Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Department for Work and Pensions Breaches FOIA by Failing to Disclose Information and Respond Within Statutory Timeframe

The ICO upheld a complaint against the Department for Work and Pensions (DWP) for failing to disclose requested briefings and breaching section 10(1) of FOIA by not responding within the statutory timeframe. The Commissioner's decision found that while section 36(2)(b)(i) was engaged, the public interest favored disclosure. DWP is required to disclose the information within 30 calendar days.

Today's question

A data protection officer is reviewing their organization's use of large language models (LLMs) for customer service. Given recent guidance, which security vulnerability should be considered a top priority for mitigation, even if no incidents have been recorded internally?

  1. Lack of robust encryption for data in transit to and from the LLM.
  2. Insufficient access controls for developers interacting with the LLM's API.
  3. Prompt injection attacks that can alter the LLM's intended behavior.
  4. Absence of regular security audits for the underlying cloud infrastructure hosting the LLM.

Answer this question on the site

Worth knowing

  1. China Rolls Out New AI Governance and Data Protection Measures, Including Simplified Regime for Small-Scale Handlers

    China is advancing AI governance and data protection with new rules for anthropomorphic AI services, financial AI use, anti cyber violence, and cross border data transfers. The Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers, effective September 1, 2026. These provisions aim to reduce compliance burdens for smaller businesses while maintaining baseline personal information protection requirements.

  2. Cathedral Schools Trust Incorrectly Relied on FOI 40(2) to Withhold Student Data

    The ICO ruled that Cathedral Schools Trust was incorrect to rely on section 40(2) of FOIA to withhold information about the number of primary school students accepted to Bristol Cathedral Choir School. The Trust had provided a spreadsheet but redacted some figures under this section. The Commissioner requires the Trust to disclose the withheld information.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.