Technology Briefing – May 2026

Welcome to the spring edition of our technology briefing, designed to keep you updated on the latest legal and regulatory developments in the technology sector.

In this edition, we unpack the EU AI Act’s transparency obligations, highlighting recent developments and timelines for compliance. Additionally, we explore how businesses can challenge procurement decisions in government IT contracts and review the CMA’s updated guidance on unfair contract terms marking 10 years since the Consumer Rights Act 2015 was introduced. We also address the latest updates in data protection law. Finally, we cover the UK Government’s recently published Report on Copyright and Artificial Intelligence, which follows its consultation.

Recent Harbottle highlights include advising on the sale of After Party Studios to SISTER Group and launching our Indie Games Collective to mentor early-stage games businesses. We also published a thought leadership piece on AI-enabled cyber threats and, at C5’s AI & crypto fraud conference, Lizzie Williams shared insights on resolving smart contract disputes.

IN THIS EDITION


EU AI Act transparency obligations: latest developments and key obligations

A core requirement imposed by the EU AI Act (the Act) is in respect of transparency obligations for the AI systems used. The majority of the Act is expected to come into force on 2 August 2026. The European Parliament, however, has agreed a proposal that would delay the obligations imposed in respect of high risk AI systems. 

Read more >


Government IT contracts: how to challenge the procurement process

If your business enters into contracts with public sector entities for the provision of IT or related services, you will be familiar with the public sector tender and procurement processes. But are you familiar with what can be done to challenge the outcome of those processes? 

Read more >


Unfair contract terms in consumer contracts: new draft guidance from the CMA

If you deal with consumers, then you need to know how consumer law applies to your contract terms and notices. Ten years on from the introduction of the Consumer Rights Act 2015, the Competition and Markets Authority is revising its current guidance on unfair contract terms. 

Read more >


UK Government holds off on immediate AI Copyright reform

The Government has published its much-anticipated Report on Copyright and Artificial Intelligence, which follows a consultation that ran from 17 December 2024 to 25 February 2025. 

Read more >


Data protection update

This update includes key developments such as the ICO-HMG memorandum on data protection, new provisions under the Data (Use and Access) Act, guidance on international data transfers and age assurance, and significant enforcement actions like fines for unsolicited marketing, misuse of biometric data, and breaches involving children’s data, alongside global concerns over AI and high-profile investigations. 

Read more >


HARBOTTLE HIGHLIGHTS

Deal announcement: sale of After Party Studios

We have recently advised the shareholders of After Party Studios, a digital-first creative production company, on the sale of a majority stake to SISTER Group. 

Read more >


Harbottle & Lewis Indie Games Collective (IGC)

We recently launched our IGC, a mentorship programme which offers legal guidance to early-stage games businesses, to help them navigate in their next steps in the industry.

Read more >


AI-enabled cybercrime

Our new thought leadership piece, developed with Sodali & Co and LevelBlue, builds on insights from our recent event. It highlights key AI-enabled cyber threats, offers practical talking points, and provides actionable recommendations to support informed discussions with risk, legal, and cyber security teams. 

Read here >


AI & crypto fraud and asset recovery conference

Lizzie Williams recently spoke at this annual conference hosted by C5 Communications. She joined a panel to discuss smart contract disputes: what they are, how to avoid them and how to resolve them. The session proved valuable for those interested in coded contracts.


Please contact our technology experts if you would like to discuss anything in this briefing.

EU AI Act Transparency Obligations: latest developments and key obligations

A core requirement imposed by the EU AI Act (the Act) is in respect of transparency obligations for the AI systems used.

The majority of the Act is expected to come into force on 2 August 2026. The European Parliament, however, has agreed a proposal that would delay the obligations imposed in respect of high risk AI systems. The remaining provisions of the Act remain largely unaffected, and businesses should operate on that basis, noting that breaching these obligations can result in a fine of up to EUR 15 million or 3% of their total worldwide annual turnover for the preceding financial year (whichever is higher).

The Act raised a number of questions around how companies would comply with their transparency obligations. This led to the creation of a draft code of practice (the “Code of Practice on Marking and Labelling of AI-generated content” (the Code)), integrating feedback from hundreds of participants and observers including industry, academia and other stakeholders.

The Code of Practice on marking and labelling of AI-generated content

The second draft of the Code was published on 3 March 2026 and a final version is expected by June 2026. The Code is subject to further amendments, but sets out four key requirements to demonstrate compliance:

  1. multi-layered marking through metadata embedding, imperceptible watermarking, or fingerprinting/logging;
  2. providers having to offer a free interface or publicly available tool enabling users and third parties to verify whether content is AI-generated;
  3. technical solutions for marking and detection must be effective and reliable; and
  4. continuous testing and improvement to keep pace with real-world developments.

The transparency obligations

The Code is underpinned by the underlying transparency obligations in the Act.

The extent of these obligations is influenced by different factors such as whether the AI system is classified as limited or high risk; and whether you are a deployer or provider.

For limited risk AI systems:

If you are a provider

A ‘provider’ is a company, individual, public authority, agency or body that: (a) develops, or procures the development of an AI system or general-purpose AI model; and (b) places it on the market or puts it into service under its own name or trademark. In other words, this applies to those who set out to create, or procure the creation of an AI system.

Providers of limited risk AI systems must comply with three core transparency requirements.

  1. AI systems must be designed to inform individuals that they are engaging with an AI system;
  2. Providers must ensure that outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated; and
  3. Technical solutions employed must be effective, interoperable, robust and reliable.

The question of how providers can satisfy these requirements has been a recurring area of discussion, such that the European Commission has stepped in to provide guidance via the voluntary code of practice on the transparency of AI-generated content. We discuss this in further detail below.

If you are a deployer

In contrast, a ‘deployer’ is a company, individual, public authority, agency or body using an AI system under its authority, except where the AI system is used in a personal non-professional activity.

Given that deployers are effectively users with little to no control over the AI system, they are subject to much fewer disclosure requirements. The Act only imposes obligations on deployers of three specific types of AI systems:

  1. emotion recognition or biometric categorisation systems;
  2. deepfakes, where the system generates or manipulates image, audio or video content; or
  3. systems generating or manipulating text published to inform the public on matters of public interest.

For high risk AI systems:

If you are a provider

Unsurprisingly, the Act imposes the most obligations for this category. In general, it will include requirements for providers to supply instructions for safe use and information about accuracy, robustness, and cybersecurity. Individuals overseeing such systems must be suitably qualified to understand the system’s capacities and limitations, with various recordkeeping and risk management protocols.

If you are a deployer

Similar to above, deployers face fewer but a broader set of obligations reflective of the higher risk AI system. These include the implementation of specific governance, monitoring, transparency and impact assessment requirements. The key obligations can be grouped under two headings:

Operational obligations

The deployer must implement appropriate measures to ensure the high-risk AI system is used in accordance with the relevant instructions for use, that input data is relevant and sufficiently representative for the intended purpose of the system, and monitor its operation in order to be able to inform the provider in the event it identifies any risks or serious incidents.

Control and risk management obligations

A deployer must conduct a fundamental rights impact assessment (FRIA) before deploying the system, assign human oversight to individuals with the necessary competence, train and regularly monitor the AI system for risks, and keep the logs of the AI system in an automatic and documented manner for at least six months.

Future outlook

The trajectory is unmistakable: the Act positions transparency as a core principle, which is going to impact design choices, user interfaces and governance processes. Organisations will be expected to comply with the Code and the underlying transparency obligations that underpin it.

Companies leveraging AI along their supply chain should therefore prioritise embedding and documenting transparency measures that can withstand both regulatory and legal scrutiny, while ensuring alignment with wider IP governance and strategic commercial decisions.

For more information the EU AI Act and the Code and how they might impact your business, contact Sacha Wilson and Jacky Lai.

Unfair contract terms in consumer contracts: new draft guidance from the CMA

If you deal with consumers, then you need to know how consumer law applies to your contract terms and notices.

Ten years on from the introduction of the Consumer Rights Act 2015 (the CRA), the Competition and Markets Authority (the CMA) is revising its current guidance on unfair contract terms.

The draft guidance is aimed at making the guidance more accessible, helping businesses better understand and comply with the CRA. The consultation closed on 19 March 2026. Once finalised, it will replace the existing guidance on unfair contract terms.

Which terms are unfair?

Contract terms are unfair if they tilt the rights and responsibilities excessively in favour of the supplier. The law currently uses a ‘fairness test’ by looking at the words in the contract, taking into consideration what is being sold, how a term relates to other terms in the contract, and all the circumstances at the time the term was agreed.

Certain terms and notices giving rise to particular concerns are ‘blacklisted’ and deemed as unsuitable for use with consumers. These include terms that exclude or restrict liability for death or personal injury resulting from negligence, a consumer’s statutory rights and any associated remedies. Blacklisted terms are never enforceable against a consumer.

What are the key changes in the draft guidance?

Enhanced CMA enforcement powers under the DMCC:

The updated guidance integrates the Digital Markets, Competition and Consumer Act 2024 (the DMCC), enabling the CMA to impose penalties without going to court for businesses that use prohibited, non-transparent or unfair terms or notices. Fines may be up to 10% of a company’s global turnover or £300,000 (whichever is higher).

Transparency – more than words:

Transparency now covers not just the content itself, but also its presentation by requiring clear fonts and headings that follow a logical structure, supported by explanation of terms which may be complex or challenging to understand.

Fairness and consumer behaviour:

The requirement of ‘good faith’ should include a behavioural dimension. Suppliers must consider consumer psychology and avoid exploiting consumer biases — for instance, consumers’ tendency not to read standard terms thoroughly, or to underestimate future costs such as renewal or termination fees. Campaigns emphasising quick benefits, such as a free trial, while using tactics to minimise attention as to future costs will face greater scrutiny. Automatic renewal of subscriptions are also specifically noted as an area of concern, with the DMCC’s new subscription provisions (to enter into force no later than August 2026) adding further obligations.

The role of advertising:

Advertising is explicitly incorporated into the fairness assessment, requiring consistency between terms and marketing claims. Small print which removes or curtails more prominent claims, failing to highlight key terms during the marketing process, or inconsistency between marketing claims and the contract terms could give rise to an unfair commercial practices. Statements made by a supplier that a consumer is likely to see may also be treated as terms of the contract.

Exclusions and variations to the contract:

Vague language such as “liability is excluded so far as the law permits” will not remedy an unfair clause; and terms allowing a supplier to vary terms such as changing the description or price of the services or goods may now be deemed unfair should they be overly wide in scope or result in changes that may be unexpected to the customer.

What are the key takeaways for consumer businesses?

The draft guidance makes clear that unfair, onerous or significantly unbalanced terms will be closely scrutinised. Suppliers should ensure that lines of communication with customers are clear, transparent and user-friendly to understand.

Contract terms should similarly be reviewed to make sure that they strike a reasonable balance without prejudicing consumers by including reasonable protections around cancellation or refund rights.

For more information on how the new guidance will impact your consumer contracts, contact Sacha Wilson and Jacky Lai.

Government IT contracts: how to challenge the procurement process

If your business enters into contracts with public sector entities for the provision of IT or related services, you will be familiar with the public sector tender and procurement processes. But are you familiar with what can be done to challenge the outcome of those processes?

Whether it is an issue with the application of the scoring criteria, or how the process has been conducted, your business may have the ability to challenge contract awards.

However, in order to do so effectively, your business will need to move quickly and ensure that it deploys the various legal tools available to it strategically.

What is the relevant legislation?

In 2025, the Procurement Act 2023 (the Act) came into force. This represented the most significant development to UK public procurement laws for over 30 years, replacing the well-established EU-founded regime under the Public Contracts Regulations 2015 (the PCR).

How long do you have to bring a claim?

The period during which a legal claim can be brought under the Act is very short and remains largely unchanged from the PCR. In summary:

  • If you are a supplier seeking to challenge an award, the period to bring a claim is just 30 days from when they knew, or ought reasonably to have known, of the circumstances giving rise to the claim. However, this may be extended for up to three months where the court considers there is a good reason to do so.
  • If you are supplier seeking to set aside a contract that has been entered into, the period to bring a claim is 30 days from the date it knew or ought to have known of the circumstances giving rise to a claim with a long stop date of 6 months from the date the contract was entered into.

However, the parties can enter into a standstill agreement which, in effect, extends the limitation period, allowing the parties an opportunity to resolve the dispute.

Can you prevent the authority from entering into a contract with another supplier whilst you challenge the decision?

Under the previous regime, contracting authorities were required to observe a 10-day waiting period following the issue of a ‘standstill letter’ to all tendering suppliers before entering into a contract with the preferred supplier. Claims issued prior to contract execution would trigger an automatic suspension of the procurement process.

The Act reduces the standstill period from 10 to eight working days, with the period now triggered by the contract award notice instead of the issue of a standstill letter. Claimants are no longer entitled to the benefit of automatic suspension up until the date of contract execution. This is a significant shift from the previous position and impacts upon strategic considerations.

What information do you have about the decision-making process?

There are various ways you can find out more about the decision-making process. One of them is that contracting authorities must publish a Contract Award Notice on a central digital platform, and an assessment summary to each supplier that submitted an assessed tender.

The assessment summary must include: (a) the scores awarded for each criterion; (b) an explanation of those scores; and (c) in respect of unsuccessful suppliers, the reasons why the contract was not awarded to them, together with the corresponding information at (a) and (b) for the successful tender.

The enhanced disclosure requirements are a positive development for suppliers looking for substantive grounds on which to base a potential challenge.

What remedies can you obtain when challenging an award?

In many cases, compromise solutions are reached with the relevant authority without a claim needing to be issued. However, if you do pursue a claim, the remedies available remain mostly unchanged from the previous regime. There are two main categories:

Pre-contractual remedies:

Where a contract has been awarded but not yet executed, a successful challenge may result in the court granting one of the following orders:

  • an order setting aside the relevant decision or action (including the decision to award the contract);
  • an order requiring the contracting authority to take specified action (such as reconsidering a decision previously made);
  • an order for damages (which may be granted in addition to any other order, and has historically encompassed lost profits arising from the breach and/or wasted bid costs); or
  • such other order as the court considers appropriate.

Post-contractual remedies:

Where the awarded contract has been executed, the available remedies are limited to damages and/or an order setting aside the contract (subject to certain conditions in the Act).

What does this mean for suppliers?

If you are concerned about a procurement decision, then given the short timeframes for challenge, it is critical to seek legal advice at the earliest possible opportunity to allow your advisors time to evaluate the claim and devise and deploy the optimum strategy.

The Act’s emphasis on transparency, creating a level playing field and the introduction of new obligations on contracting authorities, expands the scope for potential challenges.

You will however need to navigate the reduced standstill period, which now runs for 8 working days from the contract award notice, and the fact that automatic suspension is no longer available until the date of contract execution.

If you would like to find out more about how to make procurement challenges, contact Lizzie Williams and Jacky Lai.

Technology Briefing – December 2025

Welcome to our inaugural technology briefing, designed to keep you updated on the latest legal and regulatory developments in the technology sector.

In this edition, we explore the implications of the Getty Images v Stability AI ruling, practical steps for managing AI risks, and the latest updates in data protection law. We also examine new measures aimed at tackling ransomware threats and provide guidance on safeguarding sensitive information following the ChatGPT share feature breach.

Additionally, we showcase our collaboration with legal AI platform Legora, and share key highlights from recent industry events, including the SCL AI Conference and the ITechLaw European Conference.

IN RECENT NEWS


Model behaviour: Stability AI’s model is not an “infringing copy”, but legality of AI training remains unresolved

In the recent judgment in Getty Images v Stability AI [2025], the High Court considered whether the generative AI model Stable Diffusion infringed copyright in works owned by/licensed to Getty Images, and further whether the model outputs infringed Getty Images’ trade marks. Getty argued that millions of its images had been used without permission to train the Stable Diffusion model, and that the model itself was therefore an infringing copy of the works.

Read more >


Managing risks and opportunities with AI

In a GC100 poll of 106 companies, 8% of respondents reported they already regularly used Co-Pilot and Teams Premium for transcription of initial draft minutes; since then, there has been an influx of providers in the market that can prepare agendas, summarise discussions, and draft lists of action points. Before employing such AI tools in your company, it is essential to consider whether the use of AI is appropriate, and, if so, whether all the necessary risk-mitigation steps have been taken.

Read more >


HARBOTTLE HIGHLIGHTS

Early adopters of Legora

Legora recently announced the completion of a Series C round of $150 million at a $1.8 billion valuation. We were the third law firm in the UK to partner with Legora earlier this year.

It is a secure, purpose-built legal AI designed for lawyers to streamline legal workflows and enhance productivity. The solution accelerates legal reviews through AI-powered playbooks that enhance legal reviews, guiding juniors in the process.

The solution is capable of reviewing, comparing, and summarising lengthy documents, as well as extracting critical clauses, and analysing their content to support decisions on matters of law and risk.

Read more >


SCL annual conference

We attended the 2025 Society for Computers & Law (SCL) AI Conference: AI Law – what every business (and their lawyers) needs to know. As ever, the event was fully booked and offered a fantastic day of insightful discussions and debates on the development, interpretation, and implementation of AI law across businesses, government and the legal industry.


iTech Law

On 30 October, partner Lizzie Williams spoke at the ITechLaw Association‘s 2025 European Conference. As a member of iTechLaw and its Dispute Resolution Committee, Lizzie appeared on a panel to share her insights and experience on commercial disputes involving AI. The conference brings together legal professionals, tech innovators and industry leaders from around the world to discuss key topics and challenges in tech law including AI, data privacy and cybersecurity. 


Safeguarding your business in the wake of the ChatGPT share breach

In today’s fast-paced digital landscape, businesses are increasingly leveraging Artificial Intelligence (AI) tools such as OpenAI’s ChatGPT to streamline operations.

However, recent developments surrounding the now-discontinued “share” feature of ChatGPT should serve as a critical reminder of the importance of robust data governance and proactive measures to safeguard sensitive information, such as personal data and confidential business information.

Read more >


New measures announced to tackle ransomware attacks: what does this mean for business?

Earlier this year, the UK government unveiled a set of measures designed to curb ransomware attacks and protect critical public and private sector services. Following public consultation, these steps aim to dismantle the business model of cyber criminals while fortifying national resilience against cyber threats.

Read more >


Data protection update

This update outlines key changes, including the Data (Use and Access) Act 2025, which introduces reforms like a new lawful basis for data use, cookie exemptions and complaint procedures. The UK’s data adequacy status is likely to be extended to 2031, a Court of Appeal ruling confirmed compensation for non-material damage is recoverable, and plans for a secure digital ID scheme are underway. ICO consultations and enforcement actions on data breaches are also highlighted.

Read more >

Please contact our technology experts if you would like to discuss anything in this briefing.

Safeguarding your business in the wake of the ChatGPT share breach

In today’s fast-paced digital landscape, businesses are increasingly leveraging Artificial Intelligence (AI) tools such as OpenAI’s ChatGPT to streamline operations.

However, recent developments surrounding the now-discontinued “share” feature of ChatGPT should serve as a critical reminder of the importance of robust data governance and proactive measures to safeguard sensitive information, such as personal data and confidential business information.

What happened?

OpenAI recently faced scrutiny after its “share” feature in ChatGPT appeared to inadvertently expose private conversations to public search engines such as Google. While the feature allowed users to share chat links, discrepancies in the user interface and terms across platforms (e.g., Web, iOS, Android) led to confusion over whether shared chats were private or publicly discoverable. Although OpenAI has since removed the feature and requested the removal of indexed links from search engines stating it was a “short-lived experiment”, researchers have alleged that over 100,000 conversations, many containing personal data, were archived and remain accessible in some instances.

At the time of writing, it is also reported that chats from X.com’s “Grok” platform have been exposed online, highlighting a common risk within the industry.

Why it matters to your business

This issue underscores the risks associated with using AI tools and highlights potential vulnerabilities that could expose sensitive company or client data. For businesses, the key takeaways are:

  • Personal data: Conversations shared through AI platforms may include personal data about your employees, customers or clients. There are several data protection compliance issues that must be considered prior to sharing personal data with AI platforms from meeting transparency requirements via privacy policies to carrying out supplier due diligence on your data processing agreements with AI platforms.
  • Confidential information: As with personal data, conversations can be shared through AI platforms about your internal strategy, or intellectual property. Once shared outside of your business, such information can be challenging to remove entirely.
  • Reputational damage: Data leaks can severely impact your brand’s reputation, erode client trust, and lead to loss of business.
  • Regulatory implications: Mishandling of sensitive data could result in non-compliance with data protection laws such as the UK GDPR, leading to fines and legal challenges. Such fines can be up to £17.5m or 4% of your annual turnover (whichever the greater).
  • Legal claims: Clients or other individuals whose data is exposed may bring legal claims for breach of contract, breach of confidence, privacy or their data protection rights, and complain to the data protection regulator. Some larger data breaches have also attracted attempts to start ‘class-action’ claims.

What should you do?

If your organisation uses AI tools such as OpenAI’s ChatGPT, now is the time to review and strengthen your policies and practices. Below are some actionable steps to consider:

1. Implement an AI usage policy

If you haven’t already, establish a clear AI usage policy within your organisation. This should cover:

  • Approved AI tools and platforms
  • Guidelines on the type of information that can be inputted into AI systems
  • Specific processes for sharing data generated by AI tools

2. Train employees

Educate employees on the risks of using AI tools and ensure they understand how to use these platforms responsibly. Emphasise the importance of avoiding inputting personal data or confidential data into AI systems.

3. Conduct data audits

Review your organisation’s use of AI tools to identify any potential exposure of data. If you suspect that data may have been shared via ChatGPT’s “Share” feature, investigate whether these links have been indexed and take immediate steps to request their removal.

4. Monitor evolving AI risks

AI technology evolves rapidly, and so do its associated risks. Stay updated on developments in the AI space, including how tools such as ChatGPT handle data and privacy.

5. Seek legal support

If your business is impacted by the ChatGPT share breach or similar issues, legal advice can help you assess your exposure, address potential liabilities, and implement stronger safeguards.

How we can help

We understand the complex intersection of technology, data, and the law. Our team of experts can assist you with:

  • Drafting and implementing AI usage policies tailored to your business
  • Conducting data audits to assess your organisation’s risk exposure
  • Advising on regulatory compliance and potential liabilities
  • Supporting you with incident response and remediation in the event of a data breach, regulatory involvement, and legal claims

If you have any questions about how the OpenAI ChatGPT share breach might affect your business or need assistance in implementing preventative measures, please don’t hesitate to contact one of our specialists.

The UK’s Data (Use and Access) Bill passes as Lords’ concede on a push for AI transparency to protect creative industries

On 11 June, the House of Lords debated amendments to the Data (Use and Access) Bill (the Bill) and marked the culmination of an extensive “ping-pong” process between the House of Lords and the House of Commons regarding the protections for copyright holders in the context of artificial intelligence (AI).

What was the debate about?

  • The Government’s commitment to protecting copyright holders remains but it argues it cannot act prematurely without completing consultations on the issue. Emphasising the importance of transparency, enforcement and remuneration, it insisted on following due process, which includes analysing over 11,500 consultation responses and establishing technical and parliamentary working groups.
  • Several Lords, including Baroness Kidron and Lord Berkeley of Knighton, expressed frustration at the Government’s inaction. They argued that immediate transparency measures are needed to protect copyright holders from exploitation by AI companies. The creative sector fears that AI systems are using copyrighted works without consent or compensation, which could undermine the livelihoods of artists, writers, musicians and others.

What happened?

In efforts to ensure transparency and incentivise AI developers to comply with copyright law Lord Berkeley of Knighton introduced a new amendment to the Bill requiring AI developers to disclose which copyrighted works they use for training and how they access them, unless a licence has been agreed with rights holders.

Lord Berkeley ultimately withdrew his amendment, citing a desire to maintain the dignity of the House and avoid further unnecessary divisions. However, he and others urged the Government to take the concerns of the creative industries seriously and act swiftly to address them.

What will happen next?

The Bill now awaits Royal Assent and once in force, it will reform elements of the UK GDPR and Privacy Electronic Communications Regulations – from introducing a list of recognised legitimate interests to adding new exceptions to the consent requirements for cookies and similar technologies.

It should be noted that while the UK’s adequacy decision from the EU to allow a free flow of personal data transfers has been extended to 27 December 2025, the Bill does introduce changes to the UK GDPR which ultimately leads to a departure from the EU GDPR. As such, we wait eagerly to see if it decided whether or not the UK’s data protection regime will continue to offer materially equivalent protections in order to maintain the free flow of transfers between the UK and EU.

If you would like more information, please feel free to reach out to one of our dedicated data protection lawyers, or if you would like keep up to date on the latest in data protection, please subscribe to our quarterly newsletter, The Data Download.

Court of Appeal decision in digital transformation case

The Court of Appeal recently held that a customer who instructed a supplier to provide digital transformation services was not entitled to delay payments (liquidated damages) of c. £1.6m.

This is because the prompt issuing of a “non-conformance report” by the customer was said to be a condition precedent to the customer receiving delay payments, and no such report was promptly issued. The Court reached this result notwithstanding the term “condition precedent” not being used in the contract.

The relevant provision provided that:

“6.1. If a Deliverable does not satisfy the Acceptance Test Success Criteria and/or a Milestone is not Achieved due to the CONTRACTOR’s Default, the AUTHORITY shall promptly issue a Non-conformance Report to the CONTRACTOR … The AUTHORITY will then have the options set out in clause 6.2.”

“6.2 the AUTHORITY may at its discretion … choose to … require the payment of Delay Payments…”

The Court of Appeal reached this decision because:

  1. It is not necessary for the term “condition precedent” to be used if the contract clearly provides that the relief is conditional on a requirement.
  2. The “if .., then ..” structure in the clauses was clearly conditional and without the non-conformance report, the clauses would not operate properly.
  3. It is not necessary for the deadline for the condition precedent to be expressed as a precise time period – “promptly” is sufficient.

The case shows that both contract drafters and litigators must pay close attention to remedies provisions to ensure that conditions precedent are not inadvertently included and are fully complied with.

The case can be found here: Disclosure and Barring Service v Tata Consultancy Services Ltd [2025] EWCA Civ 380.

Harbottle & Lewis advises majority shareholders of MyTAG on the sale of their shares to Kinexio

We have advised the majority shareholders of MyTAG, a global software and property technology company, on the sale of their shares to Kinexio (formerly Mallcomm), backed by Synova.

MyTAG offers solutions for proof of presence, proof of compliance and enhanced security to safeguard people, property and assets. MyTAG’s products will be integrated into Kinexio’s property management platform, a leading enterprise software solution for property management.

The deal has established Kinexio as a market leader in property technology with an expanded suite of innovative software solutions.

We advised the majority shareholders on all aspects of the transaction, including negotiating the sale agreement and ancillary documentation.

Our team was led by partner Tom Macleod and associate Alex Gays, with support from associates Matthew Shannon and Kate Merry. Partner David Scott advised on corporate tax matters. We worked alongside IMAP (International Mergers and Acquisitions Partnership) and Bevan Buckland.

On working with Harbottle & Lewis, MyTAG founder Mike George said: “The Harbottle team were exceptional on this deal throughout. Tom, Alex and the rest of the team guided us through every aspect of the transaction with calm composure. Their industry experience and technical knowledge are second to none and made us feel at ease at every step.”

Commenting on the deal, Harbottle & Lewis partner Tom Macleod said: “It was a pleasure acting for Mike and co on this exit. It is great to see the years of hard work and commitment by Mike rewarded and it will be exciting to see the next step for MyTAG as part of Kinexio.” 

COURT OF APPEAL VERDICT IN EXCLUSION CLAUSE DISPUTE

In February 2025 the Court of Appeal (by a 2:1 majority) dismissed an appeal brought by EE against Virgin Mobile in relation to a significant claim arising out of a telecommunications supply agreement.

The Court of Appeal agreed with the first instance decision that the exclusion clause excluded EE’s entire £24.6m loss of profit claim against Virgin Mobile.

EE claimed that it had suffered loss and damage in the amount of £24.6m as a result of Virgin Mobile breaching an exclusivity obligation in the telecommunications supply agreement, because EE had lost the revenue that it would have received from Virgin Mobile under the terms of the agreement had the exclusivity obligation not been breached.

Virgin Mobile denied breaching the agreement as alleged but argued that, in any event, EE’s claim was precluded because it was, in substance, a claim for anticipated profits. It therefore fell within the scope of the exclusion clause in the agreement which provided that “Neither Party shall be liable to the other in respect of … anticipated profits”.

EE argued that this interpretation could not be correct because (amongst other things), on the facts which occurred, EE did not have a wasted expenditure claim or a good argument for an injunction, so excluding the loss of profits claim would leave EE without an effective remedy, creating commercial absurdity and defeating the main purpose of the agreement.

The majority of the Court of Appeal rejected this argument because the specific facts which occurred, where no alternative remedy was viable, were not known to the parties when they entered into the agreement and therefore should not affect its interpretation. It was held that, applying the proper legal principles, the exclusion clause did preclude EE’s entire claim.

However, the Court of Appeal did not reach this conclusion easily, and indeed Phillips LJ dissented, noting that “it would be surprising if the parties intended that [Virgin Media] could breach the key exclusivity provision, unlawfully diverting its customers to a third party supplier, without incurring liability to pay EE damages reflecting the loss of revenue resulting from that breach”.

This case provides a further example of the unpredictability of the interpretation of exclusion clauses and the importance of clear, future-proof, contract drafting.