Refine By
Clear all filter
About 703 results for "cybersecurity"
PRACTICE NOTES
This tracker covers the development of the EU-US Data Privacy Framework (DPF) following the invalidation of the Safe Harbor and Privacy Shield frameworks. The DPF facilitates international transfers of personal data to the US by way of an adequacy decision (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework) where such transfers would otherwise be prohibited by the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). An outline of the concept of adequacy is provided below, however, this tracker should be read alongside Practice Note: EU GDPR—transfers of personal data internationally and to international organisations for further information. In brief, Article 44 of the EU GDPR prohibits the transfer of personal data to a third country outside of the EEA, or to an ‘international organisation’ (an international transfer). However, in certain circumstances, an international transfer of personal data may be permitted where the transfer
PRACTICE NOTES
This Practice Note tracks cases currently being heard in the Court of Justice of the European Union related to the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) or the previous Directive 95/46/EC (Data Protection Directive). It is updated on a monthly basis. For an introduction to the EU GDPR, see: UK data protection law collection and Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Name and case reference Main Articles at issue Developments Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen Case C-458/25 EU GDPR: Article 83(7) 10 September 2026: Advocate General’s Opinion6 October 2025: Application (OJ)11 July 2025: Request for a preliminary hearing Ministar na zdraveopazvaneto Case C-546/26 EU GDPR: Article 9 24 August 2026: Application (OJ)26 May 2026: Request for a preliminary ruling Protectra Case C-323/26 EU GDPR: Articles 80(1) and 82 17 August 2026: Application (OJ)14 April 2026: Request for a preliminary ruling Bundesverband für Inkasso und Forderungsmanagement Case
NEWS
This week's edition of Practice Compliance weekly highlights includes TikTok’s report of a possible sanctions breach to UK and Irish regulators and NCSC interim practical advice on managing cyber risks in agentic AI systems.
NEWS
Our new Practice Compliance forecast (as at 15 October 2024) is now live. This month we report on items including: (1) the publishing of the SRA’s updated 2024–25 business plan; (2) ICO announcements on expected new and updated guidance on data security and cybersecurity; (3) the publishing of the Employment Rights Bill 2024; (4) confirmation by the Department for Science, Innovation and Technology that the Cyber Security and Resilience Bill will be introduced to Parliament in 2025; and (5) confirmation that the new Office of Trade Sanctions Implementation is up and running.
NEWS
The Council of the EU has adopted the Cyber Resilience Act, which sets out safety requirements for products with a digital element. The Act introduces EU-wide rules for the design, development, production and making available on the market of hardware and software products, for example a CE mark being used to indicate compliance with safety standards. The legislation will apply to all products that are directly or indirectly connected to another device or to a network, and aims to make it easier for consumers to identify products with appropriate cybersecurity features.
NEWS
The Foreign, Commonwealth & Development Office (FCDO) has reported on the fourth Republic of Korea (ROK)-United Kingdom (UK) cyber dialogue that was held in London on 6 November 2024. The meeting brought together 50 officials from both nations to discuss key cybersecurity issues. The two sides agreed to strengthen cooperation in combating state-backed cyber threats, reaffirming their commitment to holding perpetrators accountable and deterring future incidents through collective action. The cyber threats that emanate from North Korea, Russia and China were also recognised.
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these Standard Contractual Clauses (the Clauses) is to ensure compliance with [OPTION 1: Article 28(3) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). OR OPTION 2: Article 29(3) and (4) of Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC.] (b) The controllers and processors listed in Annex I have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 and/or Article
NEWS
MLex: Google's new plans to give users more choice in how they receive online ads are likely to face close scrutiny from European Commission officials, as they weigh possible legislative proposals on web cookies and digital advertising in the coming months.
NEWS
MLex: Potentially conflicting legal requirements, national governance approaches to ensure regulatory consistency, as well as clear legal advice to minimise the compliance burden, are the main issues seen by EU Member States in the interplay between the EU AI Act and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). European governments have pointed out that the two laws' diverging regulatory approaches might lead to conflicting outcomes, which should be avoided with systematic cooperation between the responsible authorities.
NEWS
MLex: The EU’s draft data-sharing law is primarily concerned with non-personal industrial data. But attempts to fully exclude personal data from some provisions of the EU Data Act will force policymakers starting end-game talks on 29 March 2023, on the final shape of the law to wrestle with the practical distinction between personal and non-personal data. Failure to create clear rules could leave companies wondering which to apply.
PRACTICE NOTES
This Practice Note is intended to be used to track the status of adequacy decisions relating to cross-border/international transfers of personal data under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (the EU GDPR). It includes relevant opinions, reports and guidance issued by EU bodies relating to the status of new and existing decisions. For a comprehensive introduction to the EU GDPR, collating key practical guidance, see: UK data protection law collection. Background Although the text of the EU GDPR refers throughout to the ‘Union’, it is stated on page one of the regulation that it is a text ‘with EEA relevance’, meaning all provisions are intended to be applicable in respect of all EEA members, not just those that also have EU membership. Since the EU GDPR has been incorporated into the EEA Agreement and is in force, references to EU Member States in the EU GDPR can generally be read to also include EEA members. For further information on that incorporation, see the European Free Trade Association’s GDPR tracker. Article 44 of the EU GDPR prohibits
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module four (processor to controller) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A,