Ofcom has published its guidance for implementing age assurance measures for regulated service providers. User-to-user (U2U) services and search services take note: a decision not to implement highly effective age assurance measures means that your service may be deemed by
Enforcement
CSA releases guidance on the use of artificial intelligence in capital markets
On December 5, 2024, the Canadian Securities Administrators (CSA) released CSA Staff Notice and Consultation 11-348 – Applicability of Canadian Securities Laws and the Use of Artificial Intelligence Systems in Capital Markets (the Notice). The Notice was…
TR v Land Hessen – DPA not obliged to fine under the GDPR

By Shan Nanayakkara
In TR v Land Hessen (C‑768/21) the European Court of Justice (“ECJ”) found that following a personal data breach, a supervisory authority is under no obligation to exercise its corrective powers, specifically the power to…

Lessons on international transfers to the US to organisations caught by the GDPR
The Dutch data protection authority, the Autoriteit Persoonsgegevens (AP) announced a fine of €290 million on Uber Technologies Inc. (UTI) and Uber B.V.,(UBV) (together Uber) with press releases in Dutch and English. The fine relates to the transfer of…

Recent regulatory developments in training AI models under the GDPR



In 2024, many organisations have been eager to look at how they can use the data they hold to debut or build on their artificial intelligence (AI) programme. Many are looking to use that data to train AI models, or…
Two FTC complaints that over-retention of personal data violates Section 5


On January 18, 2024, the U.S. Federal Trade Commission announced a complaint and proposed consent order with InMarket Media, LLC, a digital marketing platform and data aggregator. Less than two weeks later, on February 1, the FTC announced a complaint…

US SEC charges SolarWinds and its CISO for alleged cybersecurity misstatements and controls failures
On October 30, 2023, the SEC announced charges against SolarWinds and its Chief Information Security Officer Timothy Brown.
Read our full analysis at www.nortonrosefulbright.com.
Special thanks to Law Clerk Ian Slingsby (Washington, DC) for his assistance in the…
Avoiding, Managing And Responding To Cyber Incidents
The UK’s ICO issues a monetary penalty notice to professional services firm after ransomware attack


On 10 March 2022, the Information Commissioner’s Office (ICO) issued a monetary penalty notice to a professional services firm (the Firm) to the tune of £98,000 for a breach of Article 5(1)(f) of the General Data Protection…
Rejecting cookies should be as easy as accepting cookies: new sanctions by the French authority (CNIL)

The French Data Protection Authority (the “CNIL”) continues its campaign against companies that do not respect the rules relating to cookies and other trackers, which the CNIL has previously reminded the market about in multiple communications and decisions.…