regulation

EU Court of Justice Narrows Scope of When Pseudonymized Data Is Considered “Personal Data”

EU Court of Justice ruling narrows definition of “personal data,” stating pseudonymized data is only personal if re-identification is “reasonably likely” for the recipient. This shifts how organizations handle such data, impacting sectors like AdTech and AI training. Compliance obligations for GDPR remain based on the original controller's capabilities. Organizations can share pseudonymized data more freely, but must assess re-identification risks carefully.

https://www.armstrongteasdale.com/thought-leadership/eu-court-of-justice-narrows-scope-of-when-pseudonymized-data-is-considered-personal-data/

How to Conduct a GDPR Compliance Audit

TLDR: A GDPR compliance audit assesses an organization's handling of personal data, ensuring it meets legal requirements under the UK GDPR and the Data Protection Act. It identifies risks, verifies lawful data usage, reviews security measures, checks data subject rights, and maintains compliance through regular checks and awareness training. Proper planning and mapping data flows are essential for effective audits.

https://cybersecuritynews.com/how-to-conduct-gdpr-compliance-audit/

Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

Traditional security frameworks fail to protect against AI-specific attack vectors, exposing organizations despite compliance with established standards. High-profile incidents, such as the Ultralytics AI library breach and vulnerabilities in ChatGPT, highlight this risk. Existing frameworks, like NIST and ISO, are outdated for the evolving AI threat landscape, leading to a significant rise in data leaks. Organizations need to adopt AI-specific security measures, including prompt and model validation, and enhance team knowledge to preemptively address these new vulnerabilities, rather than relying solely on current compliance mandates.

https://thehackernews.com/2025/12/traditional-security-frameworks-leave.html

How to Build Trust in Your FinTech App

TLDR: Building trust in fintech apps involves visible security, clear data permission, compliance with regulations, seamless onboarding, and effortless recovery actions. Designing for trust from day one, highlighting compliance standards like PCI DSS and GDPR, simplifying data use explanations, and making onboarding secure yet frictionless are crucial for user retention and engagement.

https://www.fintechweekly.com/magazine/articles/build-trust-fintech-app-security-compliance-user-experience

PCI DSS 4.0.1 Compliance Guide: Web App & API Security Controls

PCI DSS 4.0.1 enforces stricter security for web applications and APIs, requiring an inventory of custom software, management of payment scripts, risk-based vulnerability prioritization, authenticated internal scans, and tamper detection on payment pages.

https://blog.qualys.com/product-tech/2025/12/19/pci-dss-4-0-1-compliance-web-application-api-security

NIS2 Compliance: How to Get Passwords and MFA Right

NIS2 Directive mandates improved cybersecurity for EU organizations, focusing on access control and password policies. It applies to medium and large entities in critical sectors with compliance penalties, emphasizing strong authentication measures. Recommendations include using long passphrases, avoiding mandatory password rotations, implementing multi-factor authentication (MFA), and educating users on security practices. Key steps include auditing password policies, deploying management solutions, and monitoring for breaches to align with NIS2 compliance effectively.

https://www.bleepingcomputer.com/news/security/nis2-compliance-how-to-get-passwords-and-mfa-right/

What Types of Compliance Should Your Password Manager Support?

Password managers are essential for compliance with regulations concerning credential security. They help organizations secure passwords and demonstrate adherence to laws like GDPR, HIPAA, and PCI DSS. Compliance frameworks such as ISO 27001 and SOC 2 guide vendor evaluations. Password managers should align with guidelines from NIST and OWASP, support multifactor authentication, and ensure proper logging and encryption. Vendor transparency and deployment options, such as on-premises storage, are also crucial. Ultimately, a robust password manager aids in meeting compliance requirements, strengthens security practices, and simplifies audits.

https://www.helpnetsecurity.com/2025/12/15/password-manager-compliance-types/

IT Compliance: From Obligation to Strategic Business Imperative

Extreme TLDR: IT compliance has evolved from a mere obligation to a business imperative, influenced by regulatory expansion, rising threats, and customer demands. Key frameworks include NIST, SEC rules, and privacy acts. Continuous monitoring, zero-trust architecture, and automation are vital for maintaining security and compliance. Emerging threats, such as AI-driven attacks and vendor risks, necessitate proactive strategies. Partnering with IT consulting firms enhances compliance efforts, while fostering a culture that embeds compliance into operations is crucial for future resilience.

https://www.mobileappdaily.com/knowledge-hub/importance-of-it-compliance-and-security

AI Act Changes: What Does the Digital Omnibus Propose for the EU AI Act? (via Passle)

EU proposes amendments to AI Act via Digital Omnibus, delaying compliance deadlines for high-risk AI systems and simplifying regulations. Key changes include grace periods for transparency requirements, removal of AI literacy obligations, and increased authority for the European AI Office. The proposals are under consultation and may undergo scrutiny in the legislative process, impacting businesses navigating AI compliance.

https://thelens.slaughterandmay.com/post/102lwy1/ai-act-changes-what-does-the-digital-omnibus-propose-for-the-eu-ai-act#page=1

What’s Driving Cybersecurity Investments and Where Lie the Challenges?

ENISA's NIS Investments report reveals shifts in cybersecurity spending towards technology over personnel, with ongoing talent shortages. Compliance drives 70% of investments, improving risk management and detection, though NIS2 implementation poses challenges. Patching and cybersecurity assessments lag, particularly for SMEs. Despite improved supply chain management, reliance on third-party services increases risks. Ransomware and supply-chain attacks are primary concerns for organizations. The findings aim to inform EU cybersecurity policy and improve resilience.

https://www.enisa.europa.eu/news/whats-driving-cybersecurity-investments-and-where-lie-the-challenges

Scroll to Top