dpas bulletin - JULY 2026
Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.
Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?
Read about all this and more in our latest DPAS Data Protection Bulletin.
UK Government tried to conceal Afghan data breach
The House of Commons Defence Committee has released a damning report on the major Ministry of Defence data breach. Unnoticed for eighteen months until parts of the dataset surfaced on social media, the breach endangered individuals who had worked alongside British forces and faced severe risks of Taliban retaliation. Rather than confronting the incident transparently, the UK government responded by securing an unprecedented superinjunction, concealing the leak and managing its fallout behind closed doors for nearly two years.
During this period of strict secrecy, ministers quietly established a secret resettlement scheme to evacuate those at highest risk, operating entirely beyond parliamentary oversight and public accountability. The committee findings reveal that this covert operation was plagued by fragmented cross-government coordination, mounting costs, and severe delays in safeguarding vulnerable families. When the injunction was eventually lifted and the resettlement schemes were abruptly shut to new applicants, affected Afghans were left to navigate the dangerous consequences with minimal support.
Most damning, in this writer’s humble opinion, was the refusal of certain defence witnesses to comment on or even participate in the inquiry.
Read more about this here.
PSNI and MI5 unlawfully spied on a journalist
In lighter news, Big Brother will start with the journalists before they come for us. A special tribunal has ordered MI5 and the Police Service of Northern Ireland to cough up £20,000 in damages after they spent years illegally snooping on journalist Vincent Kearney. Between 2006 and 2018, the security services launched no fewer than seven covert operations to sniff out his confidential sources. Rather than taking a bite out of crime, police managed to track over 1,500 of his calls and texts, and even file away the names of his wife and mother-in-law. Because nothing says national security quite like knowing what time a reporter calls his wife’s mother.
The Investigatory Powers Tribunal was thoroughly unimpressed by this grand exercise in wasted taxpayer money, ruling that spying on a journalist just to see who was blabbing to the press was entirely unlawful and vastly disproportionate. Kearney, who now works for Irish broadcaster RTÉ, celebrated the payout as a massive win for press freedom. The rest of us will have to celebrate the win without the £20,000. Truthfully, that does make it a little harder for me.
Read more about this here.
Department for Education hacked
Cyber-attackers have managed to pinch roughly 607,000 records from the Department for Education. A shadowy hacker outfit calling itself “ExfilSquad” made off with data from the department’s online helpdesk and the Turing Scheme portal, which funds international study for students. The breach is restricted to “only the customer service contact details”. Which is comforting, provided you enjoy receiving phishing emails.
The DfE says it acted with lightning speed to contain the intrusion and has involved the National Cyber Security Centre, the National Crime Agency, and the Information Commissioner’s Office to figure out how a gang with a name like an underperforming eSports team waltzed past their defences. This is representative of a wider trend in the education space, with 24% of institutions reporting experiencing a breach or attack at least weekly.
Read more about this here.
The Yanks buy control of more British healthcare
In a turn of events that should surprise precisely no-one, a US private equity titan has managed to buy up the digital infrastructure housing the medical secrets of half of England. TPG, a global investment giant, has snapped up Optum UK for roughly £300m. Included in the bargain is EMIS, the software package sitting quietly on the desktop of over 50% of English GP surgeries. This means the medical histories, prescription habits, and embarrassing consultation notes of tens of millions of Brits are now indirectly under the umbrella of an American firm whose primary operational philosophy is “maximizing shareholder return.”
Naturally, the news has gone down like a lead balloon among healthcare groups. The Doctors’ Association UK pointed out that private equity now effectively “owns the plumbing” of primary care. TPG and EMIS have rushed to pour cold water on the outrage, insisting with absolute sincerity that patient data remains wrapped in titanium-clad regulatory safeguards and that non-executive suits across the Atlantic couldn’t possibly peek at your medical files even if they wanted to.
Read more about this here.
noyb continues to fight the good fight
Digital rights privacy group noyb has officially filed a GDPR complaint against the popular online dictionary dict.cc. According to the filing, visiting the site hits you with a cookie banner that cheerfully nudges you into handing over your personal data to a staggering 1,741 “partner” companies with a single, convenient click. noyb calculated that actually reading through the privacy policies of all 1,741 ad tech leeches would take roughly 170 hours!
noyb rightly pointed out that pretending a user can give “informed” consent to an army of nearly two thousand invisible tracking entities is an absolute farce. We frequently face this with various sites based in the UK, especially certain ones that encourage you with misleading headlines to click onto their page. I, for one, will be watching this develop with great interest.
Read more about this here.
Australia federal health department raises concerns over AI scribe usage
Australian doctors are flocking to “AI scribes” to do their administrative heavy lifting. Usage has soared to two in five GPs delegating their medical note-taking to artificial intelligence so they can spend less time typing and more time actually looking at their patients. What could possibly go wrong? Well, according to Freedom of Information documents from the federal health department, quite a lot. It turns out that many of these handy digital assistants operate in a lawless wild west with virtually no oversight, often quietly shipping sensitive patient chats off to overseas cloud servers without anyone noticing.
The Australian government has issued a stern warning over the trend, raising serious red flags about patient data security, dodgy consent practices, and the occasional AI “hallucination” finding its way into national health records. To make matters spicier, some tech vendors are brazenly pitching these tools to doctors with promises of a 30% boost in revenue, effectively turning patient consultations into a high-speed billing machine. Meanwhile, patients who dare to object to having their intimate health chats recorded by a bot are increasingly being told to take their ailments elsewhere, with some clinics refusing to see anyone who won’t sign on the digital dotted line.
Spiders and snakes are still my number one and two reasons for avoiding Australia, but it’s a good day for jellyfish as they are bumped down to number four after this development.
Read more about this here.
GET IN TOUCH WITH US!

If you need any support in ensuring your organisation is complying with the relevant legislation, or require training in the areas of data protection and information security, get in contact with us.
Either call us on 0203 3013384, email us at info@dataprivacyadvisory.com, or fill out our contact form. Our dedicated team will get back to you as soon as possible.




