Data Privacy & Cybersecurity

The UK government has published its Smart Data 2035 Strategy, setting a target of five or more active smart data schemes by 2030 and 20 or more by 2035, backed by at least £36 million in public investment over four years.
Continue Reading UK Smart Data and the Data (Use and Access) Act 2025: Considerations for Businesses

Drawing on lessons learned from thousands of incident responses, this GT Advisory examines the most common and consequential mistakes organizations make when responding to a data breach. From lack of preparation to missteps in customer notification, understanding these pitfalls is the first step toward a more effective response.
Continue Reading Cyber Incident Response: 10 Lessons Learned from Thousands of Breaches

Texas AG Ken Paxton states that the drone company misrepresented its data privacy and security practices to consumers in violation of the Texas Deceptive Trade Practices Act and allegedly concealed ties to China.

Continue Reading Texas Attorney General Announces Investigation into Drone Company over Data Privacy, Surveillance Concerns

The Federal Trade Commission announced a stipulated final order resolving its enforcement action against data broker Kochava Inc. and its subsidiary Collective Data Solutions.

Continue Reading FTC Bars Kochava from Selling Sensitive Location Data

In a May 6 webinar, GT Shareholders Jena M. Valdetero and Reena Bajowala will draw on lessons from thousands of real-world data breaches to help legal and business teams build stronger cyber incident response strategies. Register now.

Continue Reading May 6 WEBINAR | Cyber Incident Response: Lessons Learned From Thousands of Breaches

With its Russmedia judgment (C-492/23, Grand Chamber, 2 December 2025), the Court of Justice of the European Union (CJEU or Court) fundamentally reshapes how online marketplaces and other platforms hosting user-generated content must approach data protection compliance.
Continue Reading CJEU’s Russmedia Decision Expands Platform Controller Duties Under GDPR

Data brokers who offered brokerage services in California in 2025 must register or re-register their status with the state’s data broker registry by Jan. 31, 2026. 

In-scope companies that fail to do so may be liable for administrative fines or even reasonable expenses incurred by the CalPrivacy regulator in investigating and bringing an administrative action