Summer 2026 Enforcement Activities - Lessons Learned
17 August 2026
Enforcement activity is a useful reminder that data protection compliance is not about having policies on paper. It is about being able to demonstrate that the right things are happening in practice.
Looking across recent enforcement activity, several practical lessons stand out, providing valuable insights for those using personal information to review, reflect and update their own practices.
1. Accountability cannot be delegated
Take ownership of the personal information processed.
That means knowing what information is held, why it was collected and how it is being used. Personal information should not simply be repurposed because it is available. Any new use needs to be properly considered against the purpose for which the information was originally collected.
The lesson: know your data, know why you have it and know why you are using it.
Read our Principles and Lawful Bases guidance here
2. Be ready for a Subject Access Request
A Subject Access Request (SAR) is not the time to start working out who does what. Have a clear, workable procedure and trained staff who understand the requirements—including time limits, exemptions, searches, review and the release of appropriate information.
The lesson: your SAR process needs to work before you receive a SAR.
Read our Subject Access Request guidance here
3. Make sure your Privacy Notice reflects reality
A Privacy Notice is only useful if it accurately describes what actually happens with personal information. Processing changes. Systems change. Suppliers change. Business models change. Privacy Notices need to change with them.
The lesson: regularly check your Privacy Notice against your actual processing activities. If they do not match, fix it. But be transparent with your customers, team members or suppliers about the changes, and above all keep it simple. Privacy notices should be short and easy to read, not long and overly legalistic.
Read our Privacy Notice guidance here
4. Policies must work beyond the filing cabinet
A documented data protection policy is only the starting point.
Policies and procedures need to be effective, communicated to staff and supported by appropriate training. Enforcement activity can expose the gap between what an organisation says its staff should do and what actually happens.
The lesson: do not just ask whether you have a policy. Check whether people know it, understand it and follow it. Any policy is not worth writing if it hasn’t been tested.
5. If you rely on consent, prove it
Consent should not be treated as a tick-box exercise. Where consent is the chosen lawful basis, ensure there is a clear process for deciding when it is required, obtaining it, recording it and reviewing it where appropriate. Staff involved in obtaining consent need to understand what they are doing and what needs to be documented. Ensure you can demonstrate that anyone giving consent was aware of what they were giving consent for.
The lesson: if you rely on consent, you should be able to demonstrate the consent and the process behind it. Remember, it needs to be freely given and can be withdrawn, so if you can, rely on a different or more appropriate legal basis.
Read our Principles and Lawful Bases guidance here
6. Know when to let personal information go
Data protection does not end when information has been collected and used. It also requires consideration of what happens when information is no longer needed. A clear disposal policy and procedure should cover personal information in every relevant format, from paper records to emails, databases and electronic files.
The lesson: have a clear answer to both when information should be disposed of and how it will be securely disposed of. Implement the process and check it is happening.
Read our Data Controller & Processor Duties guidance here
7. Keep control of your processors
Using an outsourced third party to process personal information does not remove the need for proper oversight. Responsibility remains with the data controller. Where a data processor is engaged, an appropriate contract should clearly set out the processing activities, responsibilities and obligations of the parties.
The lesson: understand what your processors are doing, and make sure your contracts properly reflect it. Also undertake a level of due diligence and check they are appropriately registered before sharing any personal information.
Access our Appointing a Data Processor guidance here
The common theme: can you demonstrate it?
Perhaps the most important lesson from enforcement activity is that saying you comply is not the same as demonstrating compliance.
You should be able to evidence your approach - from the purpose for processing personal information, through to handling Subject Access Requests, maintaining accurate Privacy Notices, training staff, recording consent, disposing of information and managing processors. But again, keep it simple and proportionate to the size of your organisation and the nature of the data you are holding.
Enforcement activity gives those using personal information an opportunity to learn without having to do so the hard way.
The question is not simply, “Do we have the right arrangements in place?” It is, “Can we demonstrate that they work?”