Cyber and Information security

The effect of the new UK cybersecurity laws

Charlotte Mullarkey

On 10 May the Network and Information Systems Regulations 2018 came into force in the UK. These implement the EU NIS Directive, EU-wide rules on cybersecurity. The NIS Directive had to be transposed into Member State laws by 9 May 2018. Many Member States have not met the deadline. Which companies are caught? The UK Read More

No Comments

Using artificial intelligence to fight financial crime – a legal risk perspective

Ian Rodgers

The Head of the Financial Crime Department at the UK Financial Conduct Authority (the FCA), Rob Gruppetta, gave a speech on “Using artificial intelligence to keep criminal funds out of the financial system” in December 2017 (1). In it, he explored how artificial intelligence (AI) could potentially be used to prevent financial crime, and for Read More

No Comments

US Consumer Financial Protection Bureau guidelines for third-party financial data sharing

Jacob Reed

On October 18, the U.S. Consumer Financial Protection Bureau (CFPB) published nine principles for the protection of consumers in the emerging financial data aggregation industry. The CFPB, which is charged with ensuring consumer access to fair and transparent financial services, emphasized that the principles are not intended as guidance on existing laws and regulations and Read More

No Comments

WP29 guidelines on personal data breach notification under GDPR

Anita Anand

The Article 29 Working Party this week published draft Guidelines on personal data breach notification under GDPR.  The relevant GDPR provisions are often misrepresented, and in many respects leave matters open to interpretation – a good or bad thing depending on the day.  Many are now asking what further clarity the draft guidelines bring for companies Read More

No Comments

The Netherlands: Obligation to notify serious cybersecurity incidents might expose banks to new risks

Peter Eijsvoogel

A draft Dutch law will, once adopted, require mandatory notification of security breaches or loss of integrity of ICT systems that may have a significant impact on the availability or integrity of certain vital products or services (the Bill). The Bill will affect the financial services sector. The new law is expected to take effect Read More

No Comments

ICO announced record fine on TalkTalk in relation to cyber attack

Lawson Caisley

On 5 October 2016, the Information Commissioner’s Office announced that it had imposed a record fine on TalkTalk in relation to the cyber attack suffered by TalkTalk last year. Click here for the official announcement. The following key points arise out of the ICO’s decision and comments: TalkTalk was fined because the ICO concluded that Read More

No Comments