UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP
indicated that the Growth Plan will inform its refresh of the National Cyber Strategy, announced in May 2025. 1.2 Cybersecurity Laws The UK has a well-developed – and growing – network of civil and criminal laws relating to cybersecurity con - tained in UK legislation, companion rules made under such legislation, decisions of UK courts, and a steady stream of regulatory guidance from UK regulators. Key cybersecurity requirements imposed on organi - sations in the UK, or on organisations that are estab - lished outside the UK but are processing personal data of individuals located in the UK, are derived from the UK General Data Protection Regulation (the “UK GDPR”), as supplemented by the UK Data Protection Act 2018, as amended (DPA). The UK GDPR applies to the security of “personal data” (ie, any information relating to an identified or identifiable individual who can be identified – directly or indirectly – by reference to an identifier such as a name, an identification number, location data or an online identifier). As such, only cybersecurity inci - dents that impact personal data will be regulated by the UK GDPR (see also 6.1 Cybersecurity and Data Protection ). The UK GDPR requires organisations to maintain “appropriate” technical and organisational security measures and to comply with certain notifica - tion obligations when “personal data breaches” occur. The DPA also allows for criminal prosecutions to be brought for certain cybersecurity-related breaches. Secondly, the NIS Regulations currently apply to two categories of key infrastructure operators – namely, “operators of essential services” (OESs) and “relevant digital service providers” (RDSPs). Like the UK GDPR, the NIS Regulations require organisations subject to them to implement certain cybersecurity measures and to report certain cybersecurity incidents that affect them. On 12 November 2025, the UK govern - ment introduced the CS&R Bill, which would expand the remit of the NIS Regulations to protect more digital services and supply chains. Please see 2.1 Scope of Critical Infrastructure Cybersecurity Regulation for additional information on these proposed updates.
Thirdly, the Product Security and Telecommunications Infrastructure Act 2022 (the “PSTI Act”), which came into force on 29 April 2024, requires manufacturers, importers and distributors of UK consumer-connect - ed products to meet certain cybersecurity standards. This includes more stringent security requirements (eg, default password requirements and minimum support periods for security updates), requirements to investigate any compliance failures and take reme - diation action, and to notify relevant authorities and other third parties about such compliance failures (see 4.2 Key Obligations Under Legislation ). Fourthly, the Computer Misuse Act 1990 (CMA) is the UK’s primary legislation for criminalising unauthor - ised access to computers and other IT systems. It contains a number of cybersecurity-related offences. A key offence under the CMA (Section 1) is where a defendant obtains “unauthorised access” to a com - puter – ie, the defendant causes a computer “to per - form any function with intent to secure access to any program or data held in any computer” or “to enable such access to be secured” where such access is “unauthorised” and this is known to the defendant at the relevant time. Fifthly, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended) (the “PECR”), the EU Notification Regulations 611/2013, and the Communications Act 2003 (the “CA 2003”) contain cybersecurity obligations applicable primarily to electronic communications networks and service operations (such as telecommunications systems operators). There are also sector-specific laws that contain cyber - security obligations, such as: • Financial Conduct Authority (FCA) rules (applicable to FCA-regulated firms); • the Payment Services Regulations 2017 (PSRs) (which transposed the Second EU Payment Servic - es Directive into English law and apply to payment service providers); and • the Official Secrets Act 1989 (OSA) (which is appli - cable to certain official government information).
443 CHAMBERS.COM
Powered by FlippingBook