Egypt’s Personal Data Protection Law – Before You Process, You Need a Licence
The Arab Republic of Egypt enacted a comprehensive data protection law in 2020. For five years, its practical impact remained [...]
Data Protection. AI. Cybersecurity. Compliance. Expert insights that turn complexity into clarity.
While regulations shift and threats evolve, the gap between legal obligation and practical action grows wider every day. The FIRST PRIVACY experts break down demanding topics – with sharp analysis, actionable guidance, and a clear view of what actually matters for your organisation.
The Arab Republic of Egypt enacted a comprehensive data protection law in 2020. For five years, its practical impact remained [...]
In April 2026, Microsoft introduced a new feature for Microsoft 365 Copilot: "Flex Routing". The name sounds harmless. The data protection implications are not. What Is Flex Routing? Flex Routing allows Microsoft to reroute Copilot AI requests to data centres [...]
On 3 April 2026 China's Cyberspace Administration (CAC) published a draft regulation titled the Provisions on Simplified Measures for Personal Information Protection by Small Personal Information Controllers (Draft for Comment) (the "Draft"). The Draft is o [...]
The information obligation on the processing of personal data is a requirement that persists whenever a processing is performed. This does not exclude the processing of personal data for the purposes of AI models or system development. Those are the cases, [...]
Germany has taken a decisive step towards implementing the EU Data Act. On 26 March 2026, the Bundestag passed the Data Act-Durchführungsgesetz (DADG), establishing the national framework for enforcement. While further legislative steps may still follow before the [...]
On 26 March 2026, the Italian data protection authority (Garante per la protezione dei dati personali, "Garante") fined Intesa Sanpaolo S.p.A. €31,800,000. This is one of the largest fines the Garante has ever imposed, and it carries clear lessons for a [...]
On 1 June 2025, China's Cyberspace Administration (CAC) brought into force the Measures for the Security Management of Face Recognition Technology Applications (the "Measures"). This landmark regulation is the first piece of dedicated legislation in Chin [...]
The Court of Justice of the European Union (CJEU) has clarified in Brillen Rottler (C-526/24) that, in exceptional circumstances, even a first data subject access request (DSAR) may be refused as “manifestly unfounded or excessive” under Article 12 para. [...]