Data and Cyber Update - July 2026

Data and Cyber Update - July 2026

Data Protection | 31/07/2026

Welcome to the latest edition of the Stephenson Harwood Data and Cyber Update, covering the key developments in data protection and cyber security law in July 2026.

In data regulation news, the EDPB has published new guidance on anonymisation; the European Commission has published guidance to support implementation of the Cyber Resilience Act; the Information Commission has taken further shape with new board appointments and the launch of the chair recruitment process; G7 data protection authorities have backed a privacy-preserving approach to age assurance; and Singapore has finalised guidance on the use of personal data in generative AI.

In cybersecurity news, two recent updates involving life sciences organisations highlight why pseudonymised clinical trial data still exposes organisations to data protection and cyber risk.

In our enforcement and civil litigation update, the General Court has confirmed the European Commission’s ability to require disclosure of work-related communications held on personal devices; and BrewDog’s founder is facing data protection complaints over emails sent to former crowdfunding investors.

More details on each of these developments are set out below.
 

Data Regulation

Cybersecurity

Enforcement and Civil Litigation

Data Regulation

EDPB Guidelines 02/2026 on anonymisation

On 7 July 2026, the European Data Protection Board (“EDPB”) adopted for public consultation the first version of its Guidelines 02/2026 on Anonymisation (the “Guidelines”). A significant feature of the Guidelines is that they invite controllers to choose between two ways of assessing anonymity: a “contextual approach” and a “simplified approach”. We took a closer look at these two approaches, and the three-criteria test to be applied to assess if data is anonymous, in our insight: The EDPB's guidelines on anonymisation: one legal standard, two approaches, three criteria.
 

Information Commission takes shape as board appointed and chair search begins

The transition of the ICO to the new Information Commission has moved forward on several fronts. On 15 July 2026, the Department for Science, Innovation and Technology ("DSIT") announced the appointment of seven non-executive members to the board of the incoming regulator and launched recruitment for its first chair; the role left vacant by John Edwards' resignation in June. The wider review of the ICO’s culture, accountability and governance will now sit with the Department for Digital, Culture, Media and Sport, following the new Burnham administration’s abolition of DSIT and the transfer of digital policy responsibilities to the revamped department.

The ICO also published its annual report for 2025-26 this month, the last full annual report of its current form before the corporation sole model is replaced by the board-governed Information Commission. Paul Arnold continues in an interim leadership role and will join the board as Accounting Officer and Interim Chief Executive Officer from 1 July 2026, pending the UK Government's decisions on the permanent leadership. We covered the background to the resignation in our June edition here, and will continue to track the transition as the new Information Commission takes over the ICO's functions.
  

European Commission publishes guidance on Cyber Resilience Act implementation

On 27 July 2026, the European Commission (the “Commission”) published its final guidance (the “Guidance”) on the application of the EU’s Cyber Resilience Act (“CRA”), following a consultation on the draft guidance earlier this year. The CRA aims to ensure "products with digital elements" are secure throughout their lifecycle by imposing mandatory cybersecurity requirements on manufacturers, importers, and distributors when making them available in the EU.

Despite the non-binding nature of the Guidance, it offers manufacturers and other economic operators a clearer understanding of areas of uncertainty in the CRA and is likely to shape how the CRA is applied in practice. It is intended to help manufacturers, developers and businesses prepare for compliance by clarifying common themes that stakeholders have raised with the Commission on the CRA's application. We explore four of these themes below:
 

1. Scope of the CRA

The Guidance initially addresses scope issues under the CRA, namely in relation to Remote Data Processing Solutions (“RDPS”) and Free and Open-Source Software (“FOSS”).

The Commission clarifies when remote data processing can qualify as an RDPS. This depends on (i) whether the processing occurs ‘at a distance’; (ii) whether the absence of that processing would prevent the product from performing one of its functions; and (iii) whether the software is designed and developed by, or under the responsibility of, the manufacturer. All three elements must be met for the remote processing to qualify as an RDPS.

Regarding FOSS, the Commission clarifies that it is not supplied in the course of a commercial activity and generally lies outside the CRA’s scope. However, the Guidance provides a number of examples illustrating when FOSS may fall within scope, particularly where it is directly or indirectly monetised, such as where the publisher charges a price, monetises other products or services through the software, requires the processing of personal data as a condition of use, or conditions access on donations.
 

2. Substantial modification

The Guidance states that a product modification is substantial where it affects the product's compliance with the CRA's essential cybersecurity requirements, or where it changes the intended purpose against which the product was assessed. Security updates, and other changes where the sole effect is to reduce the level of cybersecurity risk, are generally not considered substantial modifications, provided they do not alter the product's intended purpose or introduce new or increased risks.

Where a modification is substantial, the modified product is treated as newly placed on the market and, depending on who carries out the modification, may require a fresh risk assessment. Where applicable, a new conformity assessment procedure in respect of the modified parts may also be required.
 

3. Support periods

The CRA's five-year support period is a minimum safeguard, not a default. Manufacturers must set the support period by reference to the product’s expected use time. Products reasonably expected to be in use for longer than five years should have correspondingly longer support periods.

The Guidance clarifies that a substantial modification does not automatically reset or extend the support period. Whether it should be recalculated depends on whether the modification affects the factors that originally determined the product's expected use time. Manufacturers may also focus their vulnerability remediation efforts on the latest version of a software product, rather than on each earlier substantially modified version, provided users can upgrade to that latest version free of charge and without incurring additional costs.
 

4. Reporting obligations

The Guidance clarifies a manufacturer's reporting obligation under Article 14 of the CRA. This is triggered once it has carried out an initial assessment giving it a reasonable degree of certainty that a vulnerability contained in its product is being actively exploited, or that a severe incident affecting the product's security has occurred. Reporting follows the CRA's staged framework: (i) an early warning within 24 hours; (ii) a fuller notification within 72 hours; and (iii) a final report within 14 days of a corrective or mitigating measure being made available for an actively exploited vulnerability, or within one month of the 72-hour notification for severe incidents.

Organisations should ensure they are ready for the reporting obligations that apply from 11 September 2026 to all products with digital elements within scope of the CRA. As we reported in our January 2026 update, the CRA will be fully applicable from 11 December 2027.
 

G7 data protection authorities back privacy-preserving age assurance

Following the G7 meeting in France in late June 2026, the G7 Data Protection and Privacy Authorities (the “G7 Authorities”) published a joint statement (the “Statement”) on privacy-preserving age assurance. This follows the June 2025 G7 Data Protection and Privacy Authorities’ Action Plan, which set out the G7 Authorities’ priorities for the year. The Statement reflects the growing use of age checks and the challenges in the deployment of age-assurance technology as governments seek to strengthen protections for children online (including proposed social media bans in the UK and recently approved bans in France; both G7 countries).

The G7 Authorities recognise that age assurance can be useful in specific contexts, such as where services are age-restricted or child risks cannot be addressed by less intrusive means, but stress that it needs to sit alongside wider safeguards such as parental controls and digital literacy initiatives rather than operate as a default solution.

A central theme of the Statement is that age assurance must be proportionate, respectful of individual rights and privacy-preserving. The G7 Authorities warn that broad or indiscriminate deployment of age assurance technologies could create new risks for individuals, particularly where the tools involve sensitive data, biometric processing or large-scale identity checks. Instead, they support approaches that are risk-based and privacy by design, with careful limits on what data is collected, why it is collected, how long it is retained and who can access it.

The Statement supports the development of age assurance technologies that are interoperable and trustworthy with privacy at its core and points to existing guidance and standards work, including the EDPB statement on age assurance and the ISO 27566 framework. This is significant because age assurance is increasingly being built into online safety regimes across jurisdictions, but regulators are clearly concerned that child protection measures should not become a route to excessive data collection or unnecessary surveillance.

For organisations, age assurance may become a more common compliance requirement, but it will need to be implemented carefully. Businesses should consider whether age checks are genuinely necessary for the relevant service or feature or whether a less intrusive option is available. As more online services become subject to age-based restrictions, regulators are likely to look closely not only at whether age assurance works, but whether it does so in a way that protects privacy from the outset.
  

Singapore finalises guidelines on the use of personal data in generative AI

Singapore’s Personal Data Protection Commission has published final advisory guidelines on the use of personal data in generative AI (the “Guidelines”), following its public consultation earlier this year. The Guidelines set out how the Singapore Personal Data Protection Act applies across the AI development lifecycle, including when organisations may rely on the publicly available exception for model training, what AI-specific notices and consent mechanisms should look like, and how responsibilities should be allocated between model providers, system providers and deployers.

Our Singapore data protection team has analysed the Guidelines in an insight piece: Singapore's PDPC issues new advisory guidance on use of personal data in generative AI.
  

Cybersecurity

Novo Nordisk breach and CNIL decision highlight continuing data and cyber risks around pseudonymised health data

Recent incidents involving pharmaceutical and life sciences companies underline the challenges of properly anonymising data, and the sector’s continued exposure to cyber risk.

Last month, global healthcare company Novo Nordisk disclosed that cyber attackers had accessed internal systems and copied pseudonymised data relating to clinical trial participants. The data reportedly included trial participation, sex, year of birth, biomarkers and health and lifestyle data, alongside directly identifying details of healthcare professionals. We are continuing to monitor developments in relation to the Novo Nordisk incident.

Separately, in a recent CNIL decision concerning the processing of health data, the French data protection authority recently issued a landmark €5 million fine against a global leader in clinical research and health data analytics, after concluding that the data processed in the company’s health data warehouses contained pseudonymised personal data, despite claims that the data had been anonymised. Our life sciences team has considered the decision and its implications for organisations handling health and research data in an article available here: Anonymisation through the eyes of the French Data Protection Authority: Lessons from the CNIL’s €5 Million Decision (July 2026).
  

Enforcement and Civil Litigation

One work message is enough: General Court confirms personal devices are within the Commission's reach

In twin judgments of 3 June 2026 (Vivendi SE v Commission, T-1097/23, and Lagardère SA v Commission, T-1119/23), the General Court dismissed challenges to information requests issued by the Commission in its gun-jumping investigation into Vivendi's acquisition of Lagardère. The Commission had required both companies to collect and hand over communications held by certain employees, including messages on WhatsApp and other private channels, and extending to personal devices where those devices had been used for work.

The companies argued that the requests reached too far into their employees' private lives. The Court disagreed. A device or messaging account used even once for professional purposes falls within the Commission's document-gathering powers, and complete message threads are in scope even where they mix business content with personal exchanges. Allowing employees to withhold material by labelling it "private" or "personal" would, in the Court's view, undermine the effectiveness of the Commission's investigative powers. The Court accepted that the requests seriously interfered with the right to private life, but held the interference justified and proportionate, noting the safeguards in place, including the ability to raise specific privacy objections to individual documents during the process.

Although these are competition judgments, the data protection consequences deserve attention. Where employees conduct business over WhatsApp, the messages they exchange are business records processed on the employer's behalf, and the employer is the controller of the personal data within them under the GDPR and UK GDPR. That status carries all the usual controller obligations, and it does not stop at regulatory investigations. A data subject access request may also extend to work communications sitting on employees' personal phones, leaving the employer responsible for searching, retrieving and disclosing data held on devices it does not possess.

The use of WhatsApp for any business correspondence therefore remains a key regulatory compliance risk for any business. A policy stating that employees should not use it is not enough if, in practice, they are using it anyway. Organisations need to know which channels their staff actually communicate through, and either bring those channels within their governance, retention and collection arrangements or take genuine steps to close them off.
  

BrewDog founder faces data protection complaints over emails to former investors

Earlier this year, Tilray Brands bought BrewDog's brand and assets. This deal left BrewDog's circa 220,000 crowdfunding shareholders with no financial return. Recently, in hopes of buying BrewDog back, BrewDog's founder submitted a bid to Tilray Brands via his new venture - Second Best. As part of this process, the founder contacted the crowdfunders, aiming to offer equity in Second Best to those who had held a stake in BrewDog.

This outreach is now the subject of complaints to the ICO, which is currently investigating whether UK data protection law has been breached. The core allegation is that the founder used crowdfunders' contact details unlawfully.

This incident is a useful reminder of the data privacy issues that can surface during the course of M&A transactions:

  • Be precise about which party owns the data post-sale. Ownership of datasets (e.g. marketing lists, shareholder lists and CRM data) must be clearly allocated. This can impact who is a controller and whether subsequent or continued processing of that data is lawful.

  • Include deletion and audit rights in sale agreements. Sellers and founders should be required to delete all personal data forming part of the transferred business and prohibited from ongoing use. Buyers should have the right to verify that deletion to avoid scrutiny or complaints directed at them for mishandling personal data that was supposed to be within their control.

  • Distinguish carefully between share sales and business sales. Unlike a share sale where the target usually remains the controller of the personal data, there is no automatic entitlement to use the personal data in a business sale. The buyer must have its own lawful basis to process the personal data and meet other obligations such as transparency requirements. For example, consents given for marketing do not extend to the buyer by default.

This incident also shows the increasing awareness of individuals of their data protection rights. Not only are individuals prepared to complain to the ICO, the regulator itself is also prepared to investigate.

We hosted a webinar earlier this month on the ICO’s new complaint handling obligations, including the new right to complain. Do get in touch if you would like a recording of this session.

Share Article

Related Expertise