Latest Publications

Share:

DSARs in 2025: Stay Ahead of Regulations

As data protection regulations evolve and employee rights awareness grows, organisations are seeing a significant uptick in Data Subject Access Requests (DSARs). Pursuant to Article 15 of the UK and EU General Data Protection...more

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK...more

European Vulnerability Database Published by the European Union Agency for Cybersecurity

The European Union Agency for Cybersecurity (ENISA) has launched the European Vulnerability Database (EUVD), a tool designed to enhance digital security across the EU. The EUVD is available here....more

UK Publishes Software Security Code

Cyber security supply chain risks are growing, and attacks on vendors and other third parties cause severe disruption to businesses. For example, in recent years we have seen many incidents that have involved threat actors...more

UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident

On April 14, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined DPP Law (“DPP”) £60,000 (approximately $80,000) following a ransomware incident. In its penalty notice, the ICO found...more

Carrots and Sticks Cross the Pond: The SFO’s New Corporate Self-Reporting and Cooperation Guidance

The UK Serious Fraud Office (SFO) has issued new guidance to encourage companies to self-report suspected corporate criminal conduct and cooperate fully with investigations. Our transatlantic White Collar, Government &...more

UK Government Publishes Cyber Governance Code of Practice for Boards and Directors

On April 8, 2025, the UK government published the Cyber Code of Practice (the “Code”) to support board directors in governing cybersecurity risks. The Code is available online. The UK’s data protection regulator is actively...more

UK’s Data Protection Regulator Fines a UK SaaS Provider ~$4 Million Following a Ransomware Incident

On March 26, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined Advanced Computer Software Group Ltd (“Advanced”) £3.07 million (approximately $4 million). In 2022, Advanced suffered...more

European Commission Moves to Extend Free Flows of Personal Data to the UK

On March 18, 2025, the European Commission proposed to extend its adequacy decision in favor of the United Kingdom (‘UK’) for an additional six-month period. This would allow free flows of personal data from the EU to the UK...more

UK Government Proposes Targeted Ban on Ransom Payments and Increased Ransomware Incident Reporting

On January 14, 2025, the United Kingdom government published a consultation on ransomware proposing new measures to increase incident reporting and reduce ransom payments (the “Consultation”). The Consultation outlines three...more

UK’s National Cyber Security Centre Releases 2024 Annual Review

The United Kingdom’s National Cyber Security Centre (NCSC) has released its Annual Review for 2024. As in prior years, the report covers the UK’s cyber security position, both in terms of threats to the public and private...more

D-Day for the EU Cyber Resilience Act

Our Privacy, Cyber & Data Strategy Team discusses the new Cyber Resilience Act (CRA) that affects manufacturers and distributors of connected devices that are in use anywhere in the European Union....more

The Wait Is (Almost) Over: The UK’s “Failure to Prevent Fraud” Guidance Is Here, and the Offense Itself Is Not Far Behind

Our White Collar, Government & Internal Investigations Team discusses the UK’s new guidance on the “failure to prevent fraud” offense. The guidance addresses the “failure to prevent fraud” offense created by the Economic...more

Forthcoming UK Cyber Security and Resilience Bill to Boost the UK’s Cyber Defenses

In the July 2024 King’s Speech, the UK government announced its intention to introduce a Cyber Security and Resilience Bill (the “Bill”) to improve the UK’s cyber defenses and protect essential public services. The...more

Green Light for the Enforcement of NIS 2 in Limited EU Countries Only

EU Member States had until today, October 17, 2024, to transpose the Network and Information Security (NIS) 2 Directive into their national laws. As Directives are not directly applicable in EU Member States, the EU...more

EDPB Adopts Opinion on the Use of Processors and Sub-processors

On October 7, 2024, the European Data Protection Board (“EDPB”) adopted an opinion on obligations following from the use of processors and sub-processors (the “Opinion”). The EDPB is the body that seeks to ensure harmonised...more

DOJ Unseals Indictment of Evil Corp Member, While OFAC Announces New Evil Corp Sanctions

On October 1, 2024, the Department of Justice (“DOJ”) unsealed an indictment against Aleksandr Viktorovich Ryzhenkov (Александр Викторович Рыженков), a member of the ransomware group Evil Corp.  The indictment charges...more

17 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide