{"id":19493,"date":"2025-12-05T06:37:00","date_gmt":"2025-12-05T06:37:00","guid":{"rendered":"https:\/\/sawahsolutions.com\/alpha\/eu-proposes-digital-omnibus-regulation-as-uk-china-and-india-tighten-data-security-laws-in-2025\/"},"modified":"2025-12-05T06:45:45","modified_gmt":"2025-12-05T06:45:45","slug":"eu-proposes-digital-omnibus-regulation-as-uk-china-and-india-tighten-data-security-laws-in-2025","status":"publish","type":"post","link":"https:\/\/sawahsolutions.com\/alpha\/eu-proposes-digital-omnibus-regulation-as-uk-china-and-india-tighten-data-security-laws-in-2025\/","title":{"rendered":"EU proposes Digital Omnibus Regulation as UK, China, and India tighten data security laws in 2025"},"content":{"rendered":"<p><\/p>\n<div>\n<p>The European Commission&#8217;s Digital Omnibus Regulation proposal and recent national law updates in the UK, China, and India mark significant shifts in data law compliance for organisations in 2025, requiring renewed focus on cross-border risks and incident reporting.<\/p>\n<\/div>\n<div>\n<p>Welcome to the final edition of the Stephenson Harwood data protection update for 2025, which reviews the principal regulatory, cyber security and enforcement developments from November and highlights what organisations should prioritise as we move into 2026. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><\/p>\n<p>The European Commission published its Digital Omnibus Regulation proposal on 19 November 2025, a package of amendments aimed at simplifying and aligning the GDPR, the ePrivacy Directive, the AI Act, the Data Act, the Data Governance Act and NIS2 to reduce complexity while seeking to preserve high standards. Industry and legal observers should monitor fast-moving trilogue negotiations and consider the potential impact of proposed changes on data processing, AI compliance and cross-border data flows. According to the Commission\u2019s announcement, some deadlines for high\u2011risk AI measures have also been floated for later implementation to give stakeholders more time to prepare. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal\">[2]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/eu-delay-high-risk-ai-rules-until-2027-after-big-tech-pushback-2025-11-19\/\">[5]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/big-tech-may-win-reprieve-eu-mulls-easing-ai-rules-document-shows-2025-11-07\/\">[7]<\/a><\/sup><\/p>\n<p>In the UK, the Department for Science, Innovation and Technology introduced the Cyber Security and Resilience (Network and Information Systems) Bill to Parliament on 12 November 2025, updating the NIS Regulations to broaden scope, impose new duties on regulated entities, mandate incident reporting and strengthen regulator enforcement powers and fines. The Bill is intended to bring a wider range of digital services and critical suppliers within the framework and to raise obligations for resilience and recovery. Stakeholders should review the government factsheets and prepare for expanded compliance and reporting requirements. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.gov.uk\/government\/collections\/cyber-security-and-resilience-bill\">[3]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.gov.uk\/government\/publications\/cyber-security-and-resilience-network-and-information-systems-bill-factsheets\">[4]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/world\/uk\/uk-plans-tougher-laws-protect-public-services-from-cyberattacks-2025-11-12\/\">[6]<\/a><\/sup><\/p>\n<p>China tightened its cyber security regime in two phases: the Measures for the Administration of National Cybersecurity Incident Reporting, effective 1 November 2025, which sets out cross\u2011sector incident reporting obligations (including very short reporting windows for critical infrastructure), and an amended Cybersecurity Law, effective 1 January 2026, which increases penalties, extends extra\u2011territorial reach and strengthens data localisation and cross\u2011border assessment requirements. Businesses with operations or data processing in China should reassess localisation, incident response and documentation practices. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><\/p>\n<p>The UK\u2019s Data (Use and Access) Act 2025 continued its phased implementation in November, with sections on joint law\u2011enforcement processing and intelligence services coming into force on 17 November and most digital verification services provisions commencing from 1 December 2025 (subject to limited exceptions). Organisations should consult the DUAA implementation timeline and update policies ahead of the anticipated wave of further amendments due in early January 2026. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><\/p>\n<p>India finalised rules to operationalise the Digital Personal Data Protection Act 2023 when it notified the Digital Personal Data Protection Rules 2025 on 13 November 2025, establishing the Data Protection Board and setting a phased timetable for core obligations. Key features include the introduction of registered \u201cconsent managers\u201d, mandatory security safeguards, a two\u2011stage breach reporting framework with detailed follow\u2011up within 72 hours, parental\u2011consent regimes for children\u2019s data, obligations for Significant Data Fiduciaries and substantial fines for serious breaches. Organisations offering goods or services to individuals in India should map flows, assess SDF exposure and prepare for progressive compliance milestones through to May 2027. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><\/p>\n<p>In enforcement and litigation, the European Court of Justice held on 13 November 2025 in Inteligo Media v ANSPDCP that the ePrivacy Directive governs the use of email addresses for direct marketing and can take precedence over the GDPR in that context, reinforcing the scope of the ePrivacy \u201csoft opt\u2011in\u201d for certain freemium models while cautioning that the ruling should be read narrowly. Separately, the FCA secured a prosecution under section 170(1) of the Data Protection Act 2018 after a former employee unlawfully sold customer data that enabled a crypto boiler\u2011room fraud; the FCA said the defendant \u201cabused his position of trust\u201d and stressed it will use its powers to tackle misuse of personal data that facilitates financial crime. These developments underscore that both data protection and financial regulators are sharpening enforcement tools where data misuse enables harm. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><\/p>\n<p>Taken together, November\u2019s measures , from the Digital Omnibus proposals and the ECJ clarifications to national laws and incident reporting regimes in China, India and the UK , emphasise three immediate priorities for organisations: (1) map and minimise cross\u2011border transfer and localisation risks; (2) strengthen incident detection, reporting and record\u2011keeping to meet tightened timelines; and (3) reassess marketing and consent practices in light of evolving ePrivacy\/GDPR interaction and regional law changes. Legal teams and compliance functions should treat the coming months as a period to convert strategic planning into operational controls. <sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal\">[2]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.gov.uk\/government\/collections\/cyber-security-and-resilience-bill\">[3]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/eu-delay-high-risk-ai-rules-until-2027-after-big-tech-pushback-2025-11-19\/\">[5]<\/a><\/sup><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/world\/uk\/uk-plans-tougher-laws-protect-public-services-from-cyberattacks-2025-11-12\/\">[6]<\/a><\/sup><\/p>\n<h3>\ud83d\udccc Reference Map:<\/h3>\n<p>##Reference Map:<\/p>\n<ul>\n<li><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.stephensonharwood.com\/insights\/data-protection-update-november-2025\/\">[1]<\/a><\/sup> (Stephenson Harwood) &#8211; Paragraph 1, Paragraph 2, Paragraph 4, Paragraph 5, Paragraph 6, Paragraph 7, Paragraph 8<\/li>\n<li><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal\">[2]<\/a><\/sup> (European Commission) &#8211; Paragraph 2, Paragraph 8<\/li>\n<li><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.gov.uk\/government\/collections\/cyber-security-and-resilience-bill\">[3]<\/a><\/sup> (UK Government) &#8211; Paragraph 3, Paragraph 8<\/li>\n<li><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.gov.uk\/government\/publications\/cyber-security-and-resilience-network-and-information-systems-bill-factsheets\">[4]<\/a><\/sup> (UK Government factsheets) &#8211; Paragraph 3<\/li>\n<li><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/eu-delay-high-risk-ai-rules-until-2027-after-big-tech-pushback-2025-11-19\/\">[5]<\/a><\/sup> (Reuters) &#8211; Paragraph 2, Paragraph 8<\/li>\n<li><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/world\/uk\/uk-plans-tougher-laws-protect-public-services-from-cyberattacks-2025-11-12\/\">[6]<\/a><\/sup> (Reuters) &#8211; Paragraph 3, Paragraph 8<\/li>\n<li><sup><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/big-tech-may-win-reprieve-eu-mulls-easing-ai-rules-document-shows-2025-11-07\/\">[7]<\/a><\/sup> (Reuters) &#8211; Paragraph 2<\/li>\n<\/ul>\n<p>Source: <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.noahwire.com\">Noah Wire Services<\/a><\/p>\n<\/p><\/div>\n<div>\n<h3 class=\"mt-0\">Noah Fact Check Pro<\/h3>\n<p class=\"text-sm\">The draft above was created using the information available at the time the story first<br \/>\n        emerged. We\u2019ve since applied our fact-checking process to the final narrative, based on the criteria listed<br \/>\n        below. The results are intended to help you assess the credibility of the piece and highlight any areas that may<br \/>\n        warrant further investigation.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Freshness check<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>10<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n        <\/span>The narrative is current, published on 4 December 2025, covering developments up to November 2025. The Digital Omnibus Regulation proposal was published on 19 November 2025, and the Cyber Security and Resilience Bill was introduced to Parliament on 12 November 2025. ([digital-strategy.ec.europa.eu](https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal?utm_source=openai)) No evidence of recycled or outdated content was found.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Quotes check<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>10<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n        <\/span>The narrative does not contain any direct quotes, indicating original content.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Source reliability<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>10<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n        <\/span>The narrative originates from Stephenson Harwood, a reputable international law firm, enhancing its credibility.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Plausability check<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>10<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n    <\/span>The claims are consistent with other reputable sources. The Digital Omnibus Regulation proposal and the Cyber Security and Resilience Bill are well-documented in official publications. ([digital-strategy.ec.europa.eu](https:\/\/digital-strategy.ec.europa.eu\/en\/library\/digital-omnibus-regulation-proposal?utm_source=openai)) The narrative maintains a formal and professional tone appropriate for its subject matter.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Overall assessment<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Verdict<\/span> (FAIL, OPEN, PASS): <span class=\"font-bold\">PASS<\/span><\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Confidence<\/span> (LOW, MEDIUM, HIGH): <span class=\"font-bold\">HIGH<\/span><\/p>\n<p class=\"text-sm mb-3 pt-0\"><span class=\"font-bold\">Summary:<br \/>\n        <\/span>The narrative is current, original, and originates from a reputable source. All claims are consistent with other reputable sources, and the tone is appropriate for the subject matter.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The European Commission&#8217;s Digital Omnibus Regulation proposal and recent national law updates in the UK, China, and India mark significant shifts in data law compliance for organisations in 2025, requiring renewed focus on cross-border risks and incident reporting. Welcome to the final edition of the Stephenson Harwood data protection update for 2025, which reviews the<\/p>\n","protected":false},"author":1,"featured_media":19494,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[40],"tags":[],"class_list":{"0":"post-19493","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-london-news"},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/posts\/19493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/comments?post=19493"}],"version-history":[{"count":1,"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/posts\/19493\/revisions"}],"predecessor-version":[{"id":19495,"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/posts\/19493\/revisions\/19495"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/media\/19494"}],"wp:attachment":[{"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/media?parent=19493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/categories?post=19493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sawahsolutions.com\/alpha\/wp-json\/wp\/v2\/tags?post=19493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}