Industry News
Manchester Airport Group (MAG) reported that attackers gained access to a system containing customer information associated with: Airport Wi-Fi registrations Car park bookings Airport lounge bookings Fast Track services Approximately 8.7 million customer records are...
The Information Commissioner's Office (ICO) has fined Elderly Aids Ltd (EAL) £190,000 after the company made 758,053 unsolicited marketing calls to people registered with the Telephone Preference Service (TPS). The calls, made between May 2024 and February 2025,...
Reform UK has announced that it would repeal the UK General Data Protection Regulation (UK GDPR) and replace it with a “light-touch” privacy law modelled on New Zealand’s approach. The pledge was briefed on the evening of 25 August 2026 and formed part of a wider...
The English National Ballet (ENB) alongside a number of prominent UK cultural and charitable organisations have notified supporters of a data security incident following a cyber attack on their third-party software provider, Beacon CRM. The incident highlights the...
The Information Commissioner’s Office (ICO) has issued an enforcement notice and a formal reprimand to the Metropolitan Police Service (MPS) following significant failures in handling sensitive personal information. The regulator concluded that these incidents were...
When the Information Commissioner's Office (ICO) published its updated data protection complaints framework, much of the industry focus naturally fell on how the regulator triages its workload. Looking closer at the details, a specific metric stands out for DPOs,...
Health clubs and leisure centres have evolved into some of the most data-intensive operations around, managing everything from direct debit mandates and CCTV footage to highly sensitive medical screening records (PAR-Qs). But as new legislation takes effect, many...
The implementation of the Data (Use and Access) Act 2025 (DUAA) earlier this year brought a welcome wave of flexibility for charity fundraisers. By softening the rules around electronic marketing, the act allowed charities to utilise "soft opt-in" routes to...
The fallout from Meta’s Model Capability Initiative (MCI) serves as a stark reminder of the hidden risks of workplace tracking. Initially launched to train internal AI models by passively logging mouse movements, click locations and keystrokes on employee laptops, the...
The Information Commissioner's Office (ICO) has issued a £300,000 fine to a Manchester-based firm after it sent millions of unlawful marketing texts to people already struggling with debt. The messages included fake bailiff threats designed to frighten recipients into...
The ICO’s recent £963,900 fine against South Staffordshire Water and South Staffordshire Plc sends a clear message to organisations handling personal data. Cyber security failures are no longer viewed purely as IT issues, they are regulatory and governance failures....
Following updated guidance from the ICO, charities now have greater flexibility to contact supporters via email, text and direct messaging without prior consent, under a revised ‘soft opt-in’ regime. The change, introduced under the Data (Use and Access) Act 2025, is...
Following the recent High Court ruling in favour of the Metropolitan Police, live facial recognition (LFR) technology will continue to be deployed across London, with further expansion expected nationwide. While many interpreted this as a ‘general acceptance’ of...
Following the introduction of the EU General Data Protection Regulation (GDPR) on 25th May 2018, organisations were required to adopt a more structured and accountable approach to the management of personal data breaches. One of the most significant changes introduced...
The Information Commissioner's Office (ICO) has issued a £100,000 fine to a Birmingham-based pendant alarm company after serious breaches of marketing rules under PECR. The company made over 260,000 unsolicited marketing calls over a seven-month period, targeting...
The Information Commissioner's Office (ICO) has issued a £66,000 fine to Police Scotland after serious failures in the handling of sensitive personal information. The case highlights the importance of data minimisation, privacy by design and robust internal procedures...
The Information Commissioner's Office (ICO) has issued a £14.47 million fine to Reddit for unlawfully processing children’s personal information. The regulator found serious failings in how the platform protected children’s data, particularly around age assurance and...
From 19 June 2026, all UK organisations must have a process to handle data protection complaints internally. This is part of the new Data (Use and Access) Act 2025 and is designed to make sure complaints about personal data are dealt with quickly and fairly....
Jaguar Land Rover (JLR) has informed suppliers that production will remain suspended until at least the 24th of September following a cyber attack that occurred at the end of August.
The Information Commissioner’s Office (ICO) has hit Birth-link, a Scotland-based post-adoption support charity with an £18,000 fine for destroying an estimated 4,800 personal records without authorisation.
In April 2025, the Co-operative Group, who are home to more than 6.5 million members, experienced a major cyber attack which resulted in the personal data of every single member being stolen.
The Data Security and Protection Toolkit, often referred to as DSPT, is an online self-assessment tool that allows organisations to measure their performance against the data security and information governance.
Qantas, Australia’s largest airline, is the latest company to be targeted in a major cyber attack. On Monday, 30th June, Quantas detected unusual activity on a third-party platform used by its contact centre in the Philippines.
Over the weekend of 7-8 June 2025, Oxford City Council was hit by a cyber attack targeting its legacy IT systems. The breach exposed personal data, such as names and contact details.
The Data (Use and Access) Act 2025, first introduced in the House of Lords as the Data (Use and Access) Bill, has finally been granted royal ascent.
On 19th June 2025, the UK’s Data (Use and Access) Bill was granted Royal Assent and will now be known as The UK Data (Use and Access) Act 2025, or DUAA.
PRIVACY HELPER’s mission is to help businesses by providing expert privacy guidance and aid with data protection compliance with zero-fuss, giving you the power and resources to do more.
NHS England has made the decision to put a pause on their project to use GP data to train an artificial intelligence model, known as Foresight, following concerns raised by GP leaders.
Toyota Bank Polska S.A, a bank based in Poland, have been fined a total of PLN 576,220 (roughly £110,000) by The Polish Data Protection Authority (UODO) for two significant violations of Polish data protection regulations.
Say ‘data protection’ or ‘privacy’ to most businesspeople, and their eyes roll. They know it’s important, they know they need to be on it, but it is so complex.
The Information Commissioner’s Office, the independent supervisory authority for data protection in the UK, has fined 23andMe, a genetic testing service, £2.31 million following an investigation into a cyber attack that happened in 2023.
But why are these retailers so frequently targeted by attackers? This blog post will explore the unique risks that retailers face, what we can learn from recent incidents and how the sector as a whole can protect itself from future attacks.
Adidas, a global clothing and footwear brand, has joined the list of UK retailers to be hit by a cyber attack in the last few weeks. This comes following similar, though believed unrelated incidents on retailers such as Harrods.
Following the discovery of an attempted hack, The Co-op have been forced to shut down parts of their IT system. On the 29th of April, a letter was sent out to members of staff that as part of measures taken to “keep systems safe”.
The ICO have announced that law firm DPP Law Ltd have been fined £60,000 following a cyber attack in June 2022, that led to sensitive and personal data being published on the dark web.
The Information Commissioner’s Office have confirmed that software provider Advanced Computer Software Group Ltd (Advanced) have been fined £3 million over security failings that in 2022.
The Government announced the introduction of the Data (Use and Access) Bill (DUA Bill) in the House of Lords on 23rd October 2024 – the first draft of Labour’s proposed changes to data protection law.
A Bedford-based security expert (PRIVACYHELPER) has raised concerns over the planned use of facial recognition software by Bedfordshire Police at this weekend’s River Festival.
With a ‘no-deal’ Brexit on the horizon, many could be forgiven for thinking we won’t now need to care too much about GDPR and other data protection legislation once we leave the EU fully. Sadly, this isn’t the case.
Before COVID-19, working from home was reserved for those who were unable to get into the office and staff in this position were set up securely with a company-issued laptop and access to a VPN.
The fine imposed on British Airways (BA) by the Information Commissioners’ Office (ICO) has sent a strong message to businesses across the UK.
As is quite commonplace these days, the internet has thrown up some wonderful Christmas memes to brighten our days as we head towards the festive season, but one might be spreading a little fake news in disguise.
On Christmas Eve, a Trade Deal was announced between the EU and the UK, ending many months of speculation as to what a Deal would look like.
In November 2020, the European Commission published a draft set of Standard Contractual Clauses (SCCs) for the lawful transfer of personal data from countries bound by the GDPR to third countries.
The European Commission, the body responsible for drafting proposals for new European legislation, has fined Apple €500 million and Meta €200 million for breaches of the Digital Markets Act.
AFK Letters, a company who writes letters on behalf of customers seeking compensation or refunds for products and services, has been fined £90,000 by the ICO following an investigation.
In April, Marks & Spencer was hit by a cyber attack which continued to cause issues both in store and online. It has now been revealed that as part of this incident.
The UK Government has introduced an amendment to the Data (Use and Access) Bill, which will have a significant impact on the way that charities advertise fundraisers and activities.
The ICO have announced that they have taken enforcement action against Newcastle based sole trader Darian Bishop (trading as ECO4U) after it was found that they had made 194,110 unsolicited marketing calls.
Coinbase, an American based cryptocurrency exchange has confirmed that following a cyber attack last week, customer data has been stolen. In a report to the United States Securities and Exchange Commission.
In late April, it was revealed that the online digital services for Legal Aid, the Government agency responsible for providing legal funding, had been hit by a cyber attack.
The Data (Use and Access) Bill, introduced in the House of Lords in October 2024 is a new piece of legislation proposed by the Government with the aim of cutting out much of the “red tape and pointless paperwork”.
Marks & Spencer are expecting a £300 million hit to their operating profits following a cyber attack that is expected to lead to disruption to online operations until July.









































