On March 20, 2025, the New York Attorney General (“NYAG”) announced a settlement with Ohio-based Root Insurance, regarding privacy practices relating to its auto insurance online quoting tool. As part of the settlement, Root agreed to pay $975,000 and to undertake a variety of security measures, including creation of a data inventory, requiring Root to
Data Protection Report
Data protection legal insight at the speed of technology
Blog Authors
Latest from Data Protection Report
What do organisations need to disclose to individuals about AI and automated decisions?
Individuals have the right to receive meaningful information about solely automated decisions with significant effects under the General Data Protection Regulation (GDPR). This includes decisions that will impact an individual’s finances or employment. But how much information are individuals entitled to receive? Should they be given the underlying algorithm, or merely a high-level explanation, or…
Prohibited practices under the AI Act: Answered and unanswered questions in the Commission’s guidelines
The EU AI Act’s prohibitions came into effect on 2 February 2025 and carry fines of 7% worldwide annual turnover for non-compliance. The prohibitions at Article 5 and accompanying recitals (particularly recitals 28-44) set out a complex set of provisions. The guidelines published by the Commission on 4 February 2025 (the guidelines) were welcome for…
Happy Information Governance Day
Happy February 20th and Information Governance Day! Today is an opportunity to reflect on the evolution of information governance and, more importantly, its future. In our view, information governance is in its ascendency and is only becoming more and more important to our clients.
We have been providing legal advice on information governance (IG) to…
The Commission’s guidelines on AI systems – what can we infer?

The EU’s AI Act imposes extensive obligations on the development and use of AI. Most of the obligations in the AI Act look to regulate the impact of the specific use cases on health, safety, or fundamental rights. These sets of obligations apply to ‘AI systems’. A tool will fall out of scope of much…
CJEU Advocate General clarifies when pseudonymised data falls outside the definition of personal data
On 5 February 2025, the Advocate General of the Court of Justice of the European Union (CJEU) issued its opinion in the case of C 413/23 P European Data Protection Supervisor (EDPS) v Single Resolution Board (SRB) (Opinion). The Opinion takes the view that personal data which has been pseudonymised and shared with a third-party…
CSA releases guidance on the use of artificial intelligence in capital markets
On December 5, 2024, the Canadian Securities Administrators (CSA) released CSA Staff Notice and Consultation 11-348 – Applicability of Canadian Securities Laws and the Use of Artificial Intelligence Systems in Capital Markets (the Notice). The Notice was issued in light of the continued growth in the use of artificial intelligence (AI) systems in capital markets,…
The EDPB Opinion on training AI models using personal data and recent Garante fine – lawful deployment of LLMs
The final days of 2024 were very eventful in the world of AI and data protection: the European Data Protection Board (EDPB) published its Article 64 General Data Protection Regulation (GDPR) opinion on training AI models using personal data (the EDPB Opinion). Two days later, the Italian Garante per la Protezione dei Dati Personali (Garante)…
2024 Technology Privacy and Cybersecurity Summit | November 25 – 28, 2024

Norton Rose Fulbright Canada invites you to its leading annual technology, privacy, and cybersecurity virtual summit. Learn how to leverage AI for a competitive edge while mitigating its inherent risks.
This four-part series is tailored for legal professionals, business leaders, and IT specialists. Equip yourself with the knowledge to address critical legal challenges and ensure…
China’s proposed AI Labelling Regulations: Key points
In response to the rapid development of artificial intelligence (AI) technologies, the Cyberspace Administration of China (the CAC) recently issued two draft regulations for public consultation: Measures for Labelling Artificial Intelligence-Generated or Synthetic Content (the Draft AI Labelling Measures) and Cybersecurity technology—Labelling method for content generated by artificial intelligence (the Draft Labelling Method Standard). The Draft Labelling Method…