Data Protection News Roundup – September

Welcome to September’s edition of the iSTORM Data Protection Newsletter. Read on to discover the latest news from the world of data protection, along with updates on everything happening at iSTORM.

iSTORM Updates

August saw iSTORM continue its ongoing projects, alongside a number of new clients and proposals coming in for support across GDPR, Penetration Testing, Cyber Essentials, and ISO services implementation and audit. Our team also continued on a ISO 42001 implementation, with the client now preparing for their audit commencing in September.

A significant GDPR Gap Analysis was carried out for a new client throughout August. Following multiple meetings and detailed document reviews, iSTORM provided feedback and recommendations to help the organisation strengthen and improve its GDPR framework. The review identified several areas for improvement, and we hope to support the client further in the near future.

We also supported clients with data breaches and denial-of-service incidents. In one case, a client’s website was subject to corruption, resulting in a loss of access. iSTORM provided support with resolving the issue, reviewing the incident and advising on the decision around reporting.

August also saw the continued growth of our DSAR service, with a steady flow of DSAR support work coming in. And remember, iSTORM isn’t just here to provide GDPR support. Our Data Protection team can support organisations across the wider data protection landscape, including GDPR, PECR, DSARs, FOIA and the AI Act.

Whatever your data protection challenge, we’re here to help..

Changes to DUAA, DPA, GDPR, PECR, August 2026

Following the implementation phase that dominated June and July, August 2026 saw organisations focus on embedding the new requirements into business-as-usual operations. Alongside this, the ICO continued to update its guidance, with accountability, individual rights and emerging technologies remaining key areas of focus.

  • Data protection complaints procedure: Organisations must have a formal complaints process in place, including acknowledging complaints within 30 days and providing outcomes..
  • ICO guidance continues: The ICO published further guidance on the right to object to reflect changes introduced by the Data (Use and Access) Act 2025. Organisations should review their privacy notices, data subject rights procedures and marketing suppression processes to ensure objections are handled appropriately and consistently.
  • Automated Decision-Making (ADM): Organisations are reviewing ADM processes under the new safeguards-based framework introduced by the DUAA.
  • Emerging focus on neurotechnology and neurodata: The ICO published research exploring public expectations around neurotechnology and the processing of neurodata.
  • Stronger PECR enforcement: Higher fines now apply for breaches relating to electronic marketing and cookies.
  • Continued review of accountability and governance: Many organisations used August as an opportunity to review and update their wider accountability frameworks, including Records of Processing Activities (RoPAs), international transfer assessments, privacy notices, complaints procedures and staff training.

You may also need a Data Protection Complaints Policy, updates to your Privacy Notices, staff training on recognising and handling complaints, and contract amendments requiring processors to support this process.

If you would like any more information about this, or anything covered in this month’s newsletter, please reach out to us!

News

 

Police facial recognition audits reveal inconsistent compliance

The ICO has refreshed its guidance following the Data (Use and Access) Act 2025. Organisations should ensure privacy notices and internal processes clearly explain the right to object, particularly for direct marketing and legitimate interest processing, and review marketing suppression procedures to prevent opted-out individuals from being contacted again. Source: PDP

 

EDPB urged to simplify GDPR breach notification template

The EDPB has been urged to simplify its proposed EU GDPR breach notification template, which currently contains 125 questions. Concerns have been raised that the level of detail may be difficult to provide within the GDPR’s 72-hour reporting window, particularly where investigations are still ongoing. The template would not apply to UK GDPR-only notifications, but could be relevant to UK organisations operating in the EU or managing incidents across both jurisdictions. Source: PDP

 

Training 

Did you know it’s a legal requirement to ensure all employees and contractors are trained to handle personal data? From GDPR principles to breach response, data requests, and remote working, it’s your responsibility, and you must be able to evidence it.

iSTORM can help with bespoke training in any format: HR packs, team sessions, in-person workshops, or even voice-over training for your internal LLM. Don’t get caught out—proper training is the first thing regulators will ask for if something goes wrong.

Talk to us about what support we can provide!

 

Meet the Team…

Our friendly team of passionate Data Protection Specialists are here to help your team navigate your data protection challenges, and are happy to support you with all your queries.

 

More from iSTORM?

We can offer services including:

  • GDPR/ Data Protection gap analysis and maturity reviews
  • Auditing
  • GDPR framework implementation support
  • Outsourced Data Protection Officer Services (DPO)
  • Data Protection Impact Assessments (Review & Completion)
  • Data Flow Mapping
  • Supplier Assurance Frameworks
  • Policy and procedure writing
  • Training and awareness (online and face to face)

We hope you have enjoyed this months data protection news roundup. For more information on any of the above, please email us at info@istormsolutions.co.uk or call +44 (0) 1789 608708.