Latest Publications

Share:

The Digital Download | Alston & Bird’s Privacy & Data Security Newsletter | February 2026

The Digital Download provides a quarterly snapshot of emerging issues at the intersection of privacy, cybersecurity, and data strategy. It brings together Alston & Bird’s thought leadership, publications, events, and firm...more

The DSA and GDPR: 5 Ways These Laws Work Together

On September 11, 2025, the European Data Protection Board (EDPB) adopted guidelines on the interplay between the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR)....more

UK’s Data (Use and Access) Act 2025 – What Does It Change?

The UK Data (Use and Access) Act 2025 makes major changes to UK data protection law, including the UK General Data Protection Regulation (UK GDPR). ...more

UK Cybersecurity Legislation Soon to be Introduced

The UK Government has introduced the Cyber Security and Resilience (Network and Information Systems) Bill (the “Bill”) to Parliament, marking the most significant update to the UK’s cyber legislation since 2018. You can...more

UK’s National Cyber Security Centre Releases 2025 Annual Review

The United Kingdom’s National Cyber Security Centre (NCSC) has released its Annual Review for 2025. As in 2024, the report covers the UK’s cyber security position as well as the country’s readiness to deal with those threats....more

Cybersecurity Resources for Boards in the U.S., UK, and EU

Boards in the United States, United Kingdom, and European Union face increasing pressure to oversee cybersecurity risks amid evolving regulatory expectations. Our Privacy, Cyber & Data Strategy Team highlights key resources,...more

UK Data Protection Regulator Fines Capita ~$18.8 Million Following a Ransomware Attack

On October 15, 2025, the UK’s Information Commissioner’s Office (ICO) fined Capita plc and Capita Pension Solutions Limited (collectively “Capita”) £14 million (~$18.8 million) for failing to implement adequate security...more

The Data Act: 7 Things to Know About the Data Act and Connected Products

The EU’s sweeping Data Act is now in force. In this part of our series highlighting the Data Act’s key issues, our Privacy, Cyber & Data Strategy Team highlights new obligations for companies whose connected products collect...more

The EU Data Act Comes Into Force

The EU officially adopted the Data Act in January 2024, and it came into force on September 12, 2025. The Data Act builds on existing laws like the General Data Protection Regulation and the Data Governance Act. Now that the...more

The Data Act: 5 Things to Know About the Data Act and New Switching Requirements for Providers of Cloud Services

This advisory is part of a series that summarises the key issues arising from the introduction of the Data Act. See: On September 12, 2025, the obligations introduced under the EU’s Data Act (Regulation 2023/2854) become...more

The Digital Download | Alston & Bird’s Privacy & Data Security Newsletter | August 2025

Microsoft Announces Two New On-Premises SharePoint Vulnerabilities - On July 19, 2025, Microsoft announced two new vulnerabilities that are actively being exploited (CVE-2025-49704 and CVE-2025-49706) and relate to...more

EU-wide Breach Notification Template on the Horizon

Following their recent meeting in Finland, the EU Data Protection Authorities acting through the European Data Protection Board (EDPB) announced their intention to release new tools and ran EU-wide data breach notification...more

Inside the SK Telecom Data Breach: What Happened and What Companies Can Learn

In April 2025, SK Telecom—South Korea’s largest mobile carrier—formally notified regulators of a significant data breach that compromised sensitive SIM card data belonging to nearly 27 million users. Following an...more

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK...more

European Vulnerability Database Published by the European Union Agency for Cybersecurity

The European Union Agency for Cybersecurity (ENISA) has launched the European Vulnerability Database (EUVD), a tool designed to enhance digital security across the EU. The EUVD is available here....more

UK Publishes Software Security Code

Cyber security supply chain risks are growing, and attacks on vendors and other third parties cause severe disruption to businesses. For example, in recent years we have seen many incidents that have involved threat actors...more

UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident

On April 14, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined DPP Law (“DPP”) £60,000 (approximately $80,000) following a ransomware incident. In its penalty notice, the ICO found...more

18 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide