Deepfakes (AI-generated synthetic media capable of producing highly realistic images, audio, and video of real individuals) have graduated from a mere novelty to a genuine legal concern. Using neural networks trained on visual and audio data, deepfake systems can replicate a person’s appearance and voice with remarkable fidelity, producing content that is often indistinguishable from

Continue Reading EU and China: Deepfakes and the law: perspectives from the EU and China

A proposed common template for personal data breach notifications recently published by the European Data Protection Board (“EDPB“) for consultation has the potential to assist organisations in streamlining personal data breach reporting across the EU while also raising additional complexity and challenges for businesses.

In line with the EDPB’s Helsinki Statement on enhanced

Continue Reading EU: EDPB common template for breach notifications – welcome alignment or further complexity?

The protection of children online, including the safeguarding of their personal data, has emerged as a key regulatory focus in the UK, with the Government facing sustained pressure to address concerns about children’s safety online.[1] Recent developments have added further momentum – in particular, Australia’s recent prohibition on social media use by under-16s has

Continue Reading UK: Protecting Children Online – A Changing Regulatory Landscape

On 26 May 2026, Spain’s Council of Ministers approved a draft Organic Law on the proper use and governance of artificial intelligence, aligning Spain’s national law with Regulation (EU) 2024/1689 (the “EU AI Act”). The legislation aims to create a framework for trustworthy, human‑centric AI, combining regulatory oversight while supporting innovation.

Governance

Continue Reading Spain: Government approves the draft Organic Law on the proper use and governance of artificial intelligence

Summary

On 19 March 2026, the Court of Justice of the European Union (CJEU) handed down its judgment in Case C-526/24, Brillen Rottler, clarifying that a data subject’s first request for access to personal data under Article 15 of the General Data Protection Regulation (GDPR) may be refused as “excessive”.

Continue Reading EU: CJEU Rules That a Single DSAR Can Be Refused as Abusive

Navigating Simplification Without Sacrificing Safeguards: Key Takeaways

As the EU begins the complex task of making the European Artificial Intelligence Act[1] (the “AI Act”) workable in real life, the European Commission’s Proposal for a Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules

Continue Reading EU: EDPB and EDPS publish joint opinion on the European Commission’s Proposal for the Digital Omnibus on AI

On 20 January 2026, the European Commission proposed a new cybersecurity package, aimed at strengthening the EU’s cybersecurity resilience and capabilities. The package includes a revised Cybersecurity Act (“CSA“) and targeted amendments to the NIS2 Directive (see our blog post for further information on the amendments to the NIS2 Directive). The revised

Continue Reading EU Commission looks to strengthen EU Cybersecurity Resilience and Capabilities

The NIS2 Directive continues to evolve – and organisations must keep pace. On 20 January 2026, the Commission unveiled a set of targeted amendments to the NIS2 Directive (“the Proposal“), signalling the next phase of its push to modernise and streamline the EU’s cybersecurity legal framework.

Positioned within a broader legislative package, also

Continue Reading EU: NIS2 Update – EU Moves to Harmonise Cyber Controls, Refine Scope, and Add New In-Scope Entities

Over the last decade, the EU has launched an unprecedented constellation of laws: GDPR, the AI Act, the Data Act, NIS2, the Cyber Resilience Act, DORA, DSA, DMA, eIDAS 2.0 and more. Together – under the ‘Digital Decade’ banner – they aim to form a powerful framework to protect fundamental rights, promote trustworthy technology and

Continue Reading EU: Digital Autofocus – Will Europe’s Digital Omnibus bring clarity to Regulation? 

On June 26, 2025, the European Union Agency for Cybersecurity (ENISA) published two sets of guidelines to help businesses ensure their organizational compliance with the NIS2 Directive.

The aim of the guidelines is to support companies in understanding how legal requirements translate into operational activities, particularly regarding (i) roles and skills for professionals within essential

Continue Reading EU: ENISA Guidelines on Compliance with NIS 2 Directive Published