Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
The European Commission has adopted three new regulatory technical standards (RTSs) which aim to complement the EU regulatory frameworks on cybersecurity matters for the financial sector by specifying rules to classify cyber incidents; rules to harmonise information and communication technology (ICT) risk management tools, methods, processes and security policies for the financial entities; and rules to establish the elements of risk that financial entities shall take into account when developing their policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers
NEWS
This week's edition of EU Law weekly highlights includes analysis of the Advocate General’s opinion on the EU Intellectual Property Office and the potential conflicts with UK trademarks when considering applications filed before Brexit. In addition this week, Directive (EU) 2025/794, the ‘Stop the Clock’ Directive postponing the application of sustainability rules was published in the Official Journal of the EU, the European Data Protection Board adopted guidelines addressing personal data processing through blockchain technologies, the European Commission launched a consultation on the revision of the EU Cybersecurity Act, launched a call for evidence to assess investment needs in the EU nuclear power sector, opened a public consultation on the EU Emissions Trading System and Market Stability Reserve, aims to simplify EU Deforestation Regulation implementation with new guidance, updated harmonised standards for medical devices. It also includes the launch by the Commission of a consultation on its new European Strategy for AI in science, the publication of the second version of the Commission’s guidelines on responsible use of generative AI in research, the provisional agreement of the European Parliament and the Council on a new Toy Safety Regulation and on a new EU Soil Monitoring Act.
PRACTICE NOTES
This Practice Note considers the ‘legitimate interests’ lawful basis for processing personal data under Article 6(1)(f) of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), including key guidance on this lawful basis from the European Data Protection Board (EDPB). It assumes a degree of knowledge about EU data protection law. For a general introduction to EU GDPR, including guidance on key data protection concepts and terminology, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR) and the EU data protection law collection. Note that: • this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction • in certain circumstances the EU GDPR has extra-territorial reach, which means that it may apply alongside the requirements of a third country’s data protection laws, see Practice Note: EU GDPR—extra-territorial reach This Practice Note is informed by
FLOWCHARTS
The EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) is directly applicable and fully enforceable in EU and EEA states. This Flowchart focuses on personal data breach notification under the EU GDPR. It covers: • a summary of the overarching obligations • key guidance • types of personal data breaches • the flowchart of notification requirements • general examples of personal data breaches and who to notify • detailed examples of personal data breaches and who to notify The EU GDPR includes the following definition of a personal data breach: ‘…a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.’ Overarching obligations In summary, among other things, the EU GDPR provides that: • data processors must notify the data controller without undue delay after becoming aware of a personal data breach • unless the personal data breach is unlikely to result in a risk to the rights and freedoms of individuals, the data controller must notify the appropriate supervisory
PRACTICE NOTES
This Practice Note is a guide explaining ‘how to’ incorporate precedent controller to processor (C2P) or processor to processor (P2P) provisions for compliance with the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) into a commercial contract. It is written from a supranational perspective and the laws of applicable EEA Member States and other jurisdictions should be sought where appropriate in the context of the applicable law of the contract and the location of performance of obligations in connection with the contract. This ‘how to’ guide assumes a basic level of knowledge about data protection law, including the meaning of key terms such as ‘personal data’ and ‘processing’. For introductory information on data protection law, see Practice Notes: Key definitions under EU data protection law and The EU’s General Data Protection Regulation (EU GDPR). This guide does not address: • the drafting and negotiation of mandatory C2P/P2P provisions in and of themselves • data sharing arrangements between controllers (C2C). For further guidance on such arrangements, see Practice
PRACTICE NOTES
This Practice Note covers the principles for handling personal data that form the core of the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) applicable in the EEA (as explained further below). For a general introduction to EU data protection law, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Note that this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction. The EU GDPR contains a set of core data protection principles that controllers must comply with. These are set out in Article 5, and include: • the lawfulness, fairness and transparency principle • the purpose limitation principle • the data minimisation principle • the accuracy principle • the storage limitation principle • the integrity and confidentiality principle • the accountability principle Recital 39 also offers additional guidance on each of the above. Lawfulness, fairness and transparency The first
PRACTICE NOTES
In brief Data protection laws in the EEA (the EU plus Iceland, Norway and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure this, the EEA data protection laws impose a large number of obligations on those ‘processing’ personal data and on controllers of such processing. ‘Processing’ is broadly defined to include doing most things with data, including storing, deleting, collecting, disclosing or using it. One of the key protections under EEA data protection laws is the set of obligations placed on ‘controllers’ (usually meaning those that decide the purposes and means of processing) and ‘processors’ (those that process personal data on behalf of a controller further to the controller’s instructions). Among other things, EEA data protection laws usually require controllers and processors to put in place contracts containing certain minimum provisions and to ensure any processor(s) they engage are suitable. In a cloud computing arrangement, the end customer will often act as controller and the supplier as its processor. This
PRACTICE NOTES
EU data protection laws include a right to data portability. That right allows individuals to obtain from a controller a copy of their personal data in a structured, machine-readable format. In addition, in some circumstances, individuals have the right to have that data transferred directly by the controller to another controller. This Practice Note addresses the right of data portability. It assumes a degree of knowledge about EU data protection laws. For a general introduction to those data protection laws, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Note that this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction. The right to data portability is designed to both support and enable the free flow of personal data within the EU, and to encourage healthy competition between controllers, by not only facilitating consumers switching between various service providers,
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025, pursuant to the European Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note examines the law and practice in relation to anonymisation, pseudonymisation and privacy enhancing technologies (or PETs). In particular, it looks at the requirements for effective anonymisation and pseudonymisation and an explanation of the basic techniques that may be used. This Practice Note also provides an introduction to the area of technologies known as PETs. The Practice Note considers the position under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and guidance where relevant. Anonymisation and pseudonymisation The EU GDPR imposes obligations in relation to the processing of ‘personal data’ (being data that relates to an identified or identifiable living individual). The EU GDPR does not include a definition of
CHECKLISTS
In brief In summary, data protection law in the EU is intended to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) imposes a large number of obligations on those ‘processing’ personal data, and on the controllers of such processing, when they are in the scope of the relevant regime. They also grant rights to those whose personal data is processed (the ‘data subjects’). ‘Processing’ includes doing almost anything with personal data, including storing, sharing, deleting or using it. It is virtually impossible to operate a business or other organisation without processing personal data. Among other things, the ‘controllers’ of personal data processing are required to provide certain information to data subjects, such as to ensure they know why their personal data is being collected, how it is being used, who it is being shared with, and their own key rights (that is called the ‘right to be informed’). That
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. (d) The Appendix to these Clauses
PRECEDENTS
The training materials are customisable. Click the links below to download the training presentation and speaker notes. Contents • What is the EU GDPR? • Terminology • Data protection principles • Material scope • Territorial scope • Processors • Lawful processing—personal data • Lawful processing—standard of consent • Lawfulness of processing—children • Special categories of personal data • Lawful processing—special categories of data • Pseudonymous data • Rights of data subjects • Exemptions • Data protection officers (DPOs) • Breach notification & communication • Data protection impact assessments • Accountability • Data protection by design & default • Transfers outside of the EEA • Sanctions