
Sign up to save your podcasts
Or


APAC Spotlight is a podcast from the Hogan Lovells Cadwalader APAC Data, Privacy and Cybersecurity team, led by Charmian Aw, exploring the key developments shaping the region's fast-evolving digital regulatory landscape.
As data becomes an increasingly valuable business asset, organizations must navigate the growing intersection between data strategy and antitrust and competition law. In this episode of The Data Chronicles, Scott Loughlin sits down with Hogan Lovells Cadwalader counsel Bilal Sayyed, who advises a variety of clients on antitrust and competition matters, to explore how competition authorities are thinking about data in a digital economy where access to information can shape market outcomes.
They discuss when companies can limit access to data, why control of a valuable dataset does not necessarily create market power, and how regulators evaluate issues such as interoperability, exclusivity arrangements, and platform design. The conversation also examines how antitrust authorities assess mergers involving data assets, including whether combining datasets or acquiring critical data suppliers could affect innovation, competition, and future market entry.
Ultimately, Scott and Bilal highlight that antitrust questions are rarely about data alone. Instead, these questions tend to focus on whether companies are competing by building better products and creating value for customers or using control over data to make it more challenging for rivals. As regulators continue to scrutinize digital markets and AI-driven businesses, organizations must understand how their data strategies fit within an evolving regulatory and competition landscape.
APAC Spotlight is a podcast from the Hogan Lovells Cadwalader APAC Data, Privacy and Cybersecurity team, led by Charmian Aw, exploring the key developments shaping the region's fast-evolving digital regulatory landscape.
In this second episode of the series, Charmian Aw speaks to Hogan Lovells Cadwalader associate Ciara O’Leary – to tackle one of the biggest issues facing businesses today: AI regulation across APAC. While the EU AI Act has dominated headlines, jurisdictions across Asia-Pacific are taking very different approaches, ranging from China's extensive AI rules and South Korea's AI Basic Act to Singapore's voluntary governance frameworks and emerging laws in Vietnam and Thailand.
Charmian and Ciara bust common myths about AI regulation, explore the growing role of national security, data protection, and sector-specific rules, and discuss why EU AI Act compliance alone may not be enough for organizations operating across the region. They also share practical perspectives on navigating APAC's fragmented regulatory landscape as AI regulation continues to accelerate.
The key takeaway? There is no one-size-fits-all approach to AI compliance in APAC. Organizations should build a strong governance foundation but be ready to adapt to local requirements as the regulatory landscape evolves.
Tune in to hear what businesses, legal teams and technology professionals need to know about the future of AI regulation in Asia-Pacific.
AI is no longer just a legal technology or governance issue – it is increasingly an organizational transformation challenge. In this episode of The Data Chronicles, we sit down with Avi Goldfarb, the Rotman Chair in Artificial Intelligence and Healthcare at the University of Toronto and co-author of Prediction Machines and Power and Prediction, to examine why widespread AI pilots, strategies, deployed tools, and leadership attention have not yet produced the deeper business change many organizations expected.
We explore why simply giving teams access to AI tools is not the same as redesigning how a business works, how AI can shift decision-making power among employees, leaders, and vendors, and why organizations must decide what they value before letting external systems define success for them. Ultimately, the conversation reframes AI not as a machine that makes decisions for us, but as a powerful information technology whose transformative value depends on human judgment, clear KPIs, CEO-level commitment, and a deliberate understanding of what the organization is trying to accomplish.
APAC Spotlight is a podcast from the Hogan Lovells Cadwalader APAC Data, Privacy and Cybersecurity team, led by Charmian Aw, exploring the key developments shaping the region’s fast-evolving digital regulatory landscape.
In our first episode, we tackle cross-border data transfers and data localisation. Data and businesses are increasingly global, but regulations are not.
We bust common myths, explore why organizations should look beyond China when assessing regulatory risk, and discuss how geopolitics, national security and AI are reshaping the rules around data. We also share practical perspectives on navigating APAC’s fragmented regulatory landscape without building a separate compliance programme for every jurisdiction.
The key takeaway? Think globally, localise selectively.
Tune in to find out what businesses, legal teams and privacy professionals need to know as APAC’s data regulatory landscape continues to evolve.
AI regulation in the United States is at an inflection point. A new executive order, emerging legislation, and shifting political dynamics are rapidly reshaping the policy landscape for AI developers and adopters.
In this episode of The Data Chronicles, we examine the administration’s latest executive order on AI innovation and security, which introduces a voluntary framework for pre-release review of frontier AI models – an approach some compared to FDA-style oversight. We also explore how it differs from prior safety-focused directives and more aggressive regulatory models abroad.
The discussion highlights what this moment means for companies across the ecosystem, from major tech firms helping shape policy to startups navigating commercialization. At the core is a key tension: policymakers are unusually open to new ideas but the window to influence these frameworks may be narrower than it appears.
State-level data regulation in the United States is accelerating, with a growing patchwork of laws reshaping how organizations approach privacy, artificial intelligence, and online safety.
In this episode of The Data Chronicles, we provide a 2026 legislative wrap-up, examining how new comprehensive privacy laws in states like Oklahoma and Alabama, alongside emerging frameworks in Louisiana, are reinforcing a largely harmonized – but still fragmented – compliance landscape.
The discussion explores how AI regulation is diverging more significantly, with states such as Colorado and Connecticut shifting toward targeted, risk-based approaches focused on automated decision-making and employment use cases, while broader concerns around AI chatbots and workforce integration continue to draw legislative attention. We also unpack the rapid evolution of online safety and children’s protections, including the expansion of age-appropriate design codes, age verification requirements, and ongoing constitutional challenges.
Across all three areas, the episode highlights the practical implications of increased regulatory overlap, evolving enforcement dynamics, and the growing need for organizations to monitor state-level developments closely – particularly as lawmakers continue to experiment with technology-driven solutions and push toward more granular oversight of data-driven systems.
State-level data regulation in the United States is accelerating, with a growing patchwork of laws reshaping how organizations approach privacy, artificial intelligence, and online safety.
In this episode of The Data Chronicles, we provide a 2026 legislative wrap-up, examining how new comprehensive privacy laws in states like Oklahoma and Alabama, alongside emerging frameworks in Louisiana, are reinforcing a largely harmonized – but still fragmented – compliance landscape.
The discussion explores how AI regulation is diverging more significantly, with states such as Colorado and Connecticut shifting toward targeted, risk-based approaches focused on automated decision-making and employment use cases, while broader concerns around AI chatbots and workforce integration continue to draw legislative attention. We also unpack the rapid evolution of online safety and children’s protections, including the expansion of age-appropriate design codes, age verification requirements, and ongoing constitutional challenges.
Across all three areas, the episode highlights the practical implications of increased regulatory overlap, evolving enforcement dynamics, and the growing need for organizations to monitor state-level developments closely – particularly as lawmakers continue to experiment with technology-driven solutions and push toward more granular oversight of data-driven systems.
Data protection in the United Kingdom is entering a new phase of post‑Brexit divergence, introducing targeted but impactful changes across regulatory governance, enforcement, and day‑to‑day compliance.
In this episode of The Data Chronicles, we examine how the Data (Use and Access) Act 2025 is reshaping UK data protection through reforms to the ICO’s structure, new approaches to cookies, automated decision‑making, international data transfers, and lawful bases for processing.
The discussion explores how increased flexibility in the United Kingdom is paired with heightened enforcement risk, why operating across United Kingdom and European Union regimes is becoming more complex for global organizations, and how data protection is increasingly being reframed as both a legal compliance and economic policy tool – demanding closer coordination between legal, product, and operational teams.
Cybersecurity regulation in Europe has entered a period of rapid expansion and fragmentation, moving well beyond traditional data protection into a complex framework governing enterprise security, product security, sector specific obligations, and supply chain risk.
In this episode of The Data Chronicles, we examine how evolving regimes such as NIS2, the Cyber Resilience Act, DORA, and proposed reforms to the EU Cybersecurity Act are reshaping legal and operational expectations for organizations operating across borders.
The discussion explores why global “one size fits all” security programs and reliance on baseline standards like ISO and NIST are no longer sufficient on their own, how post Brexit divergence between the EU and U.K. is creating material compliance challenges, and why cybersecurity has shifted from a best practice exercise to enforceable law – requiring tighter integration between legal, IT, and information security teams to execute compliance at scale.
From the publisher's feed
Welcome to The Data Chronicles, hosted by partner Scott Loughlin, Co-Lead of the Hogan Lovells Cadwalader global Data, Privacy and Cybersecurity practice. This multimedia series is…

87,180 Listeners

111,779 Listeners

56,445 Listeners

225 Listeners

3,596 Listeners

5,559 Listeners