Refine By
Clear all filter
About 703 results for "cybersecurity"
CHECKLISTS
This Checklist is designed for use by a buyer undertaking data protection due diligence in the course of acquiring the shares or assets of a business that processes personal data in the context of using, developing or supplying generative artificial intelligence (GenAI) systems. It aims to surface data protection risks and enable a buyer to form a comprehensive view of a target’s risk profile in respect of its GenAI systems, models or tools used for internal operational purposes or provided externally to third parties (Business GenAI Systems). GenAI—a type of artificial intelligence that creates new content, such as text, images, audio, video or code, based on patterns learned from training data—is now widely adopted across industries and national borders. GenAI systems typically rely on substantial volumes of data, including personal data, to train and refine their underlying models. Their development and deployment may therefore give rise to significant compliance challenges under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) regime, particularly in relation
PRACTICE NOTES
This Practice Note introduces the requirements of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) where a processor will process personal data on behalf of a controller in a commercial context. It assumes a degree of familiarity with key data protection concepts and terms and the role of key regulators. For a general introduction to EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). The requirements under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) are outside the scope of this Practice Note. For more information about the requirements under the UK GDPR, see Practice Note: Supply chains under data protection law—arrangements between controllers and processors. In brief Data protection laws in the EEA (the EU plus Iceland, Norway, and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU GDPR (which applies in the EEA) imposes a large number of obligations on those ‘processing’ personal data (and on
NEWS
Law360: On 18 September 2024, the US Food and Drug Administration (FDA) issued final guidance titled ‘Conducting Clinical Trials With Decentralized Elements’, for sponsors, investigators and other interested parties to support drug, biologic and medical device development.
NEWS
This week's edition of Risk & Compliance weekly highlights includes TikTok’s report of a possible sanctions breach to UK and Irish regulators and NCSC interim practical advice on managing cyber risks in agentic AI systems.
PRACTICE NOTES
Legislative framework for data security UK GDPR Assimilated Regulation (EU) 2016/679 (UK General Data Protection Regulation or UK GDPR) is the main source of data protection law in the UK. It is supplemented by the Data Protection Act 2018 (DPA 2018). For information on the UK GDPR and the DPA 2018, see Practice Notes: UK GDPR—the basics and The Data Protection Act 2018. FCA data protection requirements The FCA’s data protection requirements are set out in its Data protection webpage. Customer data is any identifiable personal information a firm has about a customer. This can be held in any format and includes: • information obtained by a firm in compliance with its anti-money laundering requirements • information obtained by a firm as part of its customer on-boarding process • information obtained by a firm as part of its suitability and appropriateness requirements, and • any other identifiable personal information a firm may have about a customer such as address, date of birth, national insurance number, passport information, family circumstances,
NEWS
Law360: Artificial intelligence (AI) again jumps to the forefront of our news cycle as a new generation of AI models in ChatGPT-5 is scheduled to roll out soon.
NEWS
Life Sciences analysis: Hélène Boland, senior associate and Fabien Roy, partner of Hogan Lovells, consider the key takeaways from the MDCG 2025-6 guidance on the interplay between the MDR/IVDR and the EU AI Act.
NEWS
This week's edition of EU Law weekly highlights includes analyses on the European Commission’s proceedings to clarify Google’s compliance with the EU Digital Markets Act obligations, EU regulators welcoming new principles to guide the use of AI in drug development, the Court of Justice’s judgement on the reimbursement of the cost of an air ticket in the event of flight cancellation, what X’s Grok deepfake scandal means for the enforcement of the EU digital rulebook and President Donald Trump saying that he would impose a 10% tariff on several countries in the EU beginning 1 February 2026. In addition this week, the European Parliament’s Internal Market and Consumer Protection Committee adopted proposals aimed at simplifying and digitalising EU product compliance rules, the European Data Protection Board published updated guidance on the EU–US Data Privacy Framework, the Agency for the Cooperation of Energy Regulators published guidance on the voluntary submission of information to support the monitoring of cybersecurity-related operational reliability performance indicators in the electricity sector, the Commission formally designated WhatsApp as a Very Large Online Platform (VLOP) under the EU Digital Services Act (EU DSA), opened EU DSA investigation into X over Grok AI and content risks and announced the conclusion of EU-India free trade agreement negotiations.
PRECEDENTS
Introduction The AI due diligence questionnaire in respect of the proposed purchase by [insert buyer name] (the Buyer) of the [entire share capital of [insert name of target company] Limited incorporated in England and Wales under number [insert company number] (the Company) OR [insert description of the business to be acquired] (the Business) as a going concern, together with certain assets used in the Business ] from [insert seller name] (the Seller) (the Project). This questionnaire is primarily intended to enable the Buyer and the Buyer’s professional advisors to obtain information relating to the use of artificial intelligence by the [Company and its affiliates OR within the Business] and to facilitate the collation of the documents which are required for inclusion in the data room (the Data Room) which will be made available to the Buyer. Please provide your answers in italics underneath each question. In addition, please provide copies of all relevant documentation in the Data Room, ensuring that all answers and documents are clearly marked
PRACTICE NOTES
The EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) became directly applicable and fully enforceable in EU Member States on 25 May 2018. As the EU GDPR is incorporated into the EEA Agreement and in force in each EEA state, references to EU Member States in the EU GDPR can generally be read to also include EEA members. The main approach to sanctions and enforcement that has been taken under the EU GDPR is to introduce higher penalties for non-compliance in the hopes of producing higher levels of compliance because of the increased penalty provisions and in particular the increased levels of fines for non-compliance—up to the greater of 4% of total global annual turnover or €20m. The EU GDPR also created the European Data Protection Board (EDPB) in an attempt to impose a more consistent application of the EU GDPR and penalties under it. This Practice Note examines: • the approach to sanctions and enforcement under the EU GDPR, including the role of the lead supervisory authority • the role of the
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. (d) The Appendix to these Clauses
CHECKLISTS
This Checklist sets out key considerations a controller should typically take into account when conducting an audit for the purposes of evaluating the suitability of a prospective or existing processor of personal data under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). Note that this Checklist considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction. For further information about the EU GDPR and arrangements between controllers and processors, see Practice Notes: The EU’s General Data Protection Regulation (EU GDPR), EU GDPR—outsourcing and data protection and Supply chains under EU GDPR—arrangements between controllers and processors. Audits of processors Although processors subject to the EU GDPR have their own particular responsibilities under the legislation, controllers remain responsible for the processor’s processing of personal data under their instructions. Under: • the accountability principle of the EU GDPR: the controller is responsible for,