Since 12 September 2025, the EU Data Act (Regulation (EU) 2023/2854, the “EU Data Act”) has required manufacturers of connected products and providers of related services to make in-scope data accessible to users, whether through direct or indirect access mechanisms. On 12 September 2026, a further dimension of that obligation becomes applicable: new connected products and related services placed on the EU market after that date must be designed with direct access capabilities built in by default, where relevant and technically feasible. Because the obligation to provide direct access is explicitly not absolute, manufacturers that already offer users indirect access through a portal or account may find that the practical change is limited.

The September 2026 date is nonetheless a valuable opportunity for companies, including those in the life sciences sector, to review their compliance position: not only on access by design, but across the broader set of EU Data Act obligations that have been applicable for almost a year and are now increasingly attracting scrutiny from marketplaces, customers, and emerging national enforcement bodies.

Continue Reading The EU Data Act’s Access-by-Design Deadline: What Life Sciences Companies Need to Know Before September 2026

Welcome to the latest installment of Arnold & Porter’s Virtual and Digital Health digest. This digest covers key virtual and digital health regulatory and public policy developments during June and early July 2026 from the United Kingdom and European Union.

AI continues to be at the top of the agenda for regulators in Europe. The European Commission (EC) has been focused on preparing for the majority of the provisions in the AI Act to come into force this August. Among those provisions are the transparency requirements, and to assist organizations with compliance, the EC has published a voluntary Code of Practice on the marking and labeling of AI-generated content. Further, a Scientific Panel and an Advisory Forum have been appointed to advise the EC’s AI Office and national competent authorities on implementation and enforcement of the AI Act.

In the UK, we are seeing a continued commitment to regulating AI through guidance and codes of practice, as well as the provision of regulatory support through sandbox programs. The Information Commissioner’s Office (ICO), the data protection regulator, has published its plan for upcoming work in relation to AI, which sets out various plans for guidance and codes of practice. The Medicines and Healthcare products Regulatory Agency (MHRA) continues its focus on regulatory sandboxes and recently reported the outcome of the second phase of the AI Airlock. It has also announced further AI sandboxes in order to accelerate the development of medicines and to allow innovators to test AI tools that have the potential to predict how medicines behave in the body, and another, which will be London-focused.

The key legislative development this month is that the EU Council has adopted its position on the first part of the Biotech Act, which, together with the European Commission’s draft, will form the basis of the trilogue discussions between the European Union (EU) institutions, hopefully leading to agreement on a finalized text. 

Continue Reading Virtual and Digital Health Digest – July 2026

Welcome to the latest installment of Arnold & Porter’s Virtual and Digital Health Digest. This digest covers key virtual and digital health regulatory and public policy developments during May and early June 2026 from the United Kingdom and European Union.

May 2026 saw continued momentum across the European Union (EU) and United Kingdom (UK) toward modernizing and streamlining the regulatory landscape for digital health, with a particular focus on accommodating AI-enabled technologies while reducing unnecessary complexity. A central development was the provisional agreement on the Digital Omnibus package, which seeks to simplify the application of the EU AI Act by clarifying overlaps with sector-specific legislation, deferring key obligations, and introducing more proportionate requirements.

In parallel, regulators on both sides of the Channel are advancing reforms to ensure that medical device frameworks remain fit for purpose in an increasingly software-driven and data-centric environment. In the EU, the activation of key European Database on Medical Devices (EUDAMED) modules marks a major step toward enhanced transparency and traceability, while ongoing discussions on the Medical Devices Regulation 2017/745 (MDR)/In Vitro Diagnostic Regulation 2017/746 (IVDR) revisions highlight a strong policy drive toward simplification and better integration of AI. In the UK, the Medicines and Healthcare products Regulatory Agency’s (MHRA) proposed pre-market reforms and broader thinking on AI regulation signal a shift toward more flexible, lifecycle-based oversight, with greater emphasis on post-market monitoring and innovation support.

Data governance and cybersecurity also remain high on the agenda. Industry and regulators alike are emphasizing the need for coherent, proportionate frameworks that avoid duplication while enabling innovation, particularly in light of expanding AI use cases and global supply chains. Together, these developments reflect a broader trend toward risk-based, innovation-friendly regulation, coupled with increasing expectations around transparency, accountability, and data protection in digital health.

Continue Reading Virtual and Digital Health Digest – June 2026

On 19 March 2026, the Court of Justice of the European Union (CJEU or Court) issued its judgment in Case C-526/24, Brillen Rottler GmbH & Co. KG v TC. The case concerned a data subject who subscribed to a German optician’s newsletter and, thirteen days later, submitted an access request under Article 15 GDPR. The company refused the request, arguing it was abusive. The data subject maintained it was legitimate and claimed at least €1.000 in non-material damages.

The CJEU’s judgment addresses three questions of broad significance: (1) when a first access request can be refused as “excessive”; (2) whether a violation of the right of access alone can give rise to a compensation claim under Article 82 GDPR; and (3) how non-material damage should be assessed in that context. While the judgment is relevant to all companies subject tot GDPR, we examine below the considerations it raises for life sciences companies specifically.

Continue Reading CJEU rules on GDPR access rights and abuse of rights: what the Brillen Rottler judgment means for life sciences companies

On 16 December 2025, the European Commission published its Proposal for a Regulation establishing a framework of measures for strengthening the EU’s biotechnology and biomanufacturing sectors, particularly in the area of health (the “European Biotech Act” or the “Proposal”). The Proposal is ambitious in scope: it amends several major pieces of EU health legislation, including the Clinical Trials Regulation (“CTR”), the Veterinary Medicines Regulation, the Food Law Regulation and the Substances of Human Origin Regulation (“SoHO”), while also introducing a new framework for EU strategic projects, AI-enabled biotechnology, and biodefence.

On 10 March 2026, the European Data Protection Board (“EDPB”) and the European Data Protection Supervisor (“EDPS”) adopted Joint Opinion 3/2026 on the Proposal (the “Joint Opinion”). While broadly supportive of the Proposal’s objectives, the EDPB and EDPS identified a number of significant data protection concerns, and issued recommendations. Although not legally binding, the Joint Opinion carries significant weight as it reflects the views of the EU’s primary data protection authorities and will directly shape the legislative debate ahead.

In this blog we examine the key data protection implications of the Proposal and the Joint Opinion for pharma and life sciences companies.

Continue Reading EDPB/EDPS Joint Opinion on the European Biotech Act Proposal: Key Data Protection Implications for Pharma and Life Sciences

On 19 November 2025, the European Commission published two legislative proposals – the Digital Omnibus on AI Regulation Proposal and the broader Digital Omnibus Regulation Proposal (“Proposals”) – as part of a wider initiative to simplify and streamline the EU’s digital regulatory framework. Together, the Proposals introduce targeted but significant amendments across a broad range of instruments, including the EU AI Act (Regulation (EU) 2024/1689), the GDPR (Regulation (EU) 2016/679), the ePrivacy Directive (2002/58/EC), the NIS2 Directive ((EU) 2022/2555), and the EU Data Act (Regulation (EU) 2023/2854).

Continue Reading EU Digital Omnibus: What the Proposed Reforms Mean for Pharma and MedTech

The EU Commission has published its proposal for the “Digital Omnibus” aimed to simplify and streamline the EU rules governing artificial intelligence, data protection, cybersecurity, and data use more broadly. The proposal seeks to amend several cornerstone EU regulations, including Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2024/1689 (AI Act), Regulation (EU) 2023/2854 (Data Act), Directive 2002/58/EC (e-Privacy Directive) and Directive (EU) 2022/2555 (NIS2). The proposal also foresees the repeal of the fairly recent Regulation (EU) 2022/868 (Data Governance Act).

Below is a high-level snapshot of the proposal, ahead of a more detailed advisory we will publish.

The proposal will now moves through what is expected to be a challenging legislative procedure and policy and political discussions with the European Parliament and the Council.

Below we set out a quick overview of the most relevant elements for companies, including medical device manufacturers and other Life Sciences companies – e.g., changes to the AI Act, updates to the GDPR, reform of the EU cookie and tracking rules, data-sharing rules, and the new single-entry point for cybersecurity and data protection incidents reporting.

Continue Reading Digital Omnibus: The European Commission published its proposal to amend the GDPR, AI Act, Data Act and other related frameworks

On 4 September 2025, the Court of Justice of the European Union (“CJEU”) delivered a notable judgment on what is considered pseudonymised personal data under EU data protection law. While, technically speaking, the judgment concerns the interpretation of Regulation (EU) 2018/1725 (which governs the processing of personal data by the EU institutions and bodies), it fully applies to the interpretation of the concepts of personal data and pseudonymised data under Regulation (EU) 2016/679 (“GDPR”).

This question is essential for many companies operating in the EU, and in particular Life Sciences companies handling key-coded or otherwise pseudonymised patients’ personal data in the context of research and development, supply of healthcare products and related safety monitoring.

Continue Reading CJEU clarifies the concept of pseudonymised data

On 21 May 2025, the European Commission published its Proposal for a Regulation (“Proposal”), amending several existing regulations, including the General Data Protection Regulation (EU) 2016/67 (“GDPR”), to simplify obligations for small and medium-sized enterprises (“SMEs”) and extend certain mitigating measures to small mid-cap enterprises (“SMCs”).

Continue Reading Proposed GDPR Simplifications for SMEs and SMCs

The European Data Protection Body (EDPB) has published a study on how personal health data is and/or can be reused for scientific research in the EU under the EU General Data Protection Regulation (GDPR). The study highlights the related practical challenges due to divergent interpretations of the GDPR and national rules across EU Member States.

The key conclusions of the study are set out below:

Continue Reading European Data Protection Board publishes study on secondary use of personal health data for scientific research