The Data Chronicles
Welcome to The Data Chronicles, hosted by partner Scott Loughlin, Co-Lead of the Hogan Lovells Cadwalader global Data, Privacy and Cybersecurity practice. This multimedia series is dedicated to the ever-changing legal and regulatory developments in the world of data, privacy, and cybersecurity. Join us as we unravel and unpack various regulatory frameworks and legal developments around the globe.
Welcome to The Data Chronicles, hosted by partner Scott Loughlin, Co-Lead of the Hogan Lovells Cadwalader global Data, Privacy and Cybersecurity practice. This multimedia series is dedicated to the ever-changing legal and regulatory developments in the world of data, privacy, and cybersecurity. Join us as we unravel and unpack various regulatory frameworks and legal developments around the globe.
Listen on:
Episodes
23 minutes ago
Digital integration: Where data strategy meets antitrust
23 minutes ago
23 minutes ago
44 min
As data becomes an increasingly valuable business asset, organizations must navigate the growing intersection between data strategy and antitrust and competition law. In this episode of The Data Chronicles, Scott Loughlin sits down with Hogan Lovells Cadwalader counsel Bilal Sayyed, who advises a variety of clients on antitrust and competition matters, to explore how competition authorities are thinking about data in a digital economy where access to information can shape market outcomes.
They discuss when companies can limit access to data, why control of a valuable dataset does not necessarily create market power, and how regulators evaluate issues such as interoperability, exclusivity arrangements, and platform design. The conversation also examines how antitrust authorities assess mergers involving data assets, including whether combining datasets or acquiring critical data suppliers could affect innovation, competition, and future market entry.
Ultimately, Scott and Bilal highlight that antitrust questions are rarely about data alone. Instead, these questions tend to focus on whether companies are competing by building better products and creating value for customers or using control over data to make it more challenging for rivals. As regulators continue to scrutinize digital markets and AI-driven businesses, organizations must understand how their data strategies fit within an evolving regulatory and competition landscape.
23 minutes ago
44 min
Aug 20, 2026
Regulating Artificial Intelligence in APAC
Aug 20, 2026
Aug 20, 2026
22 min
APAC Spotlight is a podcast from the Hogan Lovells Cadwalader APAC Data, Privacy and Cybersecurity team, led by Charmian Aw, exploring the key developments shaping the region's fast-evolving digital regulatory landscape.
In this second episode of the series, Charmian Aw speaks to Hogan Lovells Cadwalader associate Ciara O’Leary – to tackle one of the biggest issues facing businesses today: AI regulation across APAC. While the EU AI Act has dominated headlines, jurisdictions across Asia-Pacific are taking very different approaches, ranging from China's extensive AI rules and South Korea's AI Basic Act to Singapore's voluntary governance frameworks and emerging laws in Vietnam and Thailand.
Charmian and Ciara bust common myths about AI regulation, explore the growing role of national security, data protection, and sector-specific rules, and discuss why EU AI Act compliance alone may not be enough for organizations operating across the region. They also share practical perspectives on navigating APAC's fragmented regulatory landscape as AI regulation continues to accelerate.
The key takeaway? There is no one-size-fits-all approach to AI compliance in APAC. Organizations should build a strong governance foundation but be ready to adapt to local requirements as the regulatory landscape evolves.
Tune in to hear what businesses, legal teams and technology professionals need to know about the future of AI regulation in Asia-Pacific.
Aug 20, 2026
22 min
Aug 13, 2026
Aug 13, 2026
36 min
AI is no longer just a legal technology or governance issue – it is increasingly an organizational transformation challenge. In this episode of The Data Chronicles, we sit down with Avi Goldfarb, the Rotman Chair in Artificial Intelligence and Healthcare at the University of Toronto and co-author of Prediction Machines and Power and Prediction, to examine why widespread AI pilots, strategies, deployed tools, and leadership attention have not yet produced the deeper business change many organizations expected.
We explore why simply giving teams access to AI tools is not the same as redesigning how a business works, how AI can shift decision-making power among employees, leaders, and vendors, and why organizations must decide what they value before letting external systems define success for them. Ultimately, the conversation reframes AI not as a machine that makes decisions for us, but as a powerful information technology whose transformative value depends on human judgment, clear KPIs, CEO-level commitment, and a deliberate understanding of what the organization is trying to accomplish.
Aug 13, 2026
36 min
Jul 21, 2026
APAC Spotlight
Jul 21, 2026
Jul 21, 2026
33 min
APAC Spotlight is a podcast from the Hogan Lovells Cadwalader APAC Data, Privacy and Cybersecurity team, led by Charmian Aw, exploring the key developments shaping the region’s fast-evolving digital regulatory landscape.
In our first episode, we tackle cross-border data transfers and data localisation. Data and businesses are increasingly global, but regulations are not.
We bust common myths, explore why organizations should look beyond China when assessing regulatory risk, and discuss how geopolitics, national security and AI are reshaping the rules around data. We also share practical perspectives on navigating APAC’s fragmented regulatory landscape without building a separate compliance programme for every jurisdiction.
The key takeaway? Think globally, localise selectively.
Tune in to find out what businesses, legal teams and privacy professionals need to know as APAC’s data regulatory landscape continues to evolve.
Jul 21, 2026
33 min
Jun 11, 2026
Jun 11, 2026
41 min
AI regulation in the United States is at an inflection point. A new executive order, emerging legislation, and shifting political dynamics are rapidly reshaping the policy landscape for AI developers and adopters.
In this episode of The Data Chronicles, we examine the administration’s latest executive order on AI innovation and security, which introduces a voluntary framework for pre-release review of frontier AI models – an approach some compared to FDA-style oversight. We also explore how it differs from prior safety-focused directives and more aggressive regulatory models abroad.
The discussion highlights what this moment means for companies across the ecosystem, from major tech firms helping shape policy to startups navigating commercialization. At the core is a key tension: policymakers are unusually open to new ideas but the window to influence these frameworks may be narrower than it appears.
Jun 11, 2026
41 min
Jun 1, 2026
2026 State legislative updates
Jun 1, 2026
Jun 1, 2026
23 min
State-level data regulation in the United States is accelerating, with a growing patchwork of laws reshaping how organizations approach privacy, artificial intelligence, and online safety.
In this episode of The Data Chronicles, we provide a 2026 legislative wrap-up, examining how new comprehensive privacy laws in states like Oklahoma and Alabama, alongside emerging frameworks in Louisiana, are reinforcing a largely harmonized – but still fragmented – compliance landscape.
The discussion explores how AI regulation is diverging more significantly, with states such as Colorado and Connecticut shifting toward targeted, risk-based approaches focused on automated decision-making and employment use cases, while broader concerns around AI chatbots and workforce integration continue to draw legislative attention. We also unpack the rapid evolution of online safety and children’s protections, including the expansion of age-appropriate design codes, age verification requirements, and ongoing constitutional challenges.
Across all three areas, the episode highlights the practical implications of increased regulatory overlap, evolving enforcement dynamics, and the growing need for organizations to monitor state-level developments closely – particularly as lawmakers continue to experiment with technology-driven solutions and push toward more granular oversight of data-driven systems.
Jun 1, 2026
23 min
May 4, 2026
UK Data protection reform explained
May 4, 2026
May 4, 2026
41 min
Data protection in the United Kingdom is entering a new phase of post‑Brexit divergence, introducing targeted but impactful changes across regulatory governance, enforcement, and day‑to‑day compliance.
In this episode of The Data Chronicles, we examine how the Data (Use and Access) Act 2025 is reshaping UK data protection through reforms to the ICO’s structure, new approaches to cookies, automated decision‑making, international data transfers, and lawful bases for processing.
The discussion explores how increased flexibility in the United Kingdom is paired with heightened enforcement risk, why operating across United Kingdom and European Union regimes is becoming more complex for global organizations, and how data protection is increasingly being reframed as both a legal compliance and economic policy tool – demanding closer coordination between legal, product, and operational teams.
May 4, 2026
41 min
Apr 16, 2026
Cyber developments in the EU and UK
Apr 16, 2026
Apr 16, 2026
41 min
Cybersecurity regulation in Europe has entered a period of rapid expansion and fragmentation, moving well beyond traditional data protection into a complex framework governing enterprise security, product security, sector specific obligations, and supply chain risk.
In this episode of The Data Chronicles, we examine how evolving regimes such as NIS2, the Cyber Resilience Act, DORA, and proposed reforms to the EU Cybersecurity Act are reshaping legal and operational expectations for organizations operating across borders.
The discussion explores why global “one size fits all” security programs and reliance on baseline standards like ISO and NIST are no longer sufficient on their own, how post Brexit divergence between the EU and U.K. is creating material compliance challenges, and why cybersecurity has shifted from a best practice exercise to enforceable law – requiring tighter integration between legal, IT, and information security teams to execute compliance at scale.
Apr 16, 2026
41 min
Apr 2, 2026
AI disputes and enforcement in the U.S.
Apr 2, 2026
Apr 2, 2026
33 min
AI enforcement in the United States is emerging through legacy laws, creative pleading theories, and increasing regulatory scrutiny rather than a single statute or regulator.
In this episode of The Data Chronicles, we examine how AI-related risk materializes once it moves into litigation and enforcement — from copyright and privacy class actions to consumer protection claims, product liability, and employment disputes — and why unsettled standards of care, evolving case law, and regulator focus areas are driving uncertainty for companies deploying AI systems.
Apr 2, 2026
33 min
Mar 26, 2026
DOJ’s Cybersecurity Fraud Initiative
Mar 26, 2026
Mar 26, 2026
28 min
Cybersecurity enforcement is entering a new phase – one where technical failures are increasingly reframed as fraud risk.
This episode of The Data Chronicles explores how the U.S. Department of Justice is using the False Claims Act to pursue alleged misrepresentations about cybersecurity controls, compliance, and incident disclosure in government contracts and grants.
We examine emerging enforcement patterns, practical risk signals for contractors, and what organizations should be doing now to reduce exposure, with further insights available in our 2026 False Claims Act Guide.
Mar 26, 2026
28 min
Mar 5, 2026
Mar 5, 2026
49 min
AI regulatory enforcement is accelerating – often under laws that were conceived well before the unstoppable emergence of AI. This episode of The Data Chronicles examines how regulators and courts across Europe and beyond are applying existing frameworks, from the GDPR to consumer and competition law, to AI development and deployment.
We explore emerging enforcement patterns, including scrutiny of AI training data, transparency obligations, data subject rights, and the growing use of urgent regulatory measures. The discussion also looks ahead to how enforcement may evolve as AI-specific regulation advances, and what these developments signal for organizations operating globally.
Mar 5, 2026
49 min
Jan 29, 2026
Jan 29, 2026
36 min
AI and intellectual property are evolving fast – and creating real uncertainty for companies building with or around AI.
This episode of The Data Chronicles breaks down the key IP claims emerging today, from copyright and DMCA theories to right of publicity, trademark, and output based risks.
We look at how early court decisions are treating AI training and outputs, why plaintiffs are pivoting toward DMCA and misattribution claims, and where regulators like the FTC may (and may not) step in.
We close with a practical checklist for organizations using or developing AI, as the landscape continues to shift.
Jan 29, 2026
36 min
Jan 15, 2026
Jan 15, 2026
26 min
Data brokers sit at the center of a fast-shifting legal landscape.
This episode of The Data Chronicles breaks down the expanding patchwork of state data broker laws, from registration and public listings to how these obligations interact with broader privacy requirements. It also looks at the stigma tied to the “data broker” label, how regulators and plaintiffs’ lawyers are using registration data to target scrutiny, and the added federal pressure created by PADFA and the DOJ’s Data Security Program.
The discussion closes with a practical checklist for companies that license or share data, including how to identify if you may be a data broker, where exemptions could apply, and what steps help reduce registration and enforcement risk.
Jan 15, 2026
26 min
Dec 18, 2025
2025 wrapped and 2026 predictions
Dec 18, 2025
Dec 18, 2025
48 min
In our annual “Look Back, Look Forward” edition of The Data Chronicles, Scott Loughlin and Eduardo Ustaran, co-leads of Hogan Lovells’ Global Data, Privacy and Cybersecurity practice, reflect on the most important developments in privacy, cybersecurity, and data regulation in 2025 and share their outlook for 2026. It has become the most popular episode of the year, drawing strong interest from listeners across regions and sectors.
The conversation covers the global impact of artificial intelligence, evolving regulatory priorities in the UK, EU, and US, and the ongoing balance between innovation and regulation. Topics include potential GDPR reform, biometrics and age verification, geopolitics and data protection, international data transfers, and the growing focus on AI governance and children’s data.
Dec 18, 2025
48 min
Dec 11, 2025
Dec 11, 2025
38 min
What can businesses expect from the U.S. Federal Trade Commission on privacy and data enforcement as we move into 2026? In this episode of The Data Chronicles, host Scott Loughlin is joined by Cobun Zweifel-Keegan, Managing Director at the IAPP, for a practical year-end review of the FTC’s 2025 enforcement priorities and what they signal for the year ahead.
Together, Scott and Cobun break down how a change in administration reshaped the agency’s focus this year, with heightened attention on children’s and teens’ privacy, COPPA enforcement, cross-platform data collection, and growing concerns around the sale of Americans’ sensitive information to foreign adversary countries. They also discuss the FTC’s evolving view of privacy as both a consumer protection and national security issue.
The conversation also covers the operational and strategic impact of the FTC operating with only two sitting commissioners, and how today’s enforcement posture compares with the more aggressive approach under the prior administration.
Dec 11, 2025
38 min
Dec 4, 2025
India’s DPDPA brought into force
Dec 4, 2025
Dec 4, 2025
40 min
India has taken a major step in reshaping its digital future. After years of drafts and debate, the country has finalized the Digital Personal Data Protection Act (DPDPA) and issued detailed rules that bring the law fully to life. With implementation now scheduled over the next 18 months, organizations have clear timelines and a more definitive view of the significant compliance work ahead.
In this episode, host Scott Loughlin is joined by Stephen Mathias, partner and head of the Bangalore office at Kochhar & Company, and Hogan Lovells partner Charmian Aw, who leads the Hogan Lovells APAC Data, Privacy and Cybersecurity practice. Together, they discuss the core features of India’s new law, including its consent-based framework, extraterritorial reach, and parallels with the EU GDPR.
The conversation covers the key steps companies should be taking now, from redesigning data architecture and consent flows to assessing breach response readiness. The episode also explores global business implications, enforcement expectations, and how the DPDPA fits into the broader regional privacy landscape.
Whether you’re operating in India or serving customers there, this discussion offers practical insights on what’s changing, why it matters, and how to prepare.
Dec 4, 2025
40 min
Nov 20, 2025
Nov 20, 2025
41 min
The U.S. Department of Justice’s Data Security Program is reshaping how companies manage cross-border data activities. This episode of The Data Chronicles breaks down what the rule does, why it was created, and the types of transactions it restricts or prohibits—from data brokerage to vendor access to bulk genomic data.
Host Scott Loughlin is joined by Hogan Lovells partner James Denvil and associate Lorea Mendiguren to walk through the rule’s core elements and the open questions around implementation, risk, and compliance. They share practical insights from advising companies in e-commerce, health, and life sciences as they adjust to this new national-security-driven framework.
Nov 20, 2025
41 min
Nov 13, 2025
Checking in on APAC | Regulating for innovation
Nov 13, 2025
Nov 13, 2025
49 min
In this episode of The Data Chronicles, host Scott Loughlin is joined by Hogan Lovells partners Eduardo Ustaran and Charmian Aw to examine how regulators are rethinking the relationship between AI, innovation, and privacy. They discuss why many regulators view data protection rules not as obstacles, but as guardrails that can support responsible AI development through tools like impact assessments, transparency, and data minimization.
Eduardo shares insights from the Global Privacy Assembly, which brought together more than 140 data protection authorities from over 90 countries for regulator-led discussions on AI in daily life, cross-border data transfers, children’s privacy, privacy-enhancing technologies, and other issues shaping global enforcement trends. Charmian, who leads the firm’s Asia-Pacific Data, Privacy and Cybersecurity team, adds an APAC perspective with takeaways from the Global Cross-Border Privacy Rules Forum and the region’s growing push for interoperability in data transfers and enforcement cooperation.
We also highlight the launch of our Asia Pacific Privacy Legislation Tracker, a new tool that compares privacy requirements across APAC jurisdictions designed to support companies in navigating the region’s evolving data protection landscape.
Nov 13, 2025
49 min
Nov 4, 2025
How states are shaping AI legislation
Nov 4, 2025
Nov 4, 2025
38 min
How are U.S. states shaping the future of artificial intelligence? In this episode of The Data Chronicles, we unpack The State of State AI, the latest report from the Future of Privacy Forum (FPF) analyzing more than 200 AI-related bills introduced across 42 states.
Host Scott Loughlin is joined by Justine Gluck, a policy analyst at FPF, to discuss how lawmakers are shifting toward targeted, transparency-driven regulation, focusing on areas such as healthcare, chatbot use, liability frameworks, and innovation sandboxes, rather than pursuing a single sweeping national approach. Together, they explore how these trends signal where AI policymaking is headed and what it means for developers, deployers, and consumers.
Nov 4, 2025
38 min
Oct 27, 2025
Oct 27, 2025
43 min
In this episode of The Data Chronicles, host Scott Loughlin welcomes Adam Smith, Regulatory Lead – Cybersecurity at Southwest Airlines, to explore the evolving landscape of cybersecurity in the transportation sector.
Together, they fly through the real-world stakes of protecting critical infrastructure – from airports and railways to the systems that underpin national security. The conversation unpacks the complexity of regulatory frameworks, the challenges of incident response, and the vital role of collaboration among regulators, operators, and vendors.
Oct 27, 2025
43 min


