Regulatory Outlook

Data law | UK Regulatory Outlook July 2026

Published on 29th July 2026

UK updates: Government launches calls for evidence on data regulation and AI, and on international data transfers | Government launches call for evidence on smart data schemes | ICO consults on the corporate strategy | ICO reviews data protection practices of edtech providers | EU updates: EDPB adopts guidelines on AI web scraping, anonymisation and blockchain  

UK updates 

Government launches calls for evidence on data regulation and AI, and on international data transfers 

The government's recent calls for evidence suggest that, following the major reforms introduced by the Data (Use and Access) Act 2025, further reform of data regulation may be on the horizon.  

On 15 July 2025, the government under Sir Keir Starmer launched a call for evidence seeking practical examples of how personal and non-personal data regulation interacts with AI and other data-intensive technologies, as well as insights into how technological progress may change the way data is used in the economy. It stated that responses would inform the assessment of whether further guidance, targeted changes or more fundamental reform were needed to ensure that "regulatory frameworks remain fit for this technological age". However, it is unclear whether the new government under Andy Burnham will pursue this further. 

In a separate call for evidence, Sir Keir's government sought views on whether the UK's data regime was enabling trusted data flows. In particular, it sought to understand whether the UK's approach to international data transfers is as effective as it could be, where it should preserve the current system, and which aspects are most suitable for reform. The call invited stakeholders to share evidence and real-world experience to inform future policy development. Similarly, it is not clear which direction the new government will take. 

Both calls for evidence close on 9 September.  

Government launches call for evidence on smart data schemes 

The government, under Sir Keir Starmer's leadership, launched a multi-sector call for evidence on smart data schemes, covering property, retail, agrifood, transport and trade. This follows its publication of the smart data strategy in March, which set targets of five or more active schemes by 2030 and 20 or more by 2035. The Data (Use and Access) Act 2025 provided the statutory framework for smart data schemes across sectors. It gives the secretary of state and the Treasury powers to introduce legal requirements for the creation and governance of such schemes via secondary legislation.  

The government is now considering how smart data schemes should be prioritised, designed and delivered in practice. This signals a shift from strategy to delivery.  

ICO consults on the corporate strategy 

The Information Commissioner's Office (ICO) has published its draft corporate strategy for consultation. The strategy aims to "provide a bridge" from the ICO's current approach to its future Information Commission governance model. It covers a two-year period from 2026 to 2028, and the transition to the new model is anticipated in the autumn of this year. 

The draft strategy states that the ICO will focus its regulatory effort on areas of highest risk and systemic importance and invest proportionately fewer resources in routine or lower-risk work. The ICO also intends to focus its intervention on the cases that present the greatest harm or systemic risk and will use the broader range of complaints, reports and intelligence to identify trends. 

This echoes the ICO's previously published framework on how it handles data protection complaints, in which the regulator noted that it cannot take regulatory action on every complaint – it aims to focus resources on cases where it can have the biggest impact. In February, the ICO published guidance explaining data protection complaints requirements

The ICO's four regulatory priorities are: protecting children, promoting trust and transparency in AI, improving public services' use of personal data and building cyber resilience. The draft states that the ICO will focus supervision on those entities and activities that align most closely with these priorities. The ICO also intends to increase its use of AI and data analytics to improve how it regulates. 

The consultation closes on 23 August. 

ICO reviews data protection practices of edtech providers  

The ICO has published a report setting out its engagement with educational technology (edtech) providers to review and improve data protection practices within the sector. It details the findings from audits carried out during 2024 and 2025 with 28 edtech providers, whose products are widely used across primary and secondary schools in the UK. The audits covered management information systems, safeguarding tools, behaviour management platforms, learning management systems, classroom apps and data integration services. 
 
The ICO found positive practices, particularly around information security. However, common compliance gaps across the sector included providers not correctly identifying whether they were acting as data processors or controllers, insufficiently detailed contracts with schools, incomplete data flow mapping, weak application of data minimisation and storage limitation principles, outdated or inaccessible privacy information, and gaps in data protection impact assessments. The ICO states that providers accepted and implemented most of the recommendations it made. 

EU updates 

EDPB adopts guidelines on AI web scraping, anonymisation and blockchain  

The European Data Protection Board (EDPB) has adopted guidelines on web scraping in the context of training generative AI. Web scraping is a widely used technique for extracting large amounts of data from publicly available web services. The EU General Data Protection Regulation (GDPR) applies to web scraping that involves personal data processing operations, such as collection, storage, organisation and retrieval. The guidelines clarify various aspects of EU GDPR compliance in relation to web scraping, including the legal basis for such activities and the conditions under which special categories of data may be processed in this context. 

The EDPB has also adopted guidelines on anonymisation providing a "practical framework for determining whether data has been successfully anonymised".  

Both guidelines are open for consultation until 30 October.  

Following consultation, the EDPB has adopted the final version of its guidelines on the processing of personal data through blockchain technologies, which set out key EU GDPR compliance considerations for planned processing activities. The guidelines provide an overview of the fundamental principles of the technology, assess the different possible architectures and their implications for the processing of personal data, and highlight that the roles and responsibilities of different actors in blockchain-related processing must be assessed at the design stage, including what elements need to be considered. 

View the full Regulatory Outlook

Interested in hearing more? Read all the articles in our Regulatory Outlook series

Expand
Receive Regulatory Outlook each month

A round-up of upcoming regulatory developments – straight to your inbox

* This article is current as of the date of its publication and does not necessarily reflect the present state of the law or relevant regulation.

Interested in hearing more from Osborne Clarke?