Paul Maynard
Paul Maynard is special counsel in the technology regulatory group in the London office. He focuses on advising clients on all aspects of UK and European privacy and cybersecurity law relating to complex and innovative technologies such as adtech, cloud computing and online platforms. He also advises clients on how to respond to law enforcement demands, particularly where such demands are made across borders.
Paul advises emerging and established companies in various sectors, including online retail, software and education technology. His practice covers advice on new legislative proposals, for example on e-privacy and cross-border law enforcement access to data; advice on existing but rapidly-changing rules, such the GDPR and cross-border data transfer rules; and on regulatory investigations in cases of alleged non-compliance, including in relation to online advertising and cybersecurity.
Post-Quantum Cryptography: A Practical Guide
A key benefit of quantum computing is that it may, in the future, enable a very substantial increase in computing power. This could create significant benefits, in the life sciences and financial services sectors (see our prior posts on the potential implications for these sectors here and here). However, it also creates potential risks. In particular, it could lead to the breaking of many of the encryption methods currently used by governments and businesses alike. As commercially-viable quantum computers become an increasing reality, organisations must prioritise “quantum readiness” and specifically migration to post-quantum cryptography (“PQC”).
In this post, we set out a brief overview of the main steps that regulators and industry bodies (including the U.S. National Institute of Standards and Technology (“NIST”), the UK National Cyber Security Centre (“NCSC”), and the EU Agency for Cybersecurity (“ENISA”)) have indicated businesses should take to move towards PQC and protect their data and systems from the risks posed by quantum computing.
Continue Reading Post-Quantum Cryptography: A Practical GuideHow the European Commission aims to promote the EU quantum sector through the Cloud and AI Development Act
Much of the attention on the European Commission’s recent proposal for a Cloud and AI Development Act (“CADA Proposal”) has focused on its proposed cloud sovereignty framework, the implications for cloud service providers and public sector cloud use, and the mechanisms intended to encourage data centre development in the EU (we discuss those aspects of the CADA Proposal in more detail in our post here).
But the CADA Proposal also contains several express references to the development of the EU quantum computing sector, which suggests that quantum computing may be embedded within the EU’s wider cloud, AI, and data centre strategy, and that the Commission may promote the development of the technology in that context (rather than treating it as a separate technology policy issue). That approach is consistent with the Commission’s July 2025 Quantum Strategy and its expected proposal for a Quantum Act later this year, both of which focus on building the industrial base for quantum computers in Europe (we describe the Quantum Strategy and the likely themes of the forthcoming Quantum Act in our prior post here).
In this post, we outline the two main mechanisms through which the CADA Proposal would support the development and deployment of quantum computing in Europe, in advance of the Quantum Act.
Continue Reading How the European Commission aims to promote the EU quantum sector through the Cloud and AI Development ActThe EU Cloud and AI Development Act in Depth
On 3 June 2026, the European Commission (“Commission“) published its proposal for a Regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem—the Cloud and AI Development Act (“CADA Proposal“). The CADA Proposal sits at the heart of the Commission’s broader Tech Sovereignty Package (which we describe at…
Continue Reading The EU Cloud and AI Development Act in DepthENISA’s NIS360 2026 report highlights both the criticality of the European space sector, and flags a persistent cybersecurity maturity gap
On May 28, 2026, the European Union Agency for Cybersecurity (“ENISA”) published the third edition of its NIS360 report, an annual benchmarking tool that assesses the cybersecurity maturity of entities in the sectors set out in Annex I of the NIS2 Directive (which includes certain entities in the energy, transport, healthcare, digital…
Continue Reading ENISA’s NIS360 2026 report highlights both the criticality of the European space sector, and flags a persistent cybersecurity maturity gapEU Tech Sovereignty Package
On June 3, the European Commission published its Tech Sovereignty Package, a set of legislative and policy initiatives designed to address what the Commission characterizes as Europe’s technological dependencies on non-European suppliers. The Package marks a further step in the evolution of the EU’s technology policy, with initiatives spanning the full tech stack—from chips and infrastructure to software, cloud, and artificial intelligence. Through this “ecosystem” approach, the Commission seeks to reduce supply-side dependencies by strengthening domestic capabilities in Europe and stimulating demand in downstream sectors.
The Package comprises four components: two legislative proposals—(i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0—as well as two non-legislative initiatives—(iii) the EU Open Source Strategy and (iv) a Strategic Roadmap for Digitalisation and AI in Energy.
This blog post provides an initial, high-level overview of the four initiatives through which the Commission seeks to advance a “European way” to tech sovereignty, with potential implications for industrial ecosystems in Europe and beyond, including cloud, telecoms, automotive, aeronautics, and defense sectors.
Continue Reading EU Tech Sovereignty PackageA Single EU Authorisation for Satellite Spectrum: The Commission’s Proposal for a New 2 GHz Mobile Satellite Services Regulation
On 27 May 2026, the European Commission (“Commission”) published its proposal for a Regulation on the authorisation of systems providing mobile satellite services (“MSSs”) in the harmonised 2 GHz frequency band (1980–2010 MHz and 2170–2200 MHz) (the “MSS Regulation Proposal”). The existing rights of use in the band are due to expire in May 2027, and the Commission is using that deadline to overhaul the framework for granting spectrum authorisations for MSS provides. This Proposal will therefore be of particular interest to MSS providers wishing to expand their footprint in the EU, as well as terrestrial mobile network operators contemplating satellite partnerships, and other space sector participants, as it may increase the number of operators in the European MSS sector.
Continue Reading A Single EU Authorisation for Satellite Spectrum: The Commission’s Proposal for a New 2 GHz Mobile Satellite Services Regulation
CJEU Advocate-General indicates that communications network operators can lawfully be required to remove Chinese components, and that compensation is not required
Seven Major Changes in the European Commission’s Proposal for an EU Digital Networks Act
On 21 January 2026, the European Commission (“Commission”) unveiled its landmark proposal for the Digital Networks Act (“DNA Proposal”), an ambitious attempt to overhaul the framework for the regulation and development of electronic communications networks and services across the EU. The Commission’s stated aim with the DNA Proposal is to establish a “modern and simplified legal framework that incentivises the transition from legacy networks to fibre, high quality 5G and 6G networks, and cloud-based infrastructures, as well as increased scale through service provision and cross-border operation.” To do this, the DNA Proposal would replace and consolidate several existing EU laws, including the European Electronic Communications Code (“EECC”), the BEREC Regulation, and parts of the Open Internet Regulation and e-Privacy Directive.
A key theme of the proposal is harmonization of rules—arising first and foremost from the fact that this is a directly-applicable Regulation rather than a Directive like the current European Electronic Communications Code. Several of the substantive provisions in the DNA Proposal may take a significant amount of influence over the communications networks and services away from Member State governments and up to EU level. In turn, the Commission clearly hopes to promote larger-scale communications network and service providers that can operate across the EU, and that have the funds to invest in modern communications infrastructure. The DNA Proposal could, therefore, have a substantial and long-lasting impact on the connectivity and communications markets in the EU, although we anticipate significant debate about many of the provisions of the DNA Proposal throughout the legislative process.
Below, we summarize seven of the most eye-catching changes to the regulatory framework for communications providers in the DNA Proposal.
Continue Reading Seven Major Changes in the European Commission’s Proposal for an EU Digital Networks ActFive major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill
As the UK Government has recognized, cyber incidents—such as Jaguar Land Rover, Marks and Spencer, Royal Mail and the British Library—are costing UK businesses billions annually and causing severe disruption. The Government recognizes that cybersecurity is a critical enabler of economic growth (“we cannot have growth without stability”), and that the current laws have “fallen out of date and are insufficient to tackle the cyber threats faced by the UK.” Accordingly the UK Government this week published its long-awaited Cyber Security and Resilience Bill (the “Bill”), which will amend the existing Network and Information Systems Regulations 2018 (the “NIS Regulations”), and grant new powers to regulators and the Government in relation to cybersecurity.
The NIS Regulations are the UK’s pre-Brexit implementation of Directive (EU) 2016/1148 (the “NIS Directive”), which established a “horizontal” cybersecurity regulatory framework covering essential services in five sectors (transport, energy, drinking water, health, and digital infrastructure) and some digital services (online marketplaces, online search engines, and cloud computing services). EU legislators replaced NIS Directive in 2022 with the “NIS2” Directive, which Member States were meant to transpose into national law by October of last year (although many are still late in doing so. See our post on NIS2 here for an overview of the requirements of NIS2).
The Bill is the UK’s effort at modernizing the framework originally set out in the NIS Directive. In its current form, the Bill will:
- Significantly expand the scope of the NIS Regulations—to cover, among other things, data centers and managed service providers—and impose additional substantive obligations on covered organizations.
- Increase potential fines—up to GBP 17m or 4% of the worldwide turnover of an undertaking—and extend the powers of competent authorities to share information with one another, issue guidance, and take enforcement action.
- Establish a framework for future changes to the NIS Regulations, mechanisms for competent authorities to impose specific cybersecurity requirements on covered organizations, and greater Government direction of cybersecurity matters.
Below, we set out further detail on five major changes in UK cybersecurity regulation arising from the Bill.
Continue Reading Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill