Tech & Legal Updates
Short, executive-level legal and commercial updates for founders and leaders of scaling technology businesses.
Every update, by topic
Short briefings on the regulatory and commercial shifts affecting tech contracts, AI liability, privacy and data. Newest first, tap any card to read the full snippet.
Software renewals need a priced exit strategy
The CMA is investigating Microsoft’s business software ecosystem, including bundling, interoperability and Copilot, with evidence gathering scheduled through September 2026. No new contractual rights exist yet, so price your exit before you take a multi-year discount.
Read updateG-Cloud 15 changes how SaaS deals must be structured
The Government Commercial Agency has introduced G-Cloud 15 under the Procurement Act 2023. Its buying guidance states that core terms cannot be changed, so the entire commercial negotiation now happens in the order form and schedules.
Read updateSeparate AI permissions from ordinary content distribution
The CMA has imposed requirements giving publishers controls over Google’s use of their content for AI training and grounding, with a main compliance deadline of 3 December 2026. It covers Google’s designated services only, not a universal AI licensing regime.
Read updateAdvertising contracts must support children’s privacy settings
The ICO’s latest children’s strategy update flags continuing concerns about mobile games’ default privacy settings and ad profiling, with formal enforcement available where the law is breached. Any service children are likely to use falls inside scope.
Read updateMandatory fees need to be built into the pricing architecture
The CMA has opened an investigation into whether Trainline included mandatory fees in its headline price. No finding has been made, but drip pricing is now a live enforcement target well beyond travel and ticketing.
Read updateAn opt-out registry check does not establish marketing consent
South Africa’s Information Regulator has confirmed absence from the opt-out registry does not satisfy POPIA’s consent requirements. Two live enforcement referrals, against MTN and OUTsurance, show why this distinction matters now.
Read updateSupplier notification clauses must support ADGM reporting deadlines
ADGM’s cyber rules give regulated firms 24 hours to report a material incident. Most standard SaaS and IT supplier contracts were never written to make that deadline achievable.
Read updateTurn AI marketing promises into verifiable contractual commitments
The FTC finalised orders against Cox Media Group and two reseller firms over an AI advertising service that never used voice data as claimed. Reselling an unverified AI capability claim adds you to the liability, it does not remove it.
Read updateYour AI vendor said the training data was “properly licensed.” Prove it.
The FTC concluded three enforcement actions against AI model vendors who misrepresented training data sourcing. Vendor self-certification on training data is no longer contractually acceptable.
Read updateThe FCA just made vendor self-certification worthless
The Financial Conduct Authority published guidance on AI model risk management. The guidance applies to all FCA-regulated firms using generative AI models for customer-facing decisions.
Read updateSouth Africa just made AI disclosure mandatory in government bids
The Department of Public Works now requires all suppliers bidding on South African government contracts over R5 million to disclose any generative AI or algorithmic tools used in preparing tenders.
Read updateYour UAE cloud contract is missing audit rights
The UAE Telecommunications Regulatory Authority just made data localization verification a contractual obligation. Every cloud service agreement for UAE customers now needs explicit audit rights.
Read updateYour government contracts just got more transparent
The UK Government’s Digital, Science and Innovation Team has published binding guidance on AI use in government communications, requiring explicit disclosure, review cycles, and audit trails.
Read updateGovernment procurement AI just got auditable
The UK’s new Procurement Transparency Register requires government bodies to publish algorithm scoring frameworks within 20 days of contract award. Suppliers can now challenge the methodology.
Read updateYour SaaS renewal terms are about to get renegotiated
The CMA published findings on Microsoft 365 subscription practices, flagging auto-renewal defaults, opaque switching costs, and renewal terms that make exit materially harder than entry.
Read updateYour consultation responses aren’t confidential anymore
The UK DSIT has mandated that every government department deploy the Consult AI platform to analyse consultation responses, and departments must now publish their analytical methodology.
Read updateGetty v Stability AI puts AI copyright risk back into vendor contracts
The UK’s first major AI copyright ruling is under appeal, leaving model-training risk unsettled. Businesses licensing or embedding third-party AI should revisit IP warranties, training disclosures and infringement indemnities.
Read updateYour liability cap may not matter if the exclusion clause removes the claim first
EE v Virgin Mobile is a reminder that liability caps and exclusions do different jobs. SaaS, reseller and technology agreements should test profit and revenue exclusions against the remedies the business would actually need.
Read updateUK GDPR damages are heading to the Supreme Court
Farley v Paymaster puts the threshold for UK GDPR damages back in focus. The outcome could materially affect low-value claims brought at scale and the way controllers and processors negotiate data indemnities.
Read updateApple and Google could lose control over how UK developers steer customers to payment
The CMA is considering rules allowing UK developers to direct customers to off-platform purchasing options on fair and reasonable terms, putting platform fees, subscription economics and distribution contracts in play.
Read updateData complaints are becoming a contract issue, not just a privacy-team problem
New UK data-protection complaints requirements increase the operational burden on controllers. Existing DPAs should ensure processors escalate complaints quickly and provide the records and assistance needed to respond.
Read updateSouth Africa’s new direct-marketing regime reaches your CRM and supplier contracts
South Africa’s opt-out framework changes how businesses manage outbound marketing data. CRM processes, agencies, list providers and outsourced sales partners all need clear suppression and compliance responsibilities.
Read updateDIFC is moving AI governance from policy into the operating model
DIFC’s AI-native direction points to deeper AI governance, accountability and evidence requirements. Technology vendors selling into DIFC-regulated businesses should expect those controls to surface in procurement.
Read updateIf an AI system is deliberately steering its answers, the FTC wants users told
The FTC’s proposed policy on suppression of AI accuracy puts undisclosed output steering on the contract agenda. AI vendor warranties should address deliberate configuration choices, not only hallucinations, bias, IP and data breaches.
Read updateICO redesigns its Regulatory Sandbox for AI and emerging technology
The ICO is evolving its Regulatory Sandbox to match the scale and speed of AI development, moving beyond a handful of intensive engagements to multiple levels of support…
Read updateCMA investigates Microsoft over the marketing of Microsoft 365 subscription plans
The CMA has opened a consumer-protection investigation into whether Microsoft 365 customers received clear information about plan changes, including Copilot, before renewal…
Read updateCMA imposes conduct requirements on Google’s UK search services
Publisher, fair-ranking and data-portability requirements now apply to Google’s UK general search services following its strategic market status designation…
Read updateFTC acts against Hims & Hers over health-data sharing and subscription practices
The FTC and state partners allege sensitive health information was shared with advertising platforms, and that subscriptions were charged without express informed consent…
Read updateUK Government examines how data regulation interacts with AI
DSIT has opened a call for evidence on data regulation in the age of AI and other data-intensive technologies, open until 9 September 2026…
Read updateCMA Investigates Wayfair’s Use of Time-Limited Offers
The CMA has launched an inquiry into Wayfair’s use of time-limited offers, investigating potential consumer law violations. This impacts consumer…
Read updateUK’s Digital Standards Strategy to Shape AI Future
The UK’s Digital Standards Strategy outlines ambitious goals in AI, cybersecurity, and connectivity. Businesses engaged in AI development will need…
Read updateAI Tools to Enhance Planning Decisions in England
The UK government has unveiled AI tools to modernize the planning permission system, promoting efficiency. AI integration into public systems…
Read updateAI to Accelerate NHS Cancer Diagnostics
The UK invests in AI technologies to speed up cancer diagnosis within the NHS, promising shorter waiting times. Such advancements necessitate robust…
Read updateCMA Promotes Innovation in Digital Markets
The CMA is actively working to enhance competition in digital markets. This initiative could drive innovation, impacting platform-based business…
Read updateCMA Opens First Direct Enforcement Actions Under DMCCA Pricing Architecture Now a Board-Level Risk
The CMA has launched its first direct enforcement investigations under the DMCCA, targeting drip pricing, misleading urgency tactics, hidden fees…
Read updateCourt reinforces limits on exclusion of core contractual liability
UK court reinforces limits on liability clauses, showing that core service failures cannot be fully excluded contractually.
Read updateICO increases enforcement activity on data security failures
ICO enforcement on data security failures is increasing, elevating security into a commercial and contractual risk.
Read updateCMA increases scrutiny on subscription pricing and renewal practices
CMA scrutiny on SaaS pricing and renewals is increasing, exposing revenue models to regulatory and contractual risk.
Read updateInformation Regulator increases enforcement on direct marketing practices
POPIA enforcement on direct marketing is increasing, affecting outbound growth strategies and contractual data use obligations.
Read updateICO expands enforcement focus to biometric data in AI systems
ICO scrutiny on biometric AI systems is increasing, creating direct product, compliance, and contractual risk for SaaS businesses.
Read updateSouth Africa Updates Competition Rules for Digital Advertising
The Competition Commission of South Africa has revised competition rules affecting the digital advertising market. These changes necessitate…
Read updateFTC Data Enforcement and Adtech Contract Liability
FTC enforcement is reshaping how adtech businesses use data, forcing clearer contracts and stricter liability allocation.
Read updatePOPIA Enforcement and Data Processing Contract Risk
POPIA enforcement is increasing in South Africa, shifting risk into operator agreements, breach obligations, and cross-border controls.
Read updateCookie Compliance Risk and Adtech Contract Exposure
ICO enforcement on cookies is impacting adtech revenue models and forcing contract clarity across tracking, consent, and liability.
Read updateSaaS Procurement Risk and Exit Planning Requirements
Enterprise buyers are shifting SaaS procurement toward resilience, exit planning, and vendor risk. Contracts are now driving selection.
Read updateICO AI Training Data Compliance and Contract Risk
ICO guidance on AI training data is shifting risk into contracts. SaaS providers must now prove lawful data use and absorb liability.
Read updateUAE advances AI governance framework with operational compliance expectations
UAE AI policy sets out accountability, transparency, and human oversight principles. Businesses should reflect these in how AI systems are governed…
Read updatePOPIA sets conditions for cross-border data transfers
Cross-border data transfers under POPIA require adequate protection or enforceable contractual safeguards. Businesses must ensure data transfer…
Read updatePublic sector procurement rules tighten around technology supplier risk
Updated UK procurement guidance reinforces proportionate risk allocation, pricing discipline, and clear contractual responsibility across the supply…
Read updateLiability caps remain strictly enforced in commercial contracts
Courts continue to apply strict interpretation to liability caps. Clear drafting and appropriate carve-outs remain critical in SaaS agreements.
Read updateICO guidance sets expectations for AI training data use
AI training data must meet lawful basis, transparency, and purpose limitation requirements. Businesses must address data provenance and contractual…
Read updateUAE AI Governance Framework Raises Contractual Accountability for AI Deployment
The UAE National Artificial Intelligence Strategy introduces governance expectations for responsible AI deployment across sectors. Technology vendors…
Read updateGoogle Antitrust Judgment Reinforces Distribution and Default Placement Risk
A U.S. court ruling against Google highlights how exclusive distribution agreements and default placement arrangements can constitute exclusionary…
Read updateAutomated Decision Explanations Become a Legal Expectation in the EU
A CJEU ruling confirms that individuals affected by automated decisions must be able to understand and challenge how those decisions are made…
Read updateEU Data Act Expands Contract Risk Across Product and Cloud Services
The EU Data Act has applied since 12 September 2025, expanding user access rights to connected device data and strengthening switching rights between…
Read updatePlatform Dependency Is Emerging as a Commercial Negotiation Risk
The CMA’s digital markets regime is now active and the Google search SMS investigation shows how platform power is moving from policy debate into…
Read updateEU Strengthens Consumer Protection Rules for Digital Services
The European Union is expanding consumer protection rules affecting digital services and online platforms. Technology businesses must review…
Read updateDIFC Updates Data Protection Regulatory Framework
The Dubai International Financial Centre continues to refine its data protection regime. Technology firms operating in the DIFC must ensure…
Read updateEU Court Confirms Strict Consent Standards for Tracking Technologies
European court rulings continue to reinforce strict consent requirements for cookies and tracking technologies. Businesses must ensure consent is…
Read updateEU Digital Markets Act Enforcement Expands Platform Obligations
The European Commission is enforcing obligations on designated gatekeeper platforms under the Digital Markets Act. Technology platforms face new…
Read updateUK ICO Targets Cookie Compliance on Major Websites
The UK Information Commissioner’s Office has launched enforcement action focused on cookie consent practices. Advertising and data driven companies…
Read updateSouth Africa’s Information Regulator Tightens POPIA Enforcement
POPIA enforcement highlights direct marketing consent and documented security compliance duties.
Read updateADGM Data Protection Regime Demands Demonstrable Accountability
ADGM confirms GDPR-style accountability and governance expectations for controllers and processors.
Read updateSupreme Court Reinforces Strict Contract Interpretation
The UK Supreme Court confirms courts will not rewrite unclear drafting to achieve commercial fairness.
Read updateEU AI Act Introduces Direct Compliance Duties for Providers
The EU AI Act imposes binding governance, documentation, and monitoring obligations on high-risk AI providers.
Read updateCJEU Clarifies Limits on Data Use for Online Advertising
The CJEU confirms that cross-service data combination for advertising requires a valid GDPR basis and strict necessity assessment.
Read updatePOPIA Compliance and AI Deployment
POPIA continues to define the legal framework for AI and cross-border data use in South Africa, requiring structured compliance at architecture and…
Read updateAI Governance Direction in the UAE
The UAE AI Charter signals governance expectations that should now be reflected in contracts, procurement processes, and product oversight frameworks.
Read updateGDPR Compensation and Claimant Risk
The CJEU has clarified that GDPR compensation requires proven damage and causation, reshaping contractual risk allocation and incident documentation…
Read updateAdtech Transparency Under the Digital Services Act
The DSA introduces mandatory ad transparency and targeting restrictions, requiring structural changes to audience design, consent architecture, and…
Read updateDrip Pricing and Upfront Cost Disclosure
The CMA has tightened expectations on how digital pricing must be presented at the point of purchase, with direct implications for SaaS subscription…
Read updatePlatform self-preferencing remains a litigation and structuring risk
US antitrust enforcement increases exposure around exclusivity and distribution agreements.
Read updateADGM data protection duties now sit alongside DIFC-level expectations
ADGM data protection obligations increase contractual and governance discipline for technology businesses.
Read updateDigital terms and pricing must withstand CPA scrutiny
South African consumer protection law increases scrutiny on SaaS renewals and contract fairness.
Read updateFingerprinting is a consent and enforcement risk, not a workaround
Regulatory guidance reinforces that fingerprinting technologies remain subject to consent standards.
Read updateApp store and mobile platform risk is becoming a UK conduct regime issue
UK digital markets investigations increase scrutiny of app store dependencies and platform conduct.
Read updateSmart data and verification duties are moving into statute
The Data Use and Access Act 2025 introduces statutory smart data and digital verification frameworks.
Read updateFTC treats privacy and security claims as enforceable commitments
US regulators continue to hold technology companies to their data protection and security representations.
Read updateDigital Markets Act reshapes platform contract design
EU platform regulation is now directly influencing how SaaS and digital platforms structure commercial agreements.
Read updatePOPIA responsibility stays with the business, not the operator
South Africa’s regulator has reinforced that outsourcing data processing does not transfer POPIA accountability.
Read updateICO moves AI and automated decision-making toward statutory oversight
The ICO is signalling a shift from guidance to formal standards for AI and automated decisions, raising governance expectations for technology…
Read updateCMA increases scrutiny of SaaS consumer contract terms
UK competition regulators are tightening expectations around SaaS pricing, renewals, and exit terms, increasing enforcement risk for consumer-facing…
Read updateSaaS liability exposure is being clarified through EU case law
EU courts are refining how liability attaches in complex SaaS supply chains.
Read updateUS privacy enforcement is converging on contractual accountability
US regulators are increasingly using contract terms as an enforcement lever.
Read updateADGM data protection rules are reshaping SaaS contracting expectations
ADGM’s data protection regime is driving more prescriptive contractual controls.
Read updatePOPIA enforcement is shifting from guidance to consequence
South African regulators are signalling a firmer enforcement posture under POPIA.
Read updateForce majeure clauses are being interpreted strictly by reference to contract wording
The UK Supreme Court has confirmed that force majeure obligations depend on express contract terms, not commercial convenience.
Read updateGDPR damages exposure is increasingly a shared liability problem
Recent EU case law sharpens how GDPR damages liability is assessed across controllers and processors.
Read updateThe EU AI Act turns AI features into regulated product surface area
The EU AI Act reframes AI functionality as a regulated product feature rather than a purely technical choice.
Read updateDigital markets rules are creating new contractual leverage points
New UK digital markets powers are reshaping commercial leverage for businesses dependent on major platforms.
Read updateCookie consent is tightening, even as analytics exemptions expand
UK cookie compliance expectations are tightening, even as limited analytics exemptions emerge under new legislation.
Read updateADGM Clarifies When Sensitive Data May Be Lawfully Processed
New ADGM rules clarify when special category data may be processed, but they raise expectations around justification, documentation, and contractual…
Read updateBreach Reporting Volumes Signal Tougher Enforcement Ahead
Breach notifications are rising sharply in South Africa, and regulators are signalling stronger follow-through. Scaling tech businesses should expect…
Read updateRegulators are reframing “compliance” as a product and contract design issue for tech companies
According to recent regulatory commentary and enforcement signals across the UK and EU, regulators are increasingly reframing compliance as a product…
Read updateCyber resilience obligations are tightening across UK supply chains
According to UK parliamentary materials and recent policy analysis, proposed cyber resilience reforms indicate tightening security and incident…
Read updateCloud lock-in is moving from procurement pain to competition risk
According to the UK Competition and Markets Authority (CMA), cloud lock-in is increasingly being treated as a competition risk rather than a pure…
Read updateData Act 2025 shifts the UK compliance roadmap
According to UK legislation records and commentary from the UK Information Commissioner’s Office, The Data Act 2025 reshapes the UK compliance…
Read updateCookie banner design is becoming an enforcement priority, not a UX choice
According to the European Data Protection Board (EDPB), cookie banner compliance is becoming an enforcement priority rather than a design preference…
Read updateICO signals a more risk-based approach to enforcing cookie-consent rules
According to the UK Information Commissioner’s Office (ICO), the ICO is signalling a more risk-based approach to enforcing cookie-consent rules in…
Read updateUAE AI Office Issues New AI Risk Guidelines
The UAE AI Office released comprehensive guidelines on managing AI risks, underscoring regulatory priorities in artificial intelligence governance…
Read updateSouth Africa Updates POPIA Compliance Framework
The Information Regulator of South Africa has revised its guidelines on complying with the Protection of Personal Information Act (POPIA)…
Read updateCalifornia Implements New Data Privacy Provisions
California has implemented enhanced provisions under its privacy law, modifying consumer data usage and protection duties. This impacts businesses by…
Read updateNo updates match your search.
