The first major EU Cyber Resilience Act (the “CRA“) compliance deadline is fast approaching. From 11 September 2026, manufacturers within scope of the CRA must comply with new reporting obligations for actively exploited vulnerabilities and severe incidents. These requirements take effect more than a year before the CRA’s substantive provisions, making them an

Continue Reading EU: Preparing for the Cyber Resilience Act’s September 2026 Reporting Obligations

On 7 July 2026, the European Data Protection Board (EDPB) adopted its draft Guidelines 02/2026 on Anonymisation for public consultation. The Guidelines provide long-awaited clarification on when data can truly be considered anonymous under the GDPR, updating the previous Article 29 Working Party’s 2014 Opinion on anonymisation to reflect significant legal, and technological

Continue Reading EU: EDPB Publishes Draft Guidelines on Anonymisation

Today, 17 July 2026, marks an important milestone under the EU’s Critical Entities Resilience Directive (CER), as Member States are required to identify and designate the entities considered “critical” for the provision of essential services.

Understanding the CER Directive

The CER forms part of the EU’s broader effort to strengthen the resilience of

Continue Reading EU: CER Directive enters a new phase as “critical entity” designation deadline arrives

Deepfakes (AI-generated synthetic media capable of producing highly realistic images, audio, and video of real individuals) have graduated from a mere novelty to a genuine legal concern. Using neural networks trained on visual and audio data, deepfake systems can replicate a person’s appearance and voice with remarkable fidelity, producing content that is often indistinguishable from

Continue Reading EU and China: Deepfakes and the law: perspectives from the EU and China

A proposed common template for personal data breach notifications recently published by the European Data Protection Board (“EDPB“) for consultation has the potential to assist organisations in streamlining personal data breach reporting across the EU while also raising additional complexity and challenges for businesses.

In line with the EDPB’s Helsinki Statement on enhanced

Continue Reading EU: EDPB common template for breach notifications – welcome alignment or further complexity?

The Data (Use and Access) Act 2025 (“DUAA“), introduces a new statutory requirement for all controllers, with no exceptions, to implement a formal process to handle data protection complaints by 19 June 2026.

Key changes

The DUAA received Royal Assent on 19 June 2025 and introduces a number of amendments to the UK’s data

Continue Reading UK: New complaints handling rules under DUAA take effect on 19 June 2026 – are you ready?

The protection of children online, including the safeguarding of their personal data, has emerged as a key regulatory focus in the UK, with the Government facing sustained pressure to address concerns about children’s safety online.[1] Recent developments have added further momentum – in particular, Australia’s recent prohibition on social media use by under-16s has

Continue Reading UK: Protecting Children Online – A Changing Regulatory Landscape

The UK Government’s legislative agenda, set out in the King’s Speech on 13 May 2026, places cybersecurity and digital resilience firmly at the centre of national policy. Against a backdrop of increasing geopolitical instability and rapidly evolving technological risks, the proposed measures continue the shift towards a more interventionist and systemic approach to safeguarding the

Continue Reading UK: The King’s Speech 2026 – Cybersecurity at the Forefront

Organisations are increasingly turning to AI-enabled tools throughout the recruitment lifecycle, from CV filtering and suitability scoring to online assessments and behavioural analysis. These tools can offer real advantages, including faster hiring processes and the potential to reduce human bias that inevitably exists in traditional recruitment. However, their use often creates a tension with data

Continue Reading UK: ICO Report on Automated Decision-Making in Recruitment

Summary

On 19 March 2026, the Court of Justice of the European Union (CJEU) handed down its judgment in Case C-526/24, Brillen Rottler, clarifying that a data subject’s first request for access to personal data under Article 15 of the General Data Protection Regulation (GDPR) may be refused as “excessive”.

Continue Reading EU: CJEU Rules That a Single DSAR Can Be Refused as Abusive