A new EU regulation requires all companies that provide software, as of 11 September 2026, to report actively exploited vulnerabilities and other security incidents to a designated governmental authority and to users. Breaches of this reporting obligation may result in
Connect on Tech
Connect on Tech, published by Baker McKenzie, focuses on legal developments and regulatory trends related to technology, data privacy, cybersecurity, and artificial intelligence. The blog covers topics such as AI governance and legislation, data breach notification laws, cybersecurity directives and compliance, privacy regulations including state-specific laws like those in California, and enforcement actions involving data security failures. It also addresses cross-border legal strategies, digital transformation, and the intersection of technology with other practice areas such as intellectual property, antitrust, and employment law. The content is aimed at helping businesses navigate the evolving legal landscape surrounding emerging technologies and data protection.
Blog Authors
Latest from Connect on Tech
Colombia: SIC Opens Consultation on Identity Verification Systems
On 8 September 2026, the Superintendence of Industry and Commerce (SIC) announced a public consultation to receive technical and legal input for the construction of guidelines, recommendations, and protocols on identity verification mechanisms and the processing of personal data in…
ICO updates data protection complaints framework
On 19 June 2026, Section 103 of the Data (Use and Access) Act 2025 (“DUAA“) came into force, inserting the new statutory “right to complain” into Section 164A and 164B of the Data Protection Act 2018.
This new right requires…
Thought for the week: AI-enhanced nation state cyber threats may be systemic
This article was originally published by IAPP linked here.
As AI-enhanced threats grow, organizations should continue shifting the balance toward stronger security and monitoring controls.
To begin your week, I recommend reading this recent Cybersecurity and Infrastructure Security Agency …
AI-generated marketing content: New EU AI Act disclosure rules and the UK position
What do companies need to know about disclosing use of AI in marketing in light of the changes introduced by the EU AI Act, and how does this differ for the UK? We have set out below a summary of…
U.S. Law Restrictions on International Data Transfers*
This article was originally published by BvD-News.
Until 2024, the United States had not restricted transfers of personal data to other countries and traditionally objected to data residency requirements and transfer restrictions that other countries enacted.² On February 28,…
Thought for the week: What Joy Bubbles can teach us about AI career development
This article was originally published by IAPP linked here.
What a pioneer “phone phreak” can teach today’s professionals about creativity, adaptation and finding their superpower.
To begin your week, I recommend listening to the “Click Here” podcast…
UK Government accelerates DMCCA subscription reforms to January 2027
The UK Government has announced that the new subscription contract regime under the Digital Markets, Competition and Consumers Act 2024 (“DMCCA”) will now come into force in January 2027, bringing forward the previously anticipated spring 2027 implementation date.
As noted…
Brazil: ANPD regulates Digital ECA transparency reports
First transparency report due by September 17 ANPD establishes minimum content and a deadline for September 17 for the first Digital ECA transparency report.
In brief
On August 11, 2026, the Brazilian Data Protection Agency (ANPD) issued Decision Order CD/ANPD…
Thought for the week: A shifting AI policy landscape
This article was originally published by IAPP linked here.
As AI policy evolves in China and the U.S., organizations should reassess strategy, dependencies and risks.
A recent article by The Wire China highlights remarks by China’s President Xi Jinping…