Refine By
Clear all filter
About 703 results for "cybersecurity"
PRACTICE NOTES
This Practice Note sets out a brief description of the key recent digital (Directive, Regulation and Code of Conduct) initiatives that businesses should consider when trading, offering or providing services in the EU or when they are established in the EU. It covers key initiatives related to: • Artificial Intelligence (AI) • Data • Online platforms • Online content • Liability and safety, and • Privacy and cybersecurity This Practice Note covers EU legislation or codes adopted recently as well as ongoing legislative initiatives. The initiatives are listed in chronological order. This Practice Note does not cover digital initiatives related to consumer law. For information on key EU consumer protection legislation such as the Digital Content and Services Directive (EU 2019/770), the Sale of Goods Directive (EU 2019/771), the EU Omnibus Directive (EU 2019/2161) and the EU Representative Actions Directive (EU 2020/1828), see Practice Note: Key EU consumer legislation—summary. This Practice Note does not cover cryptoassets, for more information, see Practice Note: EU regulation of cryptoassets. For more information on the key initiatives taken
PRACTICE NOTES
This Practice Note covers the material, personal and territorial scope of Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA). It also explains the classification of products under the CRA, such as non-critical, important and critical products. For more information on the background of the CRA or key obligations for economic operators, see Practice Notes: • The EU Cyber Resilience Act—overview and regulatory framework • The EU Cyber Resilience Act—obligations, compliance and enforcement The CRA is a first of its kind EU legislation that imposes mandatory cybersecurity standards on ‘products with digital elements’ throughout the EU. Products that do not meet these standards will not be eligible for sale on the EU market as of December 2027. Compliance with the CRA will therefore become essential to gain access to the EU market for hardware and software products. Manufacturers, importers and distributors of such products will be subject to extensive cybersecurity obligations and face substantial fines if they fail to comply. The CRA has been published
NEWS
Information Law analysis: On 12 November 2025, the UK Government put the Cyber Security and Resilience (Network and Information Systems) Bill (CSRB) to Parliament for its first reading. The CSRB is intended to improve the UK’s cyber defences and better protect services that the population of the UK relies on on a daily basis by introducing stronger security obligations and ensuring that critical infrastructure providers adopt proactive measures against evolving cyber threats. It will build on the existing rules in the UK Network and Information Systems Regulations 2018 (NIS Regulations), SI 2018/506 expanding the scope to new categories of providers and creating a framework for supplementary legislation and codes of practice to create a layered and flexible approach to regulating cybersecurity in the future. Although the Bill has now had its first reading in Parliament, it still needs to undergo several additional stages until we see the final version that receives Royal Assent and becomes an Act of Parliament. Written by Matthew Buckwell, a senior associate at Bird & Bird LLP with expertise in cybersecurity, telecommunications and data protection.
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a handpicked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. These highlights focus on key topics including data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
PRACTICE NOTES
STOP PRESS: This Practice Note reflects the current legislative position, however please note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025 pursuant to the Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note provides an overview of the key aspects of Directive (EU) 2022/2557 on the resilience of critical entities, the EU Critical Entities Resilience Directive (CER Directive), including its scope, key obligations for critical entities, its sanctions regime and what the new requirements mean for organisations in practice. The CER Directive is part of the EU’s broader effort to strengthen the resilience of critical infrastructure across sectors. It is not primarily a cybersecurity law, but it does intersect with cybersecurity as cyber incidents can threaten the resilience of critical entities, alongside other threats such as natural hazards, terrorism, insider threats, pandemics and sabotage. Background In an evaluation report published in July 2019, the European Commission determined that the technological, economic, social, political and environmental context
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that this position will be impacted by the Cyber Security and Resilience (Network and Information Systems) Bill which was introduced to Parliament in November 2025. For more information, see Practice Note: The UK NIS Regulations and the Cyber Security and Resilience (Network and Information Systems) Bill—tracker. This Practice Note provides an overview of the Network and Information Systems Regulations 2018 (NIS Regulations), SI 2018/506 which implemented the Network and Information Systems Directive (the NIS Directive), Directive (EU) 2016/1148 in the UK. The NIS Regulations (as amended by various Brexit legislation) continue to apply in the UK. It discusses the background and purpose of the legislation and the obligations for operators of essential services (OESs) and relevant digital service providers (RDSPs) under the NIS Regulations and the associated Assimilated Regulation (EU) 2018/151 (Assimilated DSP Regulation), in relation to RDSPs. Background to the NIS Directive The NIS Directive (also known as the Cybersecurity Directive or Network and Information Security Directive) was adopted
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
This week’s edition of Information Law weekly highlights includes a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation.
PRACTICE NOTES
The UK has one of the most web-based economies in the world, with the UK internet market valued in the order of billions of pounds a year. With this comes greater vulnerability. The threat of cybercrime to individuals, businesses and national and global security is very real. A number of organisations and schemes operate to combat that risk. This Practice Note contains a table of information on the most significant of these. National Hundreds of millions of pounds of public money is allocated to strengthen the UK’s cyber capacity and combat cyber threats. The following table gives an indication of how some of that money is