Refine By
Clear all filter
About 703 results for "cybersecurity"
PRECEDENTS
This is a set of Standard Contractual Clauses (SCCs) for compliance with Article 28(3) of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), governing relationships between controllers and processors and published by the Danish data protection supervisory authority (the Danish SCCs). It was published following an opinion by the European Data Protection Board (EDPB). The Danish SCCs should not be confused with SCCs relating to international personal data transfers under Chapter V of the EU GDPR. Access the Danish SCCs Click the link below to download the agreement from the EDPB’s website: Standard Contractual Clauses for compliance with Article 28(3) of the EU GDPR published by the Danish supervisory authority (the Danish SCCs) Background As detailed in Practice Note: Supply chains under EU GDPR—arrangements between controllers and processors, Article 28(3) of the EU GDPR requires that controllers and processors
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025, pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note is an introduction to the EU’s General Data Protection Regulation, Regulation (EU) 2016/679, which is more widely referred to as the GDPR and referred to in this Practice Note as the ‘EU GDPR’ to distinguish it from the UK GDPR. The Practice Note provides an overview of the concepts, regulatory oversight and obligations for organisations which are implemented by the EU GDPR. The Practice Note concludes with suggestions on how organisations can plan EU GDPR compliance activities. Introduction Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the General Data Protection Regulation)
PRACTICE NOTES
In brief Data protection laws in the EEA (the EU plus Iceland, Norway, and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, data protection laws impose a large number of obligations on those ‘processing’ personal data (and on the controllers of such processing). The data protection regime expressly recognises that the processing of children’s personal data requires specific protection, and provides enhanced protection for children’s personal data. This is because children may be less aware of the risks, consequences and safeguards concerned, and their rights in relation to the processing of personal data. Those additional protections are also relevant to organisations which aren’t actively seeking to process children’s personal data (eg designing a service aimed at adults) since they will need to consider whether they may inadvertently end up processing children’s personal data (eg if a child accesses that service). Organisations that do not adequately protect children’s data protection rights and privacy face particular scrutiny. For examples of enforcement
PRACTICE NOTES
Overview of legislation and key M&A considerations The EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) became directly applicable and fully enforceable in all EU Member States from 25 May 2018. It introduced substantial amendments to EU data protection law and replaced Directive 95/46/EC (the Data Protection Directive). The EU GDPR applies to the processing of personal data, provides rights to those data subjects whose data is processed and imposes obligations on both controllers and processors of the personal data. The EU GDPR is complex and principles-based. There are seven data protection principles that form the core of the EU GDPR, with which controllers that handle personal data must comply. These core principles are set out in Article 5. They are discussed in Practice Note: EU GDPR—data protection principles. Personal data and technology are increasingly important aspects of most businesses as the majority of businesses process information about employees, customers/clients, suppliers, etc. Data is a valuable and strategic corporate asset and can therefore be critical to the valuation of a
NEWS
Pensions UK has published its 2026 stewardship and voting guidelines, which set out strengthened expectations to protect and enhance long-term value in a complex investment climate. The guidelines, developed in response to increased geopolitical uncertainty, intensifying ESG scrutiny, and diminished shareholder rights, address recent market trends including a surge in AI-related resolutions, rising cybersecurity incidents, and revised UK listing rules affecting voting rights. The updated framework provides enhanced guidance on AI, cybersecurity, governance, climate and sustainability, social factors, and EDI, and introduces a pass-through voting option for direct shareholder rights. Complementary initiatives, such as a standardised vote reporting template and support for the Governance for Growth Investor Campaign, underscore the commitment to resilient and evidence-based stewardship in a rapidly evolving landscape.
NEWS
The European Commission has adopted the implementing regulation on Directive (EU) 2022/2555 (the NIS2 Directive), setting out cybersecurity risk management measures as well as the cases in which an incident should be considered significant. The implementing regulation will apply to particular categories of companies providing digital services, such as cloud computing service providers, data centre service providers, online marketplaces, online search engines and social networking platforms. The adoption by the Commission coincides with Member States having to transpose the NIS2 Directive into national law, and, from 18 October 2024, Member States must apply the necessary measures to comply with the NIS2 cybersecurity rules. The implementing regulation will come into force 20 days after it has been published in the Official Journal of the EU.
NEWS
This week's edition of EU Law weekly highlights includes analyses of the EU design reform and EU-US data transfers facing new pressure after US Supreme Court ruling. In addition this week, the European Commission released July 2026 infringement package, published EU Action Plan on cybersecurity and artificial intelligence, sought views on the proposed Cloud and AI Development Act and EU Chips Act 2.0, and adopted revised sustainability reporting standards. The European Parliament’s Industry, Research and Energy Committee also approved Parliamentary position on European Grids Package and its Environment, Climate and Food Safety Committee adopted position on changes to the EU Carbon Border Adjustment Mechanism. Finally this week, the European Parliament approved revised social security coordination rules for EU mobile workers and revised EU air passenger rights rules.
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.
NEWS
MLex: The advent of artificial intelligence (AI) technologies may prompt politicians to push for a revamp of the EU's data protection rules and an ‘attack’ on key principles of the General Data Protection Regulation, the data protection supervisor for EU institutions said in an interview. Such a review may come in 2025, EDPS Wojciech Wiewiórowski said. EU officials should be prepared to defend the questioning of the GDPR's major principles.
NEWS
MLex: A ‘majority’ of publishers, tech companies and online advertisers told the European Commission that it's ‘premature’ to sign up to a voluntary ‘cookie pledge’ that would address consumers' ‘cookie fatigue’ over repetitive banners, a spokesperson for the EU executive said on 19 April 2024. The move follows rising uncertainty facing companies about EU competition and privacy Data Protection Authorities' (DPA) views on behavioural advertising.
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module one (controller to controller) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A the data exporter is a controller and the data importer is a controller,
NEWS
This week's edition of Risk & Compliance weekly highlights includes: analysis of the Data (Use and Access) Bill of 2024 and of data breaches and liability in the age of AI, the latest sanctions news, a new anti-corruption champion and the release of the National Cyber Security Centre’s eighth Annual Review.