Big headlines.
Clear explanations.
Real enforcement cases, changing rules and practical lessons for website owners. Straight from regulator announcements and official guidance.
30 articles
TikTok accepts £12.7m UK fine
An appeal update matters: the ICO says TikTok’s 2023 children’s privacy penalty is now final.
Read the storyHow regulators decide to fine
New EDPB guidance explains how authorities approach the decision to impose a GDPR fine.
Read the storyA deletion request needs a reply
CNIL’s €300,000 EXTIA case shows why deleting information is only part of handling a request.
Read the storyUber’s €824.99m automation fine
A decision made by software can have serious consequences for the person on the receiving end.
Read the storyDoes your chatbot say it’s AI?
Article 50 transparency duties depend on what the system does and who is responsible for it.
Read the storyYour privacy inbox needs a process
The UK complaints duty is in force. A contact email alone is not enough.
Read the storyUK privacy rules have changed
The Data (Use and Access) Act updates the UK framework. It does not remove the need to protect personal information.
Read the storyWater company fined £963,900
The South Staffordshire case is a reminder that unnoticed access can turn into a major data incident.
Read the storyNew cookie guidance: check purpose
The ICO’s final guidance covers more than traditional cookies and includes conditional exceptions.
Read the storyReddit’s £14.47m privacy penalty
The ICO’s findings concern children’s information and risk assessment, not cookie banners alone.
Read the storyWhat CNIL enforced in 2025
Cookie compliance, security and employee monitoring all featured in the regulator’s annual review.
Read the storyFrance Travail’s €5m security fine
Security controls need to be implemented, not just written down in an assessment.
Read the storyReject must stop the tracking
American Express’s €1.5m cookie case covered before consent, after refusal and after withdrawal.
Read the storySHEIN’s €150m cookie warning
The French regulator found advertising cookies arriving before visitors made their choice.
Read the storyGoogle’s €325m consent case
The decision covered both Gmail advertising and consent during Google account creation.
Read the story23andMe’s £2.31m security fine
Reused passwords became a route into sensitive customer information.
Read the storyTikTok’s €530m transfer decision
Where data can be accessed matters as well as where the server is located.
Read the storyAdvanced fined £3.07m after attack
A software provider’s security failures can affect the organisations relying on it.
Read the storyLinkedIn’s €310m advertising fine
Behavioural advertising needs a defensible basis and a clear explanation.
Read the storyMeta’s €1.2bn transfer case
A landmark historical decision shows why a supplier’s transfer paperwork needs more than a quick glance.
Read the storyMeta’s €265m design case
Data protection by design includes how features expose information, not just how a notice describes them.
Read the storyMarriott’s £18.4m security penalty
Inherited systems still need clear ownership and ongoing security checks.
Read the storyBritish Airways: the £20m decision
The final 2020 penalty is a useful reminder to distinguish a proposed fine from an issued one.
Read the storyA click is not always consent
A visitor needs a real, informed choice. A button press alone does not settle the question.
Read the storyGDPR and cookies: two layers
Cookie rules and data-protection rules work together. They are not interchangeable labels.
Read the storyWhat “up to £17.5m” means
It is a possible statutory maximum for relevant infringements, not a prediction of your fine.
Read the storyYour policy should describe you
A copied privacy policy can look reassuring while describing a completely different business.
Read the storyA breach: when does 72 hours apply?
Some incidents must be reported quickly. First establish what happened and the risk to people.
Read the storyCan your team spot an access request?
A request for personal information may arrive through an ordinary inbox, not a special form.
Read the storyDo you still need that old data?
Old form entries, abandoned accounts and exports are easy to forget. They still need a reason to stay.
Read the story