Companies that create connected devices will have to fix cyber vulnerabilities as soon as they become aware of them under the EU Cyber Resilience Act, which was finalized during the trilogue process 30 Nov., Euractiv reports. The parties also agreed that nonprofit groups that sell open-source software and reinvest those funds into nonprofit activities would be excluded from certain documentation standards.
EU groups reach agreement on connected products law
Related stories
Notes from the IAPP Europe: Wrapping up November with the IAPP DPC
Ireland's DPC details legitimate interest prong of its LinkedIn enforcement action
What the new European Commission could mean for digital regulation
IAPP DPC 2024: Reynders discusses GDPR enforcement harmonization, adequacy developments
US Senate subcommittee ponders accountability for AI-assisted scams