The CNIL investigated mobile applications using embedded software development kit (SDK) and ad biding gathering personal data even when the application is not in use. The data collection is activated by default, which is contrary to the principal of privacy by design.
There has been and still remains interrogations and uncertainties around the scope of application of the General Data Protection Regulation.
Since the UK referendum vote for BREXIT much has been speculated about the situation of the UK with regard to compliance to the GDPR enforceable from 28 May 2018. Although they are uncertainties, the recent UK Information Commissioner speech has reinforced the opinion that UK businesses need to get ready to comply.