On September 23, 2025, Italy adopted Law no. 132/2025 on Artificial Intelligence (AI). The law will enter into force on 10 October 2025 and aims, inter alia, to complement the Regulation EU 2024/1689 (EU AI Act).
Data Protection Report
Data protection legal insight at the speed of technology
Data Protection Report, published by Norton Rose Fulbright, focuses on legal developments and regulatory requirements related to data privacy, cybersecurity, and information governance. The blog covers topics such as third-party vendor cybersecurity obligations, data breach notification, compliance with global privacy laws, e-Discovery challenges involving electronically stored information, and the impact of emerging technologies like artificial intelligence on data protection. It also addresses sector-specific regulations, risk assessments, contractual standards for data handling, and incident response planning. The content is aimed at helping organizations navigate the evolving landscape of data protection laws and manage risks associated with data security and privacy in various industries.
Latest from Data Protection Report - Page 5
CISA 2015 sunsets: Cyber Threat sharing without a net?
The Cybersecurity Information Sharing Act of 2015 (CISA 2015) expired on September 30, 2025, after Congress missed the reauthorization deadline. That lapse removes the decade-old legal framework that encouraged and protected cyber threat information sharing among companies, Information Sharing and…
China Issues Measures for the Administration of National Cybersecurity Incident Reporting – Published in collaboration with Shanghai Pacific Legal
In a significant regulatory development, the Cyberspace Administration of China (CAC) has officially issued the Measures for the Administration of National Cybersecurity Incident Reporting (the Final Reporting Measures), which will take effect on 1 November 2025. This follows the release…
Text messages and the new Texas registration requirement
On September 1, 2025, Texas amended its telephone solicitation law to include text messages and to add several new requirements, including a registration requirement with the Texas Secretary of State, plus a form of security (such as a bond) in…
Pseudonymised data could fall outside data protection law – introducing the “means reasonably likely” assessment
The Court of Justice of the European Union (CJEU) has delivered its judgment on case C 413/23 P European Data Protection Supervisor (EDPS) v Single Resolution Board (SRB). The CJEU has confirmed that pseudonymised data will not be personal data in all cases. This will…
Dutch DPA publishes report on personal data breaches
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (Dutch DPA) recently published a report on personal data breaches, which provides valuable insights into the Dutch DPA’s views on incident response. It also contains some helpful statistics.
Increase in follow-up action by…
Can you access your outsourced data?
Financial regulators globally emphasise the importance of financial entities being operationally resilient, which includes the ability to manage and recover from disruptions caused by their service providers. The topic receives significant attention in the financial services sector because the sector…
Explain yourself: The legal requirements governing explainability
Agentic AI brings the promise of AI making a range of decisions autonomously. It has been proposed as the way forward for some of the most impactful decisions in our lives: interacting with customers and actioning requests, triaging requests for…
NYDFS fines licensee $2 million for lack of email retention policy and MFA
On August 14, 2025, the New York Department of Financial Services (“NYDFS”) entered into a consent order with Healthplex, Inc, (“Healthplex”), which is licensed by NYDFS as an independent claims adjuster and as a life and/or accident health insurance agent. …
California’s proposed cybersecurity audit regulation
On July 24, 2025, the California Privacy Protection Agency (CPPA) approved regulations that would impose a new requirement under the California Consumer Privacy Act: mandatory annual cybersecurity audits for certain businesses. These new requirements are now undergoing review by the…