Refine By
Clear all filter
About 91497 results for "*"
PRACTICE NOTES
This Practice Note provides an overview of Directive 2019/1160/EU and Regulation (EU) 2019/1156, introduced as part of the Cross-Border Distribution of Funds (CBDF) package. Their primary aim was to facilitate and harmonise the cross-border distribution of collective investment funds across the EU, particularly alternative investment funds (AIFs) and undertakings for collective investment in transferable securities (UCITS). Key points on the CBDF package are as follows: • prior to the reforms, fund managers faced regulatory fragmentation when distributing funds across EU Member States. For instance, under the Alternative Investment Fund Managers Directive (Directive 2011/61/EU) (AIFMD), the term ‘marketing’ was interpreted differently by various Member States • in March 2018, the European Commission adopted a proposal for a regulation on facilitating cross-border distribution of collective investment funds, amending the European Venture Capital Funds (EuVECAs) Regulation (EU) 345/2013 (the EuVECA Regulation) and the European Social Entrepreneurship Funds (EuSEFs) Regulation (EU) 346/2013 (the EuSEF Regulation), and a proposal for a directive amending AIFMD and the UCITS Directive 2009/65/EC (the UCITS Directive) • the CBDF package introduced measures to further harmonise and align the operation of the marketing
NEWS
The European Commission has announced new reporting duties under the Cyber Resilience Act from 11 September 2026. Manufacturers of products with digital elements made available in the EU must report actively exploited vulnerabilities and severe cybersecurity incidents. They must submit an early warning within 24 hours and a full notification within 72 hours. A final report is due within 14 days after a corrective or mitigating measure becomes available for an exploited vulnerability, or within one month for a severe incident. Notifications must be made through the Cyber Resilience Act Single Reporting Platform, operated by the European Union Agency for Cybersecurity. The Commission has published practical guidance and national market surveillance authorities will enforce the rules. The reporting duties cover products already on the EU market and new products. The Act’s wider product cybersecurity requirements will apply from 11 December 2027.
NEWS
EU Law analysis: On 20 January 2026, the European Commission published a new ‘Cybersecurity Package’ consisting of a proposed Regulation referred to as ‘Cybersecurity Act 2’ of the ‘Revised EU Cybersecurity Act’ that would replace Regulation (EU) 2019/881, the current EU Cybersecurity Act (‘CSA’) and a proposal for a Directive amending Directive (EU) 2022/2555, the EU NIS 2 Directive (‘NIS2’). The proposals aim to address non-technical ICT supply-chain risks, reform the EU Cybersecurity Certification Framework, and make targeted changes to NIS 2. Written by Dr Henrik Hanssen, attorney and counsel at Hogan Lovells International LLP.
PRACTICE NOTES
This Practice Note tracks the key steps of legislative initiatives on cyber security in the EU. Key EU cyber security initiatives include: • Revised EU Cybersecurity Act (proposal published on 20 January 2026) • EU Cybersecurity Act (adopted, amendments adopted in January 2025) • Digital Operational Resilience Act or DORA (adopted, started to apply on 17 January 2025) • NIS 2 Directive (adopted, started to apply on 18 October 2024. Amendments proposed on 20 January 2026) • EU Critical Entities Resilience Directive or CER (adopted, started to apply on 18 October 2024) • EU Cyber Security Regulation (adopted, started to apply on 7 January 2024) • EU Cyber Resilience Act (adopted, starts to apply on 11 December 2027) • EU Cyber Solidarity Act (adopted, started to apply on 4 February 2025) All these initiatives are tracked in this document, except for DORA, which historical legislative progress is tracked in Practice Note: Operational resilience—timeline [Archived]. Note that several of these pieces of legislation will be impacted by the proposal for a Digital Omnibus on the digital acquis published
NEWS
The most stringent obligations set out by the EU Digital Services Act (EU DSA) will kick in for three Very Large Online Platforms (VLOPs) of the adult entertainment industry—Pornhub and Stripchat from 21 April 2024 and XVideos from 24 April 2024. While the EU DSA started applying to all online platforms of any size on 17 February 2024, VLOPs are subject to more stringent duties four months after the legal notification of their designation. They must identify and address in an effective manner systemic risks, particularly when it comes to mitigating risks to the well-being of minors, amplification of illegal content, and recommender systems. The European Commission will carefully monitor them and if it has suspicions of infringements of the EU DSA obligations, it will follow up with the appropriate steps, making use of the full EU DSA toolbox.
NEWS
EU Law analysis: Juan Ramon Robles, associate, Madrid; Cristina Barón, junior associate, Madrid; and Jasper Siems, associate, Hamburg of Hogan Lovells; provide some insights about the data sharing obligations under the incoming EU Data Act for smart car manufacturers and designers. They also address the possibilities to consider if data in-scope is protected by trade secret laws and explore other relevant topics such as privacy implications and the conditions for access by the users of smart cars and other potential recipients.
NEWS
MLex: The European Data Act has entered into force, putting in place new rules for ‘a fair and innovative data economy’, the European Commission said today in a statement. The Data Act will become applicable on 11 September 2025, 20 months after it entered into force.
NEWS
The EU Data Act started to apply on 12 September 2025, establishing new rules for data generated by connected devices. Under the Act, manufacturers are required to enable data sharing, while users receive enhanced rights to access device-generated data. The legislation also facilitates the switching of cloud service providers. To support implementation, the Commission will set up a dedicated legal helpdesk and issue guidance that includes model terms for data-sharing contract sand standard clauses for cloud contracts, along with clarifications on trade secret protections. Additionally, a broader Data Union Strategy is planned to simplify and enhance the EU's data framework.
NEWS
EU analysis: To aid in the implementation of Regulation (EU) 2023/2854, the EU Data Act, the European Commission has released a set of frequently asked questions (FAQ). With the EU Data Act being new and its implementation raising many questions, the Commission has now, issued an updated FAQ (version 1.2). Gernot Fitz, counsel and Estella Dannhausen, associate, of Freshfields LLP summarise the key changes of this update.
NEWS
TMT analysis: The EU Data Act has implications for vendors of Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) solutions to customers in the European Union. This article focuses on the Act's provisions (applicable from 12 September 2025) regarding customers wishing to switch to an alternative cloud provider midway through a subscription and terminate their contracts early. Written by Raj Shah of Mishcon de Reya.
NEWS
Information Law analysis: The Court of Justice held that the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (the EU GDPR) does not oblige supervisory authorities to exercise corrective powers, such as imposing fines, in every instance of a breach. Instead, they have discretion to determine whether action is appropriate, necessary, and proportionate based on the circumstances. This case underscores the importance for data protection practitioners of advising clients not only on compliance but also on engaging effectively with supervisory authorities to mitigate enforcement risks. It further acts as an aid for practitioners who are required to advise on the potential outcomes of a minor data breach and is an illustration of the benefits of implementing proper data protection measures in the event of any breach. Written by Adam Richardson, barrister at 4-5 Gray’s Inn Square.
PRACTICE NOTES
Introduction Tradeability is an essential characteristic of debt securities. Investors' ability to buy and sell—trade—debt securities depends on: • standardisation of the terms and conditions of debt securities (for more information, see Practice Notes: Terms and conditions of debt securities and Terms and conditions—first time issuer's guide) • the fungible nature of debt securities (for more information see Practice Note: Key legal issues in English law in debt capital markets—fungibility), and • the existence of a market which functions efficiently and securely and in which there is liquidity—the conditions in which debt securities can be sold quickly and easily at stable prices The market for debt securities depends on an extensive infrastructure of systems and services which can be divided into four broad areas: • infrastructure which helps create or maintain liquidity or allows investors to have access to liquidity (trading infrastructure) • infrastructure which eliminates the risk that a party who has entered into a contract for the sale and purchase of debt securities will fail to complete the transaction (clearing infrastructure) • infrastructure which