On July 24, 2025, the California Privacy Protection Agency (CPPA) approved regulations that would impose a new requirement under the California Consumer Privacy Act: mandatory annual cybersecurity audits for certain businesses. These new requirements are now undergoing review by the
Data Protection Report
Data protection legal insight at the speed of technology
Data Protection Report, published by Norton Rose Fulbright, focuses on legal developments and regulatory requirements related to data privacy, cybersecurity, and information governance. The blog covers topics such as third-party vendor cybersecurity obligations, data breach notification, compliance with global privacy laws, e-Discovery challenges involving electronically stored information, and the impact of emerging technologies like artificial intelligence on data protection. It also addresses sector-specific regulations, risk assessments, contractual standards for data handling, and incident response planning. The content is aimed at helping organizations navigate the evolving landscape of data protection laws and manage risks associated with data security and privacy in various industries.
Latest from Data Protection Report - Page 6
White House unveils AI Action Plan in artificial intelligence
On July 23, 2025, the White House released a sweeping new policy framework titled “Winning the AI Race: America’s AI Action Plan” (the “Plan”), describing the federal government’s approach to artificial intelligence (“AI”). This initiative, developed under the…
Integrating artificial intelligence in M&A processes: A new strategic era – Part 1: Leveraging AI and its advantages
Discover how artificial intelligence is reshaping the future of mergers and acquisitions. From identifying strategic opportunities to streamlining due diligence and enhancing contract negotiations, AI is revolutionizing every stage of the M&A process. This article explores the tangible advantages of integrating…
UK data protection reform – what you need to know and do
The Data (Use and Access) Act (DUAA) received Royal Assent on 19 June 2025. The DUAA enacts the changes to the UK’s data protection regime that have been contemplated since the Data: a new direction consultation in 2021.
This…
Global AI regulation
As organisations continue with their roll-out of AI, the global regulatory landscape is becoming increasingly complex. AI-specific laws like the EU AI Act already applicable and new AI-specific laws are proposed, adding to the range of existing laws and regulations…
California’s anti-employment-discrimination regulations now include AI, expand retention requirements
On June 27, 2025, the California Civil Rights Council, which is part of the Civil Rights Department, published revised regulations to protect against employment discrimination as a result of an employer’s use of artificial intelligence (AI) and other technologies that…
Canada’s Place in the AI Data Centre Boom
The Healthline Order: Privacy law grows teeth
The proposed $1.55 million CCPA settlement with Healthline is not just the largest of its kind to date – it is, more importantly, it marks a pivotal evolution in how American regulators are approaching consumer privacy enforcement.
The facts are…
AI and Job Postings: Navigating Ontario’s Upcoming Requirements
FTC’s COPPA Rule changes include AI training consent requirement
The Federal Trade Commission has published a Final Rule relating to changes in the Children’s Online Privacy Protection Act (“COPPA”) regulations, which will go into effect on Monday, June 23, 2025. The final Rule generally provides 365 days from the…

