Latest Publications

Share:

US and UK Issue Joint Cybersecurity Guidance for Operational Technology Systems

The United States’ Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI), in collaboration with the United Kingdom’s National Cyber Security Centre and other international partners,...more

In a Landmark Decision, EU Court Clarifies When Pseudonymised Data Is Not Personal Data Under the GDPR

The Court of Justice of the European Union (ECJ) has issued a landmark decision in European Data Protection Supervisor v Single Resolution Board (C-413/23 P), narrowing the circumstances in which pseudonymised data is...more

What Recent EU and UK Decisions Tell Us About GDPR Lawsuits

On 22 August 2025, the UK Court of Appeal issued its judgment in Farley v Paymaster. The case related to the Sussex Police, whose pension scheme members’ “annual benefit statements” were posted to out-of-date addresses. The...more

California Finalizes CCPA Regulations for Automated Decision-Making Technology, Risk Assessments and Cybersecurity Audits

On September 23 2025, the California Office of Administrative Law approved the California Privacy Protection Agency’s (CPPA’s) regulations under the California Consumer Privacy Act (CCPA). The final regulations create three...more

California, Colorado and Connecticut Launch Joint Sweep on Global Privacy Control Compliance

This coordinated enforcement sweep builds on the “Consortium of Privacy Regulators” announcement earlier this year, which, as we have written, marked a shift toward joint, multistate privacy enforcement. The Consortium of...more

Landmark California AI Safety Legislation May Serve as a Model for Other States in the Absence of Federal Standards

On September 29, 2025, California Governor Gavin Newsom signed into law Senate Bill 53 (SB 53), known as the Transparency in Frontier Artificial Intelligence Act (TFAIA). This landmark legislation establishes the nation’s...more

DoD Finalizes DFARS Cybersecurity Certification Rule: What Contractors Need To Know

On September 10, 2025, the U.S. Department of Defense (DoD) published its final rule implementing the contractual requirements under the Cybersecurity Maturity Model Certification (CMMC) Program. The rule (CMMC DFARS Rule),...more

EU Court Upholds EU-US Data Flows in Latombe v Commission

Under the EU General Data Protection Regulation (GDPR), the European Commission can issue “adequacy” decisions allowing data to be transferred from the EU to a non-EEA country without additional security measures such as...more

FTC Chair Warns Tech Firms: Weakening Encryption or Censoring Americans for Foreign Governments May Violate US Law

The FTC’s letters highlight the commission’s concern that tech companies may adopt content moderation or data security policies that, while designed to meet foreign legal requirements, could impermissibly infringe upon U.S....more

NIS2 Update: EU Cyber Authority Sets Out Compliance Expectations, but Implementation Is a Work in Progress

- What is new: On 26 June 2025, the EU Agency for Cybersecurity (ENISA) published guidance documents setting out security measures that regulated organisations should have in place to comply with the EU’s critical...more

DOJ Settlement With Medical Technology Company Signals Expanding Cybersecurity FCA Risk for Life Sciences Companies

- What is new: DOJ announced a $9.8 million FCA settlement with Illumina Inc. to resolve claims arising out of alleged cybersecurity deficiencies in DNA sequencing systems Illumina sold to government agencies. - Why it...more

Cookie Consent: Unpacking the UK ICO’s Proposed New Approach to Online Advertising

- What is new: The ICO is proposing to relax its enforcement of cookie consent requirements, meaning user consent would not be required for lower-risk advertising cookies. - Why it matters: The proposals aim to address...more

White House Releases AI Action Plan: Key Legal and Strategic Takeaways for Industry

- What is new: The Trump administration’s AI Action Plan reflects a striking shift in approach, with the federal government driving development, expansion and regulation, focusing on deregulation, permitting, procurement and...more

The Last Piece of DORA Falls Into Place: 10 Lessons From the First Six Months

- What is new: The EU’s Delegated Regulation on Subcontracting has come into force, completing the legal framework of the Digital Operational Resilience Act (DORA). Attention will now turn to enforcement. - Why it matters:...more

State Privacy Enforcement Accelerates, With California Targeting Substantive Compliance and Connecticut Bringing Its First Action

As federal privacy enforcement shows signs of slowing, states are aggressively stepping in to fill the void. On July 1, 2025, the California attorney general (AG) announced a $1.55 million settlement with Healthline Media,...more

Something Is Better Than Nothing: UK and EU GDPR Reform Finally Arrives

In recent weeks, the EU and UK have both introduced changes to their respective versions of Europe’s landmark privacy legislation, the General Data Protection Regulation (GDPR). These reforms mark the first substantial...more

The EU’s New Cybersecurity Law for the Space Sector

On 25 June 2025, the European Commission announced its proposal for a “Space Act” that would introduce a new regulatory framework for EU space activities. The proposed framework includes cyber-resilience obligations for EU...more

The European Health Data Space – What EU Health Care Providers and Data Holders Need To Know

- On 26 March 2025, the European Health Data Space (EHDS) Regulation entered into force. The regulation establishes a comprehensive framework for health-data sharing and access in the EU, with the dual aim of supporting the...more

Texas Charts New Path on AI With Landmark Regulation

Texas has become the second state, after Colorado, to enact omnibus legislation regulating artificial intelligence (AI) systems. On June 22, 2025, Texas Gov. Greg Abbott signed into law the Texas Responsible Artificial...more

EU Data Act: Three Months To Go Before New Rules on Data Access and Sharing Take Effect

Executive Summary - The EU Data Act, whose requirements apply from 12 September 2025, establishes new rights for businesses and consumers to access data they generated using “connected devices,” limiting the exclusive...more

Cybersecurity Trends in the Digital Asset Space

After years of regulatory uncertainty, the Trump administration has signaled a new approach to digital assets, including by establishing a working group focused on digital assets and nominating crypto-friendly chairs to the...more

Key Themes From the 2025 IAPP Global Privacy Summit

On April 23 and 24, 2025, regulators, industry leaders and data privacy leaders from across the globe convened in Washington, D.C. for the 2025 International Association of Privacy Professionals (IAPP) Global Privacy Summit....more

Eight-State Consortium of Privacy Regulators Marks Shift Toward Coordinated Enforcement

In a major development for businesses subject to state data privacy laws, eight state privacy regulators have joined forces to form the “Consortium of Privacy Regulators,” a bipartisan coalition aimed at coordinating...more

District Court Rulings Could Signal Expansion of California Consumer Privacy Right of Action

In two recent rulings, judges in the U.S. Northern District of California have allowed proposed class actions under the California Consumer Privacy Act (CCPA) to proceed without an allegation of a data breach, departing from...more

FCC Council on National Security Launches Investigation of Businesses Linked to the Chinese Communist Party

In its first major initiative, on March 21, 2025, the Federal Communications Commission’s (FCC’s) newly formed Council on National Security (Council) launched an investigation into the “ongoing U.S. operations” of businesses...more

157 Results
 / 
View per page
Page: of 7

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide