News & Analysis as of

Data Privacy Data Protection General Data Protection Regulation (GDPR)

King & Spalding

EU & UK AI Round-up – July 2025

King & Spalding on

Over the last few months, organisations have accelerated efforts to engage with the requirements of the EU AI Act as we fast approach the date for when rules relating to general purpose AI models (“GPAI models”) come into...more

Fisher Phillips

Workday Ruling: How Europe’s Top Courts Raised the Bar for Employee Data Protection

Fisher Phillips on

Cloud-based HR systems have become standard for multinational businesses, driving efficiency but also increasing compliance and privacy risks. Indeed, a recent Workday case, which originated in Germany, has clarified the...more

Womble Bond Dickinson

From Data to Decisions: Navigating Privacy and Litigation Risks in the AI Era

Womble Bond Dickinson on

While many systems that are described as AI have been around for decades (e.g., internet search engines), today’s AI tools are much more powerful and are widely accessible. Generative AI and agentic AI extend the power of...more

Skadden, Arps, Slate, Meagher & Flom LLP

Something Is Better Than Nothing: UK and EU GDPR Reform Finally Arrives

In recent weeks, the EU and UK have both introduced changes to their respective versions of Europe’s landmark privacy legislation, the General Data Protection Regulation (GDPR). These reforms mark the first substantial...more

TransPerfect Legal

DSARs in 2025: Stay Ahead of Regulations

TransPerfect Legal on

As data protection regulations evolve and employee rights awareness grows, organisations are seeing a significant uptick in Data Subject Access Requests (DSARs). Pursuant to Article 15 of the UK and EU General Data Protection...more

Osano

Customer Data Privacy: Why It’s Important and How to Protect It

Osano on

Data privacy regulations aren’t known for being light reading. That doesn’t make it easy for businesses to become compliant. When one law refers to data subjects, another to residents, another to consumers, and another...more

Alston & Bird

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

Alston & Bird on

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK...more

McDermott Will & Emery

What ICO guidance on anonymisation means for health and life sciences companies

What new guidance on anonymisation from the UK Information Commissioner’s Office (ICO) means for healthcare and life sciences companies....more

DLA Piper

Spain: Spanish Data Protection Authority Publishes Annual Report

DLA Piper on

The Spanish Data Protection Authority (“AEPD“) has published its 2024 annual report, which includes the AEPD’s awareness-raising activities; the collaboration and inspection activities of the Spanish authorities; relevant...more

Skadden, Arps, Slate, Meagher & Flom LLP

CNIL Clarifies GDPR Basis for AI Training – But It’s Just One Part of the Compliance Picture

Key Points - - The French CNIL’s recent guidance regarding the application of legitimate interest as a legal basis in AI training is welcome, but several other AI regulatory issues remain unresolved. - Issues such as...more

Skadden, Arps, Slate, Meagher & Flom LLP

EU Data Act: Three Months To Go Before New Rules on Data Access and Sharing Take Effect

Executive Summary - The EU Data Act, whose requirements apply from 12 September 2025, establishes new rights for businesses and consumers to access data they generated using “connected devices,” limiting the exclusive...more

Clark Hill PLC

Right To Know - June 2025, Vol. 30

Clark Hill PLC on

Cyber, Privacy, and Technology Report - Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed. State Action: North Dakota Passes Law...more

Wilson Sonsini Goodrich & Rosati

EU Reaches a Deal on Rules for Swifter Cross-Border GDPR Enforcement

On June 16, 2025, the Council of the EU (Council) and the European Parliament (EP) reached an agreement on a new regulation (the Draft Regulation) to enhance enforcement of the General Data Protection Regulation (GDPR). The...more

DLA Piper

EU: Brussels Court of Appeal Rules on IAB Europe and the TC String – Implications for GDPR Compliance

DLA Piper on

On 14 May 2025, the Brussels Court of Appeal (Market Court) delivered the long-awaited judgement in the case concerning the Transparency & Consent Framework (“TCF”) (case no. 2022/AR/292). The Court largely upheld the...more

King & Spalding

New Security Measures for Large Databases: When a DPA’s Directives Set Standards

King & Spalding on

In response to a record year of personal data breaches in 2024, affecting millions of individuals, the French data protection authority (CNIL) has published a set of security directives for operators of large databases. While...more

DLA Piper

Italy: The Garante Issues First GDPR Fine Over Employees Email Metadata Privacy Breach

DLA Piper on

The Italian Data Protection Authority (the Garante) has issued its first GDPR fine for, among other breaches, unlawful retention of metadata from employees’ emails and web browsing activities. The decision applies, for the...more

Goodwin

Training of Meta’s AI Systems and the Use of the European Users’ Data

Goodwin on

As of May 27, 2025, Meta (Facebook and Instagram) will start using some of the personal data of European users to train its artificial intelligence (AI) systems, including tools such as Meta AI and Llama language models....more

Constangy, Brooks, Smith & Prophete, LLP

Constangy Clips Ep. 10 - 3 Ways the GDPR Is Evolving with Today’s Tech Landscape

In recognition of the GDPR's 7th anniversary on May 25, 2025, Constangy Cyber Team member Matthew Basilotto explores how the European Union’s General Data Protection Regulation (GDPR) continues to adapt in the face of...more

Lighthouse

Current State of Data Protection Regulations in the US and EMEA

Lighthouse on

Organizations must continuously review and refine their data governance strategies to keep pace with a regulatory environment that is shifting at an unprecedented rate. In response to mandates for stronger compliance...more

Hogan Lovells

Malaysia’s Groundbreaking Cross Border Data Transfer Guidelines Explained

Hogan Lovells on

Malaysia’s newly released Cross Border Personal Data Transfer Guidelines mark a groundbreaking shift in its data protection regulatory landscape, requiring data controllers to conduct Transfer Impact Assessments and implement...more

King & Spalding

European Data Protection Board Report on AI Privacy Risks & Mitigations in Large Language Models

King & Spalding on

Large Language Models (“LLMs”) are a subset of artificial intelligence (“AI”) which use a type of machine learning called deep learning in order to understand how characters, words, and sentences function together. The advent...more

Skadden, Arps, Slate, Meagher & Flom LLP

Key Themes From the 2025 IAPP Global Privacy Summit

On April 23 and 24, 2025, regulators, industry leaders and data privacy leaders from across the globe convened in Washington, D.C. for the 2025 International Association of Privacy Professionals (IAPP) Global Privacy Summit....more

A&O Shearman

EDPB publishes draft Guidelines on personal data in blockchain and a report on AI privacy risks & mitigations in large language...

A&O Shearman on

On April 14 2025, the European Data Protection Board (EDPB) announced the outcomes of its plenary session that took place on April 8 2025, during which the EDPB adopted draft Guidelines on processing of personal data through...more

HaystackID

From Consent or Pay to AI Oversight: EDPB Expands Its Regulatory Reach in 2024

HaystackID on

What happens when data protection collides with the relentless pace of digital innovation? That’s the question the European Data Protection Board (EDPB) seemed to confront head-on in 2024, a year marked by unprecedented...more

Amundsen Davis LLC

Is My U.S.-Based Company Subject to the GDPR? Clearing Up European Data Privacy Law Misinformation

Amundsen Davis LLC on

If you are a compliance professional for a U.S.-based company, you have probably been told at some point that you have to worry about the General Data Protection Regulation (GDPR). Have you encountered one of these...more

724 Results
 / 
View per page
Page: of 29

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide