Latest Posts › Cybersecurity

Share:

EC publishes draft delegated regulation on subcontracting RTS under DORA

On March 24 2025, the European Commission (EC) adopted the final draft Delegated Regulation setting out Regulatory Technical Standards (RTS) for subcontracting ICT services supporting critical or important functions under the...more

Zooming in on AI #18: Cybersecurity requirements for AI systems

The Artificial Intelligence Act (AI Act) is the world's first comprehensive legal framework for AI regulation, which entered into force on August 1, 2024. The AI Act aims to ensure that AI systems are trustworthy, safe and...more

NIS2 Digital Providers get Implementing Regulation on cybersecurity risk management and significant incidents

On 17 October 2024, the European Commission (EC) adopted the final version of the Implementing Regulation concerning cybersecurity risk management measures and further specification of cases in which an incident is considered...more

EU – European Commission issues consultation on the European common cybersecurity certification scheme for ICT products

On 3 October 2023, the European Commission announced a public consultation regarding the draft implementing regulation (Draft Regulation) establishing the European Common Criteria-based cybersecurity certification scheme...more

India – Digital Personal Data Protection Act receives Presidential assent

The President of India gave assent for the Digital Personal Data Protection Bill 2023 on 11 August 2023, a matter of days after it had been passed by both the Lower and Upper House. The Digital Personal Data Protection Act...more

US – White House announces voluntary commitments from key AI companies to manage safety, security and trust risks posed by AI

The White House announced on 21 July 2023 that seven companies involved in development of artificial intelligence (AI) technology had voluntarily committed to manage the risks posed by AI. These companies are: Amazon,...more

Pakistan – MITT releases final draft of the personal data protection bill

The Pakistan Ministry of Information Technology and Telecommunication (MITT) released a new draft of the Personal Data Protection Bill, 2023 (the PDPB) on 19 May 2023. The PDPB aims to regulate the collection, processing,...more

Compensation claims under the GDPR unpicking the latest EU and English case law and looking ahead

The first week of May 2023 saw further EU case law emerge on the right to compensation under the GDPR, and in this blog we analyse the implications of these latest rulings and consider what may be coming next....more

European Parliament committees adopt their vision on the AI Act proposal

The European Parliament’s committees for Civil Liberties, Justice and Home Affairs (LIBE) and for Internal Market and Consumer Protection (IMCO) adopted a report setting out the Parliament’s vision for the proposed EU...more

CJEU clarifies key aspects of the GDPR: an overview of recent cases

The Court of Justice of the European Union (CJEU) issued on 4 May 2023 three decisions in cases concerning interpretation of key aspects of the GDPR. It also published three opinions of the Advocate General (AG). Below is a...more

CJEU rules that national derogations on employees data protection must respect the conditions and limits of Article 88 GDPR

The Court of Justice of the European Union (CJEU) considered appropriate conditions that apply in respect of specific national legislation which EU member states may adopt under Article 88 GDPR to regulate the processing of...more

EDPB updates the guidelines on data breach notification, addresses data processing in upcoming AML legislation

The European Data Protection Board (EDPB) held its 77th plenary meeting on 28 March 2023. The EDPB considered the following key topics...more

EDPB publishes opinion on the draft adequacy decision for the EU-US Data Privacy Framework

The European Data Protection Board (EDPB) issued its opinion on the draft adequacy decision of the European Commission (Draft Decision) regarding the EU-US Data Privacy Framework (DPF) on 28 February 2023. The DPF is a...more

Italy - Garante restricts personal data processing by an AI chatbot that generates a 'virtual friend'

The Italian supervisory authority (Garante) issued an urgent order against Luka Inc. (Luka), a US-based developer and operator of the online app “Replika” (Replika), an artificial intelligence (AI) chatbot on 2 February 2023....more

USA - NIST proposes a framework for AI Risk Management

The U.S. National Institute of Standards and Technology (NIST) of the U.S. Department of Commerce published its AI Risk Management Framework (AI RMF) on 26 January 2023, a guidance document for organisations designing,...more

WEF publishes white paper on overcoming the barriers to international data flows

The World Economic Forum (WEF), an influential international non-governmental organisation for public-private cooperation, published its white paper on overcoming the barriers to international data flows on 16 January 2023....more

EU top court rules that controllers must disclose actual identity of data recipients in response to data subject access request

The Court of Justice of the European Union (CJEU) delivered its judgment in Case C-154/21 Österreichische Post (the Österreichische Post case) on 12 January 2023. The case relates to the interpretation of Art. 15(1)(c) GDPR,...more

OECD countries adopt a declaration on government access to private sector data for national security and law enforcement purposes

The OECD countries adopted the first intergovernmental declaration setting out common approaches to providing privacy and data protection safeguards for governmental access to personal data held by private sector (on 14...more

The European Parliament adopts NIS2 and DORA proposals

The plenary session of the European Parliament adopted the final versions of the Directive on measures for a high common level of cybersecurity across the Union (NIS2 Directive) and of the Digital Operational Resilience Act...more

EDPBs October plenary harmonisation of GDPR enforcement, a new Data Protection Seal and updated guidance

On 12 October 2022, the European Data Protection Board (EDPB) announced the outcomes of its plenary meeting held on 10 October 2022....more

EU – New Cyber Resilience Act will provide cybersecurity requirements for hardware and software products

On 15 September 2022, the European Commission published its proposal for a new Cyber Resilience Act (the Act) that introduces common cybersecurity rules for placing products with digital elements on the EU market. ...more

Netherlands - VoetbalTV decision offers no further clarity on validity of a purely commercial interest as a legitimate interest...

On 27 July 2022, the Council of State (RVS), the highest administrative court of the Netherlands, published its decision in the VoetbalTV case regarding the interpretation of the legitimate interest legal basis for...more

EU – EDPB publishes Guidelines on certification as transfer tool

The European Data Protection Board (EDPB) has adopted, on 16 June 2022, the draft guidelines on certification as a tool for transfers of data to third countries without adequacy status (the Guidelines). The text of the...more

Canada – Digital Charter Implementation Act introduced to strengthen federal data protection laws and regulate AI

On 16 June 2022, the Canadian Minister of Innovation, Science and Industry and Minister of Justice and Attorney General of Canada introduced the Digital Charter Implementation Act 2022 to modernise the regulation on...more

30 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide