Remove 2025 Remove Data protection Remove Due diligence
article thumbnail

European Data Protection Roundup – January 2025

Debevoise Data Blog

Our top five European data protection developments from January are: UK ransomware reporting proposals. DeepSeek investigated by Italian DPA over AI chatbot data collection practices. The EU Digital Operational Resilience Act came into force on 17 January 2025. DORA becomes applicable. UK ICO acts on cookie compliance.

article thumbnail

UK Financial Regulators Publish Response to AI Consultation – Seven Takeaways

Debevoise Data Blog

One possibility is for the UK Financial Regulators to introduce standardized AI due diligence requirements that firms must satisfy before they can adopt third-party tools. There is strong appetite for any future regulations to align with existing domestic and international laws and regulations.

article thumbnail

National Security Update: DOJ Unveils Rules Restricting Sensitive Bulk Data Transfers

Debevoise Data Blog

Third-Party Contractual and Compliance Obligations The rule prohibits data brokerage with any foreign person who is not a covered person unless the U.S. person ensures contractually that the foreign person will not engage in subsequent covered data transactions with a country of concern or covered person. DOJ expects U.S.