Remove Blog Remove Compliance Remove Data protection
article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.

article thumbnail

European Data Protection Roundup – February 2025

Debevoise Data Blog

Our top-five European data protection developments from February are: European Commission publishes guidelines on prohibited AI practices : The EU Commission has published non-binding guidance on the EU AI Acts prohibited use cases. The ban entered into force on 2 February 2025. Spanish Telecomm Provider Fined 1.2

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

AI Gets Personal: CCPA vs. GDPR on Automated Decision-Making

Berkley Technology Law Journal

privacy legislation, is now addressing these technologies with a new set of proposed rules by the California Privacy Protection Agency (CPPA). The European Unions General Data Protection Regulation (GDPR) , particularly Article 22 , addresses similar concerns by regulating decisions made solely through automated processing.

article thumbnail

European Data Protection Roundup – January 2025

Debevoise Data Blog

Our top five European data protection developments from January are: UK ransomware reporting proposals. DeepSeek investigated by Italian DPA over AI chatbot data collection practices. DeepSeek investigated by Italian DPA over AI chatbot data collection practices. UK ICO acts on cookie compliance.

article thumbnail

GDPR Considerations When Developing and Deploying AI Models: The EDPB’s Opinion on Compliance

Debevoise Data Blog

Given that AI models require large swathes of data to operate, the GDPRs expansive definition of personal data means that many applications of AI involve complex data protection issues especially where those datasets are obtained from third-party sources. To subscribe to the Data Blog, please click here.

article thumbnail

Red Tape and Reputations: Navigating Investigations and Compliance in Complex Markets

Lineal Services

When Compliance Gets Complicated, So Does Risk In todays regulatory climate, investigations go far beyond fact-finding. This is especially true in complex, cross-border matterswhere regulatory regimes, languages, and data protection frameworks collide. They require foresight, agility, and control.

article thumbnail

Navigating Compliance in Brazil: Cross-Border Strategies for Managing Regulatory Risk

Lineal Services

Between the Clean Companies Act (Lei Anticorrupo) and the evolving requirements of the General Data Protection Law (LGPD), organizations operating in Brazil must do more than simply complythey must demonstrate accountability, transparency, and operational precision in the face of mounting enforcement.