Category: Being in Law

  • Digital Omnibus reality check: 83.5% of access requests not properly answered

    noyb

    Read original article →

    Concatena says

    Our Take: This analysis from noyb (who may have a particular point to make) shows companies – not data subjects – are the real problem: 83.5% of access requests tied to noyb cases were either incomplete or unanswered, including many from big tech, who one would have imagined would have sophisticated enough systems to automate such a process. Noyb suggest this indicates that proposals in the Digital Omnibus to restrict access rights are misdirected.

    Your Takeaway: it’s true that data subject access requests can be misused, but they are a vital check and balance for data protection. If responding to a subject access request is hard, you may wish to consider whether that shows some weakness in your overall data governance practices. Give us a call – we can help!

    Most companies do not properly answer requests for access to personal data, with 83.5% of such requests ignored or incomplete. Big tech firms often fail to provide full replies, making it hard for people to check their data use. The European Commission wants to limit these access rights, but experts warn this would harm people’s privacy protections.

    Highlights

    **Access Requests not a relevant workload.** At the same time, a recently published *noyb* survey made clear that the majority (over 70%) of Data Protection Officers (DPOs) working in companies think that data subject rights – and the Right of Access in particular – don’t create a significant workload, while being a useful tool for protecting people’s rights.

    **Real-life data: 83.5% of access requests not properly answered.** In practice, however, the primary problem concerning the right of access is not “abusive” complaints, but the huge amount of requests that don’t receive a proper answer. This also explains why a significant number of complaints before authorities concern the lack of a full reply to access requests. To gain more insight into how companies deal with the right of access, *noyb* analysed 121 access requests that have been filed in relation to *noyb* cases since 2018*. The results are clear: only 16.5% of those requests received a satisfying reply, while 53.7% were incomplete – and almost 30% were not answered at all. Overall, 83.5% of requests were not responses in line with the law.

    **The most commonly exercised right under the GDPR is the right of access to one’s personal data that is being processed by companies. After all, it’s often the prerequisite to know if there is inaccurate or unlawful personal data that needs to be corrected or deleted. However, a new** **analysis of** ***noyb*** **cases shows: Only 16.5% of all access requests** ***noyb*** **has sent to companies in the past 8 years received a satisfactory reply, while 53.7% of replies were incomplete – and almost 30% were not answered at all. In other words: while companies are lobbying Brussels to limit people’s right of access because of an alleged “abuse”, the real problem is non-compliance by these exact companies.**

  • Final storage and access technologies guidance published

    ico.org.uk

    Read original article →

    Concatena says

    Our Take: I’ve not had a chance to fully read into this yet, but my initial big takeaway is the uphill battle that the ICO has in trying to convince people that terms like SATs mean the same thing as they understand when they here cookies. I know how they feel, it’s driven me mad for years, but sometimes you need to meet people where they are. I’m slightly concerned about the references to consulting with the online advertising industry to help shape future initiatives – I’d really like to see consultation with third sector or indeed businesses who are reliant on the advertising revenue but also value their customers to pitch in here too. Final thought is to about how it’s intended that “demonstrably low privacy risks” are quantified. In 2004 I remember the then commissioner, Richard Thomas, warning that we were sleepwalking into a surveillance society. Whilst the current commissioner has stepped away for a while, I hope the ICO still remembers that report.

    Your Takeaway: Nothing really to see here, yet – but if online tracking or advertising is important to your business, or to your ethics, it’s worth a closer read – and maybe getting involved in the ongoing discussions.

    The ICO has today published its finalised guidance on Storage and Access Technologies (SATs), alongside an update on its online tracking strategy.

    Highlights

    The guidance, which covers how the Privacy and Electronic Communications Regulations (PECR) (and where relevant, the UK GDPR) apply to cookies, tracking pixels, device fingerprinting and similar technologies (‘storage and access technologies’), incorporates updates following two consultations and changes introduced by the Data (Use and Access) Act. It includes new examples and points of clarification to help organisations comply with the law. It reflects the law as it currently stands, and sits separately from our ongoing work to review regulation 6 of PECR for online advertising purposes, on which further updates will follow in the coming weeks.

    We have today published our finalised guidance on Storage and Access Technologies (SATs), alongside an update on our online tracking strategy.

  • Online tracking strategy update – April 2026

    ico.org.uk

    Read original article →

    Concatena says

    Our Take: We’ve commented on the SATs guidance in a separate post, but this wider summary from the ICO is worth a read too. I still don’t love the focus on consent for “cookies/SATs” (and don’t even get me started on consent-or-pay) – I don’t see how the average user can possibly understand the network that lies behind that little button – but that’s the legal landscape were in.

    Your Takeaway: As with the SAT guidance, there’s nothing requiring action here yet (unless you didn’t check your cookie banner compliance last year… in which case, I’d recommend a look now). Still, some ongoing discussions here it’s worth keeping on top of – and contributing to as well.

    At the start of 2025, we published our online tracking strategy setting out our plans to give people meaningful choice and control over how they are tracked online, and provide businesses with certainty to innovate responsibly.

    Highlights

    After careful consideration and review of our concerns, we concluded that further action would not be appropriate after observing positive improvements from the platforms as compared to their historical processing practices. This was communicated to the platforms in January of this year.

    We assessed key areas of concern, including: the validity of consent for the data processing carried out by these platforms and their lawful basis relied upon for processing.

    We have driven improvements in the standard products offered to website owners by working directly with key cookie banner vendors responsible for the largest market shares across the UK’s most popular websites. For example, OneTrust and Usercentrics have developed UK-specific templates aligned with our guidance. This is in addition to a range of other improvements made by these platforms and changes implemented by Sourcepoint and Inmobi to enhance their existing templates and guidance. This engagement has raised the bar across a significant portion of the market and made it easier for online businesses to offer fair, compliant choices to users.

    We committed to reviewing cookie banners on the top 1,000 websites in the UK. As we updated in December, our action has seen significant changes. It has lowered the prevalence of cookies being placed before a user has expressed their choice and has driven an increase of clear reject options on consent banners, making it easier for users to control how they are tracked.

    Next month, we will be publishing our advice to government on where PECR requirements to obtain consent for the use of storage and access technologies for online advertising purposes could be removed. We understand that the government is exploring whether to create an exception or exceptions for some online advertising purposes, using secondary regulation-making powers under regulation 6A of PECR. This work will help inform government policy–making.

    Last year, we opened a call for views on our review of regulation 6 PECR where the use of storage and access technologies for advertising may pose demonstrably low privacy risks.

  • Adobe’s legal chief calls for creator protection as policymakers and tech companies reframe copyright in the era of AI

    Craig Hale

    Read original article →

    Concatena says

    Our Take: Adobe’s legal chief urges a pragmatic path for AI regulation – don’t tear up copyright law but clarify it and protect creators whose work fuels AI. I hate to say it, but I agree – let’s focus on the fundamentals, but importantly let’s also think about whether the means for enforcing individual contributors rights is accessible in this new world, and if not, whether there ought to be a supportive regime which regulates bad actors.

    Your Takeaway: IP is always something to keep an eye on. The article talks about creator protections and provenance tools, and they are worth looking at and understanding; but it’s unclear how much control they truly give. Make sure you’re not cutting corners in your own IP compliance with third party materials at the same time as protecting your output.

    While the world establishes copyright for AI-generated assets, Adobe’s legal chief calls for greater creator protection and asset verification.

    Highlights

    The difficulty at the moment is that regions like the US, EU and UK are pushing their own goals. "It’s a fallacy to think there would be a universal standard that would apply globally," Pentland said. "but we can dream."

    When asked about watermarking, Pentland rejected visible marks as the default solution, favoring options like metadata or QR-style verification to preserve the integrity of an artist’s work.

    To date, the ‘Big Five’ camera makers (Fujifilm, Sony, Canon, Nikon and Leica) and some Android manufacturers (Google Pixel and Samsung Galaxy) have implemented Content Credentials, as have a number of popular platforms like LinkedIn, YouTube, Meta and TikTok.

    Adobe sees this type of verification protecting consumers against threats like deepfakes, enabling users to verify authenticity.

    For Adobe, this means pushing Content Credentials, which the company describes separately as "a durable, industry-standard metadata type that acts like a digital nutrition label for content," in a bid to create verifiable content trails.

    In 2025, the US Copyright Office granted protection to an image that was created with AI assistance, making this the first time anyone has ever been granted copyright protection for AI-generated work.

    "We don’t want it to stifle innovation," she said, "but at the same time, we can’t leave it completely unchecked."

    At the same time, Pentland also advocated for tech companies to get involved – not to redefine copyright law, but to maintain authenticity and protect creators in this era of AI assistance.

    Speaking with *TechRadar Pro* in an exclusive interview at Adobe Summit 2026, the company’s Chief Legal Officer, Louise Pentland, urged policymakers to resist radical changes, and for courts and companies instead to focus on a more pragmatic approach.

  • English councils to trial Google AI tool to speed up planning decisions

    Chris Smyth

    Read original article →

    Concatena says

    Our Take: Using AI to generate efficiencies could really support public services to get more done, and to be more consistent. Human in the loop is vital – but you need to ensure that those humans are empowered to really BE in that loop and to contradict the machine. “Computer says no” can be very difficult to pass over…

    Your Takeaway: Make sure that any humans in the loop using LLM powered systems have appropriate training and understanding of their outputs, so that system can support *their* critical thinking, not outsource it.

    English councils will start using a new AI tool from Google to help speed up building project decisions. The AI will give recommendations, but humans will make the final call. The government hopes this will make planning faster and support building more homes.

    Highlights

    Under the programme, humans will make the final decisions with AI providing a recommendation. For more complex applications, the AI tool will probably give officials a framework for decisions rather than a definitive answer.

    “There is a risk that in the push to harness efficiencies and insights, planning’s decision-making systems are redesigned to work well with AI, and not for optimal outcomes. There’s no value in processing applications more quickly if the developments that follow are low quality.”

    Recommendations on whether to grant or refuse building projects will be generated using a custom AI system — the Augmented Planning Decision Tool — before being signed off by council officers.

    Planning decisions in England will for the first time be made with the help of Google-built AI starting this month, in a pilot ministers say will speed up approvals.

  • EU and UK competition rules updated around tech licensing

    Out-Law from Pinsent Masons

    Read original article →

    Concatena says

    Our Take: I’ll be honest, I’ve not fully digested this. Competition law takes a lot of brain power. But I do want to dig some more into the new data licensing elements when I get the chance – I think this is where regulators need to be really thoughtful.

    Your Takeaway: Depends on who you are – commercial lawyers, make sure you have at least an understanding of these changes. Small businesses, you can probably scroll on by!

    New competition rules governing technology licensing agreements have now taken effect in both the EU and UK.

    Highlights

    The provisions of the new the UK TTBEO are for the most part in alignment with those of the TTBER

    Data licensing agreements are increasingly common, but they were not covered under the 2014 TTBER and guidelines.

    New guidelines on data licensing

    Clearer market share thresholds

    A one-year transitional period, until 30 April 2027, applies under both the EU and UK regimes for existing technology transfer agreements that comply with the old TTBER requirements but not the new rules. New technology transfer agreements implemented from today must immediately comply with the new rules.

    In the UK, a new Technology Transfer Agreements Block Exemption Order (TTBEO) – which was subject to separate review and consultation by the UK government and the Competition and Markets Authority (CMA) – also enters into force today, 1 May. The TTBEO replaces the 2014 TTBER which was “assimilated” into UK national law following Brexit. The CMA is currently consulting on draft new guidance for the UK TTBEO regime.

    In the EU, a revised Technology Transfer Block Exemption Regulation (TTBER) and revised Technology Transfer Guidelines (‘the guidelines’) enter into force today, 1 May. The revisions, which replace the 2014 versions, follow a four-year review by the European Commission into the functioning of the 2014 TTBER and related guidelines and aim to address concerns raised from a wide range of stakeholders.

  • Meta cuts contractors who reported seeing Ray-Ban Meta users have sex

    Scharon Harding

    Read original article →

    Concatena says

    Our Take: Without going into the many many layers of this story, our takeaway for anyone procuring products or services is to consider the full supply chain when looking at the ethics of a product. What feels like automated magic is often a person behind the curtain, probably in a jurisdiction with fewer safeguards, more often than you might expect.

    Your Takeaway: Beauty isn’t skin deep – make sure you do your due diligence and that your happy that your providers ahve appropriate worker protection and safeguards all the way down the chain. And if you’re running human‑review workflows – think through all the consequences. Finally, if you’re using wearable tech which captures images of everyone around you, give real consideration to how you’d feel if a someone with less moral integrity than you were to do the same.

    Meta ended its contract with Kenyan firm Sama after workers reported seeing private and explicit videos recorded by Ray-Ban Meta glasses. Sama denies failing to meet standards and says it was not warned about any issues. The situation has raised privacy concerns and led to investigations and a class-action lawsuit against Meta.

    Highlights

    BBC reported that Sama workers believe Meta ended the contract because workers spoke out about seeing Ray-Ban Meta-shot footage of people performing personal acts, like changing their clothes, having sex, and using the toilet.

    A Meta spokesperson told BBC that Meta “decided to end our work with Sama because they don’t meet our standards.” Ars Technica reached out to Meta asking how, specifically, Sama failed to meet Meta’s expectations and will update this article if we hear back. Ars has also reached out to Sama.

    In February, numerous workers from a company that Meta contracted to perform data annotation for Ray-Ban Meta reported viewing sensitive, embarrassing, and seemingly private footage recorded by the smart glasses. About two months later, Meta ended its contract with the firm.

  • Spotify rolls out ‘Verified’ badge to distinguish human artists from AI

    Agence France-Presse

    Read original article →

    Concatena says

    Our Take: Spotify’s new green “Verified by Spotify” badge and the informational panel are straightforward moves to help users spot human artists and surface authenticity signals amid a flood of AI-generated music. B the verification criteria (sustained engagement, platform-rule compliance, external presence like gigs/merch/socials) explicitly exclude primarily AI-created artists, rather than music… Is this the intention?

    Your Takeaway: It’s always worth considering what the “verification” on any site means – what needs to be demonstrated before verification is granted.

    Spotify will add a green "Verified by Spotify" badge to show which artists are real humans, not AI creations. This badge helps listeners trust the music and appears only on profiles that meet Spotify’s authenticity rules. The change comes as many AI-generated songs flood streaming platforms, causing concern in the music industry.

    Highlights

    Spotify on Thursday unveiled a new verification system designed to help listeners distinguish human musicians from AI-generated content, as people flood streaming platforms with a growing volume of synthetic tracks made with artificial intelligence.

    The initiative arrives amid mounting concern across the music industry over AI-generated content overwhelming streaming catalogues.

    The company said more than 99% of artists that listeners actively search for will be verified at launch, representing hundreds of thousands of musicians spanning genres and geographies.

    To earn verification, artists must demonstrate sustained listener engagement over time, comply with Spotify’s platform rules and show signs of a genuine presence both on and off the platform, such as concert dates, merchandise and linked social media accounts.

  • Legal AI startup Legora hits $5.6 valuation and its battle with Harvey just got hotter

    Anna Heim

    Read original article →

    Concatena says

    Our Take: We’re seeing more “market froth” more than “proven change in legal practice.” Valuations, ad campaigns and celebrity endorsements are racing ahead of most firms’ ability to use these tools in a meaningful way. Right now, the gap between the hype and what fee-earners actually do with Harvey/Legora in a normal Tuesday is still pretty stark. I’d love to hear your experience!

    Your Takeaway: Treat this as a signal to experiment deliberately, not to panic-buy a platform. If you haven’t already, pick one or two contained use cases (e.g. first-draft research notes, clause comparison) and run small, supervised pilots with clear guardrails. Then share honest internal feedback — including the “confused faces” — so you don’t let marketing headlines set your AI strategy.

    Legora is a legal AI startup valued at $5.6 billion and backed by Nvidia and other investors. It competes closely with Harvey, another legal AI company valued at $11 billion, as both expand globally. The rivalry is intense, with big marketing efforts and a focus on applying AI to reshape the legal industry.

    Highlights

    Alongside Atlassian and other new financial investors, NVentures joined Legora’s cap table as part of a $50 million Series D extension that comes a month after the startup’s $550 million Series D.

    Leveraging AI to help lawyers streamline their work, the Swedish-born legal tech startup is competing with U.S. player Harvey.

    Nvidia has laid a new brick in its AI empire. NVentures, its corporate VC fund, has backed Legora, reportedly its first legal AI investment.

  • Congress keeps kicking surveillance reform down the road

    Gaby Del Valle

    Read original article →

    Concatena says

    Our Take: Congress has kicked the FISA 702 can down the road. Whilst this legal back and forth might feel far away, the way the US sets its surveillance rules has real knock-on effects for UK/EU businesses relying on US cloud and SaaS tools, and for anyone worrying about international data transfers. This is one to watch closely in case future “reforms” either harden surveillance or, more optimistically, edge towards better privacy safeguards that could ease some cross-border risk.

    Your Takeaway: If your business leans on US tech stacks, keep in mind that ongoing FISA 702 wrangling could shift the risk profile of your international data flows overnight. Treat this as a reminder to map which services touch US infrastructure, keep your transfer impact assessments fresh, and be ready to explain to customers and boards why a very American-sounding fight in Congress still matters for their data.

    Congress extended Section 702 of the Foreign Intelligence Surveillance Act for 45 days to allow more time for reform talks. The House passed a version with minor changes but no warrant requirements, causing frustration among some lawmakers. Privacy advocates say the bill does not do enough to protect Americans’ rights.

    Highlights

    “Three weeks is more than enough time to negotiate a reform bill,” Thune said on the Senate floor on Thursday. “That is, if members are serious about negotiating.”

    The House renewed Section 702 with minor reforms on Wednesday evening. The bill didn’t include the hotly debated warrant requirement, but it did feature a provision prohibiting the Federal Reserve from issuing Central Bank Digital Currencies, which Senate Majority Leader John Thune (R-SD) described as a nonstarter.

    Congress has reauthorized Section 702 of the Foreign Intelligence Surveillance Act — but only for another 45 days. The extension is meant to give legislators more time to negotiate reforms to the controversial wiretapping bill. If the past few weeks are any indication of how future debates will go, however, we’re in for a bumpy ride.