The first major EU Cyber Resilience Act (the “CRA“) compliance deadline is fast approaching. From 11 September 2026, manufacturers within scope of the CRA must comply with new reporting obligations for actively exploited vulnerabilities and severe incidents. These requirements take effect more than a year before the CRA’s substantive provisions, making them an…

Continue Reading EU: Preparing for the Cyber Resilience Act’s September 2026 Reporting Obligations

Navigating Simplification Without Sacrificing Safeguards: Key Takeaways

As the EU begins the complex task of making the European Artificial Intelligence Act[1] (the “AI Act”) workable in real life, the European Commission’s Proposal for a Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules…

Continue Reading EU: EDPB and EDPS publish joint opinion on the European Commission’s Proposal for the Digital Omnibus on AI

Disclaimer: This article first appeared in the June 2024 issue of PLC Magazine, and is available at http://uk.practicallaw.com/resources/uk-publications/plc-magazine.

In order to capture the benefits of data-driven innovation, the EU and the UK are taking action to facilitate data sharing across various industries.

In the EU, the European Commission is investing €2…

Continue Reading EU/UK: Data-Sharing Frameworks – A State of Play in the EU and the UK

Disclaimer: The blogpost below is based on a previously published Thomson Reuters Practical Law practice note (EU AI Act: data protection aspects (EU)) and only presents a short overview of and key takeaways from this practice note. This blogpost has been produced with the permission of Thomson Reuters, who has the copyright over the…

Continue Reading Europe: The EU AI Act’s relationship with data protection law: key takeaways