regulation

VAMP and MMP Bring the Heat to Merchant Risk

Payments industry faces heightened accountability amid rising fraud, driven by Visa's VAMP and Mastercard's MMP. These programs demand stricter monitoring and early risk detection of merchants' activities. With fraud at record levels and advanced tactics like AI being used to deceive, companies must adapt merchant risk programs through AI systems and continuous monitoring to comply and innovate effectively.

https://www.mytotalretail.com/article/compliance-countdown-vamp-and-mmp-bring-the-heat-to-merchant-risk/

It Might Not Be Sexy but MSPs Need to Talk About Certification

MSPs must prioritize certification for trust and compliance due to increasing regulations and industry demands. Standards like ISO 27001 and Cyber Essentials Plus are essential for reducing breaches and enhancing customer confidence, and upcoming cybersecurity controls are mandatory for top UK MSPs. As sectors relying on MSPs tighten security requirements, certifications are crucial for competitive advantage. Digital transformation, particularly AI, complicates compliance, necessitating investment in tools and expertise. MSPs that integrate certification into services will differentiate themselves and succeed as compliance becomes vital for business growth.

https://www.iteuropa.com/news/it-might-not-be-sexy-msps-need-talk-about-certification

European Commission Proposes Significant Reforms to GDPR, AI Act

TLDR: The European Commission proposed significant reforms to the GDPR and AI Act to simplify digital regulations due to the rapid growth of AI and competitiveness concerns. Key changes include allowing organizations to process personal data for AI with legitimate interests, streamlining cookie consent, establishing a single breach notification portal, and extending compliance timelines for high-risk AI regulations. Proposed amendments aim to balance economic growth while maintaining privacy rights, but they face mixed reactions, with concerns about reducing protections for users. The reforms will undergo negotiations in the European Parliament and may take several months to finalize.

https://iapp.org/news/a/european-commission-proposes-significant-reforms-to-gdpr-ai-act

Europe Is Scaling Back Its Landmark Privacy and AI Laws

Europe is reducing protections in its privacy and AI laws due to pressure from Big Tech and the US government. The EU plans to simplify GDPR regulations, moderate AI rules, and make it easier for companies to use personal data for AI training, aiming to foster innovation and economic growth. This includes reducing cookie pop-ups and centralizing AI oversight while facing criticism for potentially weakening user safeguards. The proposal will undergo scrutiny in the European Parliament and among member states, likely leading to significant debate and modification.

https://www.theverge.com/news/823750/european-union-ai-act-gdpr-changes

Deforestation: Council Ready to Start Talks With Parliament on a Targeted Revision of the Regulation

Council adopted a negotiating mandate to revise the EU deforestation regulation, aiming to simplify implementation and postpone deadlines. New application dates are 30 December 2026 for large operators and 30 June 2027 for smaller ones. A review will assess impacts on operators, especially smaller ones, and negotiations with Parliament will proceed for final agreement.

https://www.consilium.europa.eu/en/press/press-releases/2025/11/19/deforestation-council-ready-to-start-talks-with-parliament-on-a-targeted-revision-of-the-regulation/

The EU Promised to Lead on Regulating Artificial Intelligence. Now It’s Hitting Pause.

EU is delaying AI regulations by at least a year due to pressure from the U.S. and tech companies, abandoning its goal of being a regulatory leader. The decision follows lobbying from tech industry and governments, as concerns about losing competitiveness grow. Proposed changes will exempt some companies from regulations and extend compliance timelines, prompting criticism over potential erosion of fundamental rights.

https://www.politico.eu/article/the-eu-wanted-to-lead-on-regulating-ai-now-its-hitting-pause/

The New EU Rules on Cybersecurity: What Game Developers and Publishers Need to Know

EU's NIS2 Directive and Cyber Resilience Act impose stricter cybersecurity measures on game developers and publishers. Risks include cheating, data breaches, and legal consequences. Companies must ensure compliance, involve senior management in cybersecurity, conduct regular assessments, and report breaches timely. Cybersecurity is now a business priority, crucial for reputation and consumer trust.

https://www.gamesindustry.biz/the-new-eu-rules-on-cybersecurity-what-game-developers-and-publishers-need-to-know

Council Adopts New EU Law to Speed-up Handling of Cross-border Data Protection Complaints

The Council of the EU has introduced new rules to harmonise and speed up cross-border data protection complaint handling under GDPR. Admissibility conditions for complaints are standardised across the EU, complainants and companies have common procedural rights, and straightforward cases may use a simplified process. Investigations now have set deadlines: 15 months for standard cases (extendable for complex matters), and 12 months for simple procedures. The law takes effect 20 days after publication and is enforceable 15 months later.

https://www.consilium.europa.eu/en/press/press-releases/2025/11/17/council-adopts-new-eu-law-to-speed-up-handling-cross-border-data-protection-complaints/

Scroll to Top