If you weren’t quite sure about the EU Cyber Resilience Act, this is what it does:

The Cyber Resilience Act (CRA) Regulation establishes mandatory cybersecurity requirements for “products with digital elements” (PDEs) that are placed on the EU market, in the course of commercial activity, whether in return for payment or free of charge. The stated objectives are: 1) ensuring that manufacturers improve the security of PDEs; 2) a coherent cybersecurity framework for hardware and software producers; 3) enhancing transparency; and 4) enabling businesses and consumers to use products with digital elements securely.

What are PDEs?

PDEs are software or hardware products and their remote data processing solutions, including software or hardware components being placed on the market separately. Remote data processing  is processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the PDE from performing one of its functions.

The scope is intended to cover products that have the ability to exchange digital information (not just respond or activate in response to a signal) and therefore may put it at risk. Further, software downloaded and installed or supplied to the user and that executes on the user’s system (e.g., a browser extension or mobile app downloaded from an app store) is in scope. Hardware and software provided by the same manufacturer in order for a product to function (e.g., drivers or interface apps), are together a PDE, even if supplied separately. But software that executes remotely and is only accessed by the user, is not necessarily a PDE (e.g., websites, unless they support the functionality of a PDE through remote processing).

From last Friday,  manufacturers of PDEs must report actively exploited vulnerabilities and severe security incidents using ENISA’s Single Reporting Platform. This is effectively first CRA deadline for manufacturers. The essential cybersecurity requirements — the ones most compliance programs are built around — don’t arrive until December 11, 2027, so we will not bore you with those here.

Continue Reading The EU Cyber Resilience Act’s Reporting Started last Friday, September 11. Here’s a Very, Very Brief Primer

The handbrake has been pulled on aspects of the EU’s AI Act (Act), with key workplace rules, particularly those on high-risk systems, pushed back from August 2, 2026, to December 2, 2027. 

The delay may feel welcome for multinational employers keeping up with the spread of AI adoption across their organization, but it is an opportunity to get the groundwork done. 

The European Commission in late May published draft guidelines on the classification of high-risk AI systems (Guidelineshttps://bit.ly/4vDtgOV) for the Act. This is the clearest indication yet of how EU workplace AI tools will be treated, using many real examples.

 To function efficiently across borders, business must incorporate these rules into their global compliance framework for legal, HR, talent acquisition, procurement, IT, data, compliance and operations. 

The extra months are useful runway, because HR, recruitment, performance management and workforce allocation tools will require the full gamut of “high-risk” systems compliance. Global employers need time to work this into a matrix of other global rules — including in multiple US jurisdictions (e.g., California, Colorado, Connecticut, New York), Canada, Korea’s Basic AI Act, the updated UK GDPR and emerging rules elsewhere. 

Below is a pragmatic look at what use cases trigger the Act, and what global employers need to do from governance, procurement, data protection and employee relations perspectives. 

Continue Reading Workplace AI — How Employers Should Prepare for the New EU AI Act Deadline

Episode 14 is now live. In this episode of Consumer Counterpoint, we sit down with Chicago partner Jay Carle to discuss the launch of Seyfarth’s new D.A.T.A. Law practice group. Jay shares insights into the group’s multidisciplinary approach and how it’s designed to help clients stay ahead of emerging data and technology challenges.

Watch Episode

The UK’s Data (Use and Access) Act received Royal Assent last Thursday, June 19th, bringing into law some significant changes to the country’s post Brexit data protection framework, among an array of other, related rules (on matters ranging from financial conduct to smart meters and “underground assets,” which is more to do with

As 2025 begins, businesses across the U.S. will be required to navigate an even more expanded landscape of state-level privacy regulations. In all, eight states are introducing comprehensive privacy laws, further adding to the growing patchwork of privacy requirements in the U.S.

January is kicking off with a flurry as five states (Iowa, Delaware, Nebraska, New Hampshire, and New Jersey) implement their laws in the first two weeks. Later this year, Tennessee, Minnesota, and Maryland will join the mix. For companies operating in the U.S., staying ahead in this shifting regulatory environment is essential. Failure to comply could result in hefty penalties, legal exposure, and a loss of consumer trust.

The good news? Businesses already aligned with current privacy laws may only need minor updates to meet the new requirements. However, it is important to be aware of all consumer-facing interactions, data collections, and sharing of personal information in each state to keep a firm handle on your compliance obligations.

Continue Reading A New Year and New Compliance Requirements: Additional State Privacy Laws Take Effect in 2025

The Personal Data Protection (Amendment) Bill 2024 (“PDPB”) was at last passed by the Malaysian Parliament at the end of July. After Royal Assent and publishing, it will become law (on a date to be determined by the Minister of Digital to be specified in the Gazette). The PDPB introduced several changes intended to better align Malaysia’s 2010 Personal Data Protection Act with global standards.

Continue Reading Malaysian Parliament Passes Personal Data Protection (Amendment) Bill 2024

On March 22, 2024, following nearly six months after the publication of the Provisions on Promoting and Regulating Cross-border Data Flows (Draft for Solicitation of Comments), the Cyberspace Administration of China (“CAC”) officially released the Provisions on Promoting and Regulating Cross-border Data Flows (“the Provisions”), which came into immediate effect. In accordance with the Provisions, CAC has also issued the “Guidelines for Data Export Security Assessment Declaration (Second Edition)” and the “Guidelines for Filing Standard Contracts for Personal Information Export (Second Edition).”

Continue Reading Practical Insights from China on the Newly Issued Provisions on Cross-Border Data Transfer

In recent years, privacy and cybersecurity consistently hit the top of legal leaders’ lists of their biggest concerns. In fact, a recent Association of Corporate Counsel Chief Legal Officers Survey found that, when rating a list of items on their importance to the business, CLOs placed cybersecurity, regulation and compliance issues, and data privacy as the top three most critical issues for the business.
Continue Reading Upcoming Event! Seyfarth Privacy Salon: Roundtable on Cross-Border Data Transfers, Privacy, and Cybersecurity

The European Union (EU)’s government organizations are just like any another entity trying to function in a world where global companies and even government entities are reliant on digital platforms for messaging and collaboration. For years, there has been debate about how platforms like Microsoft 365, formerly Office 365, could be deployed in a way that complies with the GDPR processing and transfer restrictions. And it turns out that even the European Commission (EC) itself can apparently get it wrong. In a surprising turn of events earlier this month, the European Data Protection Supervisor (EDPS) concluded its nearly three year investigation into the Commission’s own deployment and use of Microsoft 365, signaling a pivotal moment in the conversation about the GDPR privacy and security requirements for cloud-based messaging and document collaboration platforms.

Continue Reading Surprising Plot Twist: The European Data Protection Supervisor Reprimands the European Union for its use of Microsoft 365

On July 10th, the European Commission issued its Implementing Decision regarding the adequacy of the EU-US Data Privacy Framework (“DPF”). The Decision has been eagerly awaited by US and Europe based commerce, hoping it will help business streamline cross-Atlantic data transfers, and by activists who have vowed to scrutinize the next framework arrangement (thereby maintaining their relevance). Regardless of the legal resiliency of the decision, it poses an interesting set of considerations for US businesses, not the least of which is whether or not to participate in the Framework.

For those who followed the development and demise of the Privacy Shield program and the Schrems II case, it has been apparent for some time that the fundamental objection of the activists and the Court of Justice of the EU (“CJEU”) to the original Privacy Shield was the perception that the US intelligence community had an ability to engage in disproportional data collection without any possibility of recourse by EU residents whose personal information may be swept into an investigation. The actual functioning of the program for the certifying businesses were much less controversial.

Since the structure of the program wasn’t the primary reason for Privacy Shield’s revocation, from a business perspective, the current DPF looks a lot like the old Privacy Shield. For businesses who made the decision to participate in the Privacy Shield program in the past, the operational burden shouldn’t be much different under the new DPF, if they have already taken steps to operationalize the requirements.

What is interesting about the new DPF is how it may impact a company’s decision to choose  between the Standard Contractual Clauses (“SCCs”) and the alternative adequacy mechanism for transfers. There is also some interest vis-à-vis the DPF and its interactions with state privacy laws.

Continue Reading Adequacy for the US (kind of) – But What Are the Side Effects?