PrivacySignal
GDPR / Intl

UK: ICO statement on ‘Edtech examined’ report

DataBreaches.net · · International · GDPR & International

The UK Information Commissioner's Office has published a report summarizing findings from its audits of educational technology providers, outlining how those companies handle personal data and where improvements were identified or made.

Why this matters: Children's data sits at the center of this. Schools do not really have a choice about which tools they use, and neither do students. That makes edtech a captive market with some of the most sensitive users imaginable. When the ICO audits these providers directly, it can push for real changes before something goes wrong. The key now is whether the findings lead to lasting accountability or just a round of temporary fixes companies make to satisfy regulators and then quietly walk back.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
H Hunton Andrews Kurth LLP · · International

EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence

The European Data Protection Board has called for a review of the EU-U.S. Data Privacy Framework following a U.S. Supreme Court ruling that affects the independence of the Federal Trade Commission, a key enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
Information Commissioner's Office · · UK

ICO statement on Upper Tribunal decision

I need to work carefully here — the excerpt gives almost nothing beyond the headline. I'll write only what the headline and source reasonably imply: the UK's Information Commissioner's Office issued a public statement following a ruling by the Upper Tribunal, which is an appellate body that hears ch

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
Inside Privacy (Covington) · · International

New York Publishes Final SAFE For Kids Act Rules

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027. The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as websites, online services, and applications... Continue Reading…

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy#regulation#security Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

EDPB Publishes Draft Guidelines on Anonymisation

The European Data Protection Board has released draft guidelines updating its 2014 position on anonymisation, offering a more structured framework for determining when data can be treated as truly anonymous. The guidelines reflect the EDPB's cautious stance while attempting to give organisations clearer criteria for making that assessment.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
IAPP · · International

EDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter

The European Data Protection Board has called for a review of the EU-US Data Privacy Framework following the Trump v. Slaughter case, which relates to the dismissal of Federal Trade Commission members and raises concerns about the independence of the US enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
DataBreaches.net · · International

Cyberattack hits Liechtenstein, with 31,000 records stolen

Liechtenstein's government has confirmed a cyberattack that resulted in the theft of approximately 31,000 personal records. Given the country's population of around 41,000, the breach potentially affects the majority of its residents.

Who should care: Lawyers · Privacy officers · AI governance