GT Insight

The upcoming EU Data Act introduces a user-centric approach to data generated by IoT devices, giving individuals and organizations unprecedented control over both personal and non-personal data. Discover what this paradigm shift means for data holders, business models, and the future of data sharing in the EU.
Continue Reading Action Required for Manufacturers of Connected Devices: Challenges Under the EU Data Act

NIS 2 (Directive (EU) 2022/2555), the European Union’s updated framework for cybersecurity, is designed to enhance cybersecurity across the EU by establishing a high common level of security for network and information systems.
Continue Reading EU NIS 2 Directive: Expanded Cybersecurity Obligations for Key Sectors

On July 31, 2025, the Fraud Section of the U.S. Department of Justice’s Commercial Litigation Branch (Fraud Section) announced new settlement agreements with government contractors to resolve their respective False Claims Act (FCA) liabilities arising out of cyber fraud allegations.

Continue Reading DOJ Settles Cybersecurity FCA Claims With PE Firm and Government Contractors

The EU AI Act marks the world’s first comprehensive legal framework for using and developing AI. Implementation may pose structural, technical, and governance-related challenges for companies, particularly in the area of general-purpose AI (GPAI).
Continue Reading EU AI Act: Key Compliance Considerations Ahead of August 2025

On July 1, 2025, the California attorney general (AG) announced a $1.55 million settlement (pending court approval) with Healthline Media, LLC (Healthline), who publishes Healthline.com, a health information website. This settlement marks the regulator’s continued focus on online tracking technologies for targeted advertising and the effectiveness of consumer opt-out systems.
Continue Reading California CCPA Settlement: Health Website Penalized for Tracking Non-Compliance

The UK’s Data (Use and Access) Act 2025 (the Act) officially came into law on June 19. The Act seeks to modernize the UK’s data protection and e-privacy regimes.

Continue Reading UK Data (Access and Use) Act 2025: Key Changes Seek to Streamline Privacy Compliance

On May 31, 2025, the Texas Legislature passed House Bill 149, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA). TRAIGA sets forth disclosure requirements for government entity AI developers and deployers, outlines prohibited uses of AI, and establishes civil penalties for violations. On June 2, 2025, the bill was sent to the governor of Texas for review and signed into law on June 22.

Continue Reading TRAIGA: Key Provisions of Texas’ New Artificial Intelligence Governance Act

DOJ’s new Data Security Program (DSP), effective April 8, 2025, imposes significant restrictions on U.S. government contractors and global companies that handle sensitive U.S. personal or government-related data. The DSP is currently subject to a 90-day initial enforcement period, After July 8, 2025, NSD will implement full enforcement of the DSP.
Continue Reading DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities

On April 29, 2025, Michigan Attorney General Dana Nessel filed a lawsuit against Roku, Inc., alleging that the company collects and monetizes personal data from children without proper consent. The lawsuit claims that Roku’s practices violate the Children’s Online Privacy Protection Act (COPPA) and other privacy laws.
Continue Reading Michigan Attorney General Takes Action Against Roku, Alleging COPPA Violations