On May 15, 2026, China’s National Medical Products Administration (“NMPA”) issued the Implementation Measures for Drug Trial Data Protection (the “Measures”), effective immediately, to formalize China’s protection regime for eligible undisclosed chemistry, manufacturing and control (CMC) and clinical study data submitted in marketing authorization applications. The Measures define the eligible products, protection periods, application process, publication mechanism, and restrictions on follow-on applications that rely on protected data.

Continue Reading China’s NMPA Issues Final Measures on Regulatory Data Protection

For almost a decade, the scientific research provisions of the General Data Protection Regulation (GDPR) have lacked authoritative, European Union (EU)-wide interpretation, leaving sponsors of clinical trials and research institutions alike to navigate a patchwork of national implementing laws. A 2019 study commissioned by the European Data Protection Board (EDPB) — the body comprising EU national data protection authorities — confirmed significant divergence among EU Member States, and interim guidance published in 2021 by the EDPB highlighted — but left unresolved — several key GDPR compliance issues facing organisations in the life sciences industry. In the years since, the COVID-19 pandemic and the United Kingdom’s post-Brexit departure from the EU framework have only sharpened the need for more specific guidance. Ropes & Gray attorneys co-authored an article published in Science magazine in October 2020 that provided a summary of the complexity in this space and potential solutions.

Continue Reading The European Data Protection Board Releases New Guidelines on the Processing of Personal Data for Scientific Research

On March 30, 2026, Governor Gavin Newsom signed Executive Order N-5-26 (the “Order”), directing California state agencies to develop new certification requirements and procurement standards for companies seeking to provide AI-enabled products or services to the state.1 The Order represents the latest move in an intensifying contest between California and the federal government over the future of AI regulation in the United States.

Continue Reading Newsom Signs Executive Order Establishing AI Vendor Certification and Procurement Framework

In 2024, financial sector regulators prioritized cybersecurity issues impacting financial institutions and the public. Key U.S. federal agencies—including the Securities and Exchange Commission, Federal Trade Commission, and the Consumer Financial Protection Bureau—have been joined by state regulators such as the New York Department of Financial Services in significant new federal and state regulations and more

On January 8, 2025, the Department of Justice (“DOJ”) published its Final Rule to implement President Biden’s Executive Order 14117, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern” (the “Final Rule”). This follows the DOJ’s publication of its Notice of Proposed Rulemaking (“NPRM”) in October 2024

Following the trend towards comprehensive state consumer data privacy laws over the past half decade, five more states—New Jersey, New Hampshire, Kentucky, Nebraska, and Maryland—have passed their own such laws since the beginning of this year alone. Joining the ranks of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia, these five states bring the total number of states with comprehensive state privacy laws to 17 (or 19, if you count more narrowly scoped privacy laws in Florida and Nevada), a near 50% increase in states with comprehensive privacy laws in only five months. New Jersey led the charge at the beginning of 2024, with Governor Phil Murphy signing the New Jersey Privacy Act (NJPA) on January 16. Next followed New Hampshire Governor Chris Sununu’s signature on SB 255 (acronym surely soon to follow). Kentucky (KCDPA) and Nebraska (NDPA) were next, signing laws on April 4 and 17, respectively, and Maryland rounded out this wave of privacy legislation when Governor Wes Moore signed the Maryland Online Data Privacy Act of 2024 (MODPA) into law on May 9.

Continue Reading Five State Privacy Laws in Five Months

On February 26, 2024, the National Institute of Standards and Technology (“NIST”) released version 2.0 of its Cybersecurity Framework (“CSF 2.0”)—the first significant update to the cybersecurity guidance since its initial publication a decade ago.[1] While the original guidance was tailored to critical infrastructure entities, the new version has a broader scope and applies to organizations of all sizes across industries, from large corporations with robust data protection infrastructure to small schools and nonprofits that may lack cybersecurity sophistication.[2] CSF 2.0 notably incorporates new sections on corporate governance responsibilities and supply chain risks; additionally, NIST has released supplemental implementation guides and reference tools that can assist organizations measure cybersecurity practices and hone data protection priorities.[3]

Continue Reading NIST Publishes Long-Awaited Cybersecurity Framework 2.0

Megan Baca moderated Ropes & Gray’s annual “From the Boardroom” panel – held in San Francisco during the 2024 J.P. Morgan Healthcare Conference – which this year looked at the role of artificial intelligence and big data in the context of dealmaking. It can feel hard to escape AI at the moment, with some debate as to whether AI is currently over-hyped or in fact at a transformational tipping point. 

Continue Reading Dealmaking with AI and Big Data – Charting the new frontier in life sciences