Refine By
Clear all filter
About 703 results for "cybersecurity"
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025, pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note provides further guidance on key definitions used in the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (the EU GDPR). Scope of this Practice Note This Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction. Given the extensive data flows between EEA and other jurisdictions, practitioners may have to consider not only the extra-territorial effects of the EU GDPR in other jurisdictions, but also the extra-territorial effect of the data protection laws of third countries on the processing and use in the EEA of personal data relating to individuals located in those third countries. Background
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025, pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note explains the lawful bases for processing personal data under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). It assumes a degree of knowledge about EU data protection law. For a general introduction to EU GDPR, including guidance on key data protection concepts and terminology, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR) and the EU data protection law collection. Note that: • this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction • in certain circumstances the EU GDPR has extra-territorial reach which means that it may apply alongside
NEWS
MLex: After an unprecedented five years for digital and cybersecurity legislation, the EU must now turn to the tricky and technical task of implementation. There are growing calls for the EU to hold off on passing any more digital laws, so that companies and regulators get some time to figure out how they all work together, and how to implement the new laws in a way that works.
NEWS
Our new Risk & Compliance forecast (as at 15 October 2024) is now live. This month we report on items including: (1) ICO announcements on expected new and updated guidance on data security and cybersecurity; (2) the publishing of the Employment Rights Bill 2024; (3) confirmation by the Department for Science, Innovation and Technology that the Cyber Security and Resilience Bill will be introduced to Parliament in 2025; and (4) confirmation that the new Office of Trade Sanctions Implementation is up and running.
NEWS
The European Union Agency for Cybersecurity (ENISA) has published a report on engineering personal data protection in EU data spaces. The report has two main sections—section 2 deals with ‘Data Protection Considerations in EU Data Spaces’ and Section 3 deals with ‘Health–Pharmaceutical Use Cases’. Section 3 includes use cases on both the availability of pharmaceutical products in the market, and research and analysis on the efficiency of pharmaceutical products.
NEWS
The European Commission has announced a new package of digital cooperation measures with Moldova. As part of this, the Council has authorised Moldova’s access to the EU Cybersecurity Reserve, representing the first cyber agreement reached during the Danish Presidency. The Commission in a press release stated that this marks a ‘key advancement in regional security and EU-Moldova digital cooperation under the EU’s Cyber Solidarity Act’.
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025 pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note explores the rights provided to individuals whose personal data is processed under the EU’s General Data Protection Regulation (EU GDPR) regime. It assumes a degree of knowledge about EU data protection laws. For a general introduction to those data protection laws, including guidance on key data protection concepts and terminology, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Note that: • the EU GDPR permits a number of national derogations to the rights of data subjects • this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction This Practice Note explores each
NEWS
MLex: Microsoft has been approved to support the European Commission in its defense of a trans-Atlantic data transfer agreement at the EU's highest court, after arguing that a ruling to block data transfers would change its legal position, according to an EU court order. The appeal marks the third time the EU Court of Justice will review an EU-US data transfer deal, after it annulled two previous arrangements.
PRACTICE NOTES
This Practice Note explores the origins and practical implications of the requirements to assess levels of protection for data subjects and to implement appropriate supplementary measures, in the context of making a restricted international transfer of personal data relying on Article 46 of Regulation (EU) 2016/679, the EU’s General Data Protection Regulation (EU GDPR). This Practice Note assumes a degree of familiarity with key data protection concepts and terms such as ‘processing’, ‘personal data’, ‘controller’/‘processor’ and ‘data subject’—as well as the role of key supervisory organisations and the international transfer regime under the EU GDPR. For a general introduction to EU data protection law and key terms, see Practice Notes: • Key definitions under EU data protection law • The EU’s General Data Protection Regulation (EU GDPR) • EU GDPR—transfers of personal data internationally and to international organisations Transfer impact assessments (TIAs) are one of the most complex and uncertain aspects of data protection. This Practice Note is therefore layered, with an introductory ‘In brief’ section which gives an overview of TIAs,
PRACTICE NOTES
A key objective of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) was to achieve a level of consistency in relation to how data protection law is implemented and enforced across the EU and EEA. However, there is no single repository for enforcement actions taken by the over thirty supervisory authorities that exist across Europe. See Practice Note: EU and EEA data protection supervisory authorities for a list of the main supervisory authorities in the EU and EEA. Due to the lack of a single repository for enforcement actions, this Practice Note is not comprehensive but tracks those EU GDPR enforcement decisions: • published as a ‘national news’ press release by the European Data Protection Board (EDPB) (and generally only where these fines equal €250,000 or more, though some lower-value fines are recorded below) • that the Lexis+® UK Information Law team otherwise become aware of from various sources where total fines are over €2m References to provisions are to those of the EU GDPR. Entries may adopt common data
PRACTICE NOTES
This Practice Note tracks key developments in relation to the European Commission’s reforms to the procedure for enforcement of the EU’s General Data Protection Regulation (EU) 2016/679 (EU GDPR) in cross-border cases. The reform takes place via Regulation (EU) 2025/2518 (the Procedural Regulation). This tracker summarises legislative and regulatory developments in addition to letters, opinions, responses, recommendations and advice issued by EU institutions, bodies, associations, offices and agencies. Note that the Procedural Regulation (reform to procedure in cross-border cases) is separate from the proposals for simplification of record-keeping rules and other ‘Digital Omnibus’ package changes to the EU GDPR—for more on that score, see instead Practice Notes: EU 2024–2029 simplification agenda—tracker and EU Digital Omnibus—tracker. Background to the proposal for EU GDPR procedural rules Under the EU GDPR, independent national data protection authorities, also known as supervisory authorities (SAs), have been tasked with its enforcement and are expected to co-operate and adopt shared decisions under the ‘one-stop-shop’ mechanism. Ultimately, this ‘one-stop-shop’ mechanism allows operators to deal with a single SA in cross-border data protection cases, while
PRACTICE NOTES
ARCHIVED: This archived Practice Note introduces the 2001 and 2004 controller to controller and 2010 controller to processor standard contractual clauses (also called Model Clauses or SCCs) approved by the European Commission as applicable under Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). Collectively those SCCs are referred to as the pre-2021 SCCs in this Practice Note. A decision of the Commission published in the Official Journal of the EU on 7 June 2021 had the effect of: • introducing new SCCs approved by the Commission (the 2021 SCCs), which may be used from 27 June 2021 • repealing all the pre-2021 SCCs referred to in this Practice Note with effect from 27 September 2021 (thereby revoking the ability of organisations to use the pre-2021 SCCs in new contracts from that revocation), and • permitting contracts concluded before 27 September 2021 on the basis of the pre-2021 SCCs to continue to be used to provide appropriate safeguards for international transfers under the EU’s General Data Protection