Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
EU Law analysis: The operator of an online marketplace on which an advertisement was placed was found not to have complied with its obligations under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), despite promptly removing the advert less than an hour after receiving a removal request. The court held that it was a joint controller of the sensitive personal data contained in the advert and should have implemented measures prior to publication to (i) identify advertisements that contain sensitive personal data, (ii) verify that the advertiser is the person whose sensitive personal data appears in the advertisement and, if not, establish that explicit consent has been given by the data subject, and (iii) put in place safeguards to prevent further distribution or dissemination of the unlawful advertisements. The operator’s EU GDPR obligations were not limited by the safe harbour provisions set out in Article 14 of Directive 2000/31/EC (the E-Commerce Directive). Written by Hind Habib, partner and Sarah Reynolds, senior associate at Schillings.
NEWS
MLex: Judges at the EU's highest court heard arguments on 9 January 2024 on whether a German pharmacist can sue a competitor for breaches of the EU's data protection law. The case has attracted attention because it is the first time that the Court of Justice has been asked to clarify whether a competitor can sue under the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) in a national court.
NEWS
EU Law analysis: This case concerns the lawfulness of mandatory collecting of customers’ titles, and incidentally their gender identity, when booking a train ticket. The Court of Justice ruled that such data collection (i) is not strictly necessary for the performance of a transport service contract and (ii) subject to an in-depth assessment of the national court, may not be justified by a valid legitimate interest of the transport company. This decision emphasises the need for any data controller to reassess its data collection practices, especially concerning personal identifiers that may not be essential for its services delivery. Written by March Schuler, partner at Taylor Wessing France, and Laura Huck, associate at Taylor Wessing France.
NEWS
MLex: OpenAI, the company behind generative-AI chatbot ChatGPT, is breaching the EU data protection rules by producing false information about individuals, according to a new complaint from the Austrian campaign group Noyb. The organization announced today that it has filed a complaint with the Austrian data protection authority and is demanding a fine be imposed on OpenAI.
PRACTICE NOTES
In brief Data protection laws in the EEA (the EU plus Iceland, Norway, and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, EEA data protection laws impose a large number of obligations on those ‘processing’ personal data (and on controllers of such processing). ‘Processing’ is broadly defined to include doing most things with data, including storing, deleting, collecting, disclosing or using it. One of the key protections under EEA data protection laws is the set of obligations placed on ‘controllers’ (usually meaning those that decide the purposes and means of processing) and ‘processors’ (those that process personal data on behalf of a controller further to the controller’s instructions). Among other things, EEA data protection laws usually require controllers and processors to put in place contracts containing certain minimum provisions and ensure any processor(s) they engage are suitable. In an outsourcing arrangement, the customer will often act as controller and the supplier as its processor. This Practice Note introduces the requirements
NEWS
EU Law analysis: On 30 April 2024, the Court of Justice ruled in the case of ‘La Quadrature du Net and others v Prime Minister, Minister of Culture’. The judgment addresses the legality of the retention and access to personal data, specifically IP addresses, by public authorities for the purpose of combating copyright infringements online. The court held that such access is permissible only under strict conditions and subject to prior judicial review. This decision has significant implications for data protection and the rights of internet users within the EU. Written by Alexander Schmalenberger, knowledge lawyer at Taylor Wessing in Hamburg.
NEWS
EU Law analysis: The European Commission has released an updated version of the Model Contractual Clauses for AI Procurement (MCC-AI), providing further guidance for public-sector buyers navigating AI procurement under the EU Artificial Intelligence Act (EU AI Act). However, these clauses also serve as a practical tool to help any private organisation meet their legal obligations when providing or procuring AI systems, particularly high-risk AI solutions. Patrick Van Eecke, partner, and Enrique Capdevila, special counsel, at Cooley, discuss the key takeaways of the MCC-AI for companies.
PRACTICE NOTES
This Practice Note tracks noteworthy decisions of the Court of Justice of the European Union related to data protection, including the interpretation of the General Data Protection Regulation (EU) 2016/679 (EU GDPR). The table below lists only final decisions, and may be read in parallel with Practice Note: Data protection cases before the Court of Justice of the European Union—tracker, for more information about the status of cases currently proceeding through the court. For an introduction to the EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Cases Case name and date Summary Jautiva, Case C-798/243 September 2026 Key themes: Public disclosure of shareholder data—lawfulness and proportionality—Articles 5 and 6The Court of Justice held that Article 14(d) of Directive (EU) 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders, of public limited liability companies. It further held that Articles 5 and 6 of the EU GDPR, read with Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, preclude
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025, pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. In brief Data protection laws in the EEA (the EU plus Iceland, Norway, and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, EEA data protection laws impose a large number of obligations on those ‘processing’ personal data (and on the controllers of such processing). Key protections under EEA data protection laws include restrictions on automated individual decision-making (in summary, decision making by automated means, with those data protection laws imposing significant additional protections for data subjects where the decision making occurs in the absence of any meaningful human intervention) and profiling (in summary, automated processing of personal data to evaluate things about a person (which may or may not feature human intervention)). This Practice Note
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module three (processor to processor) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A, the data exporter is a processor and the data importer is a processor, and the name, address, contact person’s details and relevant activities for each of them is as set out in [insert where set
NEWS
The Department for Business and Trade (DBT) has announced the launch of negotiations between the UK and Malaysia on a Digital Trade Agreement (DTA). The UK-Malaysia bilateral trading relationship was valued at £6.4 billion in 2025. The proposed DTA is intended to facilitate cross-border data flows, reduce administrative burdens through digital systems and establish protections for personal data, intellectual property, online consumers and cybersecurity. It also aims to strengthen international digital and technology co-operation by supporting responsible innovation in areas such as artificial intelligence and data.
NEWS
The Department for Science, Innovation and Technology (DSIT) has announced that it has commissioned Ipsos UK to conduct research on how UK private-sector organisations manage cybersecurity risks in their supply chains. The study aims to understand the practices, challenges, and needs of professionals responsible for procurement, supplier management, and third-party risk management. It will also examine their engagement with current DSIT and National Cyber Security Centre policy tools, which include the Global Standard on AI Cyber Security, the Software Security Code of Practice, Cyber Essentials, the Cyber Governance Code of Practice, and the Enterprise Device Principles.