-
Software – How are proprietary rights in software and associated materials protected?
The main form of protection for software is through copyright, which applies to the software code (whether source code or any compiled version), any algorithms, graphics, video and audio recordings, and any documents, specifications, user manuals and other materials associated with it. Copyright arises automatically in the UK on creation of an original work, and there is no need to register this. Copyright generally protects against copying – there is no protection against independent creation of similar software or materials, where actual copying is not reasonably evident.
The functional aspects of any software application are not generally protectable in the UK unless it can be shown that a software with similar functionality came about as a result of copying of any code, specification or design materials.
Following the Court of Appeal’s decision in Emotional Perception AI Ltd v Comptroller-General of Patents, Designs and Trade Marks [2024] EWCA Civ 825, subsequently upheld by the UK Supreme Court in 2026, software-related inventions remain capable of patent protection in the UK, but only where the claimed invention makes a technical contribution beyond a computer program operating in its normal way. The courts confirmed that artificial neural networks and AI-based systems are not exempt from the exclusion for a “program for a computer … as such” merely because they use machine learning or AI techniques.
In practical terms, a patent is unlikely to be available for software that merely processes data, implements a business method, or performs an abstract intellectual task. However, patent protection may still be obtained where the software produces a technical effect, such as improving the operation of a computer, controlling an industrial process, enhancing communications systems, improving image processing, or solving a technical problem in a novel way.
The “look and feel” of any software application may be protected by registered design in the UK, which can be a quick and cost-effective way to protect unique aspects of the user interface. Software is often exploited in such a way that the source code and design materials are not disclosed to any licensee or user of the software. To the extent source code and design materials are kept confidential and reasonable steps have been taken to prevent disclosure to third parties, the laws of confidence and/or trade secrets will allow the software owner to protect and enforce their rights in that confidential information.
-
Software – In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?
The first owner of copyright is the author or creator of the copyright work. Where a software developer, consultant or contractor creates software for a customer, then the software developer, consultant or contractor will own the copyright in the software code and in any documents, specifications, graphics or other materials in the software. The same is true for any invention or concept which may give software its technical effect. Rights to any invention will remain with the software developer, consultant or contractor, who will be entitled to apply for patent protection. If it is intended that the customer owns all rights in software, it is, therefore, important to ensure that such rights, including in any inventions, concepts or ideas, and any software code, documentation or materials, are assigned to the customer under a written agreement which is signed by the software developer, consultant or contractor.
-
Software – Are there any specific laws that govern the harm / liability caused by Software / computer systems?
Liability for harm caused by software and computer systems is governed predominantly by contract law, the law of negligence and, where applicable, product liability legislation under the Consumer Protection Act 1987. Where a business provides software to a consumer, Chapter 3 of the Consumer Rights Act 2015 sets out various implied contractual terms that govern such supply of software, including that it is of satisfactory quality, fit for purpose and as described; Chapter 3 also provides remedies if those statutory rights are not adhered to.
Whilst the new Data (Use and Access) Act 2025 does not directly regulate software defects or performance failures, it does introduce new obligations and liabilities where software processes personal data in ways that affect individuals’ rights or expectations.
In 2026 the UK Jurisdiction Taskforce published its legal statement on liability for AI harms, concluding that existing English common law principles, particularly negligence and contractual liability, are generally capable of addressing many harms arising from software and AI systems, although some areas of uncertainty remain. The statement is not legislation but is influential guidance.
-
Software – To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software / computer systems?
While England does not have a general software code, the use and misuse of software and computer systems is regulated by a number of statutes depending on the circumstances.
For example, the Computer Misuse Act 1990 criminalises unauthorised access to computer systems and data that has not been authorised by the systems’ owner(s) and the Product Security and Telecommunications Infrastructure Act 2022 impose cybersecurity obligations on manufacturers, importers and distributors of certain consumer connectable products.
-
Software Transactions (Licence and SaaS) – Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?
Generally speaking, there are no technology-specific laws that govern the provision of software between a software vendor and customer, and no specific laws that govern the use of cloud technology.
Where the customer is a regulated financial services firm (hereafter referred to as a “regulated firm”), however, certain rules and guidance may apply, depending on factors such as: the vendor’s role in practice, what the regulated firm’s activities are, and the impact that the service may have on those regulated activities.
In general, the rules and guidance issued by the Financial Conduct Authority (“FCA”) and the Prudential Regulation Authority (“PRA”) are intended to be technology-neutral. The rules and guidance are not, therefore, “technology-specific”, but apply in situations where the services provided are supported by technology, including cloud services.
Specific rules and guidance apply in two circumstances: (1) outsourcing, and (2) activities which may affect a regulated firm’s operational resilience (i.e. the ability of the firm and the financial sector as a whole to prevent, adapt, respond to, recover and learn from operational disruptions (these could include disruptions caused by the failure of technology on which the regulated firm depends)). In such circumstances, one or more of the following may be relevant:
The FCA’s rules and guidance in Chapter 8 of the Senior Management Arrangements, Systems and Controls handbook (“SYSC”) within the FCA Handbook. SYSC 8.1 applies to outsourcing, meaning it can apply to SaaS. Depending on what activities the regulated firm carries out, SYSC 8 applies either as guidance or as rules.
The FCA’s Finalised Guidance FG16/5 for firms outsourcing to the cloud and other third-party IT services.
The European Banking Authority (“EBA”) Guidelines on Outsourcing Arrangements dated 25 February 2019 (EBA/GL/2019/02). The FCA and the PRA expect firms to continue to comply with the Guidelines, to the extent they remain relevant post-Brexit.
The PRA’s Supervisory Statement of March 2021 (SS2/21) on Outsourcing and Third Party Risk Management. Although directed to PRA-regulated firms such as banks, building societies, PRA-designated investment firms, insurance and reinsurance firms, the PRA’s drafting was reviewed by the FCA and the FCA’s approach aligns with the PRAs. The Supervisory Statement is a useful tool in understanding how the EBA Guidelines are likely to be interpreted and applied by UK regulators.
The FCA’s rules and guidance relating to operational resilience, in SYSC. The main rules appear in SYSC 15A.
The rules and guidance in the Operational Resilience sections of the PRA Rulebook. This is supplemented by PRA guidance in its Supervisory Statement of March 2022 (SS1/21) on Impact Tolerances for Important Business Services.
In some instances, a regulated firm may have to consider the impact of technology on its activities even where the provision of services does not amount to outsourcing, or is not considered relevant to the regulated firm’s operational resilience. For example, the PRA’s SS2/21 also discusses third party arrangements which do not involve outsourcing. Moreover, where a regulated firm is subject to the FCA’s Consumer Duty, it will have to consider the impact of the services it receives from third parties on its ability to comply with the Consumer Principle and deliver good outcomes for retail customers.
In addition, sector-specific conduct rules may affect the services the regulated firm receives. For example, if a regulated mortgage lender uses a technology platform to support the provision of documentation to applicants and potential borrowers, it will have to ensure that the documentation produced complies with requirements set out in the Mortgages and Home Finance: Conduct of Business sourcebook. Similarly, a consumer credit lender who outsources tracing of debtors or debt recovery activity must take account of the rules on data accuracy and outsourced activities in the Consumer Credit sourcebook.
In short, where the service recipient is a regulated firm then, depending on the services and the impact of those services on the firm’s activities, a complex variety of rules and guidance could apply. Regulated firms should seek specialist guidance in this area, as there is no one-size-fits-all roadmap or solution for determining how to comply with the requirements.
Cloud service providers should be especially conscious of the extraterritorial effect of certain EU laws, including Regulation (EU) 2023/2854 (EU Data Act), which contains provisions designed to avoid customers becoming “locked in” to vendors’ cloud services. From 12 September 2025, certain provisions become directly applicable that will require cloud providers to support their customers in switching service providers in certain scenarios, and to reflect these terms into their customer contracts.
The EU Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) became effective on 17 January 2025. It applies to EU-based financial institutions, and obliges institutions to ensure that their arrangements with information and communication technology (ICT) service providers are robust and support the institutions’ digital operational resilience. The measures involve pre-contractual diligence; ongoing supervision and monitoring; business continuity planning; incident response and management; and resilience testing (including threat-led penetration testing). DORA also prescribes contractual provisions which must be included in agreements with ICT service providers.
As DORA applies to financial institutions, most TMT firms will not be directly subject to DORA themselves. However, TMT firms providing ICT services to EU financial institutions will feel the effect of DORA in their contracts with those institutions, even if the TMT firms are based outside the EU. Moreover, ICT providers who are designated by the European Supervisory Authorities as being “critical ICT third-party service providers” (also known as “Critical Third-Party Providers” or “CTTPs”) will be subject to direct supervision under DORA. This means, for example, that a CTTP based outside the EU must establish a subsidiary within the EU within 12 months of being designated a CTTP, so that the EU authorities can exercise adequate oversight and enforcement.
-
Software Transactions (License and SaaS) – Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If ‘yes’, what would be considered a market standard level of cap?
It is typical for a software vendor to cap its maximum financial liability to a customer in a software transaction, although there may be certain areas of liability that are excluded from this cap (please see the response to Question 7 for further information on these excluded areas of liability).
There is no market standard level of cap in the UK, as a liability cap will depend on a range of factors unique to each transaction, including the respective negotiating positions of the customer and software vendor. That said, it is not unusual for the level of cap to range between 100% to 150% of the annualised or total value of the contract. The cap may be expressed as a percentage or as a multiplier of the total value of the contract or product(s)/service(s) to which the claim relates. The latter is a common way for software vendors to manage their risk when contracting for multiple products or services under one master contract.
-
Software Transactions (License and SaaS) – Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor’s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.
Confidentiality breaches – No typical position – deal specific. A customer will generally push for this area of liability to be excluded from any financial cap, whereas a software vendor will typically resist this position and will require confidentiality breaches to either be subject to the general cap on liability or to a separate enhanced cap.
Data protection breaches – Same position as for confidentiality breaches (covered at (a)).
Data security breaches (including loss of data) – Same position as for confidentiality breaches (covered at (a)).
IPR infringement claims – In the absence of unique deal-specific reasons, this area of liability is typically excluded from any financial cap (usually linked to an IPR infringement indemnity).
Breaches of applicable law – Same position as for confidentiality breaches (covered at (a)); although it is not uncommon for breaches, specifically of the Bribery Act 2010 and/or Modern Slavery Act 2015, by the software vendor to be excluded from any financial caps.
Regulatory fines – Same position as for confidentiality breaches (covered at (a)).
Wilful or deliberate breaches – In the absence of unique deal-specific reasons, this area of liability is typically excluded from any financial cap. Please note, however, that although English case law aids interpretation, there is no single, settled legal definition of what constitutes a “wilful or deliberate breach”, so the customer and software vendor may wish to consider including an agreed definition of these terms within the contract.
Claims arising out of or in relation to artificial intelligence (AI) – This is a developing area and there is currently no established position. The allocation of liability here will be deal-specific and depend on a number of factors, such as the AI use-case in question, the role that the software vendor has assumed within the AI value chain, and the negotiating positions of the parties.
-
Software Transactions (License and SaaS) – Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?
It is not uncommon for source codes to be held in escrow for the benefit of the software licensee, particularly where the software is either bespoke (and the software licensor has retained ownership of IP in the software) or performs critical operations for the software licensee.
Although less common, escrow providers now offer escrow services for cloud-based software as well as for traditional “on premise” software. Options available for cloud may include access continuity for single-tenanted environments, where access credentials and documentation may be deposited in escrow to allow the licensee continued access to the cloud environment in the event of a software vendor failure. Where the cloud environment is a “one-to-many” unrestricted cloud environment, the escrow provider may hold a separately hosted, mirrored instance of the cloud production environment (including source codes, deployment scripts and databases) to allow temporary continuity in the environment if the software vendor no longer supports the original service environment. Due to the complexity involved, there may be cost implications for this kind of escrow arrangement.
Commonly used escrow providers in the UK include Escode (part of the NCC Group), The Escrow Company, LE&AS, and SES.
-
IT Outsourcing – Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?
There are no specific laws governing IT outsourcing in the UK.
-
IT Outsourcing – Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.
The Transfer of Undertakings (Protection of Employment) Regulations 2006 (“TUPE”) provide the following significant protection for employees in an IT outsourcing situation:
TUPE’s primary purpose is to automatically transfer the employment of individual staff from their current employer to a third party IT outsource provider on the same date that the service they perform is transferred to the third party IT outsourcing provider.
The starting point under TUPE is that the individual employees transfer to the third party IT outsourcing provider on the same terms and conditions of employment (the name of their employer will change and they will also join or have the option of joining the pension scheme offered by the third party IT provider). The transfer of employment takes place automatically by operation of law and is not something that parties can choose to ignore.
TUPE provides enhanced protection to employees in outsourcing situations as the dismissal of an employee with at least 2 years’ continuous service where the sole or principal reason for the dismissal is the transfer itself is automatically unfair. The third party IT outsourcing provider must be able to show the dismissal was for an economic, technical or organisational reason that entailed a change in the workforce to avoid an automatic unfair dismissal finding, and even then, the dismissed employee can still challenge the fairness of their dismissal under general unfair dismissal law.
The third party IT outsourcing provider is prevented from changing the terms and conditions of employees that transfer to it under TUPE if the sole or principal reason for the change is the transfer itself. The third party IT outsourcing provider must be able to show that any changes are made for an economic, technical or organisational reason entailing changes in the workforce or that the employment contract permits the change in question.
TUPE requires the current employer to inform the employees about the proposed transfer and to consult with appropriate representatives of the employees if the third party IT outsourcing provider proposes to take any measures/make changes to their employment terms after the transfer. The penalty for failing to comply with this obligation is a protective award of up to 13 weeks’ uncapped pay to each affected employee.
-
Telecommunications – Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and/or services, including a brief explanation of the general purpose of those laws.
The primary legislation governing the UK telecommunications sector is the Communications Act 2003, as supplemented by the Wireless Telegraphy Act 2006.
The Communications Act 2003 established Ofcom as the independent regulatory body responsible for overseeing the telecommunications industry in the UK, and set out Ofcom’s duties. Together with the Wireless Telegraphy Act 2006, the Act gives Ofcom broad regulatory powers, including the ability to grant general authorisations and licences, enforce compliance, and impose penalties. The framework aims to protect consumers, promote competition, and ensure efficient use of spectrum and infrastructure.
Further laws that supplement the governance of the telecommunications sector in the UK include:
(1) The European Electronic Communications Code (“EECC”), which was transposed into UK law in late 2020. The EECC looks to improve service quality by making investment in infrastructures more attractive to companies, and to protect consumers by placing price limits on international calls, providing affordable services, and promoting better security;
(2) The Telecommunications (Security) Act 2021 (the “TSA”), which enhances the resilience of UK public telecoms networks and services against cyber threats and other security risks. The TSA imposes security duties directly on telecoms providers and gives Ofcom powers to monitor and enforce compliance.
The TSA is supported by the Electronic Communications (Security Measures) Regulations 2022, which set out specific technical and organisational measures that public telecoms providers must implement to comply with the Act. These measures include controls on access management, monitoring of network activity, risk assessments, and the need for ongoing reviews of security arrangements.
The TSA and Regulation’s requirements are codified in the Telecommunications Security Code of Practice (the “TSA Code”), a statutory code issued by the Secretary of State under section 105E of the Communications Act 2003. The TSA Code provides guidance on meeting the duties imposed under the TSA, including requirements for asset management, supply chain security, and incident response. Ofcom enforces compliance with the TSA and related regulations, with powers to issue information requests, enforcement directions, and financial penalties for non-compliance.
(3) The Open Internet Access (EU Regulation) Regulations 2016 (SI 2016/607) known as the “Net Neutrality Regulations”, which are derived from retained EU law, specifically the Open Internet Access (EU Regulation) 2015/2120, continue to apply post-Brexit. The Net Neutrality Regulations require Internet Service Providers (ISPs) to treat all traffic equally, prohibiting practices such as blocking, throttling, or prioritisation of specific content or services, except in limited circumstances (e.g., traffic management, compliance with legal orders, or security).
(4) The Product Security and Telecommunications Infrastructure Act 2022 (“PSTI”) introduces two key regimes relevant to the telecommunications sector. First, it amends the EECC to improve operators’ rights of access to land, particularly for upgrading or sharing apparatus, with the aim of facilitating faster deployment of gigabit-capable broadband and 5G infrastructure. Second, PSTI establishes a cybersecurity regime for “connectable products”, which includes telecoms-related consumer equipment such as customer premises equipment (CPE) (e.g., routers, modems, and smart hubs). Under PSTI, manufacturers, importers, and distributors of such products must that any in-scope connectable products which they make available to UK consumers conform to established baseline cybersecurity requirements.
(5) The Online Safety Act 2023 was given Royal Assent on 26 October 2023 and aims to protect the public online. The Act obliges technology companies to be more responsible for users’ safety online including duties to implement processes and systems to reduce the overall risks that can occur. Additionally, the Act provides more control for users as to the content that users wish to see online and finding the best ways to report issues when they arise. Ofcom has been provided with extra enforcement powers such as the ability to fine companies up to £18 million or 10% of qualifying worldwide revenue (whichever is greater) and to take criminal action against senior managers who fail to ensure compliance;
(6) The UK General Data Protection Regulation, which sets out how organisations must collect, store, and use individuals’ data (see also Question 17); and
(7) The Privacy and Electronic Communications Regulations, which impose sector-specific obligations on providers of public electronic communications services. Notable provisions relevant to telecommunications include:
Regulation 7: restrictions on the processing and storage of traffic data, which may only be retained where necessary for transmission, billing, or marketing with consent.
Regulation 8: requirements for the protection and erasure of location data when it is not traffic data.
Regulation 9: duties to protect subscriber data, including confidentiality of communications and directory listings.
Finally, Ofcom plays a central role in administering, interpreting, and enforcing telecommunications law in the UK. Ofcom issues detailed guidance documents, codes of practice, and consultations that shape compliance across the sector. This guidance is also supplemented through contributions from other quasi-bodies, such as the Office of the Telecommunications Adjudicator (OTA2), which facilitates process standardisation and switching arrangements between providers, particularly in the context of regulated access products (e.g., wholesale line rental).
-
Telecommunications – Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.
In the UK, providers of public electronic communications networks (PECNs) or public electronic communications services (PECSs) operate under a general authorisation regime administered by Ofcom, in accordance with the Communications Act 2003. Under that regime, in-scope providers must ensure that their services are provided in accordance with Ofcom’s General Conditions of Entitlement. The General Conditions set out legally binding rules on areas such as consumer protection, network integrity, numbering, switching, access and interconnection, and emergency services.
In essence, the UK regime does not operate on a pre-authorisation basis, and no individual licence is required to provide such services, provided that the provider complies with the General Conditions of Entitlement. The General Conditions apply automatically to all providers falling within scope and are enforced by Ofcom under its statutory powers.
Outside Ofcom’s general licensing regime, the operation of Commercial Multi‑User Gateways (COMUGs) is subject to authorisation and requires a licence from Ofcom. Similarly, formal licensing is also required for certain satellite communications, including the licensing of earth stations (ground segment) and spectrum access.
-
Telecommunications – Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.
Access to communications data by UK law enforcement agencies and public authorities is principally governed by the Investigatory Powers Act 2016 (“IPA”), which replaced the majority of the UK’s prior lawful intercept regime, established under the Regulation of Investigatory Powers Act 2000 (“RIPA”).
RIPA, however, remains valid law and still applies to certain lower-level surveillance activities, including directed surveillance (e.g., covert monitoring of individuals in public places).
Under the IPA, a range of authorised public bodies may request access to communications data, including law enforcement agencies (e.g., police forces, the National Crime Agency), intelligence agencies, and certain regulators, including the UK’s tax authority (HMRC), the Financial Conduct Authority, and the Home Office.
The types of data typically accessible include:
- Communications data: Metadata such as the time, duration, origin, and destination of a communication (but not its content).
- Internet connection records (ICRs): A record of internet services a device connects to, retained by service providers under the IPA.
- Subscriber information: Data identifying the user of a service (e.g., name, billing address, IP address).
- Intercepted content: The actual content of communications (calls, emails, messages), subject to stricter controls and typically reserved for intelligence or national security cases.
In addition to responding to lawfully served IPA warrants, UK telecommunications providers are also mandated under the IPA to maintain ICRs for up to 12 months.
The powers available to enforcement agencies under the IPA are broadly summarised as follows:
- Targeted interception: Used to obtain the content of communications for a specific individual or premises.
- Bulk interception and equipment interference: Involves the interception of large volumes of communication without necessarily targeting specific individuals at the point of collection.
- Technical Capability Notices (TCNs) and Technical Assistance Notices (TANs): Compel providers to build or maintain the ability to facilitate lawful interception or data access, often involving encryption or system-level access.
From a procedural and oversight perspective, the investigatory powers regime includes several legal and procedural safeguards. Firstly, the IPA operates a dual-authorisation regime for many surveillance powers, which requires both Secretary of State and judicial approval (known as the “double-lock”).
In addition, the Investigatory Powers Commissioner (IPC) provides independent judicial oversight of the use of powers under both IPA and residual RIPA provisions, with the Investigatory Powers Tribunal (IPT) hearing complaints from individuals and organisations who believe they have been subject to unlawful surveillance.
For those powers deemed the most invasive, namely bulk interception, TCNs, and TANs, the double-lock applies in such a way that such warrants may only be served with Secretary of State and Judicial Commissioner approval.
Finally, while responding to a lawfully served IPA warrant is a legal obligation, communications providers do have a duty to ascertain the validity and, in some cases, the proportionality of a warrant and may challenge its validity via judicial review.
-
Telecommunications – Please summarise the principal laws (present or impending) that impose cyber security and/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and/or provision of telecommunications services.
Please see response to Question 20 below for further details.
-
Mobile communications and connected technologies – What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?
For companies or individuals in the UK implementing wireless communication technologies or keen to participate in the development of the relevant standards, there are several key standard development organisations (“SDOs”) to consider:
- The European Telecommunications Standards Institute (“ETSI”) supports the development, ratification and testing of standards for ICT-enabled systems, applications and services, including 4G and 5G mobile communications, and is global in its reach.
- The International Telecommunication Union (“ITU”) whose Telecommunication Standardization Sector (ITU-T) defines standards for ICT networks and devices including the Optical Transport Network and advanced broadband access technologies such as Fibre to the Home and G.fast. In collaboration with IEC and ISO, ITU is also responsible for developing standards for video coding, with video accounting for the majority of all Internet traffic.
- The Institute of Electrical and Electronics Engineers (“IEEE”) Standards Association develops global standards in a broad range of technologies including computer networking standards for both wired and wireless networks.
These SDOs are also developing new standards specifically for the Internet of Things, digital health, and connected vehicles. For example, there is a working group within IEEE for wireless speciality networks such as wireless personal area networks, Bluetooth, Internet of Things networks, body area networks and wearables. Meanwhile, ETSI developed new standards for connectivity within vehicles.
Other organisations have developed new standards for particular connected technologies that implementers in the UK should also be aware of. For example, the SAE International (formerly Society of Automotive Engineers) Standard J2735 covers standardised messages to facilitate emergency breaking. Work to develop and outline requirements for sixth-generation wireless communication technology (6G) standards is underway, with such technology expected to reach the deployment stage around 2030. 6G is expected to play a critical role in enabling and supporting the ecosystem of emerging connected technologies.
-
Mobile communications and connected technologies – How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?
Technical standards which facilitate interoperability between connected devices mean that parties developing connected technologies which utilise a technology such as 5G or Bluetooth will need to consider patents which have been declared “essential” to those technologies – so-called standard essential patents (“SEPs”).
Any member of a standard development organisation (“SDO”) such as ETSI is required to declare any patent which it owns which is essential or potentially essential to one or more of the SDO’s technical standards. A patent will generally be ‘essential’ either if the claimed invention of the patent must be used to comply with the standard or if commercially and practically it is the only way to comply.
If a patented technology becomes part of a technical standard and it is mandatory to implement the feature, the resulting SEP will be infringed by anyone implementing a solution which complies with the standardised technology.
Balancing the patent holder’s monopoly rights against the need to ensure technologies can be implemented and prevent ‘hold up’ by a patent owner, the members of an SDO such as ETSI, in declaring their patent as standard essential, undertake to grant a licence to the SEP to any ‘willing licensee’ on ‘fair, reasonable and non-discriminatory’ (“FRAND”) terms.
Implementers of services or manufacturers of devices in the UK which use wireless connectivity technologies therefore need a licence to those patents declared essential to the relevant standard and which they must necessarily implement to comply with the standard.
Such licensing may be negotiated with patent holders individually, as has been the model for the mobile phone industry, or through patent pools where those are available, for example in the automotive industry or for IoT.
The UK Intellectual Property Office is currently analysing responses to a consultation it ran between July and October 2025 on proposed changes to the SEP regime. The consultation aims to increase transparency in relation to licensing costs and patent ‘essentiality’, as well as improve the efficiency of the dispute resolution process whilst ensuring that the UK remains the forum of choice for SEP-related dispute.
-
Data Protection – Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.
PRESENT
Principal laws Brief description UK General Data Protection Regulation (“UK GDPR”) The UK retains in modified form the General Data Protection Regulation (2016/679) (“EU GDPR”). The key principles, rights and obligations of the UK GDPR remain largely the same as the EU GDPR, which enhances individuals’ data protection and privacy rights and aims to ensure that personal data is handled responsibly by organisations and in accordance with fundamental privacy principles. The UK GDPR also applies to controllers and processors based outside the UK if their processing activities relate to:
- offering goods or services to individuals in the UK; or
- monitoring the behaviour of individuals taking place in the UK.
The UK has now passed an amendment law, the Data (Use and Access) Act 2025 (“the DUAA”), which contains changes introducing substantive divergence from the EU GDPR in selected areas. All changes made by the DUAA are now in effect except some relating to establishment of the new Information Commission. The UK GDPR sits alongside the Data Protection Act 2018 (“DPA 2018”).
The EU GDPR has extraterritorial effect and may apply to UK-based controllers and processors who have an establishment in the EEA, have customers in the EEA, or monitor individuals in the EEA.
DPA 2018 The DPA sits alongside and supplements the UK GDPR, containing exemptions and clarifications. It has been amended by the DUAA (see above), which introduced a range of reforms to the UK data protection regime, including changes relating to automated decision-making, data subject rights, complaints handling, the processing of personal data for scientific research, and law enforcement processing. The DUAA also reforms the governance framework, enforcement and investigatory powers of the UK data protection regulator through the establishment of the Information Commission, a new body corporate which is intended to replace the current Information Commissioner’s Office (ICO). The transition is expected to take place in late 2026.
Law Enforcement Directive EU 2016/680 (“LED”) Part 3 of the DPA 2018 brought the LED into UK law. This complements the UK GDPR and sets out requirements for processing personal data by law enforcement authorities. The DUAA has made changes to the regime which mirror some of the changes to the UK GDPR. The Data Protection (Charges and Information) Regulations 2018 The Data Protection (Charges and Information) Regulations 2018 require every UK controller that processes personal information to pay a data protection fee to the ICO unless all the processing of personal data by the data controller is exempt processing. The information provided to the ICO is published on a register. These regulations determine the fees an organisation will need to pay in relation to data protection charges. There are three different tiers of fee and controllers are expected to pay between £52 and £3,763.
Freedom of Information Act 2000 (“FOIA”) The FOIA provides public access to information held by public authorities. It does this in two ways: - public authorities are obliged to publish certain information about their activities; and
- members of the public are entitled to request information from public authorities.
The FOIA covers any recorded information that is held by a public authority in England, Wales and Northern Ireland, and by UK-wide public authorities based in Scotland. Information held by Scottish public authorities is covered by Scotland’s own Freedom of Information (Scotland) Act 2002.
Privacy and Electronic Communications Regulations 2003 (“PEC Regulations”) The PEC Regulations are derived from European law. They implement European Directive 2002/58/EC, also known as ‘the e-privacy Directive’, which complements the general data protection regime and sets out more specific privacy rights on electronic communications. The PEC Regulations cover:
- marketing by electronic means, including marketing calls, texts, emails and faxes;
- use of cookies or similar technologies that track information about people accessing a website or other electronic service;
- security of public electronic communications services; and
- privacy of customers using communications networks or services as regards traffic and location data, itemised billing, line identification services (e.g. caller ID and call return), and directory listings.
The DUAA contains important changes to the PEC Regulations by raising maximum penalties for infringement to UK GDPR levels and introducing exemptions for some low-risk statistical and service-improvement tracking technologies not concerned with targeted advertising. The EU is currently debating reform to e-privacy law through its Digital Omnibus package.
Environmental Information Regulations 2004 (“EIR”) The EIR provide public access to environmental information held by public authorities. They do this in two ways: - public authorities must make environmental information available proactively; and
- members of the public are entitled to request environmental information from public authorities.
The EIR cover any recorded information held by public authorities in England, Wales and Northern Ireland. Environmental information held by Scottish public authorities is covered by the Environmental Information (Scotland) Regulations 2004.
Network and Information Systems Regulations 2018 (“NIS Regulations”) The NIS Regulations address cyber threats to improve the functioning of the digital economy. They contain cyber risk management and reporting obligations for large or critical organisations in certain sectors. The NIS Regulations require these systems to have sufficient security to prevent any action that compromises either the data they store, or any related services they provide. They are based on an EU directive in effect in member states, widely known as “NIS 2”. The UK government has introduced the Cyber Security and Resilience (Network and Information Systems) Bill, to implement similar changes in the UK (see below).
Investigatory Powers Act 2016 (“IPA”) The IPA governs the use and oversight of investigatory powers by law enforcement and the security and intelligence agencies. It sets out the lawful acquisition of communications metadata, building on and superseding in part the Regulation of Investigatory Powers Act 2000 (“RIPA”). The Act was amended by the Investigatory Powers (Amendment) Act 2024 to widen government access to publicly available data and to communications data from telecoms companies for intelligence purposes.
Re-use of Public Sector Information Regulations 2015 (“RPSI”) The RPSI relate to public sector information produced as part of a public task. Under regulation 3 public sector bodies must publish a list of the main information they hold for the purpose of a public task. The RPSI do not apply to information that would be exempt from disclosure under information access legislation (such as the DPA 2018 and the FOIA).
In July 2026 the government started consulting on whether the RPSI should permit public authorities to charge more for re-use of public datasets.
Regulation (EU) 910/2014 on electronic identification and trust services for electronic transactions in the internal market (“eIDAS”) The UK eIDAS Regulations set out rules for UK trust services and establish a legal framework for electronic signatures, seals, time stamps, documents, registered delivery services and certificate services for website authentication, and also recognise equivalent services in the EU. Electronic trust services provide security for electronic documents, communications and transactions for example by ensuring that documents sent electronically have not been altered in any way and that the sender can be easily recognised.
The DUAA introduced a statutory framework for Digital Verification Services (DVS) which came into force on 1 December 2025, enabling individuals to verify their identity securely when accessing online services. The regime establishes a certification, registration and trust framework for DVS providers and is intended to underpin the UK’s digital identity strategy.
The Product Security and Telecommunications Infrastructure Act 2022 (“PSTI”) The PSTI Act and Regulations made under it (the PSTI (Security Requirements for Relevant Connectable Products) Regulations 2023) institute a UK consumer connectable product security regime. The product compliance regime outlines security requirements for manufacturers of in scope “smart” devices, such as internet-connected baby monitors, domestic appliances and smartphones. Current requirements concern default passwords, product information and product support periods. The full regime commenced in April 2024.
Online Safety Act 2023 (“OSA”) The OSA imposes duties on providers of regulated user-to-user services and regulated search services that are accessible from the UK. Core duties relating to illegal content and the protection of children from harmful content are now in force. Providers must assess risks arising on their services and implement proportionate measures to reduce those risks. Duties include assessing and mitigating the risks of illegal content and activity, protecting children from harmful and age-inappropriate content, implementing highly effective age assurance or age verification measures, and processes for reporting, complaints and content moderation. Services likely to be accessed by children are subject to additional obligations.
The final register of categorised services was published in July 2026. Category 1 services are subject to additional duties relating to transparency, user empowerment, identity verification, protection of journalistic and news publisher content, compliance reporting and other accountability measures.
Ofcom is responsible for enforcement and has extensive investigatory powers, including investigation, information, business disruption measures and imposition of fines of up to the higher of £18 million and 10% of annual worldwide turnover.
Ofcom is reviewing the effectiveness of age assurance across regulated online services in the context of proposals to restrict social media for under-16s.
Digital Markets, Competition and Consumers Act (“DMCCA”) This introduces a competition regime for the largest and powerful digital platforms including a mandatory code of conduct and merger control. It gives the Competition and Markets Authority (CMA) the power to designate undertakings with a link to the UK, and turnover of £1bn in the UK or £25bn globally, as having strategic market status (SMS) in respect of a digital activity and to impose conduct requirements on designated undertakings. The CMA can, following investigation, intervene to promote competition where it considers that activities of a designated undertaking are having an adverse effect on competition through pro-competition interventions (PCIs).
The DMCCA also introduces a duty for designated undertakings to report certain mergers and to produce compliance reports.
The first SMS designations were made in October 2025, when Apple and Google were designated by the CMA as having SMS in relation to their mobile platforms. The CMA has since undertaken consultations and interventions relating to app stores, mobile ecosystems, interoperability, steering restrictions and access to platform functionality.
IMPENDING (as of July 2026)
Principal law Brief Description Cyber Security and Resilience (Network and Information Systems) Bill (“CSR Bill”) The CSR Bill contains reforms to the UK NIS Regulations 2018. Proposed reforms include expanding the scope of regulated entities, strengthening incident reporting obligations, enhancing regulator powers and updating the enforcement regime in a similar way to the EU NIS 2 Directive. Further requirements will be implemented through secondary legislation and regulatory guidance. It is expected to become law in the next 12 months with enforceable obligations from 2028. -
Data Protection – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?
Law(s) Sanction UK GDPR and DPA 2018 The ICO can impose two tiers of fines: - a maximum fine of £17.5 million or 4 per cent of annual global turnover – whichever is greater – including for infringement of any of the data protection principles, rights of individuals or rules concerning restricted data transfers; and
- a maximum fine of £8.7 million or 2 per cent of annual global turnover – whichever is greater – for infringement of other provisions, such as administrative requirements of the legislation.
The DUAA reforms the governance framework, enforcement and investigatory powers of the UK data protection regulator through the establishment of the Information Commission, a new body corporate which is intended to replace the current ICO. The transition is expected to take place later in 2026.
EU GDPR Member states must allow for maximum fines for the most serious infringements of the greater of €20 million or 4% of annual global turnover. It also creates a lower tier of fines up to the greater of €10 million or 2% of annual global turnover. Enforcement powers of member state data protection regulators are established in national law, and they generally have similar powers to the UK ICO.
DPA 2018 The DPA 2018 includes provisions for individual criminal offences related to data protection, including: - unlawful obtaining, disclosing, or selling of personal data without lawful authority;
- unlawful re-identification of de-identified personal data; and
- knowingly altering, defacing, blocking, erasing, or destroying personal data with the intention of preventing its disclosure.
These offences are punishable by a fine or imprisonment.
An organisation, such as a company, partnership, or government body, can also be held criminally liable in certain circumstances.
Criminal penalties in the DPA 2018 apply to processing under the LED by competent law enforcement authorities.
LED In the UK, ICO fines for law enforcement authorities are subject to the same financial limits as under the UK GDPR. In European member states, maximum fines are determined by member state law.
The Data Protection (Charges and Information) Regulations 2018 Under the DPA 2018, a fine of up to 150% of the maximum registration fee can be set by the ICO for failure to pay the data protection fee. The maximum penalty is currently £4,350. FOIA The ICO does not have the power to impose administrative fines, although failure to comply may lead to court proceedings for contempt with penalties of up to two years’ imprisonment, a fine, or both. PEC Regulations Under the DUAA, the maximum penalty has been increased to levels under the UK GDPR, i.e. up to the greater of £17.5 million or 4 per cent of annual global turnover. For breaches of the PEC Regulations that occurred before 5 February 2026 the previous maximum penalty of up to £500,000 continues to apply.
EIR As under the FOIA, the ICO has no direct power to fine. However, a controller who breaches the EIR and has been served with an enforcement notice can be prosecuted for failing to comply with a notice. This offence can lead to administrative fines and court proceedings to secure compliance. NIS Regulations The NIS Regulations set out a sliding scale of maximum financial penalties which can be imposed by the ICO: - £1 million – for any contravention that the ICO determines was not ‘a material contravention’;
- £8.5 million – for a ‘material contravention which the ICO determines does not and could not have created a significant risk to, or significant impact on, or in relation to, the service provision by the OES* or RDSP*’; and
- £17 million – for a ‘material contravention which the ICO determines has or could have created a significant risk to, or significant impact on, or in relation to, the service provision by the OES or RDSP’.
*An OES is an ‘operator of essential services’, and an RDSP is a ‘relevant digital service provider’.
IPA Imprisonment for a term not exceeding 2 years, a fine, or both. eIDAS The ICO can take action for breaches of eIDAS, including by imposing fines of up to £1,000. -
Data Protection – What data protection rules are relevant to technology contracts in your country? Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?
Please see above answer to Question 17 in relation to data protection rules relevant to technology contracts. In relation to the EU GDPR, yes, especially as a result of the extraterritorial effect of the EU GDPR. References to other third country data protection laws (such as the CCPA) are not typically included in contracts, unless they are directly applicable to the processing carried out as part of the services provided under the contract.
-
Cybersecurity – Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.
Cybersecurity obligations specific to UK telecommunications providers exist across multiple frameworks which sit alongside general data protection obligations under the UK GDPR and the Data Protection Act 2018.
Firstly, the Communications Act 2003 (as amended by the TSA) requires providers of public electronic communications networks and services to take appropriate and proportionate measures to identify and reduce the risks of security compromises, and to ensure service availability and resilience. Where an incident occurs that adversely affects the network or service, and meets certain materiality thresholds (e.g. risks to public safety or service continuity), the provider must notify Ofcom “as soon as reasonably practicable.” Recent amendments introduced by the Telecommunications (Security) Act 2021 (“TSA”) has expanded this notification duty to include relevant “security compromises” (e.g., critical vulnerabilities) that may impact a network or service (see s. 105K, CA 2003).
Separately, the Network and Information Systems Regulations 2018 (“NIS Regulations”) apply to operators of essential services, including certain digital infrastructure providers such as domain name system (DNS) service providers, internet exchange points, and top-level domain name registries. These entities must implement “appropriate and proportionate” security measures to protect their network and information systems, and must notify the relevant competent authority (in the case of telecommunications providers, Ofcom) of any incident having a significant impact on the continuity of essential services.
Finally, the TSA significantly expands the scope of telecoms-specific cybersecurity duties. It imposes a layered regime of general and specific obligations, including requirements for network and supply chain risk assessments, internal security governance, access control, vulnerability patching, and incident response planning. These requirements are supplemented in the Electronic Communications (Security Measures) Regulations 2022 and collectively codified in the Telecommunications Security Code (the “Code”). The Code represents a significant overhaul of cybersecurity and operational resiliency requirements for the UK’s telecommunications sector, and Ofcom is currently in the process of compelling each in-scope entity to provide submissions relating to the steps it is taking to bring its cybersecurity governance and operational resiliency in line with the Code’s requirements.
-
Cybersecurity – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?
Under the Communications Act, Ofcom has powers to investigate non-compliance and impose civil penalties of up to £10 million, or, in the case of continuing contraventions, £100,000 for each day the breach continues. Ofcom may also elect to sanction under its General Conditions of Entitlement, which provide for fines of up to 10% of a provider’s turnover.
The NIS Regulations allow for administrative fines of up to £17 million, depending on the severity and impact of the breach.
Under the TSA, Ofcom is empowered to audit compliance, request information, and enforce through penalties of up to 10% of relevant turnover, or £100,000 per day for continuing contraventions.
From an enforcement perspective, Ofcom is considered an active enforcer of UK laws and regulations and has a strong track record of imposing sanctions and fines for non-compliance. For example, in 2021, BT was fined £17.5 million for failures in managing its emergency call handling infrastructure, following a network failure that resulted in over 190,000 calls to 999 not being connected. Ofcom found BT in breach of its obligations to ensure network availability and integrity under the General Conditions.
-
Cybersecurity – Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?
Yes, in limited circumstances – Under the NIS Regulations, Operators of Essential Services (“OESs”) are generally designated as essential by their relevant competent authority rather than through a general registration regime. However, the Information Commissioner’s Office (“ICO”), which is responsible for regulated digital service providers under the NIS Regulations, requires in-scope organisations to notify/register with the ICO. Digital service providers include cloud computing services, online marketplaces and online search engines, and organisations that believe they fall within these categories should consider whether they are required to register.
The UK’s core cybersecurity regime under the NIS Regulations is currently in the process of being reformed through the proposed Cyber Security and Resilience Bill. The Bill is expected to broaden the scope of the existing regime, including by widening the categories of organisations covered and enhancing regulators’ oversight and enforcement powers. The Bill is anticipated to enter into force towards the end of 2026 or early 2027, with enforcement expected from late 2027 or 2028.
Organisations in the UK that provide services in the EU should also be aware of registration requirements under the EU’s counterpart to the NIS Regulations, the NIS2 Directive. Under NIS2, most Member States have introduced registration and/or notification requirements for in-scope organisations. Organisations should also be aware that NIS2 contains extraterritorial elements, meaning that certain organisations established outside the EU may nevertheless be required to comply with NIS2, including applicable registration requirements, where they provide regulated services into the EU.
-
Cybersecurity – Please summarise the regulatory framework for the reporting of cybersecurity incidents.
The incident reporting framework for cybersecurity across the UK exists as a patchwork of laws, regulations, sectoral obligations and regulator-led practice that has developed over time.
Overarching Frameworks
The UK’s data protection framework, principally set out in the UK GDPR, imposes incident notification requirements for cybersecurity incidents that result in a personal data breach. Organisations must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification is not required where the breach is unlikely to result in a risk to individuals’ rights and freedoms. Where the breach is likely to result in a high risk to affected individuals, organisations must also notify those individuals.
For organisations designated as Operators of Essential Services (“OESs”) and certain Digital Service Providers (“DSPs”), the NIS Regulations require organisations to notify the relevant competent authority of incidents that have a significant impact on the continuity of the essential or digital service. Reporting timeframes are determined by sector-specific requirements, with many regulators (including the ICO) currently adopting a 72-hour reporting backstop.
However, the proposed Cyber Security and Resilience Bill is intended to move the UK incident reporting framework closer to the EU approach, including the introduction of an initial notification requirement within 24 hours.
Sector-specific reporting
- Telecommunications: Providers of public electronic communications networks and services are subject to reporting obligations under the Communications Act 2003, as amended by the Telecommunications (Security) Act 2021 (“TSA”). The TSA, as supplemented by the Electronic Communications (Security Measures) Regulations 2022 and Ofcom’s Telecommunications Security Code of Practice, requires telecommunications providers to notify Ofcom of certain security compromises and incidents affecting network security, resilience or service availability. Notifications must be made “as soon as reasonably practicable”, with Ofcom typically expecting rapid engagement and, in some cases, notification within 30 minutes for serious incidents.
- Financial Services: Financial services firms regulated by the FCA and/or PRA are subject to additional incident reporting requirements as part of the UK’s operational resilience framework (“ORF”). The ORF comprises a patchwork of rules and guidance principally set out in FCA SYSC 15A, the PRA Operational Resilience Rules, and associated FCA, PRA and Bank of England policy statements and supervisory guidance. Under the ORF, financial services firms are generally expected to notify regulators promptly of material cyber incidents and operational disruptions, particularly where they affect customers, important business services, or the operational resilience of the firm or wider financial markets. There is no prescribed statutory reporting deadline, but notifications are generally expected to be made immediately, or as soon as reasonably practicable, once the firm becomes aware of the incident. The FCA and PRA also place increasing emphasis on so-called “near-miss” reporting, with firms expected to maintain processes for identifying, recording and reporting cyber and operational incidents that could have resulted in material disruption. Regulators increasingly view effective near-miss reporting as evidence of a mature operational resilience and risk management framework.
-
Artificial Intelligence – Which body(ies), if any, is/are responsible for the regulation of artificial intelligence?
The UK does not have a central AI regulator or authority. That said, the Digital Regulation Cooperation Forum (“DRCF”) is a collaborative forum comprising the following UK regulators who are responsible for digital regulation: the ICO; Ofcom; the CMA; and the FCA. The DRCF is designed to assist organisations who operate across multiple sectors.
The White Paper issued by the UK government in March 2023 (last updated in August 2023 – “A pro-innovation approach to AI regulation”) also sets out a regulatory framework that aims to be “pro-innovation, proportionate, trustworthy, adaptable, clear and collaborative”. It identifies five “values-focused cross-sectoral principles” for AI regulation. These are: (1) safety and security; (2) transparency and explainability; (3) fairness; (4) accountability and governance; and (5) contestability and redress. These principles are intended to guide businesses in designing, developing, and using AI in a responsible manner, and are referred to as a principles-based approach.
Under the principles-based approach, Regulators are required to publish their own sectoral guidance. Indeed, the main UK regulators, including the Financial Conduct Authority (“FCA”), Competition and Markets Authority (“CMA”) and the Information Commissioner’s Office (“ICO”) have published documents outlining their strategic approaches to regulating AI generally, as well as guidance relating to discrete elements of the technology. By way of example, in March 2026 the CMA published guidance for organisations on complying with consumer law when deploying AI agents.
-
Artificial Intelligence – Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.
As of July 2026, there is no overarching piece of legislation which governs artificial intelligence in the UK comparable with, for example, the EU’s AI Act. Instead, the principal laws governing the deployment and use of AI are existing laws relating to issues such as data protection, online safety, equality and discrimination, intellectual property ownership and unfair competition, as well as certain sector-specific guidelines issued by existing regulators. It seems likely that modifications to existing laws and regulations may be promulgated as AI develops and evolves.
-
Artificial Intelligence – Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and/or generative AI (including agentic AI)?
As of July 2026, there are no laws dealing directly with the deployment and use of Large Language Models and/or generative AI.
The 2025 AI Opportunities Action Plan is focussed on fostering a regulatory environment that is pro-innovation and investment. The 2026 King’s Speech supports these objectives, with draft legislation announced and since introduced aimed at promoting regulatory agility for technologies such as artificial intelligence. Under the draft Regulators (Growth Objective) Bill, new regulatory sandboxes will be introduced, allowing businesses to ‘safely seize’ opportunities arising from emerging technologies such as artificial intelligence, by temporarily modifying or suspending existing laws to enable testing of new products and technologies in real-world settings.
-
Artificial Intelligence – Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?
Although template clauses to address AI clauses are emerging, they are not yet established. Issues or risks to consider when approaching such types of provisions include broader intellectual property licensing, ownership and infringement, whether the AI will be consumer-facing, whether there is a sector-specific regulatory angle, and whether emerging regulatory frameworks (potentially including overseas regulation with extraterritorial application such as the EU AI Act) apply, and what rights or prohibitions apply to the information that can be input into or used in conjunction with the relevant generative AI platform.
-
Artificial Intelligence – Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?
Given AI is now widely adopted and integrated within software applications, it is becoming more common to see contractual provisions around ownership and access to rights in the outputs of AI.
The outcome of various case law and legislative changes is expected to have a strong bearing on standards or best practice within contracts going forward. Arguments raised in the high-profile case of Getty vs Stability AI, may influence reforms on how AI models are trained and used, which may impact the ownership or use of generated output, notwithstanding that the complaint of primary copyright infringement was dropped during the trial for jurisdictional reasons. An ongoing consultation is expected to lead to a legal framework for use of copyright materials in an AI context, and is expected to influence best practice. Proposals aim to balance developer access to data for AI training by way of a text and data mining exemption, with protection of rights for copyright owners through transparency and compensation mechanisms.
Despite the UK Government publishing its report on Copyright and Artificial Intelligence in 2026, and rules relating to transparency and reporting coming in force under recent legislation, the position around the permitted use of text and data in training of AI remains unclear.For the time being it remains good practice when contracting for AI systems, particularly ones which create outputs which may be subject to further commercial exploitation by either party, be useful in training, or be shared or published externally, to carefully consider the rights in and ownership of any materials generated through AI.
-
Blockchain – What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?
The UK is about to undergo a significant change in respect to the regulation of crypto asset services. The Financial Conduct Authority (“FCA”) has finalised its rules for crypto asset services which will come into effect on 25 October 2027. Until the commencement of the new regime, existing rules apply under the Money Laundering regulations 2017 (“MLRs”) and the UK’s financial promotions regime (“FinProm”).
UK regulatory framework today
The UK financial services regime was not originally drafted with crypto assets in mind. Consequently, whether a crypto asset activity is regulated has depended on whether it falls within existing legislation, such as the Financial Services and Markets Act 2000 (“FSMA”), the Electronic Money Regulations or the Payment Services Regulations.
Under the current regime:
- crypto assets that qualify as specified investments (for example, tokenised securities) are regulated under the FSMA;
- certain crypto assets structured as e-money are regulated as e-money tokens; and
- other crypto assets that are often traded, including exchange and utility tokens, have generally fallen outside the FCA’s core conduct perimeter and therefore could be classified as unregulated.
However, even where crypto assets have been unregulated, firms have still been subject to regulatory obligations, including:
- financial promotion restrictions;
- anti-money laundering requirements under the Money Laundering Regulations; and
- prospectus requirements.
New rules from 25 October 2027
The headline message from the new rules is that those providing crypto asset services in the UK will now need to be authorised by the FCA to do so. Crypto asset services are being formally brought under the FSMA framework. The FCA has stated that it will determine applications made between 30 September 2026 and 28 February 2027 before the regime starts to apply.
The framework is set out in five policy statements:
1. PS26/9 – Admissions and Disclosures (“A&D”) and Market Abuse Regime for Crypto assets “(MARC”). This contains rules on crypto asset admissions, issuer disclosures and measures to prevent market abuse and improve market integrity.
2. PS26/10 – Stablecoin Issuance. This contains requirements for issuing regulated stablecoin, including governance, backing assets, redemption and consumer protection standards.
3. PS26/11 – Regulated Crypto Asset Activities. This contains the requirement for authorisation and conduct rules for firms providing regulated crypto asset activities.
4. PS26/12 – Prudential Regime for Crypto Asset Firms. This sets out requirements for financial resilience including capital, liquidity and risk management.
5. PS26/13 – Application of the FCA Handbook. This sets out that provisions within the FCA Handbook will apply to those providing crypto asset service.
The new regime applies to crypto assets that have been broadly defined in s417 of the FSMA. The definition applies to any cryptographically secured digital representation of value or contractual rights that can be transferred, stored or traded electronically and uses technology supporting the storage of data which might include distributed ledger technology.
Within this broad definition there are multiple significant sub-categories:
1. Qualifying crypto assets – fungible and transferable crypto assets, including qualifying stablecoins, but excluding tokenised versions of existing specified investments and other instruments that are already regulated (such as e-money or deposits).
2. Qualifying stablecoins – stablecoins that seek to maintain a stable value by reference to fiat currency or other assets through the use of reserve assets.
3. Specified investment crypto assets – crypto assets that meet both the FSMA definition of a crypto asset and the definition of a specified investment (for example, tokenised equities).
New regulated crypto asset activities
The Cryptoasset Regulations insert a new chapter in the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001 (“RAO”), which creates the following new categories of specified activity along with exclusions relevant to that activity, that require FCA authorisation:
1. Issuing qualifying stablecoins
Issuing qualifying stablecoins becomes a regulated activity in its own right. This activity is broken down into three components:- offering the stablecoin;
- redeeming the stablecoin; and
- maintaining the stabilisation mechanism.
Issuance requires FCA authorisation where the activity is carried out from a UK establishment. This is designed to distinguish clearly between qualifying stablecoins and tokenised e-money or deposits, avoiding the automatic application of existing e-money rules.
2. Safeguarding (custody) of qualifying crypto assets
Safeguarding qualifying crypto assets, including certain tokenised specified investments, is regulated as a standalone activity.
This captures firms that hold crypto assets on behalf of clients, whether as pure custodians or as part of a wider service offering. The focus of the regime is on safeguarding client assets, operational resilience and the management of insolvency risk.
3. Operating a qualifying crypto asset trading platform (“CATP”)
A CATP is broadly defined as a platform that brings together multiple third-party buying and selling interests in qualifying crypto assets and results in contracts for the exchange of those crypto assets for fiat (including e-money) or other qualifying crypto assets.
The regime applies to both UK based platforms and overseas platforms that provide services to UK users, reflecting the FCA’s focus on consumer outcomes rather than firm location.
4. Dealing in crypto assets and arranging deals
The regime will also regulate dealing in qualifying crypto assets as both principal and agent, as well as arranging deals in qualifying crypto assets.These activities capture a broad range of brokerage, execution and Over The Counter (“OTC”) business models and also encompass crypto asset lending and borrowing services.
5. Cryptoasset staking
Staking is regulated as a distinct activity, defined as making arrangements for qualifying crypto asset staking, where crypto assets are used in blockchain validation processes. -
Search Engines and Marketplaces – Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.
Search Engines and Marketplaces
The principal UK laws governing search engines and online marketplaces are set out below. While certain rules apply more heavily to particular business models, the regulatory framework is increasingly focused on consumer protection, transparency, online safety, privacy and platform accountability. Recent legislative reforms have also significantly strengthened regulators’ enforcement powers and increased scrutiny of online business models.
Electronic Commerce Regulations (Electronic Commerce (EC Directive) Regulations 2002 (as amended) (“E-Commerce Regulations”))
The E-Commerce Regulations apply to most online services, including search engines and marketplaces that qualify as “information society services”. They require providers to make certain information available to users, regulate aspects of electronic contracting and provide liability protections in relation to certain third-party content, subject to specified conditions.
UK Platform-to-Business Regulation (Retained Regulation (EU) 2019/1150 on promoting fairness and transparency for business users of online intermediation services (“UK P2B Regulation”))
The UK P2B Regulation promotes fairness and transparency for business users of online intermediation services and online search engines. For online marketplaces and other intermediation platforms, the Regulation imposes obligations relating to terms and conditions, complaint-handling procedures, ranking transparency and platform governance. For online search engines, the regime focuses primarily on transparency around the ranking of search results and the factors that influence business visibility.
Online Safety Act 2023 (Online Safety Act 2023 (“OSA”))
The OSA represents a significant shift towards greater accountability for online services. It imposes duties on in-scope services, including search services and certain marketplaces that host user-generated content.
Depending on the nature of the service, operators may be required to assess and mitigate risks relating to illegal content, implement reporting and complaints mechanisms, protect children from harmful content and comply with transparency, governance and record-keeping obligations. Search engines are subject to a dedicated search service regime under the OSA, whilst marketplaces may also fall within scope where they host user-generated content or otherwise meet the conditions for regulation. Ofcom is responsible for enforcement and implementation continues through a phased rollout of guidance and codes of practice.
Digital Markets, Competition and Consumers Act 2024 (Digital Markets, Competition and Consumers Act 2024 (“DMCC”))
The DMCC represents the most significant reform of UK consumer protection law in decades and is highly relevant to businesses operating search engines and online marketplaces.
The DMCC prohibits unfair commercial practices that are likely to affect consumer decision-making and applies throughout the consumer journey, including advertising, marketing, search results, rankings, product listings, purchasing processes and post-sale interactions. It strengthens pricing transparency requirements, introduces new rules relating to fake reviews and review information, and provides consumers with greater protection against misleading commercial practices.
The reforms are particularly significant for search engines and online marketplaces as they affect how products, services and offers are marketed and presented online, including the disclosure of pricing, key product information, trader information, reviews, rankings and other material information that consumers need in order to make informed purchasing decisions.
The DMCC also significantly strengthens the Competition and Markets Authority’s (CMA) enforcement powers. The CMA can now directly investigate suspected breaches and, in certain circumstances, impose financial penalties of up to 10% of a business’s annual global turnover. Recent CMA activity demonstrates a clear intention to focus enforcement on online practices such as pricing transparency, consumer reviews and digital customer journeys.
In addition, regulators are increasingly using technology, data analytics and automated monitoring tools to identify potentially non-compliant practices online. As a result, businesses should assume that misleading pricing practices, non-compliant reviews, problematic advertising and other consumer law infringements are significantly more likely to be identified than in the past.
Subscription Contracts and Online Cancellation Requirements (“DMCC”)
The DMCC also introduces a new regime for subscription contracts, which is expected to come into force in Spring 2027, separately from the unfair commercial practices provisions already in force.
The regime is intended to address so-called “subscription traps” and difficult cancellation journeys. Among other requirements, affected businesses will be required to provide prescribed pre-contract information and reminder notices, offer cooling-off rights in certain circumstances and ensure consumers can end subscriptions through a straightforward online cancellation process. This includes requirements for online traders to make available a simple online cancellation mechanism. These requirements may be relevant to search engines and marketplaces that offer paid memberships, subscription services, premium features or other recurring digital services.
Advertising Regulation (Advertising Standards Authority (ASA) and CAP Code)
Advertising appearing on or through search engines and marketplaces remains subject to regulation by the Advertising Standards Authority (ASA) and the UK Code of Non-broadcast Advertising and Direct & Promotional Marketing (CAP Code).
Advertisements and promotional communications must be legal, decent, honest and truthful. Search engines and marketplaces are increasingly scrutinised in relation to reviews, rankings, endorsements, search result presentation and pricing claims. The DMCC now provides a significantly stronger statutory enforcement framework alongside the existing self-regulatory advertising regime, increasing the risks associated with non-compliant digital marketing practices.
Data Protection and Privacy (UK GDPR, Data Protection Act 2018 and Privacy and Electronic Communications Regulations 2003 (“PECR”))
Search engines and marketplaces that process personal data must comply with applicable UK privacy laws. These rules govern the collection, use, sharing and retention of personal data and impose obligations relating to transparency, lawful processing, data security, cookies and direct marketing communications.
Accessibility Requirements (European Accessibility Act (Directive (EU) 2019/882))
Businesses offering certain in-scope digital products or services to consumers in the European Union may need to comply with the European Accessibility Act, which became applicable on 28 June 2025.
The legislation introduces mandatory accessibility requirements for certain digital products and services, including e-commerce services and online consumer interfaces. Businesses targeting EU consumers should review websites, apps and digital customer journeys to ensure accessibility requirements are met.
Emerging Regulation for Online Marketplaces
Regulation of online marketplaces continues to evolve in both the UK and EU.
In the UK, policymakers and regulators are increasingly focused on the role marketplaces play in facilitating the sale of unsafe, counterfeit and non-compliant products. The Product Regulation and Metrology Bill is expected to facilitate reforms to the UK’s product safety regime and may result in increased responsibilities for online marketplaces.
Whilst the final scope of the reforms remains under development, marketplace operators may increasingly be expected to undertake greater seller verification, improve trader traceability, maintain effective notice-and-takedown procedures, cooperate with regulators on product safety issues and take more proactive steps to identify and remove unsafe or non-compliant products from sale. The overall direction of travel is clear: regulators are increasingly seeking to move online marketplaces away from a purely passive intermediary role and place greater responsibility on them for products sold through their platforms.
-
Social Media – Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?
Many of the key laws governing social media platforms and other online platforms are the same as those discussed in the response above in relation to search engines and marketplaces, including the E-Commerce Regulations, the OSA, the DMCC, UK GDPR, PECR and, where relevant, the European Accessibility Act.
However, social media platforms and online platforms are particularly affected by:
OSA: The OSA places extensive obligations on online platforms in relation to user-generated content, illegal content, child safety, reporting mechanisms and platform governance. Given the volume of user-generated content typically hosted by social media services and other interactive platforms, this is likely to be one of the most significant regulatory regimes affecting the sector.
Advertising regulation: Social media remains a key area of focus for the Advertising Standards Authority (ASA) and the CAP Code. Regulatory scrutiny has increased in relation to influencer marketing, affiliate marketing, endorsements, user-generated promotional content and the disclosure of commercial relationships. The DMCC adds a more robust statutory consumer protection framework to these existing advertising rules.
DMCC: Whilst the DMCC applies broadly to online businesses (see the discussion above), it is particularly relevant to social media and online platforms because they increasingly influence consumer decision-making through advertising, recommendations, rankings, endorsements, influencer marketing and other forms of commercial content. The DMCC therefore sits alongside the OSA and advertising regulation as part of a wider regulatory framework focused on ensuring that consumers are presented with clear, accurate and transparent information online and are not exposed to misleading commercial practices.
More broadly, regulators are increasingly using technology, data analytics and automated monitoring tools to identify potentially non-compliant online content and commercial practices at scale. This, combined with strengthened enforcement powers under the DMCC and OSA, means social media platforms and other online platforms can expect significantly greater regulatory scrutiny than in previous years.
-
Social Media – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?
Ofcom can impose fines of up to “the greater of” £18 million and “10% of the person’s qualifying worldwide revenue for the person’s most recent complete accounting period” for breaches of the OSA by a regulated person (para. 4, Schedule 13, OSA). The same cap applies where two or more entities are jointly and severally liable for a penalty, save that the OSA sets out how the applicable 10% of qualifying worldwide revenue is to be calculated (para. 5, Schedule 13). Alongside broad powers of investigation, Ofcom can impose restriction orders on services requiring them to make unlawful content unavailable, which is of particular note for organisations based outside of the UK.
Criminal penalties can also be imposed for breach of any of the various communications and other offences set out in the OSA.
These powers are part of Ofcom’s broader enforcement toolkit to ensure that online platforms comply with their legal duties to protect users – especially children – from illegal and harmful content.
Types of breaches that may trigger enforcement action include:
- Failure to protect users from illegal content;
- Failure to protect children from harmful content; and
- Failure to implement effective systems and processes.
-
Spatial Computing – Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?
As of August 2026, the UK does not have a single, dedicated law governing spatial computing (which includes technologies such as augmented reality (“AR”), virtual reality (“VR”), mixed reality (“MR”), and digital twins). Several existing and emerging legal frameworks, however, apply to spatial computing systems depending on their use case, data handling, and interaction with physical and digital environments. For example, issues may pertain to intellectual property law, data protection and cybersecurity law, online safety and product safety regulations.
The Data (Use and Access) Act 2025 updated UK data protection law to address emerging technologies such as spatial computing, including key provisions to:
- regulate passive data collection;
- strengthen consent requirements for processing sensitive data in extended reality environments (including AR, VR, and MR); and
- introduce transparency obligations for AI-driven advertising and personalisation in spatial computing.
Regulation (EU) 2023/2854 (EU Data Act) has extraterritorial effect and may therefore also be relevant in certain spatial computing deployments, particularly where the technology is integrated with connected products, IoT infrastructure, digital twins, wearable devices, smart glasses, connected vehicles or other systems that generate and communicate usage or environmental data. In such circumstances, the EU Data Act may confer data access and portability rights on users, impose data-sharing and interoperability obligations, and affect how organisations structure contractual arrangements concerning data generated by those systems.
-
Quantum Computing – Please summarise the principal laws (present or impending), if any, that govern quantum computing and/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?
There are currently no standalone UK laws specifically governing quantum computing or quantum cryptography. However, quantum technologies are increasingly being considered within broader regulatory frameworks, such as:
- The National Security and Investment Act 2021, which includes quantum technologies in its sector screening questionnaire, identifying areas such as quantum communications, sensing, computing, and quantum-resistant cryptography as sensitive technologies. This means investments or acquisitions involving these technologies may be subject to government scrutiny for national security reasons.
- The Strategic Quantum Regulation Plan, which is a pro-innovation regulatory initiative being rolled out by the UK government and which aims to foster innovation whilst ensuring responsible governance of quantum technologies.
- Cyber and Data Protection Laws: existing cybersecurity and data protection laws (including the UK GDPR, Data Protection Act 2018, and the Data (Use and Access) Act 2025 which apply to any entity processing personal data) continue to apply where quantum technologies are used. While there are currently no quantum-specific cybersecurity or data protection regimes, regulators and cybersecurity authorities are increasingly focused on the implications of quantum computing for existing cryptographic standards. In particular, organisations, especially those operating in critical or highly regulated sectors such as telecommunications and financial services, are being encouraged to assess and plan for the transition to post-quantum cryptography to address the future risk that quantum computing could undermine current encryption methods.
- Export controls and dual-use: certain quantum technologies are likely to be subject to export control restrictions in the EU and UK (i.e., pursuant to the EU’s Dual-Use Regulation (Regulation (EU) 2021/821) and UK strategic export control rules imposed pursuant to the Export Control Act and Export Control Order). In particular, advanced quantum computing systems, hardware, software and technical know-how could constitute controlled dual-use items, meaning that exports and certain transfers may require prior authorisation. Businesses involved in the development, supply or international transfer of quantum technologies should assess whether relevant export control requirements apply.
-
Datacentres – Does your jurisdiction have any specific regulations that apply to data centres?
The main regulations of note are:
- Critical National Infrastructure Designation
Since September 2024, UK data centres have been officially designated as part of the country’s Critical National Infrastructure. This elevates their strategic importance and subjects them to increased regulatory scrutiny, similar to sectors like energy and water. The designation aims to:
- Enhance resilience against cyber threats and energy outages;
- Provide a more stable investment platform;
- Enable government oversight through a designated regulator.
- Cybersecurity and Resilience
The upcoming Cyber Security and Resilience Bill will significantly expand incident reporting obligations for data centres:
- Broader incident reporting criteria and stricter timelines;
- Mandatory customer notifications in the event of significant incidents;
- Enhanced transparency and accountability.
Additionally, UK data centres are now within scope of the NIS2 Directive, which mandates:
- Stronger cybersecurity measures.
- Risk management protocols.
- Supply chain security assessments.
- Data Protection and Privacy
Data centres must comply with:
- UK GDPR and the Data Protection Act 2018, which govern the handling of personal data;
- ISO 27001 and Cyber Essentials Plus certifications, widely adopted to demonstrate robust information security practices.
-
General – What are your top 3 predictions for significant developments in technology law in the next 3 years?
The rise of agentic AI leading to heightened focus on regulation and responsible governance.
Rapid advancements in AI capabilities will continue, as will increased business uptake of the technology. This will give rise to novel risks around cyber security, data privacy and liabilities. With no horizontal regulatory framework in the UK, the EU AI Act will continue to influence businesses, particularly insurers and cross-border operators, and without domestic legislation to refer to, may cement itself as the de facto standard.
As the risks posed by agentic AI are more complex than traditional generative AI, we are likely to see increased scrutiny of AI governance, new liability frameworks for AI-related harm, and more pressure on AI vendors to provide greater transparency and insights into their internal AI governance and risk management practices.
Legal frameworks and protections for copyrighted data used to train AI models will evolve.
The rapid evolution of AI has led to concerns within the creative industries around the legality of using data in the form of images, text or other copyright works in training AI systems. In the absence of firm legal guidance, a number of claims have been brought by copyright owners against AI systems developers, both in the US and UK courts. Whilst recent U.S. cases may have found in favour of AI providers, in applying the fair use doctrine under US. Copyright law in relation to the training of an AI model using copyrighted works, the legal framework governing the use of copyrighted material in model training outside of the U.S. remains fragmented and uncertain.
The UK Government published a Report on Copyright and Artificial Intelligence alongside an economic impact assessment into this very issue in March 2026. The documents were produced pursuant to the government’s obligations under the Data (Use and Access) Act and followed a highly active public consultation which explored potential changes to UK copyright law – which would have wide-ranging impacts on copyright owners and those training AI models using copyrighted works. The government must now carefully consider a path forward in light of opposing views from the creative industry and AI providers.
Frontier model advancements will impact upon the ‘state-of-the-art’ in cyber security and privacy.
AI systems are evolving rapidly across multiple domains, increasing the risk to national security and public safety. To combat against the risks that these systems pose, we are likely to see further collaboration between industry, academia and government focussed on research and investment. Privacy enhancing technologies and cyber security standards are likely to need to adapt to maintain pace.
-
General – Do technology contracts in your country commonly include provisions to address sustainability / net-zero obligations or similar environmental commitments?
While specific ESG-related contractual commitments concerning technology remain relatively uncommon, sustainability considerations are moving up the agenda for large corporate customers, with organisations increasingly seeking greater transparency around the environmental impact of AI, including its effect on energy consumption, water usage and related sustainability metrics. Customers requesting sustainability provisions in their contracts, may do so particularly when procuring business critical technology systems. UK government entities, large corporates, and financial institutions may be subject to extra regulatory scrutiny around their sustainability/net zero commitments.
Often, technology vendors’ public-facing websites have sections that outline their commitments to sustainability (sometimes as part of their ESG reporting), containing extensive reporting data. For technology vendors with a global presence, this data will usually be presented at a global operational level, so it may be difficult to glean UK-specific information from such websites.Technology vendors typically resist inserting sustainability commitments at a contractually binding level with individual customers. As an alternative, they may agree to provide more fulsome information than that contained on their public websites for review, including country-specific data and/or scorecards/reviews from external sustainability ratings agencies.
Where the customer is a public sector body, or a large corporate or financial institution, it may be more feasible to negotiate contractual level commitments around sustainability from technology vendors, where relevant, aligned to the customer’s own ESG policies and standards. Over time, such commitments are expected to become a more common contractual expectation for customers procuring AI from third parties.
United Kingdom: TMT
This country-specific Q&A provides an overview of TMT laws and regulations applicable in United Kingdom.
-
Software – How are proprietary rights in software and associated materials protected?
-
Software – In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?
-
Software – Are there any specific laws that govern the harm / liability caused by Software / computer systems?
-
Software – To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software / computer systems?
-
Software Transactions (Licence and SaaS) – Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?
-
Software Transactions (License and SaaS) – Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If ‘yes’, what would be considered a market standard level of cap?
-
Software Transactions (License and SaaS) – Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor’s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.
-
Software Transactions (License and SaaS) – Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?
-
IT Outsourcing – Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?
-
IT Outsourcing – Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.
-
Telecommunications – Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and/or services, including a brief explanation of the general purpose of those laws.
-
Telecommunications – Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.
-
Telecommunications – Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.
-
Telecommunications – Please summarise the principal laws (present or impending) that impose cyber security and/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and/or provision of telecommunications services.
-
Mobile communications and connected technologies – What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?
-
Mobile communications and connected technologies – How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?
-
Data Protection – Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.
-
Data Protection – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?
-
Data Protection – What data protection rules are relevant to technology contracts in your country? Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?
-
Cybersecurity – Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.
-
Cybersecurity – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?
-
Cybersecurity – Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?
-
Cybersecurity – Please summarise the regulatory framework for the reporting of cybersecurity incidents.
-
Artificial Intelligence – Which body(ies), if any, is/are responsible for the regulation of artificial intelligence?
-
Artificial Intelligence – Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.
-
Artificial Intelligence – Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and/or generative AI (including agentic AI)?
-
Artificial Intelligence – Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?
-
Artificial Intelligence – Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?
-
Blockchain – What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?
-
Search Engines and Marketplaces – Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.
-
Social Media – Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?
-
Social Media – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?
-
Spatial Computing – Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?
-
Quantum Computing – Please summarise the principal laws (present or impending), if any, that govern quantum computing and/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?
-
Datacentres – Does your jurisdiction have any specific regulations that apply to data centres?
-
General – What are your top 3 predictions for significant developments in technology law in the next 3 years?
-
General – Do technology contracts in your country commonly include provisions to address sustainability / net-zero obligations or similar environmental commitments?