News & Analysis as of

Data Privacy General Data Protection Regulation (GDPR)

King & Spalding

EU & UK AI Round-up – July 2025

King & Spalding on

Over the last few months, organisations have accelerated efforts to engage with the requirements of the EU AI Act as we fast approach the date for when rules relating to general purpose AI models (“GPAI models”) come into...more

Fisher Phillips

Workday Ruling: How Europe’s Top Courts Raised the Bar for Employee Data Protection

Fisher Phillips on

Cloud-based HR systems have become standard for multinational businesses, driving efficiency but also increasing compliance and privacy risks. Indeed, a recent Workday case, which originated in Germany, has clarified the...more

Goodwin

France and the new EU regulation on political advertising: the CNIL updates its doctrine ahead of the 2025 implementation

Goodwin on

Online political advertising has become central to modern electoral campaigns. However, the growing lack of transparency, particularly regarding funding, targeting, and data processing practices, raises serious concerns about...more

Womble Bond Dickinson

From Data to Decisions: Navigating Privacy and Litigation Risks in the AI Era

Womble Bond Dickinson on

While many systems that are described as AI have been around for decades (e.g., internet search engines), today’s AI tools are much more powerful and are widely accessible. Generative AI and agentic AI extend the power of...more

Goodwin

Goodwin Antitrust & Regulatory Shorts: Three Laws, One challenge; Complying With the DSA, AI Act, and GDPR

Goodwin on

The Digital Services Act (DSA) and the Artificial Intelligence Act (AI Act) are key components of the EU’s constantly evolving, digital regulatory landscape. Once forming policy proposals, both regulations have now evolved...more

Benesch

Vermont Passes New Privacy Law Providing Safety Measures for Children Online

Benesch on

Vermont’s new “Kids Code” hopes to improve children’s safety online by regulating the privacy, design, and data use of certain entities providing online services and collecting data about minors....more

McDermott Will & Emery

AI meets real estate – Balancing innovation and compliance in the EU, UK, and US

McDermott Will & Emery on

Artificial Intelligence (AI) is taking the global commercial real estate market by storm. It is accelerating processes, driving down costs, and enhancing efficiency across a range of functions. In the EU, AI optimizes...more

DLA Piper

Italy: Garante Issues Fine for Use of Employee’s Private Chats in Disciplinary Actions

DLA Piper on

The Italian Data Protection Authority (Garante) has fined a company EUR 420,000 for violating privacy laws in the workplace. The decision focuses on the employer’s use of content from Facebook, WhatsApp, and Messenger— shared...more

Skadden, Arps, Slate, Meagher & Flom LLP

Something Is Better Than Nothing: UK and EU GDPR Reform Finally Arrives

In recent weeks, the EU and UK have both introduced changes to their respective versions of Europe’s landmark privacy legislation, the General Data Protection Regulation (GDPR). These reforms mark the first substantial...more

Womble Bond Dickinson

The ICO’s Penalty Against 23andMe Brings New Emphasis on Cybersecurity Risks - Key Takeaways for U.S. Companies

Womble Bond Dickinson on

The dramatic increase in global reach that the internet provides U.S.-based companies comes as a double edge sword. While it significantly increases a company’s potential customer pool, it also subjects companies to...more

TransPerfect Legal

DSARs in 2025: Stay Ahead of Regulations

TransPerfect Legal on

As data protection regulations evolve and employee rights awareness grows, organisations are seeing a significant uptick in Data Subject Access Requests (DSARs). Pursuant to Article 15 of the UK and EU General Data Protection...more

Dacheng

Cross-Border Data Processing under the "Offshore Model": China's Regulatory Approach in Comparative Context

Dacheng on

As the digital economy continues to thrive and remote work becomes increasingly mainstream, an “offshore model” of business operation has emerged. Under this model, companies may provide services to users in a given...more

Osano

Customer Data Privacy: Why It’s Important and How to Protect It

Osano on

Data privacy regulations aren’t known for being light reading. That doesn’t make it easy for businesses to become compliant. When one law refers to data subjects, another to residents, another to consumers, and another...more

Alston & Bird

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

Alston & Bird on

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK...more

McDermott Will & Emery

What ICO guidance on anonymisation means for health and life sciences companies

What new guidance on anonymisation from the UK Information Commissioner’s Office (ICO) means for healthcare and life sciences companies....more

DLA Piper

Spain: Spanish Data Protection Authority Publishes Annual Report

DLA Piper on

The Spanish Data Protection Authority (“AEPD“) has published its 2024 annual report, which includes the AEPD’s awareness-raising activities; the collaboration and inspection activities of the Spanish authorities; relevant...more

Hogan Lovells

Development of an AI system: CNIL issues guidelines regarding collection of data via web scraping

Hogan Lovells on

On 19 June 2025, CNIL published two additional “how-to-sheets” on artificial intelligence, one on the legitimate interest and the other on the collection of data via web scraping. These documents aim to clarify the rules...more

Skadden, Arps, Slate, Meagher & Flom LLP

CNIL Clarifies GDPR Basis for AI Training – But It’s Just One Part of the Compliance Picture

Key Points - - The French CNIL’s recent guidance regarding the application of legitimate interest as a legal basis in AI training is welcome, but several other AI regulatory issues remain unresolved. - Issues such as...more

Skadden, Arps, Slate, Meagher & Flom LLP

EU Data Act: Three Months To Go Before New Rules on Data Access and Sharing Take Effect

Executive Summary - The EU Data Act, whose requirements apply from 12 September 2025, establishes new rights for businesses and consumers to access data they generated using “connected devices,” limiting the exclusive...more

Clark Hill PLC

Right To Know - June 2025, Vol. 30

Clark Hill PLC on

Cyber, Privacy, and Technology Report - Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed. State Action: North Dakota Passes Law...more

Wilson Sonsini Goodrich & Rosati

EU Reaches a Deal on Rules for Swifter Cross-Border GDPR Enforcement

On June 16, 2025, the Council of the EU (Council) and the European Parliament (EP) reached an agreement on a new regulation (the Draft Regulation) to enhance enforcement of the General Data Protection Regulation (GDPR). The...more

Mayer Brown

US SEC Gives Green Light to Swiss-Based Investment Adviser Registration Applications

Mayer Brown on

On June 10, 2025, the US Securities and Exchange Commission (SEC) announced that it will immediately resume processing new and pending registration applications of investment advisers with their principal office and place of...more

DLA Piper

EU: Brussels Court of Appeal Rules on IAB Europe and the TC String – Implications for GDPR Compliance

DLA Piper on

On 14 May 2025, the Brussels Court of Appeal (Market Court) delivered the long-awaited judgement in the case concerning the Transparency & Consent Framework (“TCF”) (case no. 2022/AR/292). The Court largely upheld the...more

King & Spalding

New Security Measures for Large Databases: When a DPA’s Directives Set Standards

King & Spalding on

In response to a record year of personal data breaches in 2024, affecting millions of individuals, the French data protection authority (CNIL) has published a set of security directives for operators of large databases. While...more

DLA Piper

Italy: The Garante Issues First GDPR Fine Over Employees Email Metadata Privacy Breach

DLA Piper on

The Italian Data Protection Authority (the Garante) has issued its first GDPR fine for, among other breaches, unlawful retention of metadata from employees’ emails and web browsing activities. The decision applies, for the...more

1,246 Results
 / 
View per page
Page: of 50

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide