Six pointers to 2026 as a Time of Transition
September 2026 (exactly 50 years since I conducted my three-month research visit to the US and Canada which effectively launched my career in this field) marks a time of transition for information law in the UK.
Firstly, within the ICO. The familiar role of sole Information Commissioner, which has lasted 42 years since Eric Howe was appointed as the first Data Protection Registrar in September 1984, is now in the process of being replaced by a non-executive board led by a still to be appointed part-time chair.
While the board has diverse experience in different sectors, none of them claim specialist data protection law expertise, which was not a requirement for the role. As a result, the board will a have a more strategic role.
I will watch with interest whether the government and Parliament appoint a chair who will have the organisational skill to lead the board if they choose to challenge the full-time professional IC staff on a substantive public policy issue. Would they do so on an issue which favours the IC’s objective of economic growth, now firmly within the scope of the Information Commission’s objectives, rather than data protection principles? How will such potential clashes be resolved? Will a Parliamentary committee monitor such policy changes?
Secondly, “traditional” concepts and ways of working with Data Subject Access Requests and consent mechanisms are being disrupted by widespread use of AI by both data controllers and data subjects. The relaxation of DSAR obligations in the Data Use and Access Act should enable organisations to respond to individuals’ requests with the personal data most relevant to their concerns, rather than a legal obligation to provide every conceivable piece of data fuelled by AI-assisted requests and appeals.
Thirdly, the Data Use and Access Act (DUAA) gives a substantial role to the Secretary of State to take on “Henry VIII” powers in many areas. Previously, such powers have been deployed rarely. We will have to wait to see how interventionist the new Secretary of State will be.
Freedom of Information
A fourth point of transition is that Freedom of Information will also need attention. There are increasing concerns over the balance between transparency and security regarding access to contact information for public sector employees, for example, those responsible for environmental monitoring.
An example from Canada is that, on 18 August, the government of British Columbia (BC) removed public access to its directory of information contacts.
BC Information and Privacy Commissioner Michael Harvey explained “… threat actors are increasingly targeting key individuals and public servants based on publicly available information. The cybersecurity threats are very real and must be taken seriously. However, completely removing public access to the directory without a functional replacement is a very serious transparency issue, which contributes to an erosion in the public’s trust to our democratic institutions.”
As a consequence, Harvey announced on 25 August that his Emerging Information and Privacy Technologies team has begun studying this issue. They will evaluate the validity of the security risks and identify how organizations can remain transparent in the circumstances.
Similar concerns may well become more frequent in the UK, so the IC board may need to make a new assessment of the resources devoted to this area.
International transfers
A fifth point is that international transfers are a matter of intense interest to companies but seem to have relatively little impact on the public’s privacy concerns. In the early years of data protection law, keeping personal data within UK national borders was the assumed starting point. International transfers required specific provisions in the law. Over time, international transfers have become the norm.
The EU’s slow moving “adequacy” programme has been the gold standard. But the UK government, making the most of its renewed EU adequacy status, is now energetically exploring looser arrangements which involve Associate Membership of the APEC-inspired Cross Border Privacy Rules (CBPR) framework – a certification system for evidencing data protection compliance which operates in the Asia Pacific region (1 & 2). The ICO has been keeping close watch by attending its meetings, networking with its members and learning about this process.
Children’s issues
A sixth point of transition is that the public, and therefore politicians, are far more focused on children’s issues. The New York Times reported on 26 August: “Meta’s settlement of a case in the US reached a landmark settlement with 47 states, the District of Columbia and US territories, agreeing to pay up to $17.1 billion in penalties and make major changes to its products over claims it endangered children with addictive social media platforms.”(3)
The company agreed to “financial penalties for violating federal child privacy and states’ consumer protection laws….. Meta also agreed to limit how long teenagers can spend on its platforms and to bans on features that stoke mental health issues, striking at the heart of the company’s business of engagement for advertising.”(4)
Colorado’s Attorney General, Phil Weiser, stated: “The focus of this case was to protect our kids: stopping notifications and alerts at night and when they are in school, encouraging them to take breaks from social media, protecting them against harmful features.”
However, privacy advocates have noted that: the settlement applies only to the US; the company will pay the financial penalty in instalments over ten years; and the company has not admitted liability.
Social media for under-16s?
Arguments in favour of under-16s using social media include that by banning “social media” many other services, such as communications and gaming platforms may well cause similar harms but escape the ban. Protections, even if effective, would cease at age 16, allowing the full force of potential harms to overwhelm teenagers and indeed anyone vulnerable over 16.
The argument for access to social media for under 16s has been taken up by the well-respected Robert Spano(5) former President of the Court of Human Rights, Strasbourg, and now Partner at law firm Gibson Dunn, London and Paris. He makes his case within the framework of the European Convention on Human Rights (ECHR) to which the UK is still a party.(6)
He notes that France’s legislature banned social media for under 15s, but on 14 August the Constitutional Court struck down this policy. The court’s case was based on Article 10 ECHR which protects freedom of expression — including the right to receive and impart information and ideas. Therefore, is a complete and automatic prohibition on everyone aged 13–14 using social media proportionate?
He makes the persuasive argument that a blanket ban would:
- Treat all young people in the same way, regardless of maturity or circumstances;
- Treat all platforms in the same way, regardless of their risks;
- Prevent access not only to harmful material, but also to perfectly lawful information and expression; and
- Would restrict not only the ability to speak, but the ability to receive information from others.
Could more targeted safeguards address specific risks? They might include limits on direct messaging by unknown adults, content moderation, parental controls, or restrictions on particular high-risk features rather than the entire platform.
The ICO has children’s data as its top strategic priority. But meanwhile the widespread use of social media means that hundreds of millions of people find these platforms attractive and have become dependent on them. The New York Times reported after the settlement of the case with 47 states: “Meta’s stock rose on the news, closing up just over 1 percent. The company is valued at $1.47 trillion and most recently generated $60.8 billion in quarterly revenue.”
Meta recently settled a similar case in Texas by paying a settlement of around $1 billion.
Of course, it is not only Meta. On 11 May 2026, the Texas Office of the Attorney General filed a lawsuit against Netflix under the Texas Deceptive Trade Practices Act on the basis of children’s privacy and platform design (PL&B International Report August 2026).
In short, regulatory efforts in the UK and the European Economic Area are incremental and consistent with these US cases. But only a mass user exodus from any social media platform, leading to substantial declines in advertising revenue, would likely be the driver of changes in corporate data privacy models.
So, while September marks a time of transition on the UK data protection law scene, powerful international forces remain influential. It will take creativity and nuanced understanding of the issues from the new Information Commission, and supportive agencies, to move from the widely held plea “something must be done” towards effective future policies across the range of data privacy issues that reduce harms.
Meet the Correspondents, 6 October, London
We invite all subscribers to PL&B Reports to attend free of charge our Meet the Correspondents event on 6 October in London.
We look forward to meeting you there.
Stewart Dresner
Publisher, Privacy Laws & Business
September 2026
| REFERENCE |
|
News & Blogs |
September 2026 Report Contents |
Next |