A Mid-Year Snapshot of EU and UK Data Protection Trends
A new mid-year review from international law firm Finnegan, Henderson, Farabow, Garrett & Dunner has pulled together a series of significant decisions issued across the EU and UK this year, offering fresh guidance on how regulators and courts are interpreting core data protection principles. The report focuses on three recurring themes: how organizations obtain and document consent, how data subjects can exercise their rights, and the rules governing when personal data can be published.
While the review is written primarily for businesses and legal practitioners, it offers a useful signal for everyday internet users too. EU and UK data protection law rarely changes through a single dramatic reform. Instead, it evolves through a steady accumulation of court rulings, regulatory guidance, and enforcement actions that gradually reshape what companies are allowed to do with personal information. This mid-year update is essentially a checkpoint on that ongoing evolution.
Consent, Data Subject Rights, and Publication Rules Take Center Stage
According to the review, consent remains one of the most contested areas of data protection compliance. Regulators and courts continue to scrutinize whether consent mechanisms are genuinely informed, freely given, and specific enough to meet GDPR and UK GDPR standards. This is a theme that has played out repeatedly in enforcement actions across Europe, where authorities have pushed back against consent flows that bury key disclosures in dense terms or default users into data sharing they never actively agreed to.
Data subject rights, including the ability to access, correct, or request deletion of personal information, also feature prominently in the update. These rights are the practical mechanism by which individuals can find out what data companies hold on them and push back when that data is inaccurate or excessive. The review's attention to this area suggests courts are continuing to refine exactly how far these rights extend and how quickly organizations must respond.
The third theme, the publication of personal data, speaks to a growing area of legal uncertainty: when is it lawful for an organization, a public body, or even an individual to make someone's personal information public? This question has become increasingly relevant as facial recognition, biometric tracking, and location data collection expand into public and semi-public spaces.
Real-World Enforcement Already Reflects These Trends
The themes highlighted in this mid-year update are not abstract. They are already playing out in concrete enforcement actions across Europe and the UK. In Italy, the Garante fined banking app providers after finding invasive device-monitoring tools embedded inside their applications, a case that turned heavily on questions of consent and whether users genuinely understood what data was being collected. Meanwhile, Italy's approach to storing facial biometric data from public cameras has reignited debate over how long sensitive personal data can be retained and under what legal basis.
In the UK, a similar tension has surfaced around the use of facial recognition vans in public spaces, where questions about transparency and public notice echo the publication and data subject rights issues flagged in the Finnegan review. Regulators are also examining how platforms verify user identity and age, as seen in Ofcom's investigation into TikTok's age-inference system, which touches directly on consent and the appropriate handling of biometric data used to make automated decisions about users.
What This Means For You
If you use apps, browse the web, or interact with public-facing technology like facial recognition cameras in the EU or UK, these developments matter more than the legal language might suggest. Stronger interpretation of consent rules means companies are under growing pressure to make data collection choices clearer and easier to refuse. Expanded data subject rights mean you have real, enforceable tools to ask a company what it knows about you and to demand corrections or deletion. And evolving publication rules mean regulators are actively working out the boundaries around biometric and location data collected in public spaces, an issue that affects anyone walking past a camera-equipped street or using an app that requests device permissions.
None of this requires panic. It reflects a legal system that is actively working, case by case, to keep pace with new technology.
Actionable Takeaways
Stay informed about how EU and UK data protection law is evolving by watching for regulatory guidance and enforcement decisions in your country. Read app permission requests and consent prompts carefully rather than accepting them by default. If you believe an organization holds inaccurate or excessive data about you, remember that data subject access requests are a legal right, not a favor. And keep an eye on how public facial recognition and biometric systems are regulated in your area, since this remains one of the most active and unsettled areas of EU and UK data protection law.




