Tech & Legal Updates

Short, executive-level legal and commercial updates for founders and leaders of scaling technology businesses.

Every update, by topic

Short briefings on the regulatory and commercial shifts affecting tech contracts, AI liability, privacy and data. Newest first, tap any card to read the full snippet.

SaaS14 May 2026

Software renewals need a priced exit strategy

The CMA is investigating Microsoft’s business software ecosystem, including bundling, interoperability and Copilot, with evidence gathering scheduled through September 2026. No new contractual rights exist yet, so price your exit before you take a multi-year discount.

Read update
SaaS10 Aug 2026

G-Cloud 15 changes how SaaS deals must be structured

The Government Commercial Agency has introduced G-Cloud 15 under the Procurement Act 2023. Its buying guidance states that core terms cannot be changed, so the entire commercial negotiation now happens in the order form and schedules.

Read update
AI4 Aug 2026

Separate AI permissions from ordinary content distribution

The CMA has imposed requirements giving publishers controls over Google’s use of their content for AI training and grounding, with a main compliance deadline of 3 December 2026. It covers Google’s designated services only, not a universal AI licensing regime.

Read update
Privacy & Data19 Aug 2026

Advertising contracts must support children’s privacy settings

The ICO’s latest children’s strategy update flags continuing concerns about mobile games’ default privacy settings and ad profiling, with formal enforcement available where the law is breached. Any service children are likely to use falls inside scope.

Read update
Commercial19 Aug 2026

Mandatory fees need to be built into the pricing architecture

The CMA has opened an investigation into whether Trainline included mandatory fees in its headline price. No finding has been made, but drip pricing is now a live enforcement target well beyond travel and ticketing.

Read update
Privacy & Data26 Aug 2026

An opt-out registry check does not establish marketing consent

South Africa’s Information Regulator has confirmed absence from the opt-out registry does not satisfy POPIA’s consent requirements. Two live enforcement referrals, against MTN and OUTsurance, show why this distinction matters now.

Read update
Cyber & IT Risk11 Sep 2026

Supplier notification clauses must support ADGM reporting deadlines

ADGM’s cyber rules give regulated firms 24 hours to report a material incident. Most standard SaaS and IT supplier contracts were never written to make that deadline achievable.

Read update
AI27 Aug 2026

Turn AI marketing promises into verifiable contractual commitments

The FTC finalised orders against Cox Media Group and two reseller firms over an AI advertising service that never used voice data as claimed. Reselling an unverified AI capability claim adds you to the liability, it does not remove it.

Read update
Data & Technology19 Aug 2026

Your AI vendor said the training data was “properly licensed.” Prove it.

The FTC concluded three enforcement actions against AI model vendors who misrepresented training data sourcing. Vendor self-certification on training data is no longer contractually acceptable.

Read update
AI14 Aug 2026

The FCA just made vendor self-certification worthless

The Financial Conduct Authority published guidance on AI model risk management. The guidance applies to all FCA-regulated firms using generative AI models for customer-facing decisions.

Read update
Commercial11 Aug 2026

South Africa just made AI disclosure mandatory in government bids

The Department of Public Works now requires all suppliers bidding on South African government contracts over R5 million to disclose any generative AI or algorithmic tools used in preparing tenders.

Read update
Data & Technology7 Aug 2026

Your UAE cloud contract is missing audit rights

The UAE Telecommunications Regulatory Authority just made data localization verification a contractual obligation. Every cloud service agreement for UAE customers now needs explicit audit rights.

Read update
AI30 Jul 2026

Your government contracts just got more transparent

The UK Government’s Digital, Science and Innovation Team has published binding guidance on AI use in government communications, requiring explicit disclosure, review cycles, and audit trails.

Read update
Commercial30 Jul 2026

Government procurement AI just got auditable

The UK’s new Procurement Transparency Register requires government bodies to publish algorithm scoring frameworks within 20 days of contract award. Suppliers can now challenge the methodology.

Read update
SaaS29 Jul 2026

Your SaaS renewal terms are about to get renegotiated

The CMA published findings on Microsoft 365 subscription practices, flagging auto-renewal defaults, opaque switching costs, and renewal terms that make exit materially harder than entry.

Read update
Data Governance22 Jul 2026

Your consultation responses aren’t confidential anymore

The UK DSIT has mandated that every government department deploy the Consult AI platform to analyse consultation responses, and departments must now publish their analytical methodology.

Read update
Data & Technology14 Aug 2026

Getty v Stability AI puts AI copyright risk back into vendor contracts

The UK’s first major AI copyright ruling is under appeal, leaving model-training risk unsettled. Businesses licensing or embedding third-party AI should revisit IP warranties, training disclosures and infringement indemnities.

Read update
Deals & Contracts14 Aug 2026

Your liability cap may not matter if the exclusion clause removes the claim first

EE v Virgin Mobile is a reminder that liability caps and exclusions do different jobs. SaaS, reseller and technology agreements should test profit and revenue exclusions against the remedies the business would actually need.

Read update
Privacy & Data14 Aug 2026

UK GDPR damages are heading to the Supreme Court

Farley v Paymaster puts the threshold for UK GDPR damages back in focus. The outcome could materially affect low-value claims brought at scale and the way controllers and processors negotiate data indemnities.

Read update
Commercial14 Aug 2026

Apple and Google could lose control over how UK developers steer customers to payment

The CMA is considering rules allowing UK developers to direct customers to off-platform purchasing options on fair and reasonable terms, putting platform fees, subscription economics and distribution contracts in play.

Read update
Privacy & Data14 Aug 2026

Data complaints are becoming a contract issue, not just a privacy-team problem

New UK data-protection complaints requirements increase the operational burden on controllers. Existing DPAs should ensure processors escalate complaints quickly and provide the records and assistance needed to respond.

Read update
Privacy & Data14 Aug 2026

South Africa’s new direct-marketing regime reaches your CRM and supplier contracts

South Africa’s opt-out framework changes how businesses manage outbound marketing data. CRM processes, agencies, list providers and outsourced sales partners all need clear suppression and compliance responsibilities.

Read update
Data & Technology14 Aug 2026

DIFC is moving AI governance from policy into the operating model

DIFC’s AI-native direction points to deeper AI governance, accountability and evidence requirements. Technology vendors selling into DIFC-regulated businesses should expect those controls to surface in procurement.

Read update
Data & Technology14 Aug 2026

If an AI system is deliberately steering its answers, the FTC wants users told

The FTC’s proposed policy on suppression of AI accuracy puts undisclosed output steering on the contract agenda. AI vendor warranties should address deliberate configuration choices, not only hallucinations, bias, IP and data breaches.

Read update
AI30 Jul 2026

ICO redesigns its Regulatory Sandbox for AI and emerging technology

The ICO is evolving its Regulatory Sandbox to match the scale and speed of AI development, moving beyond a handful of intensive engagements to multiple levels of support…

Read update
SaaS29 Jul 2026

CMA investigates Microsoft over the marketing of Microsoft 365 subscription plans

The CMA has opened a consumer-protection investigation into whether Microsoft 365 customers received clear information about plan changes, including Copilot, before renewal…

Read update
Commercial29 Jul 2026

CMA imposes conduct requirements on Google’s UK search services

Publisher, fair-ranking and data-portability requirements now apply to Google’s UK general search services following its strategic market status designation…

Read update
Privacy & Data29 Jul 2026

FTC acts against Hims & Hers over health-data sharing and subscription practices

The FTC and state partners allege sensitive health information was shared with advertising platforms, and that subscriptions were charged without express informed consent…

Read update
Data Governance15 Jul 2026

UK Government examines how data regulation interacts with AI

DSIT has opened a call for evidence on data regulation in the age of AI and other data-intensive technologies, open until 9 September 2026…

Read update
Commercial18 Jun 2026

CMA Investigates Wayfair’s Use of Time-Limited Offers

The CMA has launched an inquiry into Wayfair’s use of time-limited offers, investigating potential consumer law violations. This impacts consumer…

Read update
Cyber & IT Risk17 Jun 2026

UK’s Digital Standards Strategy to Shape AI Future

The UK’s Digital Standards Strategy outlines ambitious goals in AI, cybersecurity, and connectivity. Businesses engaged in AI development will need…

Read update
AI16 Jun 2026

AI Tools to Enhance Planning Decisions in England

The UK government has unveiled AI tools to modernize the planning permission system, promoting efficiency. AI integration into public systems…

Read update
Privacy & Data10 Jun 2026

AI to Accelerate NHS Cancer Diagnostics

The UK invests in AI technologies to speed up cancer diagnosis within the NHS, promising shorter waiting times. Such advancements necessitate robust…

Read update
Commercial3 Jun 2026

CMA Promotes Innovation in Digital Markets

The CMA is actively working to enhance competition in digital markets. This initiative could drive innovation, impacting platform-based business…

Read update
Cyber & IT Risk16 May 2026

CMA Opens First Direct Enforcement Actions Under DMCCA Pricing Architecture Now a Board-Level Risk

The CMA has launched its first direct enforcement investigations under the DMCCA, targeting drip pricing, misleading urgency tactics, hidden fees…

Read update
Commercial2 Apr 2026

Court reinforces limits on exclusion of core contractual liability

UK court reinforces limits on liability clauses, showing that core service failures cannot be fully excluded contractually.

Read update
SaaS2 Apr 2026

ICO increases enforcement activity on data security failures

ICO enforcement on data security failures is increasing, elevating security into a commercial and contractual risk.

Read update
SaaS2 Apr 2026

CMA increases scrutiny on subscription pricing and renewal practices

CMA scrutiny on SaaS pricing and renewals is increasing, exposing revenue models to regulatory and contractual risk.

Read update
Data Governance2 Apr 2026

Information Regulator increases enforcement on direct marketing practices

POPIA enforcement on direct marketing is increasing, affecting outbound growth strategies and contractual data use obligations.

Read update
AI2 Apr 2026

ICO expands enforcement focus to biometric data in AI systems

ICO scrutiny on biometric AI systems is increasing, creating direct product, compliance, and contractual risk for SaaS businesses.

Read update
Commercial1 Apr 2026

South Africa Updates Competition Rules for Digital Advertising

The Competition Commission of South Africa has revised competition rules affecting the digital advertising market. These changes necessitate…

Read update
Data & Technology27 Mar 2026

FTC Data Enforcement and Adtech Contract Liability

FTC enforcement is reshaping how adtech businesses use data, forcing clearer contracts and stricter liability allocation.

Read update
Data Governance27 Mar 2026

POPIA Enforcement and Data Processing Contract Risk

POPIA enforcement is increasing in South Africa, shifting risk into operator agreements, breach obligations, and cross-border controls.

Read update
Privacy & Data27 Mar 2026

Cookie Compliance Risk and Adtech Contract Exposure

ICO enforcement on cookies is impacting adtech revenue models and forcing contract clarity across tracking, consent, and liability.

Read update
SaaS27 Mar 2026

SaaS Procurement Risk and Exit Planning Requirements

Enterprise buyers are shifting SaaS procurement toward resilience, exit planning, and vendor risk. Contracts are now driving selection.

Read update
Data & Technology27 Mar 2026

ICO AI Training Data Compliance and Contract Risk

ICO guidance on AI training data is shifting risk into contracts. SaaS providers must now prove lawful data use and absorb liability.

Read update
Data & Technology20 Mar 2026

UAE advances AI governance framework with operational compliance expectations

UAE AI policy sets out accountability, transparency, and human oversight principles. Businesses should reflect these in how AI systems are governed…

Read update
Privacy & Data20 Mar 2026

POPIA sets conditions for cross-border data transfers

Cross-border data transfers under POPIA require adequate protection or enforceable contractual safeguards. Businesses must ensure data transfer…

Read update
Data & Technology20 Mar 2026

Public sector procurement rules tighten around technology supplier risk

Updated UK procurement guidance reinforces proportionate risk allocation, pricing discipline, and clear contractual responsibility across the supply…

Read update
Deals & Contracts20 Mar 2026

Liability caps remain strictly enforced in commercial contracts

Courts continue to apply strict interpretation to liability caps. Clear drafting and appropriate carve-outs remain critical in SaaS agreements.

Read update
Data & Technology20 Mar 2026

ICO guidance sets expectations for AI training data use

AI training data must meet lawful basis, transparency, and purpose limitation requirements. Businesses must address data provenance and contractual…

Read update
Data & Technology13 Mar 2026

UAE AI Governance Framework Raises Contractual Accountability for AI Deployment

The UAE National Artificial Intelligence Strategy introduces governance expectations for responsible AI deployment across sectors. Technology vendors…

Read update
Data & Technology13 Mar 2026

Google Antitrust Judgment Reinforces Distribution and Default Placement Risk

A U.S. court ruling against Google highlights how exclusive distribution agreements and default placement arrangements can constitute exclusionary…

Read update
Privacy & Data13 Mar 2026

Automated Decision Explanations Become a Legal Expectation in the EU

A CJEU ruling confirms that individuals affected by automated decisions must be able to understand and challenge how those decisions are made…

Read update
Data & Technology13 Mar 2026

EU Data Act Expands Contract Risk Across Product and Cloud Services

The EU Data Act has applied since 12 September 2025, expanding user access rights to connected device data and strengthening switching rights between…

Read update
Commercial13 Mar 2026

Platform Dependency Is Emerging as a Commercial Negotiation Risk

The CMA’s digital markets regime is now active and the Google search SMS investigation shows how platform power is moving from policy debate into…

Read update
Data & Technology6 Mar 2026

EU Strengthens Consumer Protection Rules for Digital Services

The European Union is expanding consumer protection rules affecting digital services and online platforms. Technology businesses must review…

Read update
Privacy & Data6 Mar 2026

DIFC Updates Data Protection Regulatory Framework

The Dubai International Financial Centre continues to refine its data protection regime. Technology firms operating in the DIFC must ensure…

Read update
Privacy & Data6 Mar 2026

EU Court Confirms Strict Consent Standards for Tracking Technologies

European court rulings continue to reinforce strict consent requirements for cookies and tracking technologies. Businesses must ensure consent is…

Read update
Data & Technology6 Mar 2026

EU Digital Markets Act Enforcement Expands Platform Obligations

The European Commission is enforcing obligations on designated gatekeeper platforms under the Digital Markets Act. Technology platforms face new…

Read update
Privacy & Data6 Mar 2026

UK ICO Targets Cookie Compliance on Major Websites

The UK Information Commissioner’s Office has launched enforcement action focused on cookie consent practices. Advertising and data driven companies…

Read update
Privacy & Data2 Mar 2026

South Africa’s Information Regulator Tightens POPIA Enforcement

POPIA enforcement highlights direct marketing consent and documented security compliance duties.

Read update
Privacy & Data2 Mar 2026

ADGM Data Protection Regime Demands Demonstrable Accountability

ADGM confirms GDPR-style accountability and governance expectations for controllers and processors.

Read update
Deals & Contracts2 Mar 2026

Supreme Court Reinforces Strict Contract Interpretation

The UK Supreme Court confirms courts will not rewrite unclear drafting to achieve commercial fairness.

Read update
Data & Technology2 Mar 2026

EU AI Act Introduces Direct Compliance Duties for Providers

The EU AI Act imposes binding governance, documentation, and monitoring obligations on high-risk AI providers.

Read update
Privacy & Data2 Mar 2026

CJEU Clarifies Limits on Data Use for Online Advertising

The CJEU confirms that cross-service data combination for advertising requires a valid GDPR basis and strict necessity assessment.

Read update
Cyber & IT Risk20 Feb 2026

POPIA Compliance and AI Deployment

POPIA continues to define the legal framework for AI and cross-border data use in South Africa, requiring structured compliance at architecture and…

Read update
Cyber & IT Risk20 Feb 2026

AI Governance Direction in the UAE

The UAE AI Charter signals governance expectations that should now be reflected in contracts, procurement processes, and product oversight frameworks.

Read update
Deals & Contracts20 Feb 2026

GDPR Compensation and Claimant Risk

The CJEU has clarified that GDPR compensation requires proven damage and causation, reshaping contractual risk allocation and incident documentation…

Read update
Privacy & Data20 Feb 2026

Adtech Transparency Under the Digital Services Act

The DSA introduces mandatory ad transparency and targeting restrictions, requiring structural changes to audience design, consent architecture, and…

Read update
Deals & Contracts20 Feb 2026

Drip Pricing and Upfront Cost Disclosure

The CMA has tightened expectations on how digital pricing must be presented at the point of purchase, with direct implications for SaaS subscription…

Read update
Data & Technology13 Feb 2026

Platform self-preferencing remains a litigation and structuring risk

US antitrust enforcement increases exposure around exclusivity and distribution agreements.

Read update
Data Governance13 Feb 2026

ADGM data protection duties now sit alongside DIFC-level expectations

ADGM data protection obligations increase contractual and governance discipline for technology businesses.

Read update
SaaS13 Feb 2026

Digital terms and pricing must withstand CPA scrutiny

South African consumer protection law increases scrutiny on SaaS renewals and contract fairness.

Read update
Data & Technology13 Feb 2026

Fingerprinting is a consent and enforcement risk, not a workaround

Regulatory guidance reinforces that fingerprinting technologies remain subject to consent standards.

Read update
Commercial13 Feb 2026

App store and mobile platform risk is becoming a UK conduct regime issue

UK digital markets investigations increase scrutiny of app store dependencies and platform conduct.

Read update
Commercial13 Feb 2026

Smart data and verification duties are moving into statute

The Data Use and Access Act 2025 introduces statutory smart data and digital verification frameworks.

Read update
Cyber & IT Risk6 Feb 2026

FTC treats privacy and security claims as enforceable commitments

US regulators continue to hold technology companies to their data protection and security representations.

Read update
SaaS6 Feb 2026

Digital Markets Act reshapes platform contract design

EU platform regulation is now directly influencing how SaaS and digital platforms structure commercial agreements.

Read update
Privacy & Data6 Feb 2026

POPIA responsibility stays with the business, not the operator

South Africa’s regulator has reinforced that outsourcing data processing does not transfer POPIA accountability.

Read update
Data Governance6 Feb 2026

ICO moves AI and automated decision-making toward statutory oversight

The ICO is signalling a shift from guidance to formal standards for AI and automated decisions, raising governance expectations for technology…

Read update
Deals & Contracts6 Feb 2026

CMA increases scrutiny of SaaS consumer contract terms

UK competition regulators are tightening expectations around SaaS pricing, renewals, and exit terms, increasing enforcement risk for consumer-facing…

Read update
SaaS2 Feb 2026

SaaS liability exposure is being clarified through EU case law

EU courts are refining how liability attaches in complex SaaS supply chains.

Read update
Cyber & IT Risk2 Feb 2026

US privacy enforcement is converging on contractual accountability

US regulators are increasingly using contract terms as an enforcement lever.

Read update
Data & Technology2 Feb 2026

ADGM data protection rules are reshaping SaaS contracting expectations

ADGM’s data protection regime is driving more prescriptive contractual controls.

Read update
Privacy & Data2 Feb 2026

POPIA enforcement is shifting from guidance to consequence

South African regulators are signalling a firmer enforcement posture under POPIA.

Read update
Deals & Contracts2 Feb 2026

Force majeure clauses are being interpreted strictly by reference to contract wording

The UK Supreme Court has confirmed that force majeure obligations depend on express contract terms, not commercial convenience.

Read update
Data Governance2 Feb 2026

GDPR damages exposure is increasingly a shared liability problem

Recent EU case law sharpens how GDPR damages liability is assessed across controllers and processors.

Read update
Data & Technology2 Feb 2026

The EU AI Act turns AI features into regulated product surface area

The EU AI Act reframes AI functionality as a regulated product feature rather than a purely technical choice.

Read update
Commercial2 Feb 2026

Digital markets rules are creating new contractual leverage points

New UK digital markets powers are reshaping commercial leverage for businesses dependent on major platforms.

Read update
Privacy & Data2 Feb 2026

Cookie consent is tightening, even as analytics exemptions expand

UK cookie compliance expectations are tightening, even as limited analytics exemptions emerge under new legislation.

Read update
Data Governance29 Jan 2026

ADGM Clarifies When Sensitive Data May Be Lawfully Processed

New ADGM rules clarify when special category data may be processed, but they raise expectations around justification, documentation, and contractual…

Read update
Privacy & Data29 Jan 2026

Breach Reporting Volumes Signal Tougher Enforcement Ahead

Breach notifications are rising sharply in South Africa, and regulators are signalling stronger follow-through. Scaling tech businesses should expect…

Read update
Commercial28 Jan 2026

Regulators are reframing “compliance” as a product and contract design issue for tech companies

According to recent regulatory commentary and enforcement signals across the UK and EU, regulators are increasingly reframing compliance as a product…

Read update
Cyber & IT Risk28 Jan 2026

Cyber resilience obligations are tightening across UK supply chains

According to UK parliamentary materials and recent policy analysis, proposed cyber resilience reforms indicate tightening security and incident…

Read update
Commercial28 Jan 2026

Cloud lock-in is moving from procurement pain to competition risk

According to the UK Competition and Markets Authority (CMA), cloud lock-in is increasingly being treated as a competition risk rather than a pure…

Read update
Data Governance28 Jan 2026

Data Act 2025 shifts the UK compliance roadmap

According to UK legislation records and commentary from the UK Information Commissioner’s Office, The Data Act 2025 reshapes the UK compliance…

Read update
Privacy & Data28 Jan 2026

Cookie banner design is becoming an enforcement priority, not a UX choice

According to the European Data Protection Board (EDPB), cookie banner compliance is becoming an enforcement priority rather than a design preference…

Read update
Privacy & Data28 Jan 2026

ICO signals a more risk-based approach to enforcing cookie-consent rules

According to the UK Information Commissioner’s Office (ICO), the ICO is signalling a more risk-based approach to enforcing cookie-consent rules in…

Read update
AI1 Jan 2026

UAE AI Office Issues New AI Risk Guidelines

The UAE AI Office released comprehensive guidelines on managing AI risks, underscoring regulatory priorities in artificial intelligence governance…

Read update
Privacy & Data15 Nov 2025

South Africa Updates POPIA Compliance Framework

The Information Regulator of South Africa has revised its guidelines on complying with the Protection of Personal Information Act (POPIA)…

Read update
Privacy & Data15 Sep 2025

California Implements New Data Privacy Provisions

California has implemented enhanced provisions under its privacy law, modifying consumer data usage and protection duties. This impacts businesses by…

Read update

Bring legal into the decision, not just the paperwork.