Hawktalk

“Legitimate Interests” for AI Training? Remember the common law of confidence.

There is a current debate as to whether “legitimate interests” can be reliably used as a lawful basis by a controller when using personal data to train/test AI algorithms/systems and when AI systems are deployed. This blog explains how the common law of confidence and two recent CJEU decisions work together to challenge this assumption. The first half of the blog explains why “legitimate interests” can work as a lawful basis for AI training/testing in some instances.  In the second

Read article

What are the main features of the Data (Use and Access) Bill?

The blog concerns the content of the new  Data (Use and Access) Bill (DUAB) as published last week; it bears a strong relationship with the previous Data Protection and Digital Information (DPDI) Bills.  In fact, DUAB could easily have been named the DPDI (No 3) Bill. The Bill itself is 138 Clauses, 16 Schedules and 251 pages; many of the provisions of DPDI re-appear in DUAB but with different Clause numbers. The Bill is a complex read as its data

Read article

Upper Tribunal undermines data breach reporting under the UK_GDPR?

The Upper Tribunal (UT) appeal [DSG Retail Limited -v- ICO; see references] is important even though it relates to the DPA1998; the judgement has the potential to undermine the data breach reporting requirements of the UK_GDPR/DPA2018. This blog explains why this is the case, why legislative changes might prove to be necessary and, for good measure, provides details of two errors in the UT’s analysis. The appeal concerns the meaning of “personal data” in the context of the security obligations

Read article

Data protection policy should return to the Ministry of Justice

The incoming Labour Government has expanded the role of the Department for Science, Industry and Technology (DSIT) by transferring many IT/data related functions from other parts of Government (mainly the Cabinet Office) into DSIT.  The objective is to make DSIT an important driver for economic growth. In further detail, “experts in data, digital and AI from the Government Digital Service (GDS), the Central Digital and Data Office (CDDO) and the Incubator for AI (i.AI) [have transferred to DSIT] to unite

Read article

New A.17 right to erasure in the UK_GDPR added during “wash-up”

Although the DPDI Bill is dead, you have probably missed the addition to the right to erasure (Article 17 of the UK_GDPR) which was made during “wash-up” period (last month) via another piece of legislation (the Victims and Prisoners Act ["VPA"] 2024). In summary, the change in the law concerns what controllers do when there is a malicious complaint (e.g. to social services) and the procedure for removing that complaint, following the conviction of the complainant of a stalking or harassment

Read article

Labour should not let the DPDI Bill go through in “wash-up”; it should kill it off.

When a Prime Minister calls a General Election, the Official Opposition in Parliament becomes very powerful.  The reason is that the two main political parties can agree to enact outstanding and uncontroversial pieces of legislation (e.g. in this case, before the end of next week – May 30th).  Parts of the DPDI Bill do fall into this uncontroversial category; but many bits don’t. In summary, the Opposition can say to Government something like; “we will agree to pass the DPDI

Read article
Search Hawktalk blogs by month :
Select Date
View blogs by category:
Hawktalk Taxonomy
Upcoming courses:
2 February – 6 February 2026
13 April – 17 April 2026
24 March – 26 March 2026
15 June – 17 June 2026

Workshop: Thursday 20 Nov

Cartoon: