Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
The Stockholm Chamber of Commerce (SCC) Arbitration Institute has launched a new digital form to initiate arbitration proceedings. This new method will be used instead of email and aims to increase cybersecurity and efficiency.
NEWS
This week's edition of EU Law weekly highlights includes analyses of Germany seeking a greater role for Member States in EU cybersecurity certification and a group of telecom companies seeking a clear legal basis to block CSAM websites. In addition this week, the EU Packaging Regulation came into application, the Commission published a draft delegated regulation establishing a methodology for calculating battery recycled content, the European Data Protection Supervisor issued an opinion on streamlining data protection rules for EU justice agencies, and the Commission opened a consultation on a draft delegated regulation concerning vineyard (re)planting authorisations and the EU Wine DataBank.
NEWS
The EU Agency for Cybersecurity (ENISA) has launched a survey aimed at micro, small and medium-sized enterprises (SMEs) to assess their readiness for implementing Regulation (EU) 2024/2487 (the Cyber Resilience Act (CRA)), which will apply from December 2027. The CRA introduces cybersecurity requirements for all products with digital elements placed on the EU market. The survey covers five areas: company profile, levels of awareness and readiness, existing cybersecurity practices, preferred support and communication channels and the maturity of CRA-relevant practices. The findings will support ENISA and the European Commission in developing targeted support measures, including awareness campaigns, training materials and tailored guidance, and provide evidence-based input to inform national and EU-level discussions on CRA implementation.
NEWS
The European Commission has announced new reporting duties under the Cyber Resilience Act from 11 September 2026. Manufacturers of products with digital elements made available in the EU must report actively exploited vulnerabilities and severe cybersecurity incidents. They must submit an early warning within 24 hours and a full notification within 72 hours. A final report is due within 14 days after a corrective or mitigating measure becomes available for an exploited vulnerability, or within one month for a severe incident. Notifications must be made through the Cyber Resilience Act Single Reporting Platform, operated by the European Union Agency for Cybersecurity. The Commission has published practical guidance and national market surveillance authorities will enforce the rules. The reporting duties cover products already on the EU market and new products. The Act’s wider product cybersecurity requirements will apply from 11 December 2027.
PRACTICE NOTES
This Practice Note contains guidance on digital regulation, including an explanation of the concept and the sectors in which it is relevant. What is digital regulation? The term ‘digital regulation’ does not have a defined legal meaning. In broad terms, it refers to the laws, rules, and regulatory frameworks that govern digital technologies, online activities, and data-driven services. In practical terms, digital regulation covers how governments and regulators control and oversee a number of different areas, as demonstrated below: The purpose of digital regulation is to protect users, ensure fair competition, manage risks, and promote trust in digital systems, while allowing innovation and economic growth. This Practice Note provides an introduction to the areas that form part of the digital regulation ecosystem and it also signposts more detailed content on those areas, including some of those which may be subject to sector-specific regulation. Online platforms and content The term ‘platform’ encompasses many different types of forum and functionality depending on the technologies deployed and the business model used. At a technical level, there are different kinds of platform
NEWS
This week's edition of EU Law weekly highlights includes analysis on HSBC losing its challenge to the €32m Euribor rigging fine. In addition, this week the Council of the EU adopted the EU Cyber Solidarity Act and an amendment to the EU Cybersecurity Act and approved conclusions to address labour and skills shortages, the European Data Protection Board approved the certification criteria for EU Data Protection Seal under EU GDPR, the European Commission introduced data specifications for alternative fuels infrastructure rollout, proposed common EV charging and hydrogen rules and opened consultations on implementing regulations for EUDI Wallets, and the European Central Bank published the second progress report on the preparation phase of the digital euro.
PRECEDENTS
1 Introduction 1.1 This personal data breach plan: 1.1.1 places obligations on staff to report actual or suspected personal data breaches; and 1.1.2 sets out our procedure for managing and recording actual or suspected breaches. 1.2 This plan applies to all staff[ in the UK], and to all personal data and special category personal data held by [insert organisation’s name]. This plan supplements our policies relating to [insert policies, eg data protection, information security and any other relevant policies]. 1.3 The table below explains some key terminology used in this plan: Term Meaning Personal data breach A breach of data security leading to the:—accidental or unlawful destruction of;—loss of;—alteration of;—unauthorised disclosure of; or—access to;personal data transmitted, stored or otherwise processed, eg accidental loss, destruction, theft, corruption or unauthorised disclosure of personal data. Personal data Information relating to a living individual who can be identified (directly or indirectly) from that information. Data subject The individual to whom the personal data relates. Special category personal data (sometimes known as sensitive personal data) Personal data revealing racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs or trade union membershipGenetic dataBiometric data (where used for
NEWS
Welcome to the Information Law yearly highlights for 2024: a hand-picked chronological summary of major news analysis and updates related to laws governing the use and dissemination of information and personal data. These highlights look back on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation. Key areas to watch for 2025 are also explored.
PRACTICE NOTES
This Practice Note is aimed at compliance professionals in law firms. It tracks key future developments in law firm compliance in England and Wales. It provides details of key dates for your diary (including forecasted dates where the actual date is unknown) and commentary in relation to key developments, including legislation, regulatory changes and consultations. For details of developments relating to financial crime compliance, see Practice Note: Financial crime compliance horizon scanner—2026. This horizon scanner does not cover past developments, such as legislation fully in force, implemented regulatory changes or concluded consultations. For details of past developments in the field of Practice Compliance, see Practice Notes: • Practice Compliance tracker—2026 • Financial crime compliance tracker—2026 • New and updated content 2026—Practice Compliance • Chronological list of changes to client care letter and TOB • Chronological list of changes to AML, CTF and counter-proliferation financing policy—law firms Complaints What’s happening? When? What’s the impact? Find out more LeO consultation on Scheme Rules, case fees and publication of ombudsman decisions The Legal Ombudsman (LeO) consulted on
NEWS
This week's edition of EU Law weekly highlights includes analyses on the European Commission’s revised draft on Merger Guidelines, a call for feedback on draft guidelines on trusted flaggers under the EU Digital Services Act, EU's plan to build carbon-storage market following major litigation, EU plan for telecom operators and satellite service providers to divide spectrum for government and commercial uses, EU probe on TikTok's addictive features could be resolved through stronger safeguards. In addition this week, the Commission issued formal notices to Member States for failure to transpose Directives, announced that from 28 May 2026, the use of four modules of the European Database on Medical Devices is mandatory under the Medical Devices Regulation and In Vitro Diagnostic Medical Devices Regulation published a roadmap to phase out animal testing in chemical safety assessments, presented the European Technological Sovereignty Package, appointed a Scientific Panel and an Advisory Forum to support enforcement of the EU AI Act, issued a statement supporting the G7 digital and tech ministers' agreement to create a safer and more secure digital space for minors, the Council of the EU agreed its position on the ‘Omnibus X’ on food and feed safety reforms and the European Union Agency for Cybersecurity (ENISA) published the NIS360 report on cybersecurity maturity.
NEWS
The European Parliament has approved new cyber resilience standards to protect all digital products from cyber threats in the EU. The standards adopted will ensure critical and important products are put into different lists based on their criticality and the level of cybersecurity risk they pose. The two lists will be proposed and reviewed by the European Commission. Products that pose a higher cybersecurity risk will be stringently analysed by a notified body, while others will go through a light conformity examination process, which will be managed internally by the manufacturers. The Council of the EU will now have to formally adopt the new cyber resilience standards for it to become law.
NEWS
This week's edition of EU Law weekly highlights includes analysis on expected compromise proposals on EU cybersecurity rules. In addition this week, the European Commission launched a call for evidence on a proposed Citizens Omnibus Initiative, published its third annual report on the implementation of the EU Digital Markets Act, issued guidance on the effective implementation of EU water laws, opened a consultation on proposed ecodesign requirements for iron and steel products, and proposed a regulation on 2 GHz mobile satellite services authorisation beyond 2027. The NIS2 Cooperation Group also adopted common templates for cyber incident reporting and the revised EU Waste Shipment Regulation started to apply.