Data and Cyber Update - September 2026
Welcome to the latest edition of the Stephenson Harwood Data and Cyber Update, covering the key developments in data protection, cyber security and online regulation in September 2026.
In data regulation news, the Commission has set out proposals for a new EU Kids Act; the ICO became the Information Commission on 30 September; the European Commission (“Commission”) has designated ChatGPT, Reddit and Roblox under the Digital Services Act; and Ofcom has updated its Online Safety Act codes on detecting intimate image abuse. We also share our latest insight on the risks posed by AI smart glasses.
In cybersecurity news, the EU Cyber Resilience Act’s mandatory reporting obligations are now live; and we highlight our recent briefing, the cybersecurity wave hitting life sciences and healthcare companies: what you need to know, which considers the growing EU and UK cyber regulatory burden on the life sciences and healthcare sector. Our Singapore data protection team also cover updates to the Cybersecurity Code of Practice for Critical Information Infrastructure released by the Singapore Cyber Security Agency.
In our enforcement and civil litigation update, the Dutch data protection authority has fined Uber nearly €825 million over automated driver deactivations and an Italian broadcaster has received a warning from the Garante, the Italian Data Protection Authority, for airing satirical content featuring an AI-generated deepfake without consent.
More details on each of these developments are set out below.
Data Regulation
EU Kids Act: Commission publishes proposed Regulation on Online Child Safety
Commission designates ChatGPT, Reddit and Roblox under the DSA
Ofcom updates Online Safety Act codes on intimate image abuse
Cybersecurity
Singapore updates Cybersecurity Code of Practice for Critical Information Infrastructure
The cybersecurity wave hitting life sciences and healthcare companies
Enforcement and Civil Litigation
Data regulation
EU Kids Act: Commission publishes proposed Regulation on Online Child Safety
On 17 September 2026, the Commission published its proposed EU Kids Act Regulation, officially titled EU Keeping Internet Digital Spaces Accountable and Trustworthy (COM/2026/681) (“EU Kids Act”).
The full text confirms a graduated, age-sensitive approach that goes further than many had anticipated in seeking to protect minors from online harms and the risks posed by AI systems and digital services. The EU Kids Act will apply to providers of services where the end users are based within the EU, irrespective of whether the service provider is headquartered within the EU. It prohibits autonomous account creation on social networking services and video-sharing platforms for minors under 15, with no access at all for children under 13. Between 13 and 15, guardians may set up accounts with limited functionalities on the child's behalf, but these are formally the guardian's account.
The scope of what would fall under the remit of social media is also notably broad: it adopts the "social media plus" concept recommended by the Special Panel on Child Safety Online, an independent expert group of 60 specialists in health, child psychology, computer science, digital technology and children’s rights convened by the Commission in 2025 and whose co-chairs presented their recommendations in July 2026. The proposal extends safety-by-design obligations to online social networking services, video-sharing platforms, AI companions, general conversational chatbots, online games and software application stores. Key requirements include prohibitions on manipulative or addictive design features such as infinite scroll, autoplay and engagement-maximising notifications. For example, where providers use recommender systems - being the algorithms that select and prioritise content shown to individual users - they must design those systems to ensure a high level of privacy, safety and security for minors. Profiling-based recommendations must be disabled by default, and providers must prevent the progressive amplification of harmful content and offer minors an easy way to reset their recommendation history.
Providers of AI companions must additionally disable persistent conversational memory for minors by default and prevent features likely to create emotional dependencies, while providers of software application stores will be required to implement age-rating systems and block minors from accessing age-inappropriate applications.
The proposal also establishes an EU-wide framework for age assurance, making clear that self-declaration alone is not sufficient. Age verification systems must meet strict criteria for accuracy, reliability, privacy-preservation and non-discrimination. Member States will be required to make at least one age verification solution available.
Enforcement will build on existing structures under the DSA and the EU AI Act, with an expedited procedure under which the Commission must communicate preliminary findings within 30 days and adopt a final decision within 90 days of opening proceedings.
A separate Digital Fairness Act, due later this autumn, will additionally address addictive design from a consumer protection perspective.
The proposed EU Kids Act will now proceed through the ordinary EU legislative procedure. Whilst the text will need to be considered and agreed between the Commission, the European Parliament and the EU Council before it is adopted into law, and may be subject to amendments during negotiations, organisations offering in-scope services to minors in the EU should consider reviewing their design practices, age assurance mechanisms and data processing activities against the proposed requirements.
ICO became Information Commission on 30 September
On 30 September 2026, the Information Commissioner's Office (“ICO”) became the Information Commission, completing the governance reforms introduced by the Data (Use and Access) Act 2025 ("DUAA"). At first glance, the change may look largely cosmetic, particularly as the regulator has confirmed that it will continue to be known publicly as the ICO; but in substance, this is a significant change to how the regulator is governed, with its functions transferring from a corporation sole to a body corporate with executive and non-executive members and collective responsibility for decision-making.
The transition follows the resignation of former Information Commissioner John Edwards in June 2026, which we covered in our June edition. The seven non-executive members appointed in July took up their roles on 30 September, alongside Paul Arnold as interim Chief Executive, while recruitment for the Commission's permanent chair continues.
For organisations, the immediate practical impact should be limited, and ongoing investigations, legal proceedings and consultations will be unaffected. That said, the change may still matter in practice. A board-led regulator could take a different approach to strategic priorities, risk appetite and enforcement decisions, even if the underlying statutory powers remain the same. We offered our thoughts on the ICO’s final Annual Report and the regulator’s evolving enforcement priorities as it transitions to the new Information Commission in an article: The ICO at a turning point: what its final Annual Report reveals.
Commission designates ChatGPT, Reddit and Roblox under the DSA
On 31 August 2026, the Commission designated ChatGPT as a Very Large Online Search Engine (“VLOSE”), and Reddit and Roblox as Very Large Online Platforms (“VLOPs”), under the Digital Services Act (“DSA”). Each service had declared that it reaches at least 45 million average monthly users in the EU, which is the threshold for designation under the DSA.
The designations trigger the DSA’s enhanced compliance regime for very large online services. Following notification, ChatGPT, Reddit and Roblox have four months to comply with additional obligations, including assessing and mitigating systemic risks linked to their services and algorithmic systems. Those risks include the dissemination of illegal content, negative effects on minors, users’ physical and mental wellbeing, fundamental rights, electoral processes and public security.
The services will also be subject to additional transparency, audit and governance requirements, including independent annual audits, internal compliance functions, data sharing with regulators, vetted researcher access, ad repositories and an option for recommender systems that is not based on user profiling. The Commission will also gain investigative powers to assess the functionalities behind the services and, where relevant, related systems. Non-compliance with the DSA can result in fines of up to 6% of a provider’s global annual turnover, evidenced by Temu’s €200 million fine in June 2026 relating to the sale of illegal, unsafe or counterfeit products on its platform, and a €550 million fine for AliExpress a month later for similar breaches.
The current list of designated VLOPs and VLOSEs can be found here.
Ofcom updates Online Safety Act codes on intimate image abuse
On 9 September 2026, Ofcom published its amended and updated Illegal Content Codes of Practice (“Codes”) under the Online Safety Act 2023 ("OSA"), recommending that certain types of online service providers implement automated hash matching technology to detect and reduce the spread of non-consensual intimate image abuse online. The changes to the codes will come into force on 30 September 2026.
Ofcom has opened an enforcement programme to monitor providers’ efforts to crack down on the spread of such images. If they don’t have hash matching in place, the online service provider must prove that their systems and processes are equally effective. Failure to comply with the Codes could result in enforcement action.
Hash matching works by converting an image into a unique digital fingerprint and comparing it against a database of known abusive content, allowing platforms to identify and act on matches without needing to view or share the underlying images. The Codes are directed at:
providers of regulated user-to-user services at high risk for intimate image abuse whose principal purpose is hosting pornographic content, which have more than 700,000 monthly active UK users, or which are file-storage and file-sharing services;
providers of large user-to-user services (more than seven million monthly active UK users) at medium or high risk; and
providers of large general search services.
The Codes recommend the use of perceptual hash matching for images and, where that is not feasible for video content, cryptographic Hash matching. Ofcom has also published guidance on the appropriate proportion of human review for content flagged by hash matching.
This is one of the urgent steps being taken by Ofcom to improve online safety following the Grok indecent images scandal. The updates follow a consultation in July 2025 and a statement in May 2026 in which Ofcom recommended the amendments, before fast-tracking the decision given the urgency of better protections for women and girls online.
Smart Glasses: Sighting the Risks
As the adoption of smart glasses rapidly grows, questions around privacy risk are becoming increasingly prevalent. These devices continue to capture, process, and share personal information in real time, and present unique data protection challenges around consent, transparency, and security.
Our team has analysed the growing risks and how to navigate them in our insight: Smart glasses, sighting the risks.
Cybersecurity
Cyber Resilience Act reporting obligations take effect
The Cyber Resilience Act (the "CRA"), which entered into force in the EU on 10 October 2024, represents a significant change in the regulation of cybersecurity for digital products.
As we flagged in our January 2026 update, the CRA will be fully applicable from 11 December 2027, but is being implemented in phases. Two key obligations take effect this year, the second of which is the CRA’s new mandatory reporting requirements which came into effect this month on 11 September 2026.
These requirements aim to enhance cooperation between manufacturers, the European Union Agency for Cybersecurity ("ENISA"), and national Computer Security Incident Response Teams ("CSIRTs") to help ensure that cybersecurity threats are contained and are managed effectively.
The Commission published detailed guidance on the application of the CRA in July (see our July 2026 update), including on the reporting obligations.
To recap, manufacturers of products with digital elements are now required to report two main categories of events:
Any vulnerability in a product with digital elements that is being actively exploited; and
Any severe security incident that could significantly impact the security of the product or its users.
The CRA imposes strict deadlines and a structured process for notification. Under the CRA, manufacturers must follow a three-step notification process:
1. An initial notification must be submitted within 24 hours of becoming aware of an actively exploited vulnerability or severe incident. This early notification is intended to alert authorities as soon as possible, even if all details are not yet known.
2. A further detailed notification must be provided within 72 hours of the initial notification. This submission should include more comprehensive information about the nature and impact of the actively exploited vulnerability or severe incident.
3. A final report is required to be produced, and the deadline for submitting this report depends on the type of event:
no later than 14 days after a corrective or mitigating measure becomes available for any actively exploited vulnerability; and
within one month of the 72-hour detailed notification for any severe security incident.
All notifications must be submitted through the ENISA’s new Single Reporting Platform ("SRP") (Article 16 CRA). Once a notification is submitted via the SRP, it is addressed to both ENISA and the CSIRT located in the relevant jurisdiction. The CSIRT that receives the notification is responsible for sharing the notification with any other relevant CSIRTs across the EU where the digital product operates, subject to certain exceptions. This notification process is designed to ensure the relevant authorities are informed quickly and can coordinate an effective response across the EU.
Singapore updates Cybersecurity Code of Practice for Critical Information Infrastructure
Singapore’s Cyber Security Agency (“CSA”) has released an updated version of its Cybersecurity Code of Practice for Critical Information Infrastructure. The revised code extends the scope of application to Interconnected Systems, and adds additional operational and accountability measures, alongside providing clearer governance guidance.
Our Singapore data protection team have analysed the updated code of practice in an insight piece: Singapore's CSA issues updated Cybersecurity Code of Practice for Critical Information Infrastructure.
The cybersecurity wave hitting life sciences and healthcare companies
Life sciences and healthcare companies - from pharmaceutical manufacturers and medical device makers to hospitals, care providers and digital health platforms - face a rapidly evolving cyber regulatory landscape across the EU and UK.
Our briefing, The cybersecurity wave hitting life sciences and healthcare companies: what you need to know in September 2026, covers four major EU and UK cyber laws which now impose - or are about to impose - significant new cyber security obligations on in-scope organisations, with substantial penalties for non-compliance.
Enforcement and Civil Litigation
Uber fined nearly €825 million over automated driver deactivations
On 21 August 2026, the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (“AP”), announced that it had fined Uber €824,990,000 for making fully automated decisions about drivers in breach of the EU GDPR. The AP found that Uber used software to track drivers’ behaviour and customer reviews, and that where the system detected suspected fraud or persistently low customer reviews, drivers’ accounts were automatically deactivated, either temporarily or permanently.
The decision is significant because the AP treated Uber’s driver deactivation process as prohibited automated decision-making under Article 22 EU GDPR. Article 22 EU GDPR restricts decisions based solely on automated processing, including profiling, where they produce legal effects or similarly significantly affect an individual. The AP found that the decision to deactivate a driver’s account was taken without human assessment, even though the outcome could have immediate consequences for the driver’s ability to earn income. The AP also found that Uber had not sufficiently informed drivers about the automated decision-making it was carrying out.
The fine is also striking in scale, and is the second-largest penalty issued under the EU GDPR, behind the Irish Data Protection Commission’s €1.2 billion fine against Meta Ireland in 2023 for unlawful EU/EEA to US data transfers involving Facebook user data. Uber has filed an appeal disputing the regulator’s findings.
For businesses using automated or AI-assisted decision-making, the case is a reminder of the importance of human review. Where automated systems make decisions that materially affect individuals, organisations need to be able to explain the logic and consequences of the processing, provide meaningful human intervention, and give individuals a practical route to challenge the outcome.
Warning over Deepfakes aired by Italian broadcaster
In this month’s edition of Neural Network, we covered a warning issued by the Italian Data Protection Authority (the Garante) against broadcaster Reti Televisive Italiane S.p.a (“R.T.I.”) for airing a satirical, AI-generated deepfake depicting a well-known Italian journalist and TV host without consent.
This follows the publication by the Garante at the beginning of this year of Provision No. 789 of 18 December 2025, which, albeit non-binding, warned against the creation and sharing of non-consensual deepfakes.
The Garante found that R.T.I. had breached Articles 5 and 25 EU GDPR, concerning lawfulness, fairness, transparency, and data protection by design and by default, and prohibited any further processing of the individual’s personal data in this manner. The processing was considered unfair because individual’s actual image was used, together with the television studio where he usually worked, creating a high risk that viewers would incorrectly perceive the broadcast as authentic. It concluded that the public nature of the broadcast increased the risk of harm to the individual.
This case highlights that the use of AI to generate deepfakes from data subjects’ image and voice data without consent could lead to serious harm to the rights and freedoms of the individuals involved and attract enforcement action under data protection legislation.