Big headlines.
Clear explanations.

Real enforcement cases, changing rules and practical lessons for website owners. Straight from regulator announcements and official guidance.

30 original, AI-assisted explainers · Published 1 October 2026 · Source dates shown separately. Our commentary is independent and is not legal advice.

30 articles

Enforcement
Source: 24 September 2026

TikTok accepts £12.7m UK fine

An appeal update matters: the ICO says TikTok’s 2023 children’s privacy penalty is now final.

Read the story
Regulation
Source: 21 September 2026

How regulators decide to fine

New EDPB guidance explains how authorities approach the decision to impose a GDPR fine.

Read the story
Enforcement
Source: 9 September 2026

A deletion request needs a reply

CNIL’s €300,000 EXTIA case shows why deleting information is only part of handling a request.

Read the story
Enforcement
Source: 24 August 2026

Uber’s €824.99m automation fine

A decision made by software can have serious consequences for the person on the receiving end.

Read the story
Regulation
Source: 2 August 2026

Does your chatbot say it’s AI?

Article 50 transparency duties depend on what the system does and who is responsible for it.

Read the story
Regulation
Source: 23 June 2026

Your privacy inbox needs a process

The UK complaints duty is in force. A contact email alone is not enough.

Read the story
Regulation
Source: 19 June 2026

UK privacy rules have changed

The Data (Use and Access) Act updates the UK framework. It does not remove the need to protect personal information.

Read the story
Enforcement
Source: 11 May 2026

Water company fined £963,900

The South Staffordshire case is a reminder that unnoticed access can turn into a major data incident.

Read the story
Cookies
Source: 29 April 2026

New cookie guidance: check purpose

The ICO’s final guidance covers more than traditional cookies and includes conditional exceptions.

Read the story
Enforcement
Source: 23 February 2026

Reddit’s £14.47m privacy penalty

The ICO’s findings concern children’s information and risk assessment, not cookie banners alone.

Read the story
Enforcement
Source: 9 February 2026

What CNIL enforced in 2025

Cookie compliance, security and employee monitoring all featured in the regulator’s annual review.

Read the story
Enforcement
Source: 29 January 2026

France Travail’s €5m security fine

Security controls need to be implemented, not just written down in an assessment.

Read the story
Cookies
Source: 3 December 2025

Reject must stop the tracking

American Express’s €1.5m cookie case covered before consent, after refusal and after withdrawal.

Read the story
Cookies
Source: 3 September 2025

SHEIN’s €150m cookie warning

The French regulator found advertising cookies arriving before visitors made their choice.

Read the story
Cookies
Source: 3 September 2025

Google’s €325m consent case

The decision covered both Gmail advertising and consent during Google account creation.

Read the story
Enforcement
Source: 17 June 2025

23andMe’s £2.31m security fine

Reused passwords became a route into sensitive customer information.

Read the story
Enforcement
Source: 2 May 2025

TikTok’s €530m transfer decision

Where data can be accessed matters as well as where the server is located.

Read the story
Enforcement
Source: 27 March 2025

Advanced fined £3.07m after attack

A software provider’s security failures can affect the organisations relying on it.

Read the story
Enforcement
Source: 24 October 2024

LinkedIn’s €310m advertising fine

Behavioural advertising needs a defensible basis and a clear explanation.

Read the story
Enforcement
Source: 22 May 2023

Meta’s €1.2bn transfer case

A landmark historical decision shows why a supplier’s transfer paperwork needs more than a quick glance.

Read the story
Enforcement
Source: 25 November 2022

Meta’s €265m design case

Data protection by design includes how features expose information, not just how a notice describes them.

Read the story
Enforcement
Source: 30 October 2020

Marriott’s £18.4m security penalty

Inherited systems still need clear ownership and ongoing security checks.

Read the story
Enforcement
Source: 16 October 2020

British Airways: the £20m decision

The final 2020 penalty is a useful reminder to distinguish a proposed fine from an issued one.

Read the story
Regulation
Source: 4 May 2020

A click is not always consent

A visitor needs a real, informed choice. A button press alone does not settle the question.

Read the story
Regulation
Explainer

GDPR and cookies: two layers

Cookie rules and data-protection rules work together. They are not interchangeable labels.

Read the story
Regulation
Explainer

What “up to £17.5m” means

It is a possible statutory maximum for relevant infringements, not a prediction of your fine.

Read the story
Practical guide
Explainer

Your policy should describe you

A copied privacy policy can look reassuring while describing a completely different business.

Read the story
Practical guide
Explainer

A breach: when does 72 hours apply?

Some incidents must be reported quickly. First establish what happened and the risk to people.

Read the story
Practical guide
Explainer

Can your team spot an access request?

A request for personal information may arrive through an ordinary inbox, not a special form.

Read the story
Practical guide
Explainer

Do you still need that old data?

Old form entries, abandoned accounts and exports are easy to forget. They still need a reason to stay.

Read the story