Harbottle & Lewis advises Ovation Rights on landmark acquisition of Sir Richard Stilgoe’s theatrical rights catalogue

We have advised Ovation Rights on its acquisition of Sir Richard Stilgoe’s rights in some of the most successful stage musicals of all time, including The Phantom of the Opera and Starlight Express. The transaction represents one of the most significant acquisitions of theatrical rights in recent years, marking a pivotal step in recognising the enduring value of theatrical rights and the legacies behind them.

Founded and led by producer Jamie Hendry and former Amazon executive Philip Green, Ovation Rights introduces the scale and strategy ordinarily seen with music catalogue acquisitions to the creators and rightsholders of major plays and musicals. The company collaborates closely with authors, composers, lyricists and estates, working as custodians to protect legacies, honour artistic visions and passionately champion works.

Our team was led by partners Neil Adleman and Charles Leveque, with support from managing associate Teresa Walker and associates Emma Riggs and David Jones and with partner David Scott advising on corporate tax matters.

On working with Harbottle & Lewis, Jamie Hendry commented: “Working with Harbottle & Lewis has been exceptional throughout this transaction. The team understood the unique nature of theatrical rights acquisitions and provided invaluable guidance as we navigated this deal. Their expertise in entertainment law, combined with their commercial understanding of our vision for Ovation Rights, made them the perfect partners for this acquisition. As we continue to build our portfolio and support artists’ legacies, we know we have trusted advisors who share our commitment to protecting and championing the works that have shaped global theatre.”

Neil Adleman added: “We are delighted to have supported the Ovation Rights team on this groundbreaking acquisition. This transaction demonstrates the significant value and enduring appeal of theatrical rights, and we look forward to seeing Ovation Rights continue to invest in artists and rightsholders as custodians of these remarkable legacies.”

COURT OF APPEAL VERDICT IN EXCLUSION CLAUSE DISPUTE

In February 2025 the Court of Appeal (by a 2:1 majority) dismissed an appeal brought by EE against Virgin Mobile in relation to a significant claim arising out of a telecommunications supply agreement.

The Court of Appeal agreed with the first instance decision that the exclusion clause excluded EE’s entire £24.6m loss of profit claim against Virgin Mobile.

EE claimed that it had suffered loss and damage in the amount of £24.6m as a result of Virgin Mobile breaching an exclusivity obligation in the telecommunications supply agreement, because EE had lost the revenue that it would have received from Virgin Mobile under the terms of the agreement had the exclusivity obligation not been breached.

Virgin Mobile denied breaching the agreement as alleged but argued that, in any event, EE’s claim was precluded because it was, in substance, a claim for anticipated profits. It therefore fell within the scope of the exclusion clause in the agreement which provided that “Neither Party shall be liable to the other in respect of … anticipated profits”.

EE argued that this interpretation could not be correct because (amongst other things), on the facts which occurred, EE did not have a wasted expenditure claim or a good argument for an injunction, so excluding the loss of profits claim would leave EE without an effective remedy, creating commercial absurdity and defeating the main purpose of the agreement.

The majority of the Court of Appeal rejected this argument because the specific facts which occurred, where no alternative remedy was viable, were not known to the parties when they entered into the agreement and therefore should not affect its interpretation. It was held that, applying the proper legal principles, the exclusion clause did preclude EE’s entire claim.

However, the Court of Appeal did not reach this conclusion easily, and indeed Phillips LJ dissented, noting that “it would be surprising if the parties intended that [Virgin Media] could breach the key exclusivity provision, unlawfully diverting its customers to a third party supplier, without incurring liability to pay EE damages reflecting the loss of revenue resulting from that breach”.

This case provides a further example of the unpredictability of the interpretation of exclusion clauses and the importance of clear, future-proof, contract drafting.

Important amendments to procurement legislation

On 24 February 2025 the Procurement Act 2023 (PA 2023) came into force.

This is significant for both public sector entities and their suppliers because the PA 2023 replaces the well-established EU-founded regime under the Public Contracts Regulations 2015 which previously governed public sector procurement processes.

The most striking change to the law is that the PA 2023 introduces a new supplier exclusion and debarment regime which means that suppliers who fail to meet particular standards or pose particular risks (for example, risks to national security) can be debarred from tendering for public contracts. This goes further than the previous regime which only allowed for suppliers to be excluded from particular projects.

In addition to the obvious financial implications of being precluded from participating in new tenders or being awarded call-off contracts, there are likely to be reputational consequences for the affected suppliers as debarred suppliers will be added to a public register, with the ground for their debarment also given.

There are routes to challenge disbarment but, just like any other public procurement challenge, it is advisable to take action quickly and obtain specialist advice to avoid falling foul of the procedural hurdles and limitation issues which claims of this nature often face.

Trump saves TikTok: Influencing the influencers

President Trump will reverse the TikTok ban within hours of being sworn in as President of the United States, as he promises to find a solution for the 170 million TikTok users in the United States (US). The US ban officially came into force at midnight on 19 January 2025.

The US, and President Trump’s ‘new best friend’ Elon Musk, know a lot about the power of social media, but can we really expect TikTok to sell to a US company? The US played a game of chicken with TikTok and it didn’t flinch – shutting its US site down, rather than handing over control. With the potential of a foreign adversary having access to its population, and the mass market data TikTok controls, the US would prefer to trust one of its own with such power.

Social media is a powerful tool for influencing its users, and it is clear that the US would prefer to keep control of its influencers rather than allow the Chinese to wield such influence. The TikTok ban has highlighted a much bigger issue, which is the power of social media and mass market data sets. Can we trust social media platforms with such data, irrespective of where they are based? The need for proper regulation and governance is clear and this must be addressed. Even in the land of the free, who is guarding the gatekeepers?

Alleged ‘Smear Campaigns’ under the legal spotlight in the UK and USA

A recent UK judgment and a number of US court claims have referenced allegations of sophisticated ‘smear campaigns’ being conducted against the claimants by business or personal rivals.

Last week saw judgment on a preliminary issue in Marinakis v Karipidis & Ors*, a claim brought by the owner of Nottingham Forest Football Club who has sued a number of people and companies who he alleges have conducted a defamatory public relations campaign against him. It is said that this has involved the creation of websites, videos, social media posts, and even mobile advertising boards, to make serious allegations against him disguised as a ‘grassroots’ campaign by Nottingham Forest fans. The claim continues.

In unrelated disputes, a number of US celebrities have also recently alleged they are the target of ‘hostile’ campaigns by others, designed to damage their reputation, and have commenced legal proceedings in response. It has been reported that these campaigns involved widespread inauthentic social media postings, and other attempts to establish public narratives critical of the claimants.

One similarity between the UK and one US case is evidence obtained by claimants from Public Relations firms alleged to have been involved.

The legal risks of engaging in such campaigns are clearly obvious.

*Marinakis v Karipidis & Ors [2025] EWHC 13 (KB) (10 January 2025)

Meta to end third party fact checking

Mark Zuckerberg‘s announcement that Meta will end its third party fact checking programme is the latest threat to the integrity of online data.

We live in a world where misinformation can spread quickly, and where bots and targeted posts can be used to push false stories. The harm is greater when large parts of society now obtain their news solely from social media and chat groups, and when algorithms push “stories for you” to specific user groups entrenching beliefs, and polarising positions. This is the same no matter which side of a debate you are on.

Meta says it has programmes in place to spot misinformation, and it will rely on its own community to moderate content, but the potential for misuse is huge, and the need to guard against misinformation is greater than ever. If we are being generous perhaps Zuckerberg felt like King Canute, unable to stem the tide of misinformation flooding the beach.

This latest development highlights the need for a comprehensive strategy to deal with misinformation on social media. This can include calling out false claims, enforcing social media terms of use, which prevents the posting of harmful and unlawful content, or taking action through the courts.

All of this is turbo charged by AI which harnesses its data from the net, so misinformation can not be left unchecked. Apple has faced calls to withdraw its AI feature that has been pushing out inaccurate summaries of BBC content to its latest AI enabled iPhones.

There is of course an old fashioned technology that is fact checked, and that is held accountable through editorial and legal processes. It is found with traditional newspapers and broadcasters. If we can respect proper journalism with accuracy at its core it will benefit us all.

Emma Wright and Rupam Davé contribute to the 18th edition of the ICLG

Our technology, data and digital team has written the UK Q&A chapter on ICLG with Emma, as contributing editor, writing an expert analysis chapter which provides an overview of telecoms in 2025. In addition, Emma and Rupam have together written the UK Q&A chapter in the guide.

Emma’s chapter gives an overview of the common issues currently impacting telecoms law and regulation, particularly on the UK’s efforts to regulate online content through the establishment of the Online Safety Act and the challenges of regulating such content in the aftermath of major global events. The chapter also addresses the surge in interest surrounding generative artificial intelligence and the associated concerns about the spread of disinformation. This chapter is available to read in full here.

The UK Q&A chapter put together by the team looks in detail at common issues in telecoms, media and internet laws and regulations from a UK perspective. This chapter can be read in full here.

The ICLG series covers 58 practice areas and brings cross-border insights to legal practitioners worldwide. The Telecoms, Media & Internet section covers the key issues in the laws and regulations of this area including telecoms, radio spectrum, cybersecurity, interception, encryption, data retention, distribution of audio-visual media, internet infrastructure, and industry changes across 18 jurisdictions.

The UK’s data protection regulator publishes a new code of conduct for UK private investigators and litigation services

On 13 November, the Information Commissioner’s Office (ICO) approved and published a new sector-owned code of conduct – the Association of British Investigators Limited (ABI) UK GDPR Code of Conduct for Investigative and Litigation Support Services (Code).

What is the Code?

The Code seeks to address key challenges faced by investigators and enable code members to demonstrate compliance with specific areas of data protection law in the provision of investigative and litigation support services.

It aims to provide sector-specific guidance and to increase accountability in handling personal data. As such, by complying with the Code, you are complying with data protection laws in the UK.

The Code includes advice, guidance, and practical examples in relation to:

  • the roles and responsibilities of investigators;
  • how to conduct Data Protection Impact Assessments;
  • identification of the lawful basis for processing personal data;
  • Legitimate Interests Assessments including for invisible processing such as covert surveillance, tracking devices, background checks and social media monitoring; and
  • consent to share when tracing and locating individuals in certain cases.

How does the Code help your private investigation or litigation service?

  • Public confidence: Verified adherence to the Code is intended to give confidence to users and subjects of investigative and litigation support services. It demonstrates that Code members comply with key aspects of data protection law and operate to a high standard in key areas.
  • Reduce risk and enforcement action: Showing compliance with the Code reduces the risks of enforcement action from the ICO. This means you are less likely to receive fines, reprimands or other regulatory action in the event of a breach of data protection laws.
  • Due diligence carried out by users: Users of investigation and litigation services (particularly other businesses who are controllers) should be carrying out diligence on service providers. Your prospective clients may check whether you adhere to the Code when they are carrying out due diligence prior to instructing you.

Can I sign up to the Code? If so, how?

Investigators and litigation services can voluntarily sign up for the Code and Code membership is managed by an independent ICO approved and UKAS accredited monitoring body. Code members must satisfy the monitoring body with the requirements explained in Appendix I to the Code. Such requirements include:

  • Administrative evidence: Such as registration with the ICO, basic DBS disclosure, two references, finance checks and CV.
  • Training: Satisfactory completion and maintenance of data protection training to the level comparable to the ABI UK GDPR compliance workshop, or training to an equivalent standard on the areas covered by the Code – including data protection impact assessments, lawful bases and more.
  • Roles and responsibilities: Evidence that the Code member has documented and communicated to its client the roles and responsibilities in respect of the data processing undertaken in the delivery of Code services. This could be evidenced for example by providing a copy of the client engagement letter and/or contract.
  • Case extracts: Samples of Data Protection Impact Assessments, lawful bases relied on, Legitimate Interest Assessments. In particular for children and the Code notes that Code members must not maintain a register of criminal convictions.
  • Complaints: Evidence of any complaints received by the Code member from individuals in relation to data protection and the steps the Code member took to respond to the complaint and where relevant, evidence that in relation to monitoring body investigations of alleged breaches of the Code, the Code member has communicated with the monitoring body in accordance with the Code and the cooperation criteria in this Code.

The Code builds on the existing standards and criteria required for ABI membership however, Code members are not required to be ABI members and Code membership is available to any sector agency that meets the Code member criteria as at Appendix I to the Code, whether affiliated to the ABI or not.

What to do next?

We can assist you with your data protection compliance programme ahead of signing up to the Code. The following checklist describes the compliance steps that we suggest to cover:

  • Registration with the ICO: As a data controller you are obliged to pay a fee to the ICO depending on your size.
  • Records of processing activity: This document explains what data you process, how, who it is shared with and why. This is a legal requirement under GDPR (in most cases) but in any case will be a necessary exercise in order to satisfy the other requirements below.
  • Privacy policies: Such as website privacy policy, employees privacy policy, recruitment privacy policy, privacy policy for users and third parties subject to the services – this is to comply with transparency requirements.
  • Cookie audit: Policy and mechanism cookie banner – this is the consent mechanism that allows you to drop cookies. A good cookie banner will be tailored to your needs and allow users to decide what type of cookies they want. This is a requirement under the electronic marketing rules.
  • Assessments: Such as Data Protection Impact Assessments, Legitimate Interests Assessments and Transfer Risk Assessments – this is to demonstrate your compliance and prove accountability.
  • Supplier onboarding checklist and procedure and template data sharing clauses: To ensure you have carried out due diligence on any third parties you choose to use to help fulfil your services.
  • Data protection rights procedure: This document sets out how to manage DSARs and other requests in relation to an individual’s data. Dealing with these requests is a legal requirement, getting it wrong can lead to fines and to reputational damage.
  • Security incident management policy: This document sets out what each team needs to do in the event of a data breach. Dealing with these requests is a legal requirement, getting it wrong can lead to fines and to reputational damage.
  • Regular privacy training: We can provide introductory or further training sessions depending on what your staff have already received. In order to comply with your security obligations you must train people to ensure that human error is avoided to the extent possible and that they understand what the GDPR requirements are.
  • Data handling policy: This policy contains an explanation on why data protection is important and how you and your staff and comply with data protections laws on a day to day basis.
  • BYOD and acceptable use policy: This policy would contain rules on how employees are allowed to use their personal devices including acceptable use practices.
  • Data security policy: This policy documents how you keep data safe from an organisational and technical perspective.
  • Data retention policy: This document explains how long you keep each type of data.

If you would like more information, please feel free to reach out to one of our dedicated data protection lawyers, or if you would like keep up to date on the latest in data protection, please subscribe to our newsletter, The Data Download here.

Further details about the Code can be found here.

The UK’s data protection regulator publishes a new code of conduct for UK private investigators and litigation services

On 13 November, the Information Commissioner’s Office (ICO) approved and published a new sector-owned code of conduct – the Association of British Investigators Limited (ABI) UK GDPR Code of Conduct for Investigative and Litigation Support Services (Code).

What is the Code?

The Code seeks to address key challenges faced by investigators and enable code members to demonstrate compliance with specific areas of data protection law in the provision of investigative and litigation support services.

It aims to provide sector-specific guidance and to increase accountability in handling personal data. As such, by complying with the Code, you are complying with data protection laws in the UK.

The Code includes advice, guidance, and practical examples in relation to:

  • the roles and responsibilities of investigators;
  • how to conduct Data Protection Impact Assessments;
  • identification of the lawful basis for processing personal data;
  • Legitimate Interests Assessments including for invisible processing such as covert surveillance, tracking devices, background checks and social media monitoring; and
  • consent to share when tracing and locating individuals in certain cases.

How does the Code help your private investigation or litigation service?

  • Public confidence: Verified adherence to the Code is intended to give confidence to users and subjects of investigative and litigation support services. It demonstrates that Code members comply with key aspects of data protection law and operate to a high standard in key areas.
  • Reduce risk and enforcement action: Showing compliance with the Code reduces the risks of enforcement action from the ICO. This means you are less likely to receive fines, reprimands or other regulatory action in the event of a breach of data protection laws.
  • Due diligence carried out by users: Users of investigation and litigation services (particularly other businesses who are controllers) should be carrying out diligence on service providers. Your prospective clients may check whether you adhere to the Code when they are carrying out due diligence prior to instructing you.

Can I sign up to the Code? If so, how?

Investigators and litigation services can voluntarily sign up for the Code and Code membership is managed by an independent ICO approved and UKAS accredited monitoring body. Code members must satisfy the monitoring body with the requirements explained in Appendix I to the Code. Such requirements include:

  • Administrative evidence: Such as registration with the ICO, basic DBS disclosure, two references, finance checks and CV.
  • Training: Satisfactory completion and maintenance of data protection training to the level comparable to the ABI UK GDPR compliance workshop, or training to an equivalent standard on the areas covered by the Code – including data protection impact assessments, lawful bases and more.
  • Roles and responsibilities: Evidence that the Code member has documented and communicated to its client the roles and responsibilities in respect of the data processing undertaken in the delivery of Code services. This could be evidenced for example by providing a copy of the client engagement letter and/or contract.
  • Case extracts: Samples of Data Protection Impact Assessments, lawful bases relied on, Legitimate Interest Assessments. In particular for children and the Code notes that Code members must not maintain a register of criminal convictions.
  • Complaints: Evidence of any complaints received by the Code member from individuals in relation to data protection and the steps the Code member took to respond to the complaint and where relevant, evidence that in relation to monitoring body investigations of alleged breaches of the Code, the Code member has communicated with the monitoring body in accordance with the Code and the cooperation criteria in this Code.

The Code builds on the existing standards and criteria required for ABI membership however, Code members are not required to be ABI members and Code membership is available to any sector agency that meets the Code member criteria as at Appendix I to the Code, whether affiliated to the ABI or not.

What to do next?

We can assist you with your data protection compliance programme ahead of signing up to the Code. The following checklist describes the compliance steps that we suggest to cover:

  • Registration with the ICO: As a data controller you are obliged to pay a fee to the ICO depending on your size.
  • Records of processing activity: This document explains what data you process, how, who it is shared with and why. This is a legal requirement under GDPR (in most cases) but in any case will be a necessary exercise in order to satisfy the other requirements below.
  • Privacy policies: Such as website privacy policy, employees privacy policy, recruitment privacy policy, privacy policy for users and third parties subject to the services – this is to comply with transparency requirements.
  • Cookie audit: Policy and mechanism cookie banner – this is the consent mechanism that allows you to drop cookies. A good cookie banner will be tailored to your needs and allow users to decide what type of cookies they want. This is a requirement under the electronic marketing rules.
  • Assessments: Such as Data Protection Impact Assessments, Legitimate Interests Assessments and Transfer Risk Assessments – this is to demonstrate your compliance and prove accountability.
  • Supplier onboarding checklist and procedure and template data sharing clauses: To ensure you have carried out due diligence on any third parties you choose to use to help fulfil your services.
  • Data protection rights procedure: This document sets out how to manage DSARs and other requests in relation to an individual’s data. Dealing with these requests is a legal requirement, getting it wrong can lead to fines and to reputational damage.
  • Security incident management policy: This document sets out what each team needs to do in the event of a data breach. Dealing with these requests is a legal requirement, getting it wrong can lead to fines and to reputational damage.
  • Regular privacy training: We can provide introductory or further training sessions depending on what your staff have already received. In order to comply with your security obligations you must train people to ensure that human error is avoided to the extent possible and that they understand what the GDPR requirements are.
  • Data handling policy: This policy contains an explanation on why data protection is important and how you and your staff and comply with data protections laws on a day to day basis.
  • BYOD and acceptable use policy: This policy would contain rules on how employees are allowed to use their personal devices including acceptable use practices.
  • Data security policy: This policy documents how you keep data safe from an organisational and technical perspective.
  • Data retention policy: This document explains how long you keep each type of data.

If you would like more information, please feel free to reach out to one of our dedicated data protection lawyers, or if you would like keep up to date on the latest in data protection, please subscribe to our newsletter, The Data Download here.

Further details about the Code can be found here.

Emma Wright included in top 20 Most Influential Women in UK Tech 2024

Emma Wright, partner and head of our technology, data and digital group, has been included in the top 20 Most Influential Women in UK Tech 2024. Emma is the only practising lawyer to be included in the top 50.

Emma was commended for her work with the OECD, WEF and the ITU on the regulation of AI, as well as her work with the Ditchley Foundation to consider whether the collaborative approach used for telecoms can also work for AI regulation.

The list, compiled by Computer Weekly, showcases the most influential and successful women in the technology industry, shining a light on the sector’s role models who look to inspire the next generation of women in tech with the aim of creating a more diverse and inclusive sector.

The top 50 shortlist was whittled down by a panel of expert judges from a longlist of more than 700 nominated women. You can find the full list here.

Emma also gave a keynote speech at this week’s Diversity in Tech conference hosted by Harvey Nash and Computer Weekly.