Skip to content

menu

Data Protection Report logo
Current Page:HomeAboutContact
Search
Close
Compliance and risk managementRegulatory responseData breachCybersecurity
View topics Archives
Subscribe

Data Protection Report

Data protection legal insight at the speed of technology

Agentic AI: the ICO’s early thoughts on the data protection implications

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on January 12, 2026

The ICO has kicked off 2026 with sharing its early thoughts on the data protection implications of agentic AI in its ICO tech futures: Agentic AI report. The report considers the novel data protection risks presented by agentic AI.

Subscribe to Data Protection Report

Subscribe to this publication

New York’s algorithmic pricing law

Photo of Annmarie Giblin (US)Photo of Susana Medeiros (US)Photo of Susan Ross (US)
By Annmarie Giblin (US), Susana Medeiros (US) & Susan Ross (US) on December 22, 2025

On November 10, 2025, New York’s disclosure law on algorithmic pricing went into effect.  This post will describe the law, a recent federal court case, and some potential effects, using precise geolocation data as an example.

The law

The law…

Regulators, including FCC, emphasize third party vendor cybersecurity monitoring requirements

Photo of David Kessler (US)Photo of Susana Medeiros (US)Photo of Susan Ross (US)
By David Kessler (US), Susana Medeiros (US) & Susan Ross (US) on December 19, 2025

Many data breaches occur not at the company that controls or owns the data, but rather at the company’s third-party service providers or vendors.  Regulators have noticed and have begun placing emphasis on a company’s obligation to monitor its service…

Happy e-Discovery Day

Photo of David Kessler (US)Photo of Andrea D'Ambra (US)Photo of Susana Medeiros (US)Photo of Ellen Blanchard (US)
By David Kessler (US), Andrea D'Ambra (US), Susana Medeiros (US) & Ellen Blanchard (US) on December 4, 2025

Happy e-Discovery Day! On December 4, 2025, legal professionals around the globe will unite to celebrate e-Discovery Day, a day where we honor the pivotal 2006 amendments to the Federal Rules of Civil Procedure (FRCP) that marked a turning point…

UK Cyber Security and Resilience Bill – new obligations for the data centre sector

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on December 3, 2025

This blog post includes headline points on new obligations for the data centre sector proposed under the Cyber Security and Resilience Bill, and existing obligations under the NIS Regulations. 

Continue reading

NIS Regulations Keeling Schedule for the Cyber Security and Resilience Bill – changes to the UK’s cyber security law

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on December 3, 2025

The Cyber Security and Resilience Bill proposes changes to the UK’s NIS Regulations. Without a ‘Keeling Schedule’ marking up the amendments, these can be difficult to track. We have prepared a mark-up reflecting the proposed changes.

Continue reading

Service provider outages test customer resiliency

Photo of Annmarie Giblin (US)Photo of Susan Ross (US)
By Annmarie Giblin (US) & Susan Ross (US) on November 26, 2025

On November 18, 2025, companies had another opportunity to test their resiliency when connectivity and security provider Cloudflare had an outage of about four hours, which resulted in several popular websites going offline while others managed to provide some services…

Update: CISA 2015 is reauthorized until January 2026

Photo of Will Daugherty (US)Photo of Remi Gambino (US)
By Will Daugherty (US) & Remi Gambino (US) on November 13, 2025

The Cybersecurity Information Sharing Act of 2015 (CISA 2015) has been temporarily reauthorized as part of the broader legislation passed on November 12, 2025, to reopen the federal government. Under the appropriation legislation, CISA 2015 is now reauthorized until January…

Changes to EU and UK data protection law – a tale of two GDPRs?

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on November 12, 2025

The EU Commission recently held a call for evidence on “simplification” of legislation in the data, cybersecurity, and AI space, ahead of a “Digital Omnibus” Act.  These changes look to make the EU’s digital rulebook more innovation-friendly, supporting the Commission’s…

California tightens data breach notification timelines, imposes 30-day notice requirement

Photo of Annmarie Giblin (US)Photo of Susana Medeiros (US)
By Annmarie Giblin (US) & Susana Medeiros (US) on November 5, 2025

California recently signed into law Senate Bill No. 446, which amends its data breach notification law, Section 1798.82 of the Civil Code, to require covered companies to notify affected California residents within 30 calendar days of discovery of the data…

Post navigation

Older Posts 
The latest from our blog network
Norton Rose Blog Network
Global Regulation Tomorrow

Open banking – process to establish a Future Entity

January 16, 2026
Global Regulation Tomorrow

ECB staff contribution to the Commission’s targeted consultation on the application of the market risk prudential framework

January 16, 2026
Global Regulation Tomorrow

Commission issues consultations on the EU venture and growth capital funds reform

January 16, 2026
Financial Institutions Legal Snapshot

Stricter Charter Flight Entry Requirements: Advance Passenger and Crew Manifest Vetting for 20 or More Passengers

January 16, 2026
Global Regulation Tomorrow

PRA ‘Dear CEO’ letters on 2026 priorities for supervising UK deposit takers and international banks

January 15, 2026
Global Workplace Insider

Commencement of The Paternity Leave (Bereavement) Act and Associated Regulations

January 15, 2026
Global Regulation Tomorrow

FMSB 2026 work plan

January 14, 2026
Global Regulation Tomorrow

Commission Notice on the application of the sustainable finance framework and the Corporate Sustainability Due Diligence Directive to the defence sector

January 14, 2026
Global Regulation Tomorrow

ESMA thematic notes on clear, fair and not misleading sustainability-related claims and ESG strategies

January 14, 2026
View the Norton Rose blog network

Data Protection Report

Facebook Twitter RSS LinkedIn YouTube
Published by
Norton Rose Fulbright LLP logo
DisclaimerPrivacy policy

About

More than a news source, the Data Protection Report provides thought leadership on emerging privacy, data protection and cybersecurity issues, and helps its readers proactively address risks and anticipate next steps in this crucial emerging field.

Read more

Topics

Archives

Copyright © 2026, Norton Rose Fulbright LLP. All rights reserved.