Latest Posts › EU

Share:

Civil Aviation Cybersecurity: EASA Part-IS Sets New Information Security Obligations

The Situation: The aviation industry is increasingly reliant on digital systems, from air traffic management to ground operations and predictive maintenance. This digital transformation has significantly broadened the...more

BaFin's Expectations for ICT Risk Management and the Use of AI

The German Financial Supervisory Authority ("BaFin") has issued non-binding guidance ("Guidance") clarifying how financial institutions should manage Information and Communication Technology ("ICT") risks arising from...more

EU Geopolitical Risk Update Key Policy & Regulatory Developments No. 124

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

EU Digital Omnibus: How EU Data, Cyber, and AI Rules Will Shift

On November 19, 2025, the European Commission published two "Digital Omnibus" proposals as part of a wider Digital Package: (i) a Digital Legislation Omnibus that amends and consolidates large parts of the European Union's...more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 123

This update (No. 123 | 8 October 2025) covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber...more

New ECB Guide on Outsourcing Cloud Services to Cloud Service Providers

On 16 July 2025, the European Central Bank ("ECB") published a non-binding Guide clarifying supervisory expectations for institutions outsourcing cloud services....more

Italy Leads the Way in Shaping National AI Legislation Within the EU

Italy is the first EU Member State to enact national legislation on Artificial Intelligence ("AI"), thereby positioning itself as a frontrunner in shaping AI rule-making within the European Union....more

Strengthening Critical Infrastructure: Germany's New KRITIS Umbrella Law and NIS-2 Implementation

Implementing the NIS-2 Directive (EU 2022/2555) and the Critical Entities Resilience ("CER") Directive (EU 2022/2557) into national law, Germany is reinforcing the security and resilience of its critical infrastructure,...more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 122

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

CJEU Clarifies Scope of Personal Data in EDPS v SRB Decision

The Single Resolution Board ("SRB") transferred pseudonymized comments from data subjects to Deloitte without informing them. The European Data Protection Supervisor ("EDPS") found a violation of information duties applicable...more

EU General Court Upholds EU-U.S. Data Privacy Framework

On September 3, 2025, the General Court of the European Union dismissed an action for annulment brought by a French member of Parliament against the European Commission's decision recognizing the adequacy of the level of...more

European Parliament's New Study on Generative AI and Copyright Calls for Overhaul of Opt-Out Regime

On July 9, 2025, the European Parliament's Committee on Legal Affairs ("JURI") published a study examining how generative artificial intelligence ("AI") interacts with European Union copyright law....more

EU AI Act: European Commission Publishes General-Purpose AI Code of Practice

The European Union's Artificial Intelligence Act ("AI Act") establishes a comprehensive, risk-based regulatory framework including provisions relating to general-purpose AI ("GPAI") models that apply as from 2 August 2025. In...more

EU Standards for Threat-Led Penetration Testing: New Cyber Compliance Imperatives for Financial Institutions

The EU has introduced Delegated Regulation (EU) 2025/1190, establishing the first harmonized standards for threat-led penetration testing ("TLPT") across the financial sector. The regulation aims to strengthen the cyber...more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 121

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 120

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

EU AI Act: First Rules Take Effect on Prohibited AI Systems and AI Literacy

The European Union's Artificial Intelligence Act ("AI Act"), the world's first comprehensive legal framework on AI, entered into force on August 1, 2024. The AI Act sets out staggered compliance deadlines for the various...more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 119

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

European Commission's AI Code of Practice and Training Data Summary Template

The European Commission has released a new template for summarizing training data used in general-purpose artificial intelligence ("AI") models, as part of its broader AI regulatory framework....more

Understanding DORA: Digital Operational Resilience Act Now in Effect for Financial Entities and ICT Service Providers

DORA, the first EU regulation designed to establish a unified and robust digital resilience standard for the financial sector, becomes directly applicable on January 17, 2025, introducing significant penalties and...more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 118

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 117

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

NIS 2 Directive: Transposition Period is Up for EU Member States

As the national implementation deadline for the NIS 2 EU Directive is over, businesses in scope should ensure they will soon be ready to comply with the strengthened cybersecurity requirements....more

EU Enacts Broad Cybersecurity Requirements for Hardware and Software Products

On October 10, 2024, the EU Cyber Resilience Act ("CRA") was adopted by the Council of the European Union....more

EU Geopolitical Risk Update - Key Policy & Regulatory Developments No. 116

This regular alert covers key policy and regulatory developments related to EU geopolitical risks, including in particular, economic security, Russia’s war against Ukraine, health threats, and cyber threats. It does not...more

160 Results
 / 
View per page
Page: of 7

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide