UK ISPs forced to keep customer data by EU
An EU ruling comes into force which means that British ISPs will have to retain data by law, in order to aid police and intelligence agencies.

From this Sunday, internet service providers (ISPs) will be forced to store data from their customers for up to one year under the EU Data Retention Directive.
This data will include names, dates of birth, billing addresses and credit card information, in addition to IP addresses and session data.
The directive will represent a move from the current voluntary scheme that ISPs have with law enforcement, to one that meets minimum requirements across the EU.
Supporters claim that the directive is necessary as police, security and intelligence agencies all rely heavily on communications data to carry out their law enforcement and public safety functions efficiently.
It's believed that data will be available to support long running investigations such as terrorism, and will help build stronger prosecution cases.
However, opponents have criticised the proposals due to reasons like the cost of the operation - estimated at 46 million over a four year period - and low confidence about businesses' handling of data security.
Jamie Cowper of encryption firm PGP Corporation said that ISPs needed to take their obligations seriously.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He said in a statement: "If privacy violation is to be avoided, and the huge cost of the operation is to be justified, then the security of public's data must be watertight."
-
Enterprises face delicate balancing act with data center sustainability goals
News High energy consumption, raw material requirements, and physical space constraints are holding back data center sustainability efforts, according to new research from Seagate.
By Emma Woollacott
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
‘Europe could do it, but it's chosen not to do it’: Eric Schmidt thinks EU regulation will stifle AI innovation – but Britain has a huge opportunity
News Former Google CEO Eric Schmidt believes EU AI regulation is hampering innovation in the region and placing enterprises at a disadvantage.
By Ross Kelly
-
The EU just shelved its AI liability directive
News The European Commission has scrapped plans to introduce the AI Liability Directive aimed at protecting consumers from harmful AI systems.
By Ross Kelly
-
A big enforcement deadline for the EU AI Act just passed – here's what you need to know
News The first set of compliance deadlines for the EU AI Act passed on the 2nd of February, and enterprises are urged to ramp up preparations for future deadlines.
By George Fitzmaurice
-
EU agrees amendments to Cyber Solidarity Act in bid to create ‘cyber shield’ for member states
News The EU’s Cyber Solidarity Act will provide new mechanisms for authorities to bolster union-wide security practices
By Emma Woollacott
-
The EU's 'long-arm' regulatory approach could create frosty US environment for European tech firms
Analysis US tech firms are throwing their toys out of the pram over the EU’s Digital Markets Act, but will this come back to bite European companies?
By Solomon Klappholz
-
EU AI Act risks collapse if consensus not reached, experts warn
Analysis Industry stakeholders have warned the EU AI Act could stifle innovation ahead of a crunch decision
By Ross Kelly
-
Three quarters of UK firms unprepared for NIS2 regulations, study finds
News Senior management can be held personally liable for non-compliance under NIS2 rules
By Ross Kelly
-
US-UK data bridge: Everything you need to know
News The US-UK data bridge will ease the complexity of transatlantic data transfers
By Ross Kelly