On October 4, 2022, the EU adopted the Digital Services Act (“DSA”), which imposes new rules on providers of intermediary services (e.g., cloud services, file-sharing services, search engines, social networks and online marketplaces). The DSA will enter into force on November 16, 2022 — although it will only fully apply as of February 17, 2024.
Continue Reading EU Adopts Digital Services ActEMEA Tech Regulation
The Digital Markets Act for Privacy Professionals
This post is the first of a series of blog posts about the Digital Markets Act (“DMA”), which was adopted on July 18, 2022, and it deals specifically with those provisions of the DMA that are relevant to organizations’ privacy programs.
Continue Reading The Digital Markets Act for Privacy ProfessionalsNearing the Finish Line: Updates on the Digital Services Act
The Digital Services Act (“DSA”) is nearing final approval. The DSA imposes new rules on providers of intermediary services (e.g., cloud services, file-sharing services, search engines, social networks and online marketplaces). As we reported in July, the European Parliament voted to adopt the DSA on 5 July 2022. As we wait for the Council to adopt it, there have been a couple of updates in recent weeks, which we set out below. We will keep this blog updated as the finish line approaches.
Continue Reading Nearing the Finish Line: Updates on the Digital Services ActEU Publishes Draft Cyber Resilience Act
On September 15, 2022, the European Commission published a draft regulation that sets out cybersecurity requirements for “products with digital elements” (PDEs) placed on the EU market — the Cyber Resilience Act (CRA). The Commission has identified that cyberattacks are increasing in the EU, with an estimated global annual cost of €5.5 trillion. The CRA aims to strengthen the security of PDEs and imposes obligations that cover:
- the planning, design, development, production, delivery and maintenance of PDEs;
- the prevention and handling of cyber vulnerabilities; and
- the provision of cybersecurity information to users of PDEs.
The CRA also imposes obligations to report any actively exploited vulnerability as well as any incident that impacts the security of a PDE to ENISA within 24 hours of becoming aware of it.
The obligations apply primarily to manufacturers of PDEs, which include entities that develop or manufacture PDEs as well as entities that outsource the design, development and manufacturing to a third party. Importers and distributors of PDEs also need to ensure that the products comply with CRA’s requirements.
The requirements apply for the lifetime of a product or five years from its placement on the market, whichever is shorter. Due to the cross-border dimension of cybersecurity incidents, the CRA applies to any PDEs that are placed on the EU market—regardless of where they are manufactured—and imposes new mandatory conformity assessment requirements. The proposed regulation will now undergo review and potential approval in the Council of the EU and the European Parliament. Its provisions would apply fully within two years after entry into force, potentially in late 2026. We set out more detail and commentary below based on our initial review of the proposal.
Continue Reading EU Publishes Draft Cyber Resilience ActUK Government Sets Out Sector-Specific Vision for Regulating AI
The UK Government recently published its AI Governance and Regulation: Policy Statement (the “AI Statement”) setting out its proposed approach to regulating Artificial Intelligence (“AI”) in the UK. The AI Statement was published alongside the draft Data Protection and Digital Information Bill (see our blog post here for further details…
Continue Reading UK Government Sets Out Sector-Specific Vision for Regulating AIEuropean Parliament Adopts DSA
On July 5, 2022, the European Parliament adopted the Digital Services Act (“DSA”) with 539 votes in favor, 54 votes against and 30 abstentions, following the political deal reached on April 23, 2022 (see our previous blog here).
Key aspects
The DSA is addressed to providers of intermediary services…
Continue Reading European Parliament Adopts DSAPolitical Agreement Reached on New EU Horizontal Cybersecurity Directive
In the early hours of Friday, 13 May, the European Parliament and the Council of the EU reached provisional political agreement on a new framework EU cybersecurity law, known as “NIS2”. This new law, which will replace the existing NIS Directive (which was agreed around the same time as GDPR, see here) aims to strengthen EU-wide cybersecurity protection across a broader range of sectors, including the pharmaceutical sector, medical device manufacturing, and the food sector.
Continue Reading Political Agreement Reached on New EU Horizontal Cybersecurity DirectiveOnline Safety Bill to Proceed Through Parliament
On May 10, 2022, Prince Charles announced in the Queen’s Speech that the UK Government’s proposed Online Safety Bill (the “OSB”) will proceed through Parliament. The OSB is currently at committee stage in the House of Commons. Since it was first announced in December 2020, the OSB has been the subject of intense debate and scrutiny on the balance it seeks to strike between online safety and protecting children on the one hand, and freedom of expression and privacy on the other.
Continue Reading Online Safety Bill to Proceed Through ParliamentEuropean Parliament and Council Strike Deal on DSA and DMA
On April 23, 2022, the European Parliament and Council of the EU announced that they reached a provisional political agreement on the Digital Services Act (“DSA”) during their final trilogue meeting. The news comes roughly one month after the provisional political agreement on the Digital Markets Act (“DMA”).
Both acts…
Continue Reading European Parliament and Council Strike Deal on DSA and DMA
Draft Version of the European Health Data Space Regulation
Update: On May 3, 2022, the European Commission published the official version of the proposal for a European Health Data Space Regulation. It’s open for feedback until July 14, 2022.
Original blog post: On March 3, 2022, a leaked version of the proposal for a regulation setting up the European Health Data Space was published. The draft regulation will set up a common framework across EU Member States for the sharing and exchange of quality health data (such as electronic health records, patient registries and genomic data). The European Commission has not yet released an official version of the proposal. It is expected to do so on May 3.
The leaked proposal is a lengthy document (126 pages, excluding annexes) that contains within it a number of different sets of rules. Key requirements that are likely to be of interest to organizations in the life sciences sector are that the draft regulation proposes to:
- create new patient rights over their electronic health data, and sets out rules regarding use of electronic health data for primary care;
- establishes a pre-market conformity assessment requirement for electronic health record systems (“EHR systems”);
- sets out rules that apply to digital health services and wellness apps; and
- introduces a harmonized scheme for providing access to electronic health data for secondary use.
Continue Reading Draft Version of the European Health Data Space Regulation