Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (“NIS2 Directive”) entered into force on January 16, 2023.…
The deadline for NIS2 implementation passed more than 3 months ago. To date, 9 EU Member States have enacted implementing legislation, with registration requirements…
On 2 February 2025 the first deadlines under the EU AI Act took effect. We consider where these are likely to sit on your…
On 18 December 2024, the European Data Protection Board (“EDPB”) adopted its new opinion on the use of personal data for the development and…
The new Cyber Resilience Act is the first EU regulation on the cyber security of products with digital elements. This includes not only software…
The deadline for NIS2 implementation passed on 17 October, but only 6 EU Member States met that deadline, and 14 of the remaining 22…
While the GDPR imposes strict rules on sensitive data processing, gender identity does not automatically fall under this category. Only personal data revealing racial…
GDPR compliance and inclusion: striking the right balance The General Data Protection Regulation (GDPR) generally prohibits the processing of sensitive data relating to, e.g.,…
The use of Artificial Intelligence (AI) can, inadvertently, give rise to issues relating to data protection compliance and equality law. However, used properly, it…