Skip to content

menu

Data Protection Report logo
HomeAboutContact
Search
Close
Compliance and risk managementRegulatory responseData breachCybersecurity
View topics Archives
Subscribe

Data Protection Report

Data protection legal insight at the speed of technology

Data protection

Subscribe to Data protection via RSS

Record €18m fine for an IT service provider to the aviation sector – reuse of customer data

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on June 15, 2026

Spain’s data protection agency, the Agencia Española de Protección de Datos (AEPD), has fined Amadeus IT Group, S.A. (Amadeus) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026…

UK data protection complaints – new complaints handling obligations for controllers from 19 June

Photo of Elaine HilesPhoto of Rosie Nance
By Elaine Hiles & Rosie Nance on April 27, 2026

The changes to data controllers’ complaints handling obligations, made via the Data (Use and Access) Act, will come into force on 19 June 2026.  These include a new obligation to acknowledge complaints within 30 days, respond without undue delay, and…

Subscribe to Data Protection Report

Subscribe to this publication

Cybersecurity and Personal Data: The CNIL toughens its stance

Photo of Nadège Martin (FR)Photo of Laura HellocoPhoto of Geoffroy Coulouvrat (FR)
By Nadège Martin (FR), Laura Helloco & Geoffroy Coulouvrat (FR) on March 19, 2026

On 9 February 2026, the Commission Nationale de l’Informatique et des Libertés (CNIL) published its 2025 report on its enforcement action. Beyond the €487 million – in cumulative fines – largely driven (unsurprisingly) by two sanctions related to cookies, another…

Agentic AI: the ICO’s early thoughts on the data protection implications

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on January 12, 2026

The ICO has kicked off 2026 with sharing its early thoughts on the data protection implications of agentic AI in its ICO tech futures: Agentic AI report. The report considers the novel data protection risks presented by agentic AI.

Happy e-Discovery Day

Photo of David Kessler (US)Photo of Andrea D'Ambra (US)Photo of Susana Medeiros (US)Photo of Ellen Blanchard (US)
By David Kessler (US), Andrea D'Ambra (US), Susana Medeiros (US) & Ellen Blanchard (US) on December 4, 2025

Happy e-Discovery Day! On December 4, 2025, legal professionals around the globe will unite to celebrate e-Discovery Day, a day where we honor the pivotal 2006 amendments to the Federal Rules of Civil Procedure (FRCP) that marked a turning point…

UK Cyber Security and Resilience Bill – new obligations for the data centre sector

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on December 3, 2025

This blog post includes headline points on new obligations for the data centre sector proposed under the Cyber Security and Resilience Bill, and existing obligations under the NIS Regulations. 

Continue reading

NIS Regulations Keeling Schedule for the Cyber Security and Resilience Bill – changes to the UK’s cyber security law

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on December 3, 2025

The Cyber Security and Resilience Bill proposes changes to the UK’s NIS Regulations. Without a ‘Keeling Schedule’ marking up the amendments, these can be difficult to track. We have prepared a mark-up reflecting the proposed changes.

Continue reading

Changes to EU and UK data protection law – a tale of two GDPRs?

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on November 12, 2025

The EU Commission recently held a call for evidence on “simplification” of legislation in the data, cybersecurity, and AI space, ahead of a “Digital Omnibus” Act.  These changes look to make the EU’s digital rulebook more innovation-friendly, supporting the Commission’s…

Happy Cyber Awareness Month

Photo of Chris Cwalina (US)Photo of Will Daugherty (US)
By Chris Cwalina (US) & Will Daugherty (US) on October 14, 2025

Happy October and Cyber Awareness Month! While October ends with ghosts and goblins and other scary monsters for Halloween, the entire month of October is dedicated to raising awareness of cyber security and preventing (and if necessary responding to) cyber…

Pseudonymised data could fall outside data protection law – introducing the “means reasonably likely” assessment

Photo of Marcus Evans (UK)Photo of Rosie Nance
By Marcus Evans (UK) & Rosie Nance on September 4, 2025

The Court of Justice of the European Union (CJEU) has delivered its judgment on case C 413/23 P European Data Protection Supervisor (EDPS) v Single Resolution Board (SRB).  The CJEU has confirmed that pseudonymised…

Post navigation

Older Posts 

Data Protection Report

Facebook Twitter RSS LinkedIn YouTube
Published by
Norton Rose Fulbright LLP logo
DisclaimerPrivacy policy

About

More than a news source, the Data Protection Report provides thought leadership on emerging privacy, data protection and cybersecurity issues, and helps its readers proactively address risks and anticipate next steps in this crucial emerging field.

Read more

Topics

Archives

Copyright © 2026, Norton Rose Fulbright LLP. All rights reserved.