Generative AI systems are trained using vast amounts of data, often taken from sources in the public domain that may be protected by copyright or other intellectual property rights. So could training a generative AI system using publicly accessible copyright
Data Protection Report
Data protection legal insight at the speed of technology
Data Protection Report, published by Norton Rose Fulbright, focuses on legal developments and regulatory requirements related to data privacy, cybersecurity, and information governance. The blog covers topics such as third-party vendor cybersecurity obligations, data breach notification, compliance with global privacy laws, e-Discovery challenges involving electronically stored information, and the impact of emerging technologies like artificial intelligence on data protection. It also addresses sector-specific regulations, risk assessments, contractual standards for data handling, and incident response planning. The content is aimed at helping organizations navigate the evolving landscape of data protection laws and manage risks associated with data security and privacy in various industries.
Latest from Data Protection Report - Page 7
AI literacy – the Commission’s pointers on building your programme
The EU AI Act’s AI literacy obligation applied from 2 February 2025. This applies to anyone doing anything with AI where there is some connection to the EU – to providers and deployers of any AI systems.
The AI Act…
The California Privacy Protection Agency may be clicking through your website
The California Privacy Protection Agency (CPPA) just issued its second enforcement action under the CCPA and the message is clear: the CPPA is looking at your digital properties and tallying up the violations. Your website is more than a marketing tool;…
Navigating regulatory challenges in data centres
Businesses investing in, financing or operating data centres face a complex matrix of laws and regulatory requirements. Ensuring compliance is important for lender and investor due diligence and is crucial to avoiding fines, penalties and contractual or regulatory breaches that…
NT Analyzer can help determine “data broker” status under the new Bulk Data Transfer requirements
Even if your business only sells goods or services in the U.S., your business may be a “data broker” under the new bulk data regulations, according to an April 11, 2025 Compliance Guide issued by the U.S. Department of Justice,…
North Dakota law heightens data security requirements for some financial institutions
Background
On January 7, 2025, North Dakota’s House Industry, Business, and Labor Committee introduced HB 1127, at the request of the Department of Financial Institutions. HB 1127 successfully passed through both legislative chambers and was signed into law by the…
NT Analyzer adds JavaScript file analysis feature
In addition to NT Analyzer recently adding API mapping to its complement of services, we have also incorporated JavaScript file analysis targeting those JavaScript files that are downloaded to a user’s browser from third-party remote hosts while navigating a company’s…
NT Analyzer adds API mapping feature
This month, we have added “API mapping” and “JavaScript file analysis” as core components of the NT Analyzer tool suite. This post explains what API Mapping is and how the feature provides critical insights regarding the transmission and processing of…
New York Attorney General, personal data, and SHIELD Act
On March 20, 2025, the New York Attorney General (“NYAG”) announced a settlement with Ohio-based Root Insurance, regarding privacy practices relating to its auto insurance online quoting tool. As part of the settlement, Root agreed to pay $975,000 and to…
The differences between non-disclosure, exfiltration and notice – a court’s view
By David Kessler and Sue Ross
Although there is scant case law on the question, it is generally accepted that it is not a violation of one’s duty not to disclose information if it is stolen from you. Put another…