On September 30, 2026, the California Governor signed SB 690, which amends the California Invasion of Privacy Act (CIPA) to restrict private enforcement—but only for claims under CIPA’s pen register and trap-and-trace provisions arising from websites and online or
Happy Cyber Awareness Month
Happy October and Cyber Awareness Month! Ghosts and ghouls of Halloween are not the only danger lurking around the corner. Beware of increasingly sophisticated cyber threats. It is time to ward your surroundings with appropriate cybersecurity measures and candy.
As…
Internet privacy updates: CalPrivacy fines data brokers, Colorado proposes new AI regulations
Anyone who contracts for internet or social-media-based advertising may have overlooked two recent actions by the California Privacy Protection Agency (CalPrivacy) and the proposed draft AI regulations from Colorado, but there are some important takeaways that should not be missed. …
Cyber incidents and litigation risk: Key developments for UK organisations

As cyber incidents become more costly and complex, organisations are facing increasing exposure to personal data claims, mass actions and contractual disputes. We explore the key litigation trends, emerging risks and practical considerations shaping the UK data breach claims landscape.…
NYDFS levies $250,000 fine on licensee for inadequate cyber risk assessment
On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation…
The EU AI Act – when does it become enforceable now?

The Digital Omnibus on AI (AI Omnibus) has now been published in the EU’s statute book. This pushes back some of the application dates for the AI Act. So, what’s applicable now and when will the rest become applicable? This post gives an overview of key dates to be aware of and a timeline of when the obligations now become enforceable.…
Quantum computing and cyber risk


Most security commentators believe that quantum computing will put the “cracking” of public-key cryptography in reach. This underscores the importance of preparing for the quantum revolution from a legal and security perspective. Here we consider where to start in that…
Rhode Island’s new AI and healthcare privacy law

We recently published an article to commemorate AI Appreciation Day, but readers may also appreciate a law that recently passed In Rhode Island, known as the “Use of Artificial Intelligence by Healthcare Providers Notification Act.” The bill…
AI Appreciation Day 2026 and key developments in governance and compliance
As artificial intelligence (AI) becomes embedded in business operations, data protection frameworks are increasingly shaping how organizations manage AI use. This update highlights key regulatory developments, including risk-based approaches and sector-specific rules, and outlines practical considerations for compliance…
Record €18m fine for an IT service provider to the aviation sector – reuse of customer data

Spain’s data protection agency, the Agencia Española de Protección de Datos (AEPD), has fined Amadeus IT Group, S.A. (Amadeus) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026…











