News & Analysis as of

Reporting Requirements General Data Protection Regulation (GDPR)

A&O Shearman

Polish supervisory authority publishes updated guide on personal data protection breaches

A&O Shearman on

On February 20, 2025, the Polish Personal Data Protection Office (UODO) published an updated version of the guide on personal data protection breaches. The first edition was released in 2018. The latest version...more

Pillsbury Winthrop Shaw Pittman LLP

Navigating the EU’s “NIS 2” Directive: Key Cybersecurity Compliance Points for Businesses Operating in the EU to Consider

The NIS 2 Directive requires a wide range of in-scope organizations to adopt robust cybersecurity measures and incident response plans....more

A&O Shearman

Zooming in on AI – #10: EU AI Act – What are the obligations for “high-risk AI systems”?

A&O Shearman on

Companies deploying high-risk artificial intelligence (AI) systems must prepare to navigate a complex landscape of new obligations by August 2, 2026. In this post we explain the key obligations for providers and deployers of...more

Ankura

Ensuring Compliance With Data Privacy Regulations: The Role of e-discovery Services in the Indian Landscape

Ankura on

In today's digital era, the volume of electronic data generated by organizations is staggering. For law firms conducting due diligence, managing this data while ensuring compliance with stringent data privacy regulations is a...more

Morgan Lewis

EU AI Act, US NIST Target Cyberattacks on AI Systems—Guidance and Reporting Obligations

Morgan Lewis on

The European Union published on July 12, 2024 the final text of its Artificial Intelligence (AI) Act, in force on August 1, 2024, which will implement material cybersecurity and incident reporting requirements, among other...more

Ankura

The EU’s AI Act: Obligations of AI Users and GDPR Article 35

Ankura on

In December 2023, European Union (EU) lawmakers reached an agreement on the EU AI Act. In our article titled An Introduction to the EU AI Act, we focused on applicability, thresholds, timing, and penalties related to the EU...more

BCLP

Quebec Law No. 25: a Little-known Privacy Law With a Big Reach

BCLP on

In late 2021, the Quebec legislature passed “The Privacy Legislation Modernization Act” or Law No. 25 (“Law 25”), which was designed to modernize and make significant changes to Quebec’s existing privacy framework....more

NAVEX

Understanding the Updates and Implications of the EU Corporate Sustainability Due Diligence Directive

NAVEX on

On February 23, 2022, the European Commission released a proposal for the Corporate Sustainability Due Diligence Directive (CSDDD or the Directive). The Directive aims to mandate both EU and non-EU companies that conduct...more

K&L Gates LLP

Brussels Regulatory Brief: August-September 2023

K&L Gates LLP on

ANTITRUST AND COMPETITION - The European Commission’s Merger Simplification Package Enters Into Force - On 20 April 2023, the European Commission (Commission) adopted a new legislative package that entered into force on 1...more

Seward & Kissel LLP

"An Ounce of Prevention"...How to Reduce the Risk of Litigation and Enforcement Proceedings

Seward & Kissel LLP on

To paraphrase what Ben Franklin may have been alluding to nearly 300 years ago in his famous quote, often the best approach when it comes to reducing the risk of litigation and government enforcement proceedings is to take...more

Latham & Watkins LLP

Cybersecurity Incidents: 10 Things a General Counsel Must Know About EU Cyber Incidents

Latham & Watkins LLP on

Cybersecurity incidents pose legal challenges for in-house counsel, alongside their technical implications. This overview highlights key aspects that legal departments must know when reacting to data breaches. ...more

White & Case LLP

Towards a unified whistleblower system across Europe

White & Case LLP on

Whistleblowing in Europe has been governed by country-specific regulations, some of which differed widely in terms of content. A number of Member States did not even have a dedicated generally applicable protection system in...more

HaystackID

[Webcast Transcript] Data Mining in Incident Response: Managing Risk and Spend through an Effective Evidence-Based Approach

HaystackID on

Editor’s Note: On August 31, 2022, HaystackID shared an educational webcast on the topic of data mining in data breach incident response. As data mining has increasingly become one of the largest expenses during a cyber...more

Pietragallo Gordon Alfano Bosick & Raspanti,...

Italy Becomes Latest Country to Pass Sunshine Act

Takeaway: Although the enactment of the Italian Sunshine Act furthers the global expansion of healthcare transparency, the implied consent provision may not comply with the GDPR....more

Ankura

Data Privacy Requirements Have Launched Records Management 3.0, Joe Shepley

Ankura on

We’ve had two seismic, discipline-altering events in Records Management in the last 20 years: 2006: change to the Federal Rules of Civil Procedures brought electronic records management to the forefront. 2011:...more

White & Case LLP

France: The new whistleblower

White & Case LLP on

Adoption of a new law improving the protection of whistleblowers in companies with more than 50 employees. The law implements an EU directive and goes beyond the European requirements. A whistleblower remains a "natural...more

Alston & Bird

The Digital Download – Alston & Bird’s Privacy, Cyber & Data Strategy Newsletter – February 2022

Alston & Bird on

 Selected Developments in U.S. Law - SEC Proposed Rule Will Require Private Funds to Report Certain Cyber Events On January 26, 2022, the U.S. Securities and Exchange Commission (SEC) proposed new rules to enhance hedge fund...more

Skadden, Arps, Slate, Meagher & Flom LLP

Skadden's 2020 Insights

Despite political and economic uncertainties, markets and deal activity were resilient in 2019, and strong fundamentals remain in place heading into 2020. Companies continue to face a challenging litigation and enforcement...more

Hogan Lovells

A new model for obtaining data protection consents: unbundling the proposed amendments to China's Personal Information Security...

Hogan Lovells on

On 1 February, 2019, the National Information Security Standardization Technical Committee issued an amended version of the GB/T 35372-2017 Information Technology – Personal Information Security Specification for public...more

White & Case LLP

Chapter 11: Obligations of processors – Unlocking the EU General Data Protection Regulation

White & Case LLP on

Why does this topic matter to organisations? Under the GDPR, the concept of a "processor" has not changed. Any entity that was a processor under the Directive likely continues to be a processor under the GDPR. However,...more

White & Case LLP

Chapter 10: Obligations of controllers – Unlocking the EU General Data Protection Regulation

White & Case LLP on

Why does this topic matter to organisations? Each time an organisation processes personal data, it will do so as either a controller or a processor. These roles bear different responsibilities. Therefore, it is critically...more

Skadden, Arps, Slate, Meagher & Flom LLP

UK Employment Flash - January 2019

We are pleased to announce the launch of our UK Employment Flash, covering the latest employment law developments, news and insights from the U.K. Our inaugural issue includes commentary on the U.K. government's proposed...more

BakerHostetler

Racing to Meet the 72-hour Deadline to Report a Personal Data Breach in the EU? A GDPR Resource Is Available

BakerHostetler on

Companies face substantial challenges in complying with breach notification requirements under Article 33 of the General Data Protection Regulation (GDPR). Article 33 requires a data controller to report a personal data...more

Hogan Lovells

IPunkt | IP auf den Punkt gebracht - Oktober 2018

Hogan Lovells on

Datenschutzgrundverordnung stark im Zeichen des Datenschutzes. Viele Unternehmen hatten die Mammut-Aufgabe, die relevanten Anforderungen des Datenschutzes an die Verarbeitung personenbezogener Daten umzusetzen. ...more

Littler

Littler Global Guide - Brazil - Q3 2018

Littler on

Brazil’s New Data Privacy Law - New Legislation Enacted - On August 14, 2018, Brazil enacted its first omnibus data protection law, to become effective in February 2020. ...more

39 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide