News & insights
The latest news, insights, and updates on information & cyber security, privacy, and AI governance from Taylor Baines.
Get the latest threats, vulnerabilities, and legal, standards, and AI updates in your inbox every Monday.
Get our weekly insights by emailRansomware attack on Synnovis disrupts London hospitals
A ransomware attack on pathology provider Synnovis forces south-east London NHS trusts to postpone thousands of appointments and operations.
Türkiye’s data transfer amendments take effect
Amendments to Türkiye’s KVKK introduce standard contracts for cross-border transfers of personal data.
Snowflake customer accounts raided in wave of data thefts
Attackers use stolen passwords to access Snowflake cloud accounts at Ticketmaster, AT&T, Santander, and others, stealing data on many millions of people.
France’s SREN Law is promulgated
France’s SREN law introduces cloud market rules and sovereign cloud requirements for sensitive public sector data.
eIDAS 2 enters into force: European Digital Identity Wallets
The revised EU eIDAS Regulation introduces European Digital Identity Wallets and new trust services.
Colorado enacts first comprehensive US state AI law
Colorado has passed the first comprehensive US state law on high-risk AI systems, targeting algorithmic discrimination in consequential decisions.
NIST SP 800-171 Revision 3 published
NIST has published Revision 3 of SP 800-171, realigning CUI protection requirements with SP 800-53 Rev. 5.
FTC Safeguards Rule breach notification requirement takes effect
US non-bank financial institutions must now notify the FTC within 30 days of discovering a breach affecting 500 or more consumers.
UK product security regime for connected products takes effect
The PSTI Act product security requirements now apply to consumer connectable (IoT) products sold in the UK.
Investigatory Powers (Amendment) Act 2024 becomes law
Amendments to the Investigatory Powers Act 2016 introduce notification notices and update bulk data and communications data powers.
Brazil’s ANPD sets three-day breach notification rule
Brazil’s data protection authority adopts Resolution 15/2024, requiring notification of relevant security incidents within three working days.
US reauthorises FISA Section 702
The US has reauthorised FISA Section 702 for two years, expanding the definition of electronic communication service providers.