GDPR 2026 Archives -

Information Policy in 2026: Why It Has Never Been More Important

Information — how it is created, stored, shared, protected, and governed — sits at the heart of virtually every significant regulatory challenge facing organisations today. GDPR compliance, data breach response, AI governance, national security frameworks, internet governance, and the legal obligations of internet service providers all converge on a single discipline: information policy.

Baretzky & Partners LLP is led by Dr. Ricardo Baretzky, a PhD in Law specialising in Information Policy and National Cyber Security — bringing a depth of expertise to this field that very few advisory practices can match. Our Information Policy & Security practice provides comprehensive advisory on information governance, security policies, and data protection frameworks for organisations operating across multiple jurisdictions.

From GDPR compliance and data governance frameworks to internet governance and information policy in the government sector, our practice covers the full spectrum of information-related legal and regulatory challenges facing organisations today.

GDPR in 2026: The Enforcement Landscape Has Changed

The General Data Protection Regulation has been in force since 2018, but the enforcement landscape has changed dramatically. Data protection authorities across the EU have significantly increased the frequency and scale of enforcement actions — with multi-million euro penalties becoming routine for organisations that fail to implement adequate technical and organisational measures, conduct proper Data Protection Impact Assessments, or manage data breaches effectively.

Under UK GDPR (which applies post-Brexit with substantial equivalence to EU GDPR), the Information Commissioner’s Office has similarly intensified its enforcement posture. Organisations with operations in both the EU and UK face the additional complexity of managing two regulatory regimes that are closely aligned but not identical.

Key areas of enforcement focus in 2026 include cross-border data transfers (particularly in light of the ongoing evolution of Standard Contractual Clauses and adequacy decisions), AI-generated personal data processing, and the security of personal data held by third-party processors.

The Four Core Information Policy Services

1. Data Protection and GDPR Compliance

Comprehensive GDPR and data protection advisory must be structured around the specific risk profile of each organisation — not a generic compliance checklist. Our approach begins with a GDPR gap analysis: a systematic assessment of where current policies, procedures, and technical measures fall short of applicable requirements.

From this foundation, we provide privacy policy development, Data Protection Impact Assessments for high-risk processing activities, DPO (Data Protection Officer) advisory services, and cross-border data transfer compliance. Subject Access Request management — one of the most operationally challenging aspects of GDPR compliance — is an area where specialist advisory can significantly reduce both compliance burden and legal risk.

For organisations processing significant volumes of EU personal data, ensuring that processor and sub-processor agreements are compliant, that Article 30 records of processing activities are current, and that breach notification procedures are tested and functional is a continuous compliance obligation, not a one-time exercise.

2. Information Security Policy and Governance

Information security governance is the framework within which technical security controls operate. Without robust policy frameworks — covering information classification, access control, incident response, and security governance structures — even the most sophisticated technical controls will be undermined by process failures and human factors.

Our information security policy advisory covers the full range of governance requirements: information security policy design, ISO 27001 alignment, security governance frameworks, incident response policy, access control frameworks, and PCI DSS advisory for organisations in scope for payment card industry standards.

ISO 27001 certification is increasingly required by enterprise clients as a condition of doing business, and provides a credible framework for demonstrating the adequacy of information security management to regulators, clients, and insurers alike.

3. Information Policy in Legal and Government Contexts

The intersection of information policy and the government sector presents distinctive challenges. Public sector organisations and those working with government clients must navigate a complex landscape of obligations: freedom of information requirements, national security information frameworks, the specific data protection obligations applicable to law enforcement and national security processing, and internet governance frameworks that are evolving rapidly under both EU and international pressure.

Our practice, led by a PhD specialist in National Cyber Security, provides advisory on these complex intersections — helping organisations understand where their information policy obligations arise and how to build frameworks that satisfy them without compromising operational effectiveness.

4. WISP and ISP Information Policy Advisory

Wireless internet service providers and ISPs face a distinctive set of information policy obligations. Lawful intercept compliance, data retention policy, content regulation advisory, and the full range of ISP regulatory compliance requirements create a complex operational environment that demands specialist expertise.

Data retention obligations in particular vary significantly across jurisdictions — with some requiring extensive retention of communications data for law enforcement purposes and others restricting it. Navigating these requirements while maintaining operational efficiency and protecting user privacy is a specialist discipline where generic legal advice is rarely adequate.

Cross-Border Data Transfers: Navigating Post-Schrems II Complexity

One of the most technically complex areas of GDPR compliance remains cross-border data transfers — the movement of EU personal data to countries outside the European Economic Area that do not benefit from an adequacy decision. Since the Schrems II judgment invalidated the EU-US Privacy Shield in 2020, organisations have relied primarily on Standard Contractual Clauses supplemented by transfer impact assessments to legitimise such transfers.

The practical implementation of this framework is demanding. Transfer impact assessments must assess the law and practice of the destination country, evaluate whether that country’s legal regime provides essentially equivalent protection to EU law, and determine what supplementary measures (if any) can address identified deficiencies. For organisations with complex global data flows involving multiple destination countries, this is a significant ongoing compliance obligation.

The EU-US Data Privacy Framework, adopted in 2023, provides a mechanism for transfers to certified US organisations — but its durability remains subject to legal challenge, and organisations should maintain alternative transfer mechanisms as a precaution.

AI and Personal Data: The Emerging Frontier

The intersection of artificial intelligence and personal data protection has emerged as one of the most significant new information policy challenges of 2026. AI systems that process personal data — for profiling, automated decision-making, or training purposes — are subject to GDPR obligations that were not designed with AI in mind, creating interpretive challenges that regulators are still working through.

Key issues include the lawful basis for AI training data, transparency requirements for automated decision-making under Article 22, the categorisation of AI-generated inferences as personal data, and the application of data minimisation principles to machine learning systems that depend on large data sets.

The EU AI Act, which entered into force in 2024, adds a further layer of obligation for high-risk AI applications — requiring conformity assessments, technical documentation, and ongoing monitoring. Organisations developing or deploying AI systems must now navigate the intersection of GDPR and the AI Act, which do not always align neatly.

Information Governance Gaps: The Risk They Create

Information governance gaps — where an organisation’s policies, procedures, and controls fail to adequately govern its information assets — create exposure on multiple dimensions. Regulatory penalties for GDPR non-compliance can reach €20 million or 4% of global annual turnover, whichever is higher. Data breaches resulting from inadequate security measures create both regulatory and litigation exposure. And increasingly, cyber insurers are requiring evidence of robust information governance as a condition of coverage.

Beyond the direct financial exposure, information governance failures damage the trust that organisations depend on — with clients, employees, regulators, and the public. Rebuilding that trust after a significant data breach or regulatory investigation is a lengthy and costly process.

Baretzky & Partners: PhD-Led Information Policy Advisory

Our Information Policy & Security practice is built on a foundation of genuine expertise in a field that demands both legal depth and technical understanding. Led by Dr. Ricardo Baretzky — PhD in Law with specialisation in Information Policy and National Cyber Security — our practice covers the full spectrum of information governance challenges facing organisations in 2026.

We work with organisations across sectors and jurisdictions, providing advisory that bridges legal frameworks with practical operational implementation — ensuring that compliance programmes are not only technically sound but actually work in the organisations they are designed to serve.

Contact Baretzky & Partners LLP to request an information policy review or discuss your GDPR compliance needs. Initial consultations are strictly confidential.

Baretzky & Partners LLP provides strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.