HeadFlash

Privacy

Privacy Watchdog, Biometric Backlash, and Platform Crackdowns

NHS admits Palantir data access error, Italy's AI Act clash, India's Aadhaar age checks, OneDrive Photos biometrics, and Australia sues Telegram.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

NHS England Admits Error in Palantir Data Access Disclosure

NHS England has admitted that a key data-protection document misstated who could see patients’ medical records, failing to disclose that staff at US data-analytics firm Palantir can view identifiable patient data within the new Federated Data Platform. The admission followed a request from the National Data Guardian, the statutory office that advises the NHS on confidentiality. NHS England conceded the error and apologized, stating it is correcting the Data Protection Impact Assessment (DPIA) and apologizing for any confusion caused. The access sits inside the platform’s National Data Integration Tenant, which NHS England confirmed in May allows some supplier staff to reach identifiable patient information for specific technical purposes under NHS direction. Palantir won the £330m contract to build the platform in 2023 after landing £60m in COVID-era contracts without competition. National Data Guardian Nicola Byrne said the error shows how quickly confidence erodes if the ‘no surprises’ principle is not upheld, adding that many remain uneasy about Palantir’s role in the NHS. The row lands as scrutiny of Palantir’s public-sector work intensifies across Europe, with France dropping Palantir for a homegrown rival and both France and Germany backing a European alternative on sovereignty grounds, while Britain holds the opposite line. NHS England says it will implement the National Data Guardian’s recommendations in full.

NHS England admits its paperwork hid that Palantir staff can see identifiable patient data →

Italy’s Privacy Watchdog Says Police Facial Recognition Decree Violates EU AI Act

Italy’s data protection authority, the Garante, has confirmed that a core provision of the Council of Ministers’ decree on police facial recognition is not coherent with the EU AI Act. The contested provision authorizes preemptive capture and seven-day storage of biometric data from everyone attending a political demonstration, sports event, or any gathering at a location the government designates as sensitive for public order, before any crime has been committed. The Garante stated the EU AI Act permits post-event facial recognition only for targeted searches, not mass preemptive collection. The decree establishes a two-track framework: one track allows police to integrate existing video surveillance with AI facial recognition to identify suspects in recorded footage after a crime, aligning with the AI Act’s high-risk classification; the other permits real-time biometric identification in public spaces for prevention of specific serious threats, subject to prior judicial authorization. The contested provision sits at the intersection, creating what opposition legislative offices characterized as a third category: temporal biometric capture with no connection to any specific crime or suspect. The decree deviates from the AI Act in two documented respects: it grants authorization designation power to the questore, a senior police official, rather than an independent authority; and it permits oral communication to a prosecutor rather than written judicial authorization for urgent real-time deployment. The decree now proceeds to the Camera dei Deputati’s European Affairs Committee and other committees for non-binding opinions before final adoption. The Garante has specified modifications, including clearer rules on human oversight, more precise definitions of responsibilities, and explicit prohibition on databases assembled through indiscriminate web scraping. Italy is the first EU member state to attempt implementing the AI Act’s narrow law enforcement biometric exceptions via enabling legislation, and its own national authority has concluded one element overreaches what the regulation permits.

Italy’s Own Privacy Watchdog Says Its New Police Facial Recognition Decree Violates EU AI Act →

India Child Safety Plan Would Force Every Adult to Verify Age via Aadhaar

India’s Central government is reportedly preparing legislation that would establish three distinct age tiers for children’s social media access — 8 to 12, 12 to 16, and 16 to 18 — each carrying different platform obligations. The Central government has ruled out a blanket ban, with senior officials describing the approach as nuanced and graded. Measures under consideration include time-based login limits, mandatory parental consent, and obligations on platforms to modify engagement-maximizing design features. A key conclusion from a MediaNama expert convening in Bengaluru was that all age verification in India becomes Aadhaar verification, meaning every user must be identified through the national biometric identity system. The Digital Personal Data Protection Act (DPDP Act, 2023) requires verifiable parental consent before platforms process children’s data but does not specify a mechanism. The Draft Data Protection Rules of 2025 propose two pathways: an Aadhaar-linked DigiLocker system or an electronic token system in which a government ID is converted into an encrypted credential. The token architecture does not eliminate the metadata trail: a platform that pings DigiLocker creates a record that it queried India’s national identity infrastructure on behalf of that user at that time, constituting a surveillance database at population scale. State governments are moving independently ahead of any national framework. Karnataka’s Chief Minister announced the state would ban social media for children under 16, making it the first Indian state to announce such a measure; Andhra Pradesh targets children under 13; Goa is examining similar restrictions. A 2026 open letter signed by 438 security and privacy scientists from 32 countries called for a moratorium on age-based online restrictions, citing the absence of clear scientific evidence that such systems improve outcomes for children. Australia’s experience provides a cautionary datapoint: after the world’s first under-16 social media ban took effect in December 2025, the country’s eSafety Commissioner found by March 2026 that seven in ten parents reported their child still had an active account on a restricted platform, and VPN usage among Australian teenagers spiked.

India Child Safety Plan Would Force Every Adult to Verify Age via Aadhaar →

OneDrive Photos Silently Installs on Windows 11 With Biometric Scan Capability, No Removal Path

OneDrive Photos, a photo organizer with facial recognition capability, began appearing on Windows 11 systems in late July 2026 via a Windows Update or OneDrive client update, without a consent prompt or independent removal path. The app runs through a distinct executable while the core OneDrive sync client runs separately, and because it runs as a sub-process of the OneDrive sync client, it does not appear as a standalone item in software inventory tools. Removing the app requires uninstalling the OneDrive sync client. Windows Latest’s hands-on testing confirmed that OneDrive Photos detects and displays local photos without requiring a Microsoft account sign-in. When signed in, the app adds AI-powered cloud search and optical character recognition. The interface includes sections for Moments, Gallery, People, Albums, Favorites, and a local This PC view, with the People section grouping similar faces. Microsoft asks for explicit permission before enabling it and warns in the consent prompt that the data could be considered biometric data in some regions. Under GDPR Article 9, biometric data processed for uniquely identifying a natural person is a special category requiring explicit consent that is freely given, specific, informed, and an unambiguous indication of the data subject’s wishes. Regulators have found that a consent request embedded in an interface the individual did not choose to install does not meet this bar. Illinois’ Biometric Information Privacy Act requires written notice, purpose and retention period disclosure, and a written release before collecting biometric identifiers. Google paid $100 million in 2022 to resolve a BIPA class action over Google Photos’ face-grouping feature; Facebook paid $650 million in 2020 over its photo-tagging feature. Microsoft says the People feature is visible only to the individual user, that facial grouping data is not shared with third parties or used to train broader AI models, and that all data is permanently deleted within 30 days of disabling the feature. The disable option has been documented to carry a restriction: users can turn it off only a limited number of times per year — reportedly three, in preview builds. Microsoft has not published documentation confirming whether facial analysis runs on-device or on Microsoft’s servers. As of July 30, 2026, Microsoft has not issued a public statement about the OneDrive Photos rollout, has not updated privacy documentation to address facial analysis processing location, and has not provided an independent removal path or policy guidance.

OneDrive Photos Silently Installs on Windows 11 With Biometric Scan Capability, No Removal Path →

Australia Takes Telegram to Court Over Terrorist Content It Says the App Left Up

The eSafety Commissioner, Julie Inman Grant, filed civil penalty proceedings in the Federal Court on 30 July against Telegram, alleging the messaging app failed to remove terrorist and violent extremist content after being notified. The material in question includes footage of the 2019 Christchurch mosque attack, the 2022 white-supremacist mass shooting in Buffalo, and Islamic State beheadings. The regulator states it began pressing Telegram to comply in March 2024, but found the platform non-responsive for months, a pattern Inman Grant described as a permissive hosting environment for terrorist content. The case is brought under Australia’s Online Safety Act, passed in 2021, which requires platforms to remove illegal and pro-terrorism material once notified. Telegram faces a maximum penalty of about A$54.6 million, roughly $38 million, if the court finds against it. eSafety previously fined Telegram over delays in answering questions about its handling of child-abuse and terror material. Inman Grant said, When platforms are alerted to terrorist content, they must act. Telegram said, We reject these allegations and will contest them in court, adding that it had blocked more than 150,000 terrorist-related communities in 2026. In the same week, Russia’s FSB charged Telegram’s founder, Pavel Durov, with facilitating terrorism, an accusation Telegram called a pretext. The proceedings will go through the Federal Court.

Australia takes Telegram to court over terrorist content it says the app left up →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches