← Hub

Topic

Data Sovereignty

Geopolitics x Legal1 MIN READ

EU AI Act Article 10 High-Risk AI Data Governance Enforceable from August 2 — GDPR Chapter V Cross-Border AI Data Transfers Now Simultaneously Regulated

The EU AI Act's high-risk AI system obligations — including Article 10 data governance requirements — became enforceable on 2 August 2026, creating a new layer of data-sovereignty obligations that operate simultaneously with existing GDPR Chapter V cross-border transfer requirements. For law firms and their enterprise clients deploying or procuring high-risk AI systems: Article 10 requires documen

Source: NeuralTrust: Data Sovereignty Requirements Under the EU AI Act (2026)Legal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

Iran War: Mercuria v. Baltic Exchange — English High Court Proceedings Test Whether TD3C Benchmark Remains Valid During Strait of Hormuz Closure

A significant commercial litigation has been filed in the English High Court that may define how index-linked contracts respond to geopolitical disruption of benchmark routes. Mercuria Energy Trading S.A. sued Baltic Exchange Information Services Limited, claiming that the TD3C benchmark — which tracks freight rates for Very Large Crude Carriers transporting crude oil from the Gulf to China — no l

Source: Mishcon de Reya: UK, US and UAE Perspectives on the War in IranLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

EU-Canada Digital Trade Agreement Makes Progress on Cross-Border Data Flows

The European Commission reported on July 30 that the third round of EU-Canada digital trade agreement negotiations made substantial progress on cross-border data flows, privacy and personal data protection, bans on prior authorization requirements, and e-contracts. A fourth negotiating round is now being arranged. The development is significant in context: the EU's digital trade negotiation with C

Source: MLex: EU, Canada Make Progress on Cross-Border Data Flows, Privacy in Digital Trade TalksLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

Trump v. Slaughter Triggers NOYB Challenge to EU-US Data Privacy Framework

A July 24 analysis by Sheppard Mullin documents the downstream legal risk from the Supreme Court's Trump v. Slaughter decision: by creating uncertainty about the independence of the Federal Trade Commission — which is the enforcement backbone of the EU-US Data Privacy Framework (DPF) — the ruling has prompted Max Schrems and NOYB to formally ask the European Commission to review the adequacy decis

Source: Sheppard Mullin: Trump v. Slaughter — Future Hurdles for DPF-Based EU and UK Data Transfers to the USLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

Russia Severs Data Adequacy Framework from Council of Europe Convention (Effective July 26)

Federal Law No. 265-FZ was published and entered force on July 26, 2026, amending Article 12 of Russia's Federal Law on Personal Data (152-FZ). The law removes all references to the Council of Europe Convention 108 from Russian data protection legislation, eliminating the presumption that European servers provide adequate protection for Russian personal data. Roskomnadzor now has explicit authorit

Source: Kremlin: Federal Law on Cross-Border Transfer of Personal DataLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

Asia-Pacific Regulators Push Back on Broad Data Localization

Singapore, Philippines, and Thailand privacy regulators speaking at a July 23 privacy forum called for targeted rather than broad data localization mandates, advocating interoperable transfer mechanisms, accountability frameworks, and privacy-enhancing technologies. The position contrasts with the EU's regulatory direction and reflects a deliberate policy choice by ASEAN members to compete for dat

Source: MLex: Singapore Philippines Thailand Caution Against Broad Data LocalizationLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

EU Abolishes De Minimis Exemption; Steel Quotas Cut 47%

EU Council Regulation 2026/382 abolished the €150 customs exemption for low-value shipments effective July 1, 2026, replacing it with a €3 flat customs duty per item category — a direct targeting of the Temu/Shein/AliExpress direct-shipping model. The EU simultaneously cut steel import quotas 47% (from ~33M to 18.3M tonnes), doubled penalty duties to 50% through 2031, and introduced "melt and pour

Source: Equity Edge Research: The Tariff Fortress — Decoding Europe's Trade StrategyTrade LawLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

Trump v. Slaughter: Supreme Court Eliminates FTC Independence — EU–US DPF Under Active Commission Review

On June 29, 2026, the U.S. Supreme Court ruled 6–3 in *Trump v. Slaughter* that the FTC's for-cause removal protection — which since *Humphrey's Executor* (1935) had prohibited presidents from removing commissioners without cause — is unconstitutional, and that officers exercising executive power must be removable by the president at will. The DPF adequacy decision (Commission Implementing Decisio

Source: DLA Piper Privacy Matters: US Supreme Court Overturns Humphrey's Executor — Implications for EU-US Data TransfersLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

UK–India CETA Digital Trade Chapter Enters Into Force — Data Localisation and Cross-Border Flow Rules Deferred

The UK–India Comprehensive Economic and Trade Agreement Chapter 12 on Digital Trade entered into force on July 15, 2026. The chapter reduces barriers to digital trade, supports legal recognition of electronic contracts and authentication, includes source code protections (firms cannot be required to transfer or disclose source code), and safeguards consumers against harmful commercial practices in

Source: UK Government: UK–India CETA Chapter 12: Digital TradeLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

EU Commission Opens Data Sovereignty Consultation — Cross-Border Access, Dependency, and Third-Country Risk Are the Focus

The European Commission opened a targeted consultation on safeguarding EU data sovereignty on July 8, 2026, running through September 8, 2026. The consultation covers four areas: data-related dependencies, barriers to accessing or using data in third countries, obstacles to transferring data back into the EU, and risks linked to third-country access to sensitive data. The exercise connects the Clo

Source: Techopia: Europe asks how sovereign its data really isLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

Supreme Court's Trump v. Slaughter Ruling Reopens Questions Over EU-US Data Privacy Framework

On June 29, 2026, the US Supreme Court issued Trump v. Slaughter, a separation-of-powers ruling holding that restrictions on presidential authority to remove executive officials — including at the Federal Trade Commission — are unconstitutional; while the opinion never mentions the GDPR or the Data Privacy Framework, privacy advocates including Max Schrems and noyb argue it undermines the FTC's in

Source: Shumaker: U.S. Supreme Court Decision Prompts New Questions About EU-U.S. Data TransfersLegal RiskGeopoliticsData Sovereignty
Geopolitics x Legal1 MIN READ

Irish Data Protection Commission Opens Inquiry Into EU-to-China Data Transfers

The Irish Data Protection Commission opened an inquiry this month into an online fashion retailer's transfers of EU and EEA personal data from its Irish entity to China, examining compliance with GDPR Article 5, Article 13, and Chapter V, with particular scrutiny on whether the arrangement guarantees protection "essentially equivalent" to EU standards. Separately, the Dutch data protection authori

Source: Gibson Dunn: Europe Data Protection – June 2026Legal RiskGeopoliticsData Sovereignty
Legal AI — Trans-Atlantic1 MIN READ

EU Converts AI Regulation Into Industrial Sovereignty Policy

A New Space Economy analysis published June 25 documents how the European Commission has fused AI regulation with industrial policy into a single strategic program. The combined framework now encompasses the AI Act, the AI Continent Action Plan, the Apply AI Strategy, the European Data Union Strategy, AI Factories, planned AI gigafactories, and the proposed Cloud and AI Development Act (CADA). The

Source: New Space Economy: How Is Europe's AI Strategy Turning Regulation into Industrial Policy?Legal AIGeopoliticsEU RegulationData Sovereignty
Legal AI — Trans-Atlantic1 MIN READ

Austria Urges Europe to Host Anthropic Following US AI Export Curbs

Austria formally urged European institutions this week to provide infrastructure and incentives to host Anthropic following U.S.-imposed restrictions on AI model exports and access. The move reflects a broader European anxiety, articulated sharply in a Euronews commentary published June 30: "America can switch off the world's AI. Europe must switch gears before it's too late." The commentary argue

Source: Euronews: America can switch off the world's AI. Europe must switch gears before it's too lateLegal AIGeopoliticsUK DevelopmentsData Sovereignty
Legal AI — Trans-Atlantic1 MIN READ

US-EU AI Partnership Sought on Regulation and Supply Chains — But Industrial Policy Diverges

Bloomberg reported June 25 that the US is actively seeking an AI partnership with the EU covering both regulatory alignment and supply chain coordination. The outreach comes as the two sides are moving in structurally different directions: the US toward federal preemption and a permissive innovation framework, the EU toward layered regulation combined with industrial sovereignty infrastructure. Th

Source: Bloomberg: US Seeks AI Partnership With EU on Regulation, Supply ChainsLegal AIGeopoliticsRegulatory DivergenceData Sovereignty
Legal AI — Trans-Atlantic1 MIN READ

GDPR-Compliant AI Is Not the Same as Sovereign AI — A Four-Condition Framework

An Eden AI analysis published June 25 draws a critical distinction that legal and compliance teams are frequently missing: data residency (servers in the EU) is not the same as data sovereignty (legal control over data). Four conditions must all be met for an AI deployment to qualify as genuinely sovereign: the provider must be incorporated in the EU; servers must be physically in the EU; API requ

Source: Eden AI: EU Data Residency vs Data Sovereignty — Why Most "GDPR-Compliant" AI Isn't SovereignLegal AIEU RegulationLegal OperationsData Sovereignty
Geopolitics x Legal1 MIN READ

EU Digital Omnibus Defers AI Act High-Risk Obligations to December 2027

The European Parliament on June 16 adopted its plenary position on the Digital Omnibus on AI, provisionally deferring the AI Act's Annex III high-risk AI system obligations from August 2, 2026 to December 2, 2027, and Annex I embedded systems to August 2, 2028. The deferral follows the political agreement reached on May 7 and is not yet formally adopted — formal Council adoption and Official Journ

Source: Acompli: European Parliament Advances Digital Omnibus on AI, Confirming DeferralsLegal RiskGeopoliticsData SovereigntyAI Regulation
Geopolitics x Legal1 MIN READ

EU Proposes Cloud and AI Development Act — Sovereign Cloud Framework with Four Assurance Levels

On June 3, the European Commission published the Cloud and AI Development Act (CADA), the centerpiece of its Technological Sovereignty Package. CADA introduces a four-level sovereignty assurance framework for cloud procurements by EU public authorities: Level 1 requires EU-hosted servers; Level 2 prohibits third-country data access or kill-switch authority; Level 3 requires the provider not be sub

Source: Lawfare: The EU Cloud and AI Development ActLegal RiskGeopoliticsData SovereigntyAI Regulation