News & Analysis as of

Information Technology Data Protection European Union

A&O Shearman

EC publishes draft delegated regulation on subcontracting RTS under DORA

A&O Shearman on

On March 24 2025, the European Commission (EC) adopted the final draft Delegated Regulation setting out Regulatory Technical Standards (RTS) for subcontracting ICT services supporting critical or important functions under the...more

A&O Shearman

ESAs roadmap for designation of critical ICT third-party service providers under DORA

A&O Shearman on

The European Supervisory Authorities (ESAs) have published a roadmap for the designation of critical ICT third-party service providers (CTPPs) under the EU Digital Operational Resilience Act (DORA). The roadmap of key dates...more

A&O Shearman

European Central Bank updates TIBER-EU framework to align with DORA RTS on TLPT

A&O Shearman on

The European Central Bank (ECB) has published an updated version of the threat intelligence-based ethical red teaming framework (TIBER-EU framework) (dated January) to align with the Digital Operational Resilience Act (DORA)...more

A&O Shearman

EU joint report on the feasibility for further centralization of reporting of major ICT-related incidents

A&O Shearman on

The European Supervisory Authorities have published a joint report on the feasibility of further centralization of the reporting of major ICT-related incidents by financial entities to competent authorities. The ESAs' joint...more

Goodwin

Entry into force of DORA on January 17, 2025: The CSSF will be at the heart of the compliance framework in Luxembourg

Goodwin on

Digital Operational Resilience Act (DORA) aims to harmonize provisions related to cybersecurity and information and communication technology (ICT) risk management in the financial sector. Its scope covers nearly all entities...more

A&O Shearman

The EU Cyber Resilience Act - What You Need to Know

A&O Shearman on

The EU Cyber Resilience Act (CRA) entered into force on 10 December 2024. The CRA is the first legislation of its kind in the world that aims to enhance the cyber security of products or software with a digital component...more

DLA Piper

Navigating the European Cyber Resilience Act: key dates and obligations

DLA Piper on

First introduced in December 2020 by the European Commission, the European Cyber Resilience Act (“ CRA”) regulation was published in the Official Journal on November 20th. It will come into force on December 10, 2024, but...more

A&O Shearman

CJEU Commercial interests of controller can serve as a legitimate interest

A&O Shearman on

The CJEU considered: (a) whether a legitimate interest of the controller or third party must be determined by law, and (b) whether provision of personal data of the members of a sports federation to third parties in return...more

Coblentz Patch Duffy & Bass

2024 Mid-Year Privacy Report - A Comprehensive Look at New Developments in Data Privacy Laws

Introduction - 2024 has been another big year for privacy. Several new state privacy laws are going into effect, with several more coming in 2025, while a federal privacy law continues to be discussed that would further...more

BCLP

The French Law on the Regulation of Games Including NFT is Passed: Place Your Bets

BCLP on

We have been talking about it since last year: the bill to secure and regulate the digital space ("SREN") has now been passed. The legislative process leading up to the enactment of the SREN bill has been slow (as a reminder:...more

Jones Day

UK-U.S. Data Bridge Allows Transfer of Personal Data From the United Kingdom to the United States

Jones Day on

Beginning October 12, 2023, the UK-U.S. Data Bridge will allow UK companies to transfer personal data to the United States using the new EU-U.S. Data Privacy Framework....more

Skadden, Arps, Slate, Meagher & Flom LLP

AI in Europe: Road Map for Navigating the IP, Data Protection and Regulatory Considerations

Organizations developing or using generative AI tools should implement cross-functional governance frameworks to develop and continuously monitor their use of such tools. From the earliest stages of generative AI use,...more

Pillsbury Winthrop Shaw Pittman LLP

Upcoming EU Rules on Digital Operational Resilience

There will be additional compliance obligations and mandatory contractual provisions introduced for financial entities and outsourced IT service providers. The new DORA seeks to strengthen the resilience of financial...more

Osano

GDPR Compliance in the U.S.: What to Know

Osano on

In 1992, Singapore banned the sale of all chewing gum. But if you owned a cornerstore in the U.S. and a Singaporean tourist came to visit your business, there would be nothing to stop you from selling them a pack of gum—in...more

Seyfarth Shaw LLP

The EU Digital Services Act: Overview and Impact

Seyfarth Shaw LLP on

On 16 November 2022, EU Regulation 2022/2065, better known as the Digital Services Act (“DSA”), came into force. The DSA is a key development in the use of online services in the European Union (“EU”), with an impact on...more

BCLP

Cyber laws will be updated to boost UK’s resilience against online attacks

BCLP on

The UK government confirmed on 30 November 2022 that there will be changes to the UK’s cybersecurity regulations in response to a public consultation launched earlier this year. This follows recent updates relating to the...more

Wilson Sonsini Goodrich & Rosati

European Commission Proposes New EU Cybersecurity Rules for Software and Hardware Products

On September 15, 2022, the European Commission (EC) published a Proposal for a Cyber Resilience Act (CRA Proposal) that sets out new rules in the European Union (EU) for software and hardware products and their remote data...more

Littler

International Data Transfer of HR Data From the EU to Non-EU Entities – The Deadline for Adapting SCCs is December 27, 2022

Littler on

The EU’s General Data Protection Regulation (GDPR) regulates the transfer of personal data in the European Union. For many multinational employers, Standard Contractual Clauses (SCCs) offer the only practical means of...more

Jenner & Block

US Tech Companies Under Increased Scrutiny from EU Data Protection Authorities

Jenner & Block on

By the close of 2021, EU data protection authorities (“DPA”) had initiated investigations into a number of US tech companies operating in Europe and further investigations are set to continue. In a recent case concerning...more

Burr & Forman

U.S. and Europe Target Top Ransomware Cartel

Burr & Forman on

An international law-enforcement effort has led to the arrest of multiple individuals affiliated with the most prolific ransomware cartel operating today. In November, Justice Department officials announced indictments and an...more

McDermott Will & Emery

Investing in European Healthcare - What's on the Horizon for 2022? - Regulatory and Legal Changes

McDermott Will & Emery on

Today’s global healthcare marketplace is marked by unprecedented transformation. The seismic shifts in healthcare delivery and drug development during COVID-19 have, in 2021, continued to demonstrate the power and capacity...more

Hogan Lovells

German Bundestag adopts IT Security Act 2.0 – update for companies

Hogan Lovells on

The German Bundestag adopted the IT Security Act 2.0 (IT-Sicherheitsgesetz 2.0 – "IT-SiG 2.0") on 23 April 2021. On 7 May, the draft IT-SiG 2.0 has now also been endorsed in the Bundesrat. We have set out the latest key...more

Morgan Lewis - Tech & Sourcing

European Commission Adopts Roadmap for 2030 ‘Digital Decade’

The European Commission adopted a roadmap for the European Union's digital economy until 2030 on February 10, 2021. The roadmap aims to provide the following: This digital transformation targets European citizens, businesses,...more

Spirit Legal

CJEU: Website operators are "jointly responsible" for embedding social media or 3rd party code

Spirit Legal on

Website and app operators are jointly liable with Facebook for violations of European data protection law - In its judgment of 29 July 2019 (ref.C-40/17), the European Court of Justice has ruled on two essential points...more

Hogan Lovells

Recent Developments on Cookies – a Pan-European Overview

Hogan Lovells on

The legal requirements for the use of cookies have been subject to discussion over the last few years, with little to no enforcement and guidance from European data protection authorities (DPAs). That has changed recently....more

31 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide