Privacy & Data Protection Journal - Back Issues

PDP Journals Back Issues

Privacy & Data Protection

This page sets out the subject matter of the main articles in each edition of Privacy & Data Protection journal to date. To search for a specific word/subject on this page, click Ctrl+F on the keyboard.

Back issues of Privacy & Data Protection journal are £130.00 each for the electronic version (PDF format).

To purchase a copy of any journal back issues simply send us an email detailing your order or call our Journal Subscriptions department on: +44 (0)207 014 3399.

June 2026

Volume 26,

Issue 6

View PDF Cover

News Items

  • King’s Speech signals growing focus on digital identity and cyber resilience
  • ICO issues near £1m fine following ransomware attack on South Staffordshire companies
  • Irish DPC launches Shein China transfer probe
  • New DUAA complaints procedures: implementation expectations for organisations

Articles

  • Expert Comment — Bridget Treacy, Tamarillo Consulting
  • Mind the gap: collective actions and damages under UK GDPR — Joanne Elieli and Doug Henderson, Stephenson Harwood LLP
  • List of monetary penalties levied by UK Information Commissioner — PDP News Team
  • Facial recognition, proportionality and Article 8 — Ashley Roughton, Barrister
  • Australia’s privacy reforms and the path to global alignment — Sarah Birkett and Clarissa Kwee, DLA Piper Australia

April/May 2026

Volume 26,

Issue 5

View PDF Cover

News Items

  • ICO issues open letter to platforms on strengthening age assurance
  • Joint ICO and Ofcom statement on age assurance and privacy compliance
  • Luxembourg Court overturns €746m Amazon GDPR fine
  • Data protection needs to be central to use of facial recognition technology, says regulator

Articles

  • Expert Comment — Bridget Treacy, Tamarillo Consulting
  • Not such a modest duty: why the new DUAA complaints regime deserves attention — Kate Brimsted, Shoosmiths LLP
  • Agentic AI and data protection: navigating the ICO’s recent ‘Tech Futures’ report — Emma Erskine-Fox and Olympia Critchley, TLT LLP
  • The CJEU in Russmedia: much ado about nothing new? — Sophie Stalla-Bourdillon and Aleksandra Kuczerawy, Brussels Privacy Hub and Centre for IT & IP Law
  • Transparency in 2026: why many organisations should revisit their privacy notices — Duc Tran, Herbert Smith Freehills Kramer
  • Tensions, tariffs, trust and technology — Carolyn Bigg, DLA Piper

March 2026

Volume 26,

Issue 4

View PDF Cover

News items:

  • Major DUAA provisions enter into force
  • ICO issues raft of updated guidance
  • Latest GDPR and UK GDPR fines

Articles:

  • Expert Comment – Bridget Treacy, Tamarillo Consulting
  • From adequacy to TRAs: Decoding the ICO’s latest international transfers guidance – Tim Hickman and Joe Devine, White & Case
  • Navigating compliance with children’s data protection requirements in the EU and UK – Jonathan Wright and Ashley Webber, Hunton
  • Adequacy maintained: The Commission’s assessment of UK data protection, post-DUAA – Dr Karen Mc Cullagh, University of East Anglia
  • DSARs in 2026: How UK organisations are getting caught out – Ann Bevitt, Cooley
  • Ultimate transparency – growing data protection filing requirements in Asia – Carolyn Bigg, DLA Piper

January/February 2026

Volume 26,

Issue 3

View PDF Cover

News Items

  • Latest UK GDPR and GDPR fines
  • Cyberattack takes France’s postal and banking services offline before Christmas
  • Nomad faces FTC action after $186m hack

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • A new cyber order: inside the UK’s Cyber Security and Resilience Bill – Pilar Arzuaga, Will & Schulte
  • Redrawing the line between the DSA and GDPR/UK GDPR: a critical look at the EDPB’s new guidelines – Hannah Perry, Mason Hayes & Curran
  • The EU Data Act — what does it mean for controllers? – Sarah O’Brien and Alison Llewellyn, Stephenson Harwood
  • AI governance: embracing the opportunities and challenges posed by democratisation and agentic AI – Emma Keeling and Steve Wood, A&O Shearman

December 2025

Volume 26,

Issue 2

View PDF Cover

News Items

  • Latest GDPR and UK GDPR fines
  • UK GDPR now confirmed to apply to overseas providers
  • Civil liberties groups demand inquiry into ICO

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • ‘Consent or pay’: recent developments – Gareth Oldale, TLT LLP
  • Data protection complaints — what’s new? – Lorna Cropper, Fieldfisher
  • Déjà vu in data protection law: the risks of rewriting what counts as personal data – Sophie Stalla-Bourdillon, Brussels Privacy Hub
  • Best practice for use of biometric recognition and facial recognition technology in schools and colleges – Dr Claire Bessant, Northumbria Law School

October/November 2025

Volume 26,

Issue 1

View PDF Cover

News Items

  • Latest GDPR fines
  • Germany launches sovereign AI initiative with OpenAI
  • ICO continues to investigate social media platform following UK exit

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • From reactive to proactive: will the DUAA’s new internal complaints procedure requirement shift power back to controllers – Emma Erskine-Fox and Olympia Critchley, TLT LLP
  • Between nuance and caution: how to apply the CJEU’s judgment in EDPS v SRB – Sophie Stalla-Bourdillon, Brussels Privacy Hub
  • Criminal prosecution for obstructing a SAR: when failing to comply becomes a criminal offence – Alison Llewellyn, Katie Hewson and Doug Henderson, Stephenson Harwood LLP
  • Living in a (non-)material world — the impact of Farley v Paymaster on GDPR damages claims – Ann Bevitt, Cooley

September 2025

Volume 25,

Issue 8

View PDF Cover

News Items

  • Landmark ruling on ‘special purposes’ exemption in UK
  • DUAA’s initial provisions enter into force
  • Afghan data breach triggers major class action

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • Joint controller relationships: when they arise and why organisations continue to avoid them – Duc Tran and Tom Cadman, Herbert Smith Freehills Kramer LLP
  • On the frictions between the GDPR and the Data Act: a closer look at the Hamburg SA’s position paper – Sophie Stalla-Bourdillon and Barbara da Rosa Lazarotto, Brussels Privacy Hub
  • The age of agency: the powers and perils of agentic AI – Sandy Tsakirindi, Coca Cola Company

July/August 2025

Volume 25,

Issue 7

View PDF Cover

News Items

  • Data protection claim over personal injury clients is abusive, High Court hears
  • 16 billion passwords exposed in recordbreaking data breach
  • Civil society urges EU to reassess Isreal’s adequacy status

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • UK data reforms and post-Brexit drift: a widening gulf, or still close friends? – Kate Brimsted and Alice Wallbank, Shoosmiths LLP
  • Face-off: the intersection between biometric technologies and data protection law – Rebecca Morgan, Jade Kowalski and Peter Given, DAC Beachcroft
  • euIDK? The EU’s age assurance plan has some growing up to do – Hannah Perry, Mason Hayes & Curran
  • Employees and data protection — taking responsibility – Vicki Bowles, Bevan Brittan
  • Guidelines for the responsible use of AI in the public sector – Maureen Daly, Pinsent Masons

June 2025

Volume 25,

Issue 6

View PDF Cover

News Items

  • Irish regulator launches investigation into X’s use of EU data to train Grok AI
  • Latest GDPR/ UK GDPR fines
  • EDPB releases guidelines on blockchain

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • The state of pseudoanonymisation in the EU – Sophie Stalla-Bourdillon, Brussels Privacy Hub
  • The Data Use and Access Bill (Part 3) — comparing it with the DPDI Bill – Alison Llewellyn and Katie Hewson, Stephenson Harwood
  • The EDPB’s Opinion on AI Models: towards a principle-based approach to innovation? – Sophie Stalla-Bourdillon, Brussels Privacy Hub and Alfred Rossi, Immuta

April/May 2025

Volume 25,

Issue 5

View PDF Cover

News Items

  • Tribunal starts hearing Apple case in private
  • New Code on AI and cyber security
  • UK users may get ‘pay or consent’ after Meta agrees to stop tracking UK user

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • The Data Use and Access Bill (Part 2) — smart data and digital ID verification – by Katie Hewson and Joanne Elieli, Stephenson Harwood,
  • The AI-vengers: age of the LLM – Alastair Edmonson and Sol Pearson, TLT
  • Subject access rights and the scope of personal data – Ashley Roughton, Barrister

March 2025

Volume 25,

Issue 4

View PDF Cover

News Items

  • Revised data protection fees in UK
  • EDPB reports on right of access (coordinated enforcement topic)
  • ICO on watch for inaccurate AI-generated chat summaries based on personal data
  • ICO’s public sector approach to become standard

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • The Data Use and Access Bill (Part 1) — what are the changes, and how will it be enforced?, Katie Hewson and Joanne Elieli, Stephenson Harwood
  • ‘Consent or pay’: examining the ICO’s guidance – Bridget Treacy, Tamarillo Consulting
  • AI in recruitment: insights from the ICO’s Audit Outcomes Report – Emma Erskine-Fox, TLT –
  • A gamble with consent – Ashley Roughton, Barrister

January/February 2025

Volume 25,

Issue 3

View PDF Cover

News Items

  • ICO’s public sector approach to become standard
  • Fingerprinting not a fair means of tracking users online, says regulator
  • Ryanair faces further GDPR complaint over face-scanning verification
  • Brazilian regulator launches calls for views on AI, and acts against TikTok

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • The devil’s in the detail: the LPP exemption to the Right of Access – Olivia Whitcroft, OBEP
  • Down the Sub-processor rabbit hole – Alastair Edmonson, TLT LLP
  • The EDPB’s Opinion on AI models – what now?! – Hannah Perry, Mason Hayes & Curran
  • GDPR, AI and HR: a guide to compliance for HR professionals – Ann Bevitt, Cooley LLP
  • The Prismall case – more bad news for class action claims – Ashley Roughton

December 2024

Volume 25,

Issue 2

View PDF Cover

News Items

  • UK government’s new Data Use and Access Bill is broad in scope
  • ICO makes series of recommendations on AI to recruiters
  • New framework helps organisations assess their data protection compliance
  • EDPB adopts Opinion on relationship between controllers and their processors/sub-processors

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • What are the implications of the ICO’s first processor fine under the UK GDPR – Duc Tran, Of Counsel and Kamilla Khairul Anuar, Herbert Smith Freehills LLP
  • Recent CJEU decisions – Emma Erskine-Fox and Flora Ragless-Green, TLT LLP
  • Back to Basics – DSARs: Navigating the pitfalls and ensuring compliance – Rachael Perry, Bevan Brittan LLP
  • Ensuring data protection, security and AI ethics in AI Systems – Hamsa Hassan and Dr Hussain Aldawood, NEOM and University of Newcastle Australia and World Economic Forum
  • Identifiability – DSG v IC considered – Ashley Roughton

October/November 2024

Volume 25,

Issue 1

View PDF Cover

News Items

  • Protecting children from online harms remains priority, says ICO
  • Cookie crackdown continues in earnest
  • IBM report reveals average cost of a data breach in 2024
  • UK signs Council of Europe treaty on AI risks

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • Processing Biometric Data in the Workplace – Tim Hickman, White & Case LLP
  • The Problem with Data Sharing – Eleonor Duhs, Bates Wells
  • The Evolving Personal Data Breach Notification Regime in the EU – Adam Finlay, McCann FitzGerald
  • The European Commission’s Second Report on the GDPR – Hannah Perry, Mason Hayes & Curran

September 2024

Volume 24,

Issue 8

View PDF Cover

News Items

  • Government unveils vision for cyber security, data protection and AI
  • ICO acts against platforms to improve children’s privacy practices
  • EU AI Act now in force and Commission consults on
    Code of Practice
  • ICO reprimands Electoral Commission

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • UK GDPR compliant school social media use — recommended guidance – Claire Bessant, Northumbria University, School of Law
  • Access rights: GDPR vs the EU Data Act – Katie Hewson and Sarah O’Brien, Stephenson Harwood LLP
  • Safeguarding Critical Infrastructure and Digital Services — recent UK and EU developments – Peter Warcup and Nina Lazic, Osborne Clark LLP

July/August 2024

Volume 24,

Issue 7

View PDF Cover

News Items

  • Data Protection and Digital Information Bill – future unknown
  • ICO reviews public sector approach trial
  • ICO to investigate 23andMe data breach with Canadian regulator
  • Meta halts AI rollout in UK and Europe

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • Learning from the (security) mistakes of others – Peter Given, DAC Beachcroft LLP
  • Emerging approaches to the regulation and enforcement of AI use (a UK perspective) – Gareth Oldale and Emily Holdsworth, TLT LLP
  • DPIAs – how to avoid ‘box ticking’ mentality – Rachael Perry, Bevan Brittan LLP
  • The EU AI Act’s Enforcement provisions – Part 3 – Tim Hickman and Aishwarya Jha, White & Case LLP
  • ‘Impressions’ from inaccurate data – a case of interest – Ashley Roughton

June 2024

Volume 24,

Issue 6

View PDF Cover

News Items

  • Organisations need to do more to prevent cyber attacks, says ICO
  • Generative AI, fourth call for evidence
  • EDPB Adopts Opinion on facial recognition in airports
  • ICO outlines Strategic Approach to regulating AI

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • Pay or OK? ‘No way, not today’, says the EDPB (well, sort of) – Emma Erskine-Fox, TLT LLP
  • Legitimate Interests and the Right to Object in the context of AI training models – Hannah Perry, Mason Hayes & Curran
  • The EU Digital Operational Resilience Act – what is it and what to do now – Peter Given, DAC Beachcroft LLP
  • The EU AI Act (Part 2) – Tim Hickman and Thomas Harper, White & Case LLP
  • Health bodies and processing that is in the ‘public interest’ – finally, a case! – Ashley Roughton

April/May 2024

Volume 24,

Issue 5

View PDF Cover

News Items

  • New detailed fining guidance in UK
  • ICO seeks clarity on ‘pay or okay’ model
  • Regulator planning to continue cookie crackdown
  • EU strikes deal on European Health Data Space

Articles

  • Expert comment – Bridget Treacy, Tamarillo Consulting
  • Are you afraid of the dark? Protecting children from the harms of dark patterns – Karishma Brahmbhatt and Steve Wood, Allen & Overy
  • Online safety and data protection: where the two meet – Matthew MacLachlan, Shoosmiths
  • CJEU confirms the broad definition of ‘personal data’ and ‘joint controllership’ – but how long’s a piece of (TC) String? – Georgia Philippou and Emma Erskine-Fox, TLT LLP
  • The EU AI Act (Part 1) – Tm Hickman and Aishwarya Jha, White & Case LLP

March 2024

Volume 24,

Issue 4

View PDF Cover

News Items

  • Lack of staff training at fault in
    police body breach
  • Home Office’s electronic monitoring of
    migrants deemed overly intrusive
  • Updated Opinion on age
    assurance
  • content moderation technologies
    and processes

Articles

  • Is applying for EU and UK Binding Corporate Rules becoming easier? – Nuria Pastor and Anna Rawlinson, Fieldfisher
  • ICO’s second Tech Horizons report: what does it tell us? – Sarah O’Brien, Stephenson Harwood LLP
  • The ICO’s Consultation on Generative AI: plugging the regulatory gap – Andrew Kimble, Jenny Gibbs, Jess Mant and Katie Simmonds, Womble Bond Dickinson
  • The notion of Main Establishment – the EDPB’s new Opinion – Hannah Perry, Mason Hayes and Curran

January/February 2024

Volume 24,

Issue 3

View PDF Cover

News Items

  • EU court lowers requirements for imposing fines for breaches
  • Police breach a result of outdated approach, review finds
  • EU approves Data Act
  • G7 publishes code of conduct on AI

Articles

  • Fundamental changes to the UK GDPR – what they mean in practice – Elearnor Duhs, Bates Wells
  • What are the implications of Clearview AI’s win? – Katie Hewson, Daniel Jones and Nelson Kiu, Stephenson Harwood LLP
  • Anonymisation through separation: what recent cases teach us about the EU’s anonymisation standards – Lore Leitner, Gabe Maldoff and Mickey Lee, Goodwin
  • The Online Safety Act 2023 – what to do now – Matthew MacLachlan, Shoosmiths

December 2023

Volume 24,

Issue 2

View PDF Cover

News Items

  • ‘Christmas Tree’ Data Bill moved forward in UK Parliament
  • How the ICO will fine – new draft guidance
  • Clearview AI successfully overturns ICO fine; ICO to appeal
  • UK holds AI Safety Summit

Articles

  • The New Guidance on Workplace Monitoring – Ann Bevitt, Cooley LLP
  • Data Scraping and Data Protection – Key Things to Consider – Duc Tran, Of Counsel and Erin Bibb, Herbert Smith Freehills LLP
  • The UK-US Data Bridge – advantages and challenges – Sharon Lamb, Pilar Arzuaga and Michaela Novakova, McDermott Will & Emery UK LLP
  • Higher fines through the back door – Ellis Parry, Data Privacy Compliance Solutions Limited

October/November 2023

Volume 24,

Issue 1

View PDF Cover

News Items

  • UK-US Data Bridge approved
  • Sending bulk communications by email – new guidance
  • Norway to extend ban on Meta’s tracking ads without consent
  • Poland opens privacy probe of ChatGPT
  • Share information to protect children, says ICO

Articles

  • Implementing AI – what you need to know – Stephanie Pritchett and Ben Wootton, Pritchetts Law LLP
  • Subtle but helpful – changes to the right of access under DPDI 2 – Olivia Whitcroft, OBEP
  • The ICO’s draft Biometric Data Guidance – what it means for you – Emma Erskine-Fox, TLT LLP
  • Assessing the Assessments – Robert Bond

November/December 2023

Volume 12,

Issue 6

View PDF Cover

News Items

  • Crypto exchange Binance pays $4bn in money laundering fines
  • Advertising Standards Agency bans Toyota ad on environmental grounds
  • Information Commissioner warns UK’s top websites to make cookie changes
  • Iceland’s full-day women’s strike aims to close pay gap
  • European Parliament adopts Data Act

Articles

  • Next steps for diversity and inclusion in financial services: FCA and PRA proposals – Monicia Kurnatowska, Zelander Gray, Rachel Farr, Kimberly Everitt, Baker & McKenzie LLP
  • Don’t wait until it’s too late: will regulators in the UK and across Europe follow the US Securities and Exchange Commission’s lead? – Nicholas Thorpe, Richard BRanson and Abbie Griffiths, Fieldfisher LLP
  • A new frontier of corporate sustainability reporting – John Aherne and Nessa Joyce, William Fry LLP

September 2023

Volume 23,

Issue 8

View PDF Cover

News Items

  • Europe adopts adequacy decision on EU-US Framework
  • PSNI data breach: review launched
  • European Parliament and Council release agreed text on Data Act
  • UK government announces proposed ban on financial cold callers
  • UK escalates inquiry into how to regulate AI

Articles

  • Harmful design in digital markets — key do’s and don’ts – Bridget Treacy
  • Cybersecurity Standards and Certifications – what’s the right fit? – Nick Soni, CyberStreet
  • International data transfers — the new ‘normal’- Liz Fitzsimons, Eversheds Sutherland
  • Damages for actions for breach of privacy or misuse of data – the Yao case – Ashley Roughton

Request your FREE sample of Privacy & Data Protection

Journal Testimonials

“I find it a good way of keeping up to date with industry thinking. The “News & Views” section is particularly interesting, as are the major articles on the new DP regime changes.”

Carolyn Webb
Cancer Research UK

“The journal provides insightful, well written articles covering key legislative areas and changes. In my view, it is an essential tool for any data protection practitioner”

Michael Lewis
The Admiral Group

"The journal is fantastic.– clarity, simplicity, patience and authority. Cannot ask for more!"

Jigna Patel
British Safety Council

"The articles are well researched and written, and cover relevant topics."

Victoria Ferguson
Dickinson Dees

"I think the format is excellent and is the best Data Protection Journal around and I have been a subscriber for many years. Keep up the good work!"

Doreen Broom
Scottish Borders Council

"We have subscribed to Privacy and Data Protection journal for several years now and find it a valuable source of information to assist us in our work."

Claire Robson LLM
Kent & Medway NHS Trust

"The journal is excellent as it is informative, very practical and provides in depth updates, all of which are essential when abiding by Data Protection and Privacy Legislation."

Diane Gore
RSPB

“Privacy & Data Protection is an essential tool. The articles are both informative and extremely well written. Along with its sister email update, Compliance News from PDP, I have a summary of legislation changes, compliance updates and enforcement action at my fingertips. They enable me to give timely advice to managers and employees, ensuring we remain compliant. I can’t image working without them.”

David Taylor
Northampton Borough Council