises and domestic tech startups. To further appeal to small businesses, the policy package also introduces caps on civil liabilities for non-executive directors at companies generating under £15 million in annual revenue, limiting personal financial exposure to £50,000 or three times their average pay.
Read more about this here. (Paywall, FT subscription required)
ICO extends Children’s Code strategy
The ICO has announced a six-month extension to its Children’s Code strategy. It will maintain its focus on high-risk processing practices, aligning its intervention strategy alongside evolving government policy and Ofcom’s online safety framework. Regulatory efforts will center on areas where child data faces the most severe exposure, with ongoing horizon-scanning to include AI chatbots and health apps.
Looking ahead, the ICO plans to publish an impact assessment of its two-year enforcement drive in winter 2026/27 as it transitions toward a broader corporate strategy. Future regulatory priorities will feature a dedicated statutory code for educational technology, alongside tailored child privacy protections integrated into an upcoming code for AI and automated decision-making.
Read more about this here.
Nightmare on Spear Street (Technology)
San Francisco Spear Street Technology has developed an AI assistant designed to act as an all-encompassing digital chief of staff. The platform requests extensive device-level access across users’ email, calendars, messaging apps, screen activity, and keystrokes to execute tasks like managing inboxes and booking travel. However, in their terms of service Instinct claims a perpetual, irrevocable license to store and utilise user data for AI model training, while granting the assistant binding legal authority to execute transactions on a user’s behalf.
The controversy intensified after several early beta testers documented significant data handling failures and operational vulnerabilities. Users reported that the assistant continued summarising inbox activity after account access was revoked, retained plain-text email records without clear deletion mechanisms, and sent unauthorised communications without explicit approval. Furthermore, security demonstrations highlighted the system’s susceptibility to prompt-injection attacks, where malicious inputs could trick the assistant into exposing sensitive communications.
Read more about this here.
Cyber security is on the ropes
A coalition of over 100 leading technology companies and cybersecurity leaders, including Google, Microsoft, OpenAI, AWS, and Anthropic, has issued an open letter warning of a rapidly shrinking window to defend against AI-amplified cyber threats. The joint statement warns that AI-driven cyberattacks will reach unprecedented levels of speed and sophistication within months, rendering traditional reactive security frameworks obsolete.
The coalition calls for action comes amid a growing industry consensus that frontier AI models have fundamentally altered the offensive cybersecurity landscape. To counter the escalating risks, the coalition advocates for a global surge in defensive infrastructure investments, standardised incident reporting, and mandatory fallback systems across essential supply chains.
Read more about this here.
GET IN TOUCH WITH US!

If you need any support in ensuring your organisation is complying with the relevant legislation, or require training in the areas of data protection and information security, get in contact with us.
Either call us on 0203 3013384, email us at info@dataprivacyadvisory.com, or fill out our contact form. Our dedicated team will get back to you as soon as possible.




