
Insights
Analysis of telecoms, data, payments and technology regulation and transactions
Clear, practical commentary on legal and regulatory developments affecting telecoms operators, digital infrastructure providers, technology companies, financial institutions, fintechs and investors.
Our blogging history
We have been publishing insights since 2010, when Rob first built the website on WordPress. From the outset, the aim was the same: careful research, precise language and analysis that explains not just the legal issue, but its practical and commercial effect.
That remains our approach today. Artificial intelligence now helps with parts of the research and drafting process, and it has supported the development of this website. But technology does not replace judgement, experience or specialist expertise. Our insights are shaped by real advisory work across regulation, compliance and transactions.
Through this Insights section, Bratby Law aims to provide clear analysis that helps organisations make informed decisions in complex and fast-moving areas of law and regulation. For advice on a specific issue, regulatory strategy or a transaction, please get in touch.
Recent articles
-
The EU AI Act explained: what applies to UK businesses and when
The EU AI Act explained for UK businesses: what already applies, the high-risk dates moved to 2027 and 2028 by the Digital Omnibus, penalties and the authorised representative duty.
-
Does the Online Safety Act apply to my service?
In short: three tests answer “does the Online Safety Act apply to my service?” as at 28 August 2026: whether the service enables user-generated content, includes a search engine or publishes pornographic content (ss 3 and 80); whether it has links with the UK (s 4, or s 80(4) for pornography providers); and whether an…
-
The Bailey Mansion House speech: growth, regulation and the future of money
In short: the Bailey Mansion House speech of 14 July 2026 links growth to regulatory design. Andrew Bailey applies that test to bank capital, tokenised money and AI. The Bank’s test for new forms of sterling is whether they preserve nominal value and settlement finality. Two deadlines are now close: the Retail Payments Infrastructure Board…
-
Digital Regulation | EU | UK
Meta child safety settlement: implications for UK and EU platforms
In short: The Meta child safety settlement, filed in the Northern District of California on 26 August 2026, commits Meta to a two-hour default daily limit for teenagers, an overnight night access mode and hidden like counts on Instagram and Facebook. The agreement limits those obligations to the settling US states. Neither Ofcom nor the…
-
Digital Omnibus on AI: the amended EU AI Act timetable
In short: the Digital Omnibus on AI, Regulation (EU) 2026/1744, has been in force since 27 July 2026. It moves the EU AI Act’s high-risk obligations to 2 December 2027 for AI in listed uses such as recruitment and credit scoring, and to 2 August 2028 for AI built into a regulated product. The Article…
-
Apple gatekeeper judgment: when a DMA obligation can be challenged
In short: the Apple gatekeeper judgment of 8 July 2026 dismissed all three of Apple’s actions against its Digital Markets Act designation. The General Court held that a gatekeeper cannot challenge Article 6(7) in an action against its designation decision, because designation only starts a six-month clock; the duty comes from Article 3(10) read with…
-
CMA drip pricing investigations: the warning that came first
In short: The CMA drip pricing investigations into Trainline, Virgin Atlantic and RED Driving School were opened on 18 August 2026, and each firm had received a CMA advisory letter nine months earlier. Under section 225(4)(b) of the DMCCA, omitting the total price from an invitation to purchase is unfair without proof that any consumer…
-
Bulk email data protection: why BCC is not a control
In short: Bulk email data protection falls within the security duty in section 40 of the Data Protection Act 2018, which the Information Commissioner applied to the Metropolitan Police in a reprimand and enforcement notice dated 27 July 2026. Telling staff to use BCC was not a sufficient measure, and unevidenced training infringed section 40…
-
The objective test for data subject consent, and what the court left open
In short: the objective test for data subject consent means a data controller proves consent by what the data subject did, not by what was in their mind. In RTM v Bonne Terre [2026] EWCA Civ 488, handed down on 21 April 2026, the Court of Appeal reversed the subjective test the High Court had…
-
CMA markets remedies review: 23 removals and what replaces them
In short: the CMA markets remedies review covers 33 market investigation remedies made between 1987 and 2017. On 12 August 2026 the Competition and Markets Authority provisionally decided to remove 23 in full, remove 4 in part and retain 6. Representations close at 5pm on 11 September 2026, with a final decision expected in October…
-
ICO reprimand for cyber security failings: what Article 32 actually requires
In short: The ICO’s reprimand for cyber security failings, issued to ACRO Criminal Records Office on 7 August 2026, turns on named ownership of patch management and monitoring of security alerts under UK GDPR Article 32. A hacker held access to ACRO’s website for seven months, exposing sensitive data for up to 10,920 people. The…
-
FCA high-growth firms: what the 2026 review repeats from 2023
In short: the FCA high-growth firms review, published on 10 August 2026, covers a pilot with 15 asset management, wealth management and payments firms. Four of its findings repeat the FCA’s 2023 fast-growing firms review. A payment institution’s obligations are unchanged: regulation 6(6) of the Payment Services Regulations 2017 still requires governance proportionate to its…
Telecoms, data protection and payments regulation lawyers
Bratby Law advises on telecoms regulation, data protection, payments regulation, transactions and digital regulation across the communications, financial services and technology sectors.
How we work
Bratby Law works with clients in three ways: as direct legal advisers on specific matters, as specialist co-counsel supporting other legal teams, and as fractional general counsel on a longer-term retained basis. Each model delivers partner-level input without delegation.
Why Choose Bratby Law?
Sector expertise
Bratby Law advises exclusively across the telecoms, data and payments sectors. That concentration means deeper knowledge of the regulatory environment, faster analysis, and advice that reflects how regulators actually behave: not how the textbook says they should.
Senior delivery
Every instruction is handled by Rob Bratby personally. With 30 years’ experience spanning a secondment to Oftel, senior in-house roles at UK telecoms operators, and partnership at international law firms, you receive the analysis directly: not through a junior team. The firm uses AI tools to extend research capacity and accelerate document review, so senior judgment is applied to more of your matter, not less.
Current appointments
Rob Bratby currently holds fractional General Counsel appointments at TOTSCo, TelXL, Core and the UK Payments Initiative. These ongoing roles keep his advice grounded in how regulated businesses run day to day.
Ready to discuss your matter?
Prefer an RSS reader? Subscribe via RSS.
