Since its announcement during the King’s Speech on 17 July 2024, there has been much anticipation over the contents of the Cyber Security and Resilience Bill (“CS&R Bill”) and in particular the extent to which it will bring the UK
Privacy Matters, published by DLA Piper, focuses on legal developments and regulatory changes related to data privacy, cybersecurity, and information security. The blog covers topics such as amendments to cybersecurity laws in various jurisdictions, enforcement actions and fines under data protection regulations like the GDPR, insider threat management, and the intersection of emerging technologies like AI with privacy and cybersecurity law. It also addresses compliance challenges for organizations, contractual considerations with third-party vendors, and evolving standards of care in information security. The content reflects global perspectives, including updates from regions such as Singapore, the EU, China, and the Netherlands.
In a decision on immaterial damages under Article 82 of the EU General Data Protection Regulation (GDPR), the Higher Regional Court of Dresden, Germany (case number 4 U 940/24), set out important monitoring and auditing obligations of controllers…
On April, 8 2025, the Department of Justice’s final rule, implementing the Biden-era Executive Order 14117 restricting the transfer of Americans’ Sensitive Personal Data and United States Government-Related Data to countries of concern (the “Final Rule”), came into force.…
Following Malaysia’s introduction of data breach notification and data protection officer (“DPO”) appointment requirements in last year’s significant amendments to the Personal Data Protection Act (“PDPA”) (click here for our summary), the Personal Data Protection Commissioner of Malaysia (“Commissioner”) recently…
This article was originally posted to our Market Edge blog.
By Era Anagnosti, Brent Bernell, Daniel Caprio, Steven Phillips, Andrew Serwin, and John Gevertz
On February 18, 2025, President Donald J. Trump signed an Executive Order…
Chinese data regulators are intensifying their focus on the data protection compliance audit obligations under the Personal Information Protection Law (“PIPL”), with the release of the Administrative Measures for Personal Information Protection Compliance Audits (“Measures”), effective 1 May 2025.
The…
In a December, the Information Commissioner’s Office (ICO) responded to Google’s decision to lift a prohibition on device fingerprinting (which involves collecting and combining information about a device’s software and hardware, for the purpose of identifying the device) for organisations…