Practical steps for navigating the landmark AI legal framework shaping Europe’s digital future.
The EU AI Act (the Act) comprehensively regulates the development and deployment of AI along the AI value chain. The Act forms part of a wider landscape
The Global Privacy & Security Compliance Blog, published by Latham & Watkins LLP, focuses on developments in privacy, data protection, and cybersecurity law across multiple jurisdictions. It covers regulatory updates, compliance strategies, and legal interpretations related to frameworks such as the GDPR, CCPA, and emerging AI regulations. The blog addresses topics including data breach reporting, non-material damages for data violations, cybersecurity incident management, and the evolving legal landscape for digital and AI technologies. It also analyzes significant court rulings and legislative proposals impacting privacy and security compliance for businesses operating globally.
The Resolution reaches any social media platform whose services are made available in, or directed at users in, the UAE.
By Brian A. Meenagh, Danielle van der Merwe, Ksenia Koroleva, and Fady Saleh
The United Arab Emirates…
Organizations should prioritize compliance efforts in light of mounting regulatory scrutiny and potential fines.
By Brian A. Meenagh, Danielle van der Merwe, and Faisal Imam*
The Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL) is now firmly…
Organisations doing business in India should note the differences between GDPR and DPDPA requirements, including potential programmes that may need uplift to ensure compliance.
By Gail E. Crawford, Calum Docherty, Fiona M. Maclean, Rhys McWhirter, Esther…
The executive actions emphasize public-private partnerships, enhanced information sharing, and leveraging commercial cybersecurity capabilities.
By Jennifer C. Archie, Marissa R. Boynton, Antony (Tony) Kim, Clayton Northouse, Michael H. Rubin, and Serrin Turner
On March 6,…
The Amendments, which took effect on January 1, 2026, will impact network operators and CIIOs within China and overseas.
By Rhys McWhirter, Hui Xu, and Bianca H. Lee
On October 28, 2025, the Standing Committee of the PRC…
The law has extraterritorial reach over digital platforms and internet service providers that operate in, or target users in, the UAE.
By Brian A. Meenagh, Danielle van der Merwe, Ksenia Koroleva, and Fady Saleh
The United Arab…
The Commission’s proposals may present far-reaching implications for companies operating in the EU’s digital landscape.
By Sophie Goossens, Jean-Luc Juhan, Susan Kempe-Müller, Alfonso Lamadrid, Myria Saarinen, Tim Wybitul, Gail E. Crawford, James Lloyd…
While the case is likely to be mentioned in upcoming non-material damages claims, its unique circumstances mean defence arguments remain robust.
By Tim Wybitul, Isabelle Brams, Timo Hager, and Thies Schmitte
On 1 October 2025, the General…
The measures, which take effect on November 1, 2025, position China with one of the more rigorous cybersecurity incident notification regimes in Asia.
By Hui Xu, Rhys McWhirter, and Bianca H. Lee
The Cyberspace Administration of China (CAC)…