Zambia Split Cybersecurity Regulation From Cybercrime. The Obligations Got Sharper.

Zambia's two 2025 cyber laws separate regulatory security duties from criminal offences while sharpening incident, audit, hosting and licensing obligations.

Zambia's two 2025 cyber laws separate regulatory security duties from criminal offences while sharpening incident, audit, hosting and licensing obligations.

Peru’s replacement data-protection regulation turns security incidents, advertising consent and privacy governance into defined operating processes. Peru’s new Regulation of Law No. 29.733 entered into force on 31 March 2025. Approved by Supreme Decree No. 016-2024-JUS, it replaces the earlier…

The European Health Data Space creates infrastructure and governance for exchanging and reusing health data. It entered into force in March 2025, but most operational duties arrive through a long, staged implementation. Regulation (EU) 2025/327 entered into force on 26…

Mexico’s 2025 federal privacy law preserves many familiar obligations for private organisations while changing the institution that interprets and enforces them. Mexico published a new Federal Law on the Protection of Personal Data Held by Private Parties on 20 March…

The Online Safety Act is no longer a future policy argument. Since March 2025, regulated services have had to turn risk assessments into operating controls. On 17 March 2025, the next phase of the United Kingdom’s Online Safety Act took…

The European Commission's action plan, launched in January 2025, aims to enhance cybersecurity in hospitals and healthcare providers, recognising its vital role in patient safety. The plan focuses on prevention, detection, response, recovery, and deterrence, providing guidance and resources tailored to the sector's unique needs, while integrating existing regulations like GDPR and NIS2.

DORA is usually discussed in terms of risk frameworks, incident reporting and resilience testing. Those subjects matter, but many real attacks still succeed through something much simpler: an identity with more access than it should have. An administrator account is…

The Cyber Solidarity Act is not another enterprise compliance checklist. It builds shared European capacity to detect, prepare for and respond to large-scale cyber incidents. The EU Cyber Solidarity Act entered into force on 4 February 2025. It responds to…

Botswana replaced its earlier privacy regime with a more operational 2024 Act covering overseas services, breach reporting, high-risk processing and regulator powers.

Romania’s NIS2 framework arrived on the final day of 2024 through an emergency ordinance, turning a delayed transposition into an immediate scope, registration and governance exercise. Emergency Ordinance No. 155 of 30 December 2024 was published and entered into force…