As cyber incidents become more costly and complex, organisations are facing increasing exposure to personal data claims, mass actions and contractual disputes. We explore the key litigation trends, emerging risks and practical considerations shaping the UK data breach claims landscape.
Data Protection Report
Data protection legal insight at the speed of technology
Data Protection Report, published by Norton Rose Fulbright, focuses on legal developments and regulatory requirements related to data privacy, cybersecurity, and information governance. The blog covers topics such as third-party vendor cybersecurity obligations, data breach notification, compliance with global privacy laws, e-Discovery challenges involving electronically stored information, and the impact of emerging technologies like artificial intelligence on data protection. It also addresses sector-specific regulations, risk assessments, contractual standards for data handling, and incident response planning. The content is aimed at helping organizations navigate the evolving landscape of data protection laws and manage risks associated with data security and privacy in various industries.
Blog Authors
Latest from Data Protection Report
NYDFS levies $250,000 fine on licensee for inadequate cyber risk assessment
On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation…
The EU AI Act – when does it become enforceable now?
The Digital Omnibus on AI (AI Omnibus) has now been published in the EU’s statute book. This pushes back some of the application dates for the AI Act. So, what’s applicable now and when will the rest become applicable?…
Quantum computing and cyber risk
Most security commentators believe that quantum computing will put the “cracking” of public-key cryptography in reach. This underscores the importance of preparing for the quantum revolution from a legal and security perspective. Here we consider where to start in that…
Rhode Island’s new AI and healthcare privacy law
We recently published an article to commemorate AI Appreciation Day, but readers may also appreciate a law that recently passed In Rhode Island, known as the “Use of Artificial Intelligence by Healthcare Providers Notification Act.” The bill…
Record €18m fine for an IT service provider to the aviation sector – reuse of customer data
Spain’s data protection agency, the Agencia Española de Protección de Datos (AEPD), has fined Amadeus IT Group, S.A. (Amadeus) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026, has found breaches of…
NYDFS issues guidance “in a heightened cybersecurity environment”
On May 21, 2026, the New York Department of Financial Services (NYDFS) issued industry guidance to licensees regarding security measures they should consider taking “in a heightened cybersecurity threat environment.” Even organizations not subject to NYDFS regulation may want to …
Is my use case a high-risk AI system? Applying the Commission’s guidelines and next steps
The EU Commission’s long-awaited guidelines on high-risk AI systems were published on 19 May 2026. This is the promised explainer on what is – and is not – a high-risk AI system under the EU AI Act.
The guidelines
The…
When AI becomes the cyber attacker: Mythos and what comes next
Anthropic’s April 7, 2026 announcement that it built a model too powerful for public consumption, Claude Mythos Preview (Mythos), marks a notable moment for the legal, compliance, and cybersecurity communities. It is no surprise that the US Department of the…
Colorado’s new AI governance law
We recently published an alert that highlights Colorado’s new artificial intelligence (AI) governance law. After X.AI sued to enjoin enforcement of Colorado’s first AI governance law and the federal government moved to intervene, the Colorado Attorney General agreed to temporarily…