IAPP UK Data Protection Intensive 2024 Highlights: Dive into AI, Data Privacy, & Cybersecurity
April 2024
By
Franziska Schulze
Welcome to the recap of the highly anticipated IAPP UK Data Protection Intensive 2024. This leading industry event brought together legal professionals and privacy experts to explore the latest trends and developments in AI, data privacy, and cybersecurity. A focal point of the event was the keynote speech delivered by UK Information Commissioner John Edwards, who shed light on the key themes dominating the legal landscape in the UK. Let's delve into the highlights from this thought-provoking conference.
UK Regulatory Priorities:
During his keynote speech, Edwards outlined the key areas of the UK Information Commissioner's Office (ICO) strategy:
- Social Media and Children: The ICO will continue to prioritise the protection of children online and in particular on social media and video sharing platforms, in line with the Children’s Code of Practice that was introduced in 2021. This year, the ICO will focus on default settings, in particular relating to capturing location data and targeted advertisement, on recommender systems through algorithms using behaviourial profiles and on age assurance technologies.
In other sessions, participants discussed the regulatory framework in other jurisdictions, how to conduct relevant risk assessments and how best to incorporate the best interests of children into product design. Age-appropriate design will remain a key concern for online businesses interacting with children, and efforts to understand whether users are in fact children may have to become more effective.
- Cookies and Consent: The ICO reviewed the cookie consent mechanisms on websites with the highest traffic in the UK and gave recommendations to more than half of the websites it reviewed, inter alia to ensure that it is as easy to accept as it is to reject cookies. The ICO is planning to launch an automated tool to accelerate the review of more websites going forward. How best to obtain cookie consent will be of interest to most companies with an online presence, in light of the continued regulatory interest in this area.
- AI and ICO Consultation Papers: As AI continues to transform industries, the UK’s strategy is to regulate Artificial Intelligence through existing laws, including UK GDPR. The ICO published consultation papers to conceptualise responsible AI last year and will follow on with more papers this year. The panel following the keynote speech featured insights from AI industry insiders who discussed the shift in public perception of AI and its trustworthiness – one participant highlighted a study showing a significant shift from even just a few years ago. A large majority of samples in an age group below thirty would now trust AI more than a human reviewer. The panel highlighted the responsibility this trust entails and how easily it could be lost if AI is not developed and deployed ethically.
- Interplay between Competition Law and Data Protection Law: Edwards outlined the cooperation between the ICO and the Competition and Markets Authority and in the joint statement with the CMA.
- Biometrics: The ICO will continue to focus on the appropriate use of biometrics. Edwards mentioned its investigation into Serco where it found that the use of facial recognition and fingerprints to log attendance without offering an alternative was not compliant.
Key Topics Explored in the Conference:
The conference featured captivating sessions, presentations, and networking opportunities that deepened the discussions around AI, data privacy, and cybersecurity. Some of the key topics explored include:
- Significance of AI and Data Privacy/Cybersecurity: The legal industry is embracing AI as a transformative force. The conference highlighted the increasing importance of integrating robust data privacy and cybersecurity measures into AI endeavors to foster regulatory compliance, build trust, and mitigate risks.
- AI and the new EU AI Act: The conference had a strong focus on AI in a number of sessions including on the EU AI Act that was officially adopted after the conference took place as well as the laws and initiatives in other jurisdictions including the US. Participants discussed how to frame responsible AI governance and identifying appropriate risk models.
There were lively discussions as to whether and how training data could be extracted from models or what other remediation might be possible where training data was not collected in compliance with privacy and/or Intellectual Property laws.
AI regulation will affect most companies, and many companies have stood up governance frameworks for ethical AI use, allocating responsibility from board level down. This is important for all companies to consider appropriately. While only few companies develop cutting-edge AI models inhouse, most companies are already using AI as part of their business and this will only accelerate going forward, whether third party AI models are being deployed as part of products, within the enterprise, or as part of their customer service.
- EU Data Act and Manufacturing/Utility Companies: The EU Data Act and its sharing obligations were discussed in several sessions, recognizing its profound implications for manufacturing, providers of “related services” and utility companies, as well as cloud hosting companies. A session took us through the complexity of a real-world example featuring a papermill and an electricity company. This showcased the challenges in identifying and preparing the data assets that would need to be shared, and the prerequisites for sharing, as well as the limitations.
- Competition and Data Protection Interplay: Sessions featured speakers from the CMA and the ICO who illustrated how the use of personal data by companies can be relevant under both regulatory regimes, and how regulators work to coordinate enforcement actions. The CJEU decision in Facebook reviewing whether the German Federal Cartel Office had acted ultra vires when investigating not only competition law but also GDPR was discussed as an example, as were the ongoing discussions on Google's sandbox for phasing out third-party cookies.
The speakers highlighted the challenges to reconcile the goals of competition law for access to personal data with the goals of data protection law to achieve data minimization, individual control over data, and its safe handling. But they also drew out the common ground and how that is reflected, for example, in the EU Digital Markets Act and the EU Digital Services Act. These could be said to use tools of competition law to reinforce privacy rules when it comes to technology companies with the highest market power.
Companies should therefore consider fostering collaboration and interaction between their antitrust/competition lawyers with their privacy teams to ensure that companies can equally be ready to approach their compliance stance from all angles, reconciling their antitrust and privacy programs to a coherent whole. - Challenges and Opportunities in AdTech and Privacy: The pervasive role of AdTech in the digital age brought forth intriguing conversations about its compatibility with privacy regulations. Attendees scrutinized the challenges and explored innovative approaches to strike a balance between effective advertising and preserving privacy. The conference discussed the permissibility of the Consent or Pay model that is subject to review by European regulators. The European Data Protection Board issued an Opinion on its limitations in April. These developments are triggered by social media platforms that are subject to the investigations at a Member State level that have risen to discussion at EDPB level, but the outcome of these investigations could also affect the many publishers employing a pay or consent model for cookies on their websites.
- Recent Enforcement Actions and Notable Cases: Insights into recent enforcement actions included an interesting discussion on the recent ICO finding against Snap, finding that Snap’s privacy impact assessment on a generative AI chatbot that was used by a large number of users between 13 and 17 years old was insufficient in that it did not review the privacy risks appropriately. A panel also discussed the ICO decision in Clearview (finding that Clearview’s use of billions of images was incompliant) and Clearview’s successful appeal against that decision on grounds of lack of jurisdiction. ICO decisions against Experian and the ongoing investigation into TikTok were also discussed. Speakers from the ICO also mentioned the forthcoming fining guidelines by the ICO, which is hoped to bring more clarity. These case studies provoked thoughtful discussions around best practices and risk mitigation.
- Ongoing Discussions on International Data Transfers: International data transfers and the EU-US Data Protection Framework as well as the US-UK Data Bridge continued to be a focal point, with attendees actively engaging in discussions surrounding evolving standards and strategies to comply with varying global regulations.
Top Three Takeaways:
- Networking Opportunities: The IAPP UK Data Protection Intensive 2024 offered invaluable networking opportunities, enabling privacy lawyers and professionals to forge connections, foster collaboration, and share knowledge. The power of community support in navigating the evolving legal landscape cannot be understated.
- AI Regulations: AI regulations extend beyond developers of large language models. Privacy lawyers are encouraged to delve into the EU AI Act and global regulations to stay abreast of compliance requirements when clients develop AI models as well as when they adopt third-party AI systems. Expanding expertise in this area will enable legal professionals to better support their clients in an AI-driven world.
- Beyond AI: The EU Data Act carries significant implications for manufacturing and utility companies, requiring them to prioritize the management and protection of data assets. Additionally, the scrutiny surrounding the Consent or Pay model underscores the need for publishers to reassess their approach, ensuring both compliance and sustainable monetization.
Conclusion:
The IAPP UK Data Protection Intensive 2024 provided a platform for legal and privacy professionals to engage with cutting-edge topics in AI, data privacy, and cybersecurity. The event highlighted the growing importance of staying informed about evolving regulations and emerging best practices in privacy. Closing speeches reminded us of the bigger picture, the ethical dimension of why we regulate privacy and AI, how important decent privacy and legal practices will continue to be. Lord Holmes focused on equality and inclusion in AI, as reflected in the private members bill he introduced to UK Parliament on AI, while Anna Funder highlighted the historical dimension of privacy rights as a human right, and how significant it will be to keep the lessons of past abuses in mind as we forge ahead in AI.
💡 Better navigate evolving regulations surrounding AI, data privacy, and cybersecurity.
Posted by Franziska Schulze
Franziska Schulze is a former divisional General Counsel of a multinational company. For Axiom, Franziska has used her deep subject matter experience in technology, privacy, and AI to advise clients across a range of industry sectors on complex legal matters. Her clients have included multinational technology companies, business service and data companies, an international hospitality brand, life science and manufacturing companies, and even a global luxury brand.
Related Content
AI Contract Management: What Legal Teams Need to Know
As legal teams face mounting pressure to do more with less, AI contract management solutions offer a compelling answer, transforming the contract process.
Why 80% of In-House Teams Are Rethinking Their Law Firm Relationships
New research reveals a legal market caught between legacy habits and transformation, with significant implications for how legal work gets done.
Why Axiom Outperforms LPO on Quality, Flexibility, and Business Impact
While LPO can solve some problems, it frequently creates new ones. This is where Axiom’s model offers a fundamentally different and better approach.
The AI Paradox: Why Your Legal Team's Productivity Gains Are Fueling a Retention Crisis
93% of legal professionals say AI boosts productivity, yet 76% fear job loss. New research reveals how AI anxiety is driving turnover. See the new data.
Essential Resources for In-House Legal Teams: 2025 Year in Review
Explore Axiom's top 2025 legal resources on AI adoption, talent retention, budget transformation, regulatory insights for in-house legal teams, and more.
Time Management for Lawyers: Win Back Hours with Delegation
Master time management for lawyers through effective delegation. Learn proven strategies to train your team, boost productivity, & reclaim your time.
Lawyers Weekly: Reflections on 2025 and APAC Legal Predictions for 2026
Jacob Flax reflects on 2025's shifts in legal operations across APAC, and predicts how 2026 brings accelerated adoption of flexible legal talent, AI, and portfolio-based legal resource management.
Attracting and Retaining Top Legal Talent: Building High-Performance Legal Teams
Discover how to build high-performance legal teams through trust, development, and strategic talent retention—beyond bigger budgets or new tech.
AI for In-House Legal Teams: A Practical Playbook for Fast, Safe Wins
Practical strategies for in-house legal teams to adopt AI safely — from defining problems to proving ROI without compromising security or quality.
Balancing Innovation and Governance: How Legal Teams Manage AI Risk
Learn how legal teams balance AI innovation with governance. Mastercard shares practical insights on managing risk, data protection, & implementation.
Finding Professional Confidence, Personal Balance: How Axiom Empowered a Commercial Attorney's Career Transformation
Discover how Axiom empowered commercial attorney Eileen to rebuild her career and confidence while balancing single parenthood after personal tragedy.
Immediate Impact through Legal Operations: Sharon's Journey from In-House Attorney to Strategic Problem Solver
Former in-house attorney Sharon shares how transitioning to legal operations enabled greater impact, flexibility, and meaningful project work.
Unlocking a Career at the Intersection of Technology and Law through Axiom
William is a data privacy attorney who navigates AI & cybersecurity law, leveraging his software development background to deliver practical solutions.
Building a Legal Career without Boundaries: Spotlight on Axiom Attorney Michael
Michael is a corporate counsel building his career across Fortune 100 companies in pharma & tech, gaining diverse expertise through the flexibility Axiom offers.
Bringing a Human Connection to Law and Ministry
Conan is a commercial lawyer in London who has spent nearly 16 years at Axiom, balancing his legal career with ministry through the flexibility the ALSP offers.
The Hidden Crisis Destroying In-House Legal Teams: How to Retain Legal Talent
Discover why 46% of satisfied in-house lawyers are job hunting and how ALSPs cut attrition risk by 50%. New research reveals the hidden retention crisis.
Why Half Your Legal Team Is Job Hunting — And What It Means for Retention
Half of in-house legal professionals are job hunting. New research reveals departments using ALSPs cut attrition risk by 50%. Download the findings.
The Global Disconnect: Why Legal Departments Are Diagnosing Problems They Can't Solve
Legal teams globally face identical challenges but lack capacity to solve them. Discover why flexible resourcing is key to legal department success in 2026.
State Privacy Laws: 2026 Changes & Compliance
Navigate 2026 state privacy law changes across 15 states. Learn compliance requirements for Indiana, Kentucky, Rhode Island & key CCPA updates.
Digital Finance, Real Risks: Insights from Axiom's Legal Roundtable
Explore insights on how financial services legal departments are navigating AI implementation challenges, quality concerns, and evolving hiring practices.
- North America
- Must Read
- Expertise
- Legal Department Management
- Work and Career
- Perspectives
- State of the Legal Industry
- Legal Technology
- United Kingdom
- Australia
- Hong Kong
- Artificial Intelligence
- Singapore
- General Counsel
- Central Europe
- Legal Operations
- Solutions
- Spotlight
- Regulatory & Compliance
- Data Privacy & Cybersecurity
- Commercial & Contract Law
- Technology
- Corporate Law
- Axiom in the News
- Global
- Tech+Talent
- Featured Talent Spotlight
- Finance
- Large Projects
- Videos
- Healthcare
- Cost Savings
- Budgeting Report
- Capital Markets
- Diversified Financial Services
- Intellectual Property
- Labor & Employment
- Law Firms
- In-House Report
- Secondments
- Commercial Transaction
- DGC Report
- Investment Banking
- Litigation
- Regulatory Response
- Banking
- Consulting
- Energy
- Financial Services
- GC Report
- Insurance
- Legal Support Professionals
- Mergers and Acquisitions
- News
- Pharmaceuticals
- Recruitment Solutions
- Retail
Get more of our resources for legal professionals like you.

