On December 9, 2025, the Financial Industry Regulatory Authority (FINRA) released its 2026 Annual Regulatory Oversight Report (2026 Report). The nearly 90-page report highlights emerging risks — including cybersecurity, data privacy, and generative AI (GenAI) — and offers tools and
Data Matters
Data Matters, published by Sidley Austin LLP, focuses on legal developments and regulatory issues related to data privacy, cybersecurity, and digital regulation. The blog covers topics such as compliance with financial industry regulations, data protection in financial services, implications of EU digital legislation including the AI Act and GDPR, and enforcement actions involving data and privacy. It also addresses practical guidance on consent-based marketing communications and emerging risks like generative AI. The content is relevant to legal professionals and businesses navigating the intersection of data governance, technology, and regulatory compliance.
Latest from Data Matters - Page 5
EU Digital Omnibus: Implications for MedTech Companies
The European Commission (Commission) released its Digital Omnibus package, which aims to streamline and recalibrate certain aspects of the fast-growing body of EU digital regulations, on November 19, 2025. Rather than rewrite the core legislative instruments, including Regulation (EU) 2024/1689…
EU Digital Omnibus: The European Commission Proposes Important Changes to the EU’s Digital Rulebook
On November 19, 2025, the European Commission officially adopted a proposal for the Digital Omnibus package. Specifically, the Digital Omnibus package consists of two legislative proposals, a Digital Omnibus on AI and a general Digital Omnibus (Digital Legislation Omnibus). The…
Texting in Texas: Texas AG Settlement Clarifies No Registration Needed for Consent-Based Text Messaging
Businesses that obtain consent prior to sending text marketing messages in Texas can breathe a cautious sigh of relief: the Texas Attorney General (Texas AG) has clarified that recent amendments to Texas’ telephone solicitation and telemarketing law enacted through Senate…
Data Protection in Financial Services Week 2025 – Webinar Recordings Now Live
Data Protection in Financial Services (DPFS) Week 2025 consisted of a series of webinars featuring industry leaders who offered invaluable insights on balancing AI with privacy, cybersecurity, and regulatory challenges within the financial services industry. DPFS Week was relevant to…
U.S. FDA and CMS Actions on Generative AI-Enabled Mental Health Devices Yield Insights Across AI Product Development
Industry is increasingly exploring the use of AI chatbots to potentially diagnose and treat various medical conditions, including in the area of mental health. FDA is just beginning to develop its regulatory framework for approved, cleared, or authorized devices in…
The UK’s First Copyright vs. AI Decision: Key Takeaways on a Win for the AI Industry
The UK’s first “Copyright vs. AI” decision (Getty Images (US) Inc & ors vs. Stability AI Limited [2025] EWHC 2863 (Ch)) marks a clear win for the artificial intelligence industry. The English High Court raised the rhetorical question on the…
Women in Privacy – Global Privacy Leadership Lunch
Join us in Brussels for our next Women in Privacy – Global Privacy Leadership Lunch.
The post Women in Privacy – Global Privacy Leadership Lunch appeared first on Data Matters Privacy Blog.
U.S. SEC Regulation S-P and Checklist: Compliance Deadline, December 3, 2025, Approaching for Large Entities
On May 16, 2024, the U.S. Securities and Exchange Commission (SEC or Commission) issued amendments to Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information, which became effective on August 2, 2024 (the Final Amendments). The deadline for…
New York Department of Financial Services (NYDFS) Clarifies Expectations for Third-Party Cybersecurity Risks Under its Cybersecurity Regulation, and Additional Amendments Go into Effect on November 1, 2025
On October 21, 2025, NYDFS, the New York State agency responsible for regulating financial services and products, issued an Industry Letter clarifying how “Covered Entities”[1] should manage cybersecurity risks arising from Third‑Party Service Providers (TPSPs) under the NYDFS Cybersecurity…