An interactive map of the laws, acts and norms shaping technology, AI, data and IP in Europe. Each node is a piece of legislation; lines show how they connect. Click any node to read every Legal Tech Tea post tagged with that law. Ten of them open one level deeper — every chapter, every article, and, for the GDPR and the EU AI Act, the points where the two regimes touch. Drag to explore, scroll to zoom.
Tip: the double-ringed laws zoom in to article level. The list below covers the same ground without the graph.
All laws & acts
Data Protection
- GDPR — Regulation (EU) 2016/679
- ePrivacy Directive 2002/58/EC
- Data Act (EU) 2023/2854
- Data Governance Act (EU) 2022/868
Artificial Intelligence
- EU AI Act (EU) 2024/1689
- AI Liability Directive (proposed)
- Product Liability Directive (EU) 2024/2853
Intellectual Property
- Copyright in the Digital Single Market — Directive (EU) 2019/790
- Trade Secrets Directive (EU) 2016/943
- Database Directive 96/9/EC
- EU Trade Mark Regulation (EU) 2017/1001
- Unitary Patent & Unified Patent Court
- EU Design Rights
Cybersecurity
- NIS2 Directive (EU) 2022/2555
- Cyber Resilience Act (EU) 2024/2847
- Cybersecurity Act (EU) 2019/881
- DORA (EU) 2022/2554
Digital Markets & Platforms
Where the AI Act meets the GDPR
26 points of contact between Regulation (EU) 2024/1689 and Regulation (EU) 2016/679 — the places where building an AI system and processing personal data become the same compliance question.
| EU AI Act | GDPR |
|---|---|
| Art. 14 Human oversight | Art. 22 Automated individual decision-making, including profiling |
| Art. 27 Fundamental rights impact assessment for high-risk AI systems | Art. 35 Data protection impact assessment |
| Art. 9 Risk management system | Art. 35 Data protection impact assessment |
| Art. 10 Data and data governance | Art. 9 Processing of special categories of personal data |
| Art. 10 Data and data governance | Art. 5 Principles relating to processing of personal data |
| Art. 26 Obligations of deployers of high-risk AI systems | Art. 13 Information to be provided where personal data are collected from the data subject |
| Art. 26 Obligations of deployers of high-risk AI systems | Art. 14 Information to be provided where personal data have not been obtained from the data subject |
| Art. 26 Obligations of deployers of high-risk AI systems | Art. 15 Right of access by the data subject |
| Art. 26 Obligations of deployers of high-risk AI systems | Art. 22 Automated individual decision-making, including profiling |
| Art. 11 Technical documentation | Art. 30 Records of processing activities |
| Art. 12 Record-keeping | Art. 30 Records of processing activities |
| Art. 26 Obligations of deployers of high-risk AI systems | Art. 30 Records of processing activities |
| Art. 15 Accuracy, robustness and cybersecurity | Art. 32 Security of processing |
| Art. 12 Record-keeping | Art. 15 Right of access by the data subject |
| Art. 12 Record-keeping | Art. 16 Right to rectification |
| Art. 12 Record-keeping | Art. 17 Right to erasure (‘right to be forgotten’) |
| Art. 12 Record-keeping | Art. 18 Right to restriction of processing |
| Art. 12 Record-keeping | Art. 21 Right to object |
| Art. 50 Transparency obligations for providers and deployers of certain AI systems | Art. 13 Information to be provided where personal data are collected from the data subject |
| Art. 50 Transparency obligations for providers and deployers of certain AI systems | Art. 14 Information to be provided where personal data have not been obtained from the data subject |
| Art. 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox | Art. 6 Lawfulness of processing |
| Art. 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox | Art. 9 Processing of special categories of personal data |
| Art. 57 AI regulatory sandboxes | Art. 35 Data protection impact assessment |
| Art. 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | Art. 5 Principles relating to processing of personal data |
| Art. 86 Right to explanation of individual decision-making | Art. 22 Automated individual decision-making, including profiling |
| Art. 86 Right to explanation of individual decision-making | Art. 15 Right of access by the data subject |
Article by article
GDPR Regulation (EU) 2016/679
Chapter I — General provisions Arts. 1–4
- Subject-matter and objectivesLays down the rules on processing personal data and on its free movement, protecting fundamental rights and in particular the right to data protection.
- Material scopeApplies to wholly or partly automated processing, and to manual processing in a filing system. Excludes purely personal or household activity and law-enforcement processing.
- Territorial scopeApplies to controllers and processors established in the EU, and to those outside it that offer goods or services to, or monitor the behaviour of, people in the EU.
- DefinitionsDefines the Regulation’s core vocabulary: personal data, processing, controller, processor, consent, pseudonymisation, personal data breach and more.
Chapter II — Principles Arts. 5–11
- Principles relating to processing of personal dataSix principles govern all processing: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality. Accountability sits on top.
- Lawfulness of processingProcessing needs one of six legal bases: consent, contract, legal obligation, vital interests, public interest, or legitimate interests.
- Conditions for consentThe controller must be able to demonstrate consent. Requests must be clearly distinguishable and in plain language, and consent can be withdrawn at any time as easily as it was given.
- Conditions applicable to child’s consent in relation to information society servicesFor online services, consent is valid from age 16, though Member States may lower this to 13. Below that age a holder of parental responsibility must authorise it.
- Processing of special categories of personal dataProhibits processing data on racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetics, biometrics used for identification, health, sex life or orientation, unless a listed exception applies.
- Processing of personal data relating to criminal convictions and offencesData on criminal convictions and offences may only be processed under official authority, or where Union or Member State law authorises it with appropriate safeguards.
- Processing which does not require identificationIf the controller cannot identify the data subject, it need not retain extra data just to comply. The subject may supply identifying information to exercise their rights.
Chapter III — Rights of the data subject Arts. 12–23
- Transparent information, communication and modalities for the exercise of the rights of the data subjectInformation must be concise, transparent, intelligible and in plain language. Rights requests must normally be answered within one month, free of charge.
- Information to be provided where personal data are collected from the data subjectWhen data is collected from the subject, they must be told who the controller is, the purposes and legal basis, recipients, transfers, retention, their rights, and whether providing the data is obligatory.
- Information to be provided where personal data have not been obtained from the data subjectWhere data comes from somewhere else, the same information is owed plus the categories of data and its source, given within a reasonable period and at most one month.
- Right of access by the data subjectThe subject can confirm whether their data is being processed and obtain a copy, together with the purposes, categories, recipients, retention period and any automated decision-making.
- Right to rectificationThe subject can have inaccurate personal data corrected without undue delay, and incomplete data completed.
- Right to erasure (‘right to be forgotten’)Data must be erased where it is no longer needed, consent is withdrawn, the subject objects, or processing was unlawful. Balanced against free expression, legal obligations and public-interest grounds.
- Right to restriction of processingThe subject can require processing to be limited to mere storage while accuracy is contested, instead of erasure, or while an objection is being decided.
- Notification obligation regarding rectification or erasure of personal data or restriction of processingThe controller must notify every recipient of any rectification, erasure or restriction, unless that proves impossible or disproportionate.
- Right to data portabilityWhere processing rests on consent or contract and is automated, the subject can receive their data in a structured, commonly used, machine-readable format and have it sent to another controller.
- Right to objectThe subject may object to processing based on public interest or legitimate interests. For direct marketing the objection is absolute and must be honoured immediately.
- Automated individual decision-making, including profilingA person has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Exceptions are contract, Union or Member State law, and explicit consent, each with safeguards including human intervention.
- RestrictionsUnion or Member State law may restrict these rights and obligations for objectives such as national security, defence, public security or criminal enforcement, provided the essence of fundamental rights is respected.
Chapter IV — Controller and processor Arts. 24–43
- Responsibility of the controllerThe controller must put in place appropriate technical and organisational measures to ensure, and be able to demonstrate, that processing complies. Measures are reviewed and updated as needed.
- Data protection by design and by defaultData protection must be designed into processing from the outset, and by default only the data necessary for each specific purpose should be processed.
- Joint controllersWhere two or more controllers jointly determine the purposes and means, they must allocate their responsibilities transparently by arrangement. The subject may exercise rights against either of them.
- Representatives of controllers or processors not established in the UnionControllers and processors caught by the extraterritorial rule must designate a representative in the Union in writing, unless processing is occasional and low risk.
- ProcessorProcessors must offer sufficient guarantees, act only on documented instructions, and be bound by a contract covering subject-matter, duration, security, sub-processors, assistance and deletion.
- Processing under the authority of the controller or processorAnyone acting under the authority of the controller or processor may only process personal data on instructions from the controller.
- Records of processing activitiesControllers and processors must keep written records of their processing activities. A narrow exemption exists for organisations under 250 employees where processing is occasional and low risk.
- Cooperation with the supervisory authorityControllers and processors must cooperate with the supervisory authority on request in the performance of its tasks.
- Security of processingSecurity must be appropriate to the risk, and may include pseudonymisation, encryption, confidentiality, integrity, availability and resilience, restoration after incidents, and regular testing.
- Notification of a personal data breach to the supervisory authorityPersonal data breaches must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to individuals.
- Communication of a personal data breach to the data subjectWhere a breach is likely to result in a high risk, the affected individuals must be told without undue delay, subject to exemptions such as strong encryption or disproportionate effort.
- Data protection impact assessmentA DPIA is required where processing is likely to result in a high risk, notably for systematic automated evaluation, large-scale special-category data, or large-scale monitoring of public areas.
- Prior consultationWhere a DPIA shows a high residual risk that the controller cannot mitigate, the supervisory authority must be consulted before processing begins.
- Designation of the data protection officerA data protection officer is mandatory for public authorities, and where core activities involve large-scale regular systematic monitoring or large-scale special-category data.
- Position of the data protection officerThe DPO must be involved properly and in good time, given resources and independence, must not be instructed on how to perform their tasks, and cannot be dismissed for performing them.
- Tasks of the data protection officerThe DPO informs and advises on obligations, monitors compliance, advises on data protection impact assessments, and acts as contact point for the supervisory authority.
- Codes of conductAssociations may draw up codes of conduct specifying how the Regulation applies to their sector, which supervisory authorities approve.
- Monitoring of approved codes of conductCompliance with an approved code may be monitored by an accredited body with an appropriate level of expertise, under supervisory oversight.
- CertificationEncourages data protection certification mechanisms, seals and marks. Certification is voluntary and does not reduce the controller’s responsibility.
- Certification bodiesSets out the accreditation requirements for bodies issuing certification. Certification lasts up to five years and can be withdrawn.
Chapter V — Transfers of personal data to third countries or international organisations Arts. 44–50
- General principle for transfersTransfers to third countries or international organisations are only permitted on the conditions in this Chapter, including for onward transfers.
- Transfers on the basis of an adequacy decisionTransfers may take place where the Commission has decided that the third country ensures an adequate level of protection.
- Transfers subject to appropriate safeguardsWithout an adequacy decision, transfers need appropriate safeguards such as standard contractual clauses, binding corporate rules, codes or certification, with enforceable rights.
- Binding corporate rulesBinding corporate rules for intra-group transfers must be approved by the competent supervisory authority, be legally binding, and confer enforceable rights on data subjects.
- Transfers or disclosures not authorised by Union lawA third-country court or authority decision requiring a transfer is only recognisable if it rests on an international agreement such as a mutual legal assistance treaty.
- Derogations for specific situationsNarrow exceptions permit a transfer: explicit informed consent, contractual necessity, important public interest, legal claims, vital interests, or a public register.
- International cooperation for the protection of personal dataRequires the Commission and supervisory authorities to develop international cooperation mechanisms and mutual assistance with third countries.
Chapter VI — Independent supervisory authorities Arts. 51–59
- Supervisory authorityEach Member State must provide for one or more independent public authorities to monitor the application of the Regulation.
- IndependenceSupervisory authorities must act with complete independence, free from external influence, with their own staff, budget and premises.
- General conditions for the members of the supervisory authorityMembers must be appointed through a transparent procedure, be suitably qualified, and may only be dismissed for serious misconduct or failure to meet the conditions of office.
- Rules on the establishment of the supervisory authorityMember States must set out by law the authority’s establishment, member qualifications, term of at least four years, and duties.
- CompetenceEach authority is competent on the territory of its own Member State, but is not competent over courts acting in their judicial capacity.
- Competence of the lead supervisory authorityFor cross-border processing, the authority of the main or single establishment acts as lead authority, through the one-stop-shop mechanism.
- TasksAuthorities monitor and enforce the Regulation, promote awareness, advise, handle complaints, investigate and cooperate. Their action is free of charge for data subjects.
- PowersAuthorities hold investigative powers such as audits and access, corrective powers including warnings, reprimands, bans and fines, and authorisation and advisory powers.
- Activity reportsEach authority must draw up an annual activity report, make it public, and send it to parliament, government, the Board and the Commission.
Chapter VII — Cooperation and consistency Arts. 60–76
- Cooperation between the lead supervisory authority and the other supervisory authorities concernedSets out how the lead authority cooperates with other concerned authorities, sharing draft decisions and working towards consensus.
- Mutual assistanceAuthorities must provide each other with relevant information and mutual assistance, normally within one month and free of charge.
- Joint operations of supervisory authoritiesAuthorities may run joint investigations and joint enforcement measures, including seconded staff exercising powers on the host territory.
- Consistency mechanismEstablishes the mechanism through which supervisory authorities cooperate via the Board to apply the Regulation consistently across the Union.
- Opinion of the BoardThe Board issues opinions on draft measures with cross-border effect, such as DPIA lists, codes of conduct, binding corporate rules and standard clauses.
- Dispute resolution by the BoardThe Board adopts binding decisions where supervisory authorities disagree about a lead authority’s draft decision or about competence.
- Urgency procedureIn exceptional urgency an authority may adopt provisional measures for up to three months, and request an urgent opinion or binding decision from the Board.
- Exchange of informationThe Commission may specify the arrangements for electronic exchange of information between supervisory authorities and the Board.
- European Data Protection BoardEstablishes the European Data Protection Board as a Union body with legal personality, made up of the head of each authority and the EDPS.
- IndependenceThe Board must act independently, and neither seek nor take instructions from anyone when performing its tasks.
- Tasks of the BoardThe Board advises the Commission, issues guidelines, recommendations and best practice, promotes consistency, and produces an annual report.
- ReportsThe Board’s annual report on data protection in the Union is made public and sent to the Parliament, Council and Commission.
- ProcedureThe Board takes decisions by simple majority unless otherwise provided, and adopts its own rules of procedure.
- ChairThe Board elects a chair and two deputy chairs from among its members for a five-year term, renewable once.
- Tasks of the ChairThe Chair convenes meetings, prepares the agenda, notifies decisions, and ensures the Board’s tasks are performed in good time.
- SecretariatThe European Data Protection Supervisor provides the Board’s secretariat, acting solely on the instructions of the Chair.
- ConfidentialityBoard discussions are confidential where its rules of procedure so provide. Access to documents follows the general Union transparency rules.
Chapter VIII — Remedies, liability and penalties Arts. 77–84
- Right to lodge a complaint with a supervisory authorityEvery data subject may lodge a complaint with a supervisory authority, in particular in their own Member State, and must be told the outcome.
- Right to an effective judicial remedy against a supervisory authorityEveryone has the right to an effective judicial remedy against a legally binding decision of a supervisory authority, or against its failure to act within three months.
- Right to an effective judicial remedy against a controller or processorData subjects may bring court proceedings where the controller or processor is established, or where they themselves habitually reside.
- Representation of data subjectsData subjects may mandate a not-for-profit body active in data protection to lodge complaints and exercise remedies on their behalf.
- Suspension of proceedingsA court may suspend proceedings concerning the same processing where those proceedings are already pending in another Member State.
- Right to compensation and liabilityAnyone suffering material or non-material damage is entitled to compensation. Controllers and processors are liable unless they prove they are not responsible for the event.
- General conditions for imposing administrative finesFines must be effective, proportionate and dissuasive, up to 10 million euro or 2% of global annual turnover, and up to 20 million euro or 4% for the most serious infringements.
- PenaltiesMember States must lay down additional penalties for infringements not already covered by administrative fines.
Chapter IX — Provisions relating to specific processing situations Arts. 85–91
- Processing and freedom of expression and informationMember States must reconcile data protection with freedom of expression and information, providing exemptions for journalistic, academic, artistic and literary purposes.
- Processing and public access to official documentsPersonal data in official documents held by a public body may be disclosed in line with Union or Member State law on public access.
- Processing of the national identification numberMember States may impose specific conditions on the processing of a national identification number, with appropriate safeguards.
- Processing in the context of employmentMember States may provide more specific rules for processing in the employment context, covering recruitment, performance of the contract, management and termination.
- Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposesProcessing for archiving in the public interest, scientific or historical research, or statistics requires safeguards such as data minimisation and pseudonymisation, and may derogate from certain rights.
- Obligations of secrecyMember States may regulate the investigative powers of authorities where controllers are subject to professional secrecy obligations.
- Existing data protection rules of churches and religious associationsComprehensive data protection rules already applied by churches and religious associations may continue if brought into line with the Regulation and independently supervised.
Chapter X — Delegated acts and implementing acts Arts. 92–93
- Exercise of the delegationSets out the conditions for the Commission’s delegated powers, which run indefinitely but may be revoked and are subject to objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
Chapter XI — Final provisions Arts. 94–99
- Repeal of Directive 95/46/ECRepeals the 1995 Data Protection Directive with effect from 25 May 2018. References to it are read as references to the GDPR.
- Relationship with Directive 2002/58/ECThe GDPR imposes no additional obligations where the ePrivacy Directive already sets specific obligations with the same objective.
- Relationship with previously concluded AgreementsInternational agreements concluded before 24 May 2016 remain in force until they are amended, replaced or revoked.
- Commission reportsThe Commission must report on the evaluation and review of the Regulation by 25 May 2020 and every four years after that.
- Review of other Union legal acts on data protectionThe Commission shall, where appropriate, propose amendments to other Union data protection instruments to ensure consistency.
- Entry into force and applicationThe Regulation entered into force on 24 May 2016 and has applied since 25 May 2018.
EU AI Act Regulation (EU) 2024/1689
Chapter I — General provisions Arts. 1–4
- Subject matterLays down harmonised rules for placing on the market, putting into service and using AI systems in the Union, following a risk-based approach.
- ScopeApplies to providers, deployers, importers and distributors whose AI systems affect the Union. Excludes military, defence and national security uses, purely scientific research, and personal non-professional use.
- DefinitionsDefines the Regulation’s vocabulary, including AI system, provider, deployer, general-purpose AI model, substantial modification and serious incident.
- AI literacyProviders and deployers must take measures to ensure a sufficient level of AI literacy among the staff who deal with their AI systems.
Chapter II — Prohibited AI practices Art. 5
- Prohibited AI practicesBans manipulative and subliminal techniques, exploitation of vulnerabilities, social scoring, predictive policing based on profiling alone, untargeted scraping of facial images, emotion recognition at work or school, biometric categorisation for sensitive traits, and real-time remote biometric identification in public for law enforcement save narrow exceptions.
Chapter III — High-risk AI systems Arts. 6–49
- Classification rules for high-risk AI systemsA system is high-risk if it is a safety component of a product covered by listed Union harmonisation law, or falls within an Annex III area, unless it poses no significant risk.
- Amendments to Annex IIIEmpowers the Commission to add or modify the high-risk use cases listed in Annex III by delegated act.
- Compliance with the requirementsHigh-risk systems must meet the requirements of this Section, taking account of their intended purpose and the generally acknowledged state of the art.
- Risk management systemRequires a continuous, iterative risk management process across the lifecycle: identify and evaluate foreseeable risks, adopt mitigation measures, and test. Particular attention is owed to minors and vulnerable groups.
- Data and data governanceTraining, validation and testing data must be relevant, sufficiently representative, and as far as possible free of errors and complete, and must be examined for possible biases.
- Technical documentationTechnical documentation must be drawn up before the system is placed on the market and kept up to date, containing the Annex IV elements that demonstrate conformity.
- Record-keepingHigh-risk systems must technically allow the automatic recording of events over their lifetime, ensuring a level of traceability appropriate to the intended purpose.
- Transparency and provision of information to deployersSystems must be transparent enough for deployers to interpret the output and use it appropriately, supported by instructions covering characteristics, performance and limitations.
- Human oversightHigh-risk systems must be designed so that people can effectively oversee them: understand capacities and limits, remain alert to automation bias, interpret output, and decide not to use the system or to stop it.
- Accuracy, robustness and cybersecuritySystems must achieve appropriate levels of accuracy, robustness and cybersecurity, perform consistently across their lifecycle, and resist errors and adversarial attacks.
- Obligations of providers of high-risk AI systemsProviders must ensure compliance, identify themselves on the system, run a quality management system, keep documentation and logs, carry out conformity assessment, register, and take corrective action.
- Quality management systemProviders must operate a documented quality management system covering regulatory strategy, design, testing, data management, risk management, post-market monitoring and accountability.
- Documentation keepingProviders must keep the technical documentation, quality management records, approvals and EU declaration of conformity for ten years after the system is placed on the market.
- Automatically generated logsProviders must retain the logs automatically generated by their high-risk systems, where those logs are under their control, for at least six months.
- Corrective actions and duty of informationA provider who considers a system non-conforming must immediately take corrective action, withdraw, disable or recall it, and inform distributors, deployers and authorities.
- Cooperation with competent authoritiesOn a reasoned request, providers must give competent authorities all the information and documentation needed to demonstrate conformity, in an easily understandable language.
- Authorised representatives of providers of high-risk AI systemsProviders established outside the Union must appoint an authorised representative in the Union by written mandate before making a high-risk system available.
- Obligations of importersImporters must verify conformity assessment, technical documentation, CE marking and the authorised representative before placing a system on the market, and keep records.
- Obligations of distributorsDistributors must check the CE marking, documentation and instructions, and must not make a system available if they consider it non-conforming.
- Responsibilities along the AI value chainA distributor, importer, deployer or third party becomes a provider if it puts its name on a high-risk system, substantially modifies it, or changes its intended purpose so that it becomes high-risk.
- Obligations of deployers of high-risk AI systemsDeployers must follow the instructions for use, assign competent human oversight, ensure input data is relevant, monitor operation, keep logs, inform workers, and tell affected people where a decision concerns them.
- Fundamental rights impact assessment for high-risk AI systemsPublic bodies and certain private deployers must assess the impact on fundamental rights before first use, covering the processes involved, the people affected, the risks and the oversight measures.
- Notifying authoritiesEach Member State must designate a notifying authority responsible for assessing, designating and monitoring conformity assessment bodies.
- Application of a conformity assessment body for notificationConformity assessment bodies apply to the notifying authority, describing their activities and supplying an accreditation certificate.
- Notification procedureNotifying authorities may only notify bodies that satisfy the requirements, using the Commission’s electronic notification tool.
- Requirements relating to notified bodiesNotified bodies must be independent, competent, impartial and confidential, adequately insured, and must follow documented procedures.
- Presumption of conformity with requirements relating to notified bodiesA body that conforms to the relevant harmonised standards is presumed to meet the requirements for notified bodies.
- Subsidiaries of notified bodies and subcontractingA notified body stays responsible for tasks it subcontracts, needs the provider’s agreement, and must keep the relevant documents available.
- Operational obligations of notified bodiesNotified bodies must verify conformity proportionately, avoiding unnecessary burden particularly for SMEs, and make documentation available on request.
- Identification numbers and lists of notified bodiesThe Commission assigns each notified body a single identification number and publishes the list of notified bodies.
- Changes to notificationsGoverns the suspension, restriction or withdrawal of a notification where a body no longer meets the requirements, and what happens to its certificates.
- Challenge to the competence of notified bodiesThe Commission may investigate and require corrective action where it has reason to doubt a notified body’s competence.
- Coordination of notified bodiesThe Commission ensures coordination and cooperation between notified bodies through a sectoral group.
- Conformity assessment bodies of third countriesBodies established under the law of a third country may perform conformity assessment where an international agreement provides for equivalence.
- Harmonised standards and standardisation deliverablesConformity with harmonised standards published in the Official Journal gives a presumption of conformity with the requirements they cover.
- Common specificationsWhere harmonised standards are insufficient, the Commission may adopt common specifications by implementing act, which also give a presumption of conformity.
- Presumption of conformity with certain requirementsSystems trained on data reflecting the specific setting in which they will be used are presumed to meet the data requirement. Systems certified under a cybersecurity scheme are presumed to meet the cybersecurity requirement.
- Conformity assessmentSets out when internal control is enough and when a notified body must be involved, notably for biometric systems where harmonised standards were not applied.
- CertificatesCertificates must be in an easily understandable language, are valid for up to five years, or four years for Annex III systems, and can be renewed.
- Information obligations of notified bodiesNotified bodies must tell notifying authorities about certificates issued, refused, suspended or withdrawn, and about their conformity assessment activities.
- Derogation from conformity assessment procedureMarket surveillance authorities may exceptionally authorise a specific system to be placed on the market for public security or protection reasons, while assessment is pending.
- EU declaration of conformityProviders must draw up a written, machine-readable EU declaration of conformity for each high-risk system and keep it for ten years.
- CE markingThe CE marking must be affixed visibly, legibly and indelibly, or digitally where appropriate, with the notified body’s identification number where one was involved.
- RegistrationProviders must register themselves and their Annex III high-risk system in the EU database before placing it on the market. Certain public-authority deployers must also register.
Chapter IV — Transparency obligations for providers and deployers of certain AI systems Art. 50
- Transparency obligations for providers and deployers of certain AI systemsPeople must be told when they are interacting with an AI system, or exposed to emotion recognition or biometric categorisation. Deep fakes and AI-generated text on matters of public interest must be disclosed, and outputs marked in a machine-readable way.
Chapter V — General-purpose AI models Arts. 51–56
- Classification of general-purpose AI models as general-purpose AI models with systemic riskA general-purpose AI model has systemic risk where it has high-impact capabilities, presumed when the cumulative training compute exceeds 10^25 floating point operations.
- ProcedureProviders must notify the Commission within two weeks of meeting the systemic-risk threshold, and may argue exceptionally that their model nonetheless does not present such risk.
- Obligations for providers of general-purpose AI modelsProviders must keep technical documentation, give information to downstream providers, comply with Union copyright law including text-and-data-mining reservations, and publish a sufficiently detailed summary of the training content.
- Authorised representatives of providers of general-purpose AI modelsProviders established outside the Union must appoint an authorised representative in the Union before placing a general-purpose AI model on the market.
- Obligations of providers of general-purpose AI models with systemic riskAdditional duties apply: model evaluation including adversarial testing, assessing and mitigating systemic risks, reporting serious incidents, and ensuring an adequate level of cybersecurity.
- Codes of practiceThe AI Office encourages codes of practice at Union level to help providers of general-purpose AI models demonstrate compliance.
Chapter VI — Measures in support of innovation Arts. 57–63
- AI regulatory sandboxesEach Member State must establish at least one AI regulatory sandbox by 2 August 2026, giving a controlled environment for development, training, testing and validation under supervision.
- Detailed arrangements for, and functioning of, AI regulatory sandboxesSets out the detailed conditions for sandboxes: eligibility, application, participation and exit, and the guidance and supervision that authorities must provide.
- Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandboxAllows personal data lawfully collected for another purpose to be reused in a sandbox to develop AI in the public interest, subject to strict conditions and safeguards.
- Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxesProviders may test high-risk systems outside a sandbox under a plan submitted to the market surveillance authority, subject to time limits and safeguards.
- Informed consent to participate in testing in real world conditions outside AI regulatory sandboxesSubjects must give freely given, informed and documented consent before taking part in real-world testing, and may withdraw at any time without detriment.
- Measures for providers and deployers, in particular SMEs, including start-upsMember States must give SMEs priority access to sandboxes, run awareness activities, provide dedicated channels, and reduce conformity assessment fees.
- Derogations for specific operatorsMicroenterprises may comply with the quality management system requirement in a simplified manner.
Chapter VII — Governance Arts. 64–70
- AI OfficeThe Commission’s AI Office builds Union expertise and capability in AI and supports implementation, especially for general-purpose AI models.
- Establishment and structure of the European Artificial Intelligence BoardEstablishes the Board, composed of Member State representatives, to advise and assist the Commission and Member States towards consistent application.
- Tasks of the BoardThe Board advises on implementation, coordinates national authorities, issues recommendations and opinions, and contributes to guidance and standardisation.
- Advisory forumProvides technical expertise to the Board and the Commission, with a balanced selection of stakeholders from industry, SMEs, civil society and academia.
- Scientific panel of independent expertsA panel of independent experts supports enforcement, particularly on general-purpose AI models, and may issue qualified alerts about systemic risks.
- Access to the pool of experts by the Member StatesMember States may call on the pool of experts to support their enforcement activities, potentially against a fee.
- Designation of national competent authorities and single points of contactEach Member State must designate at least one notifying authority and one market surveillance authority, give them adequate resources, and name a single point of contact.
Chapter VIII — EU database for high-risk AI systems Art. 71
- EU database for high-risk AI systems listed in Annex IIIThe Commission maintains a public EU database of registered Annex III high-risk systems, with limited restricted sections.
Chapter IX — Post-market monitoring, information sharing and market surveillance Arts. 72–94
- Post-market monitoring by providers and post-market monitoring plan for high-risk AI systemsProviders must run a proportionate post-market monitoring system and plan, actively collecting and analysing performance data throughout the system’s life.
- Reporting of serious incidentsSerious incidents must be reported to market surveillance authorities immediately, generally within 15 days, and within 2 or 10 days in the gravest cases.
- Market surveillance and control of AI systems in the Union marketApplies the Union market surveillance rules and designates market surveillance authorities, including full access to documentation and, where needed, to training data and source code.
- Mutual assistance, market surveillance and control of general-purpose AI systemsWhere a system is built on a general-purpose AI model from the same provider, the AI Office holds exclusive powers to supervise and enforce.
- Supervision of testing in real world conditions by market surveillance authoritiesMarket surveillance authorities verify and supervise testing in real world conditions, and may require it to be suspended.
- Powers of authorities protecting fundamental rightsNational bodies protecting fundamental rights may request and obtain access to documentation, and may ask for technical testing support.
- ConfidentialityAll parties must respect the confidentiality of information obtained, in particular intellectual property rights, trade secrets and source code.
- Procedure at national level for dealing with AI systems presenting a riskMarket surveillance authorities must evaluate systems presenting a risk and require corrective action, withdrawal or recall within a set period.
- Procedure for dealing with AI systems classified by the provider as not high-risk in application of Annex IIIWhere an authority finds that a system the provider classified as not high-risk in fact is, it requires the provider to bring it into compliance.
- Union safeguard procedureWhere a national measure is contested, the Commission evaluates it and decides whether the measure is justified.
- Compliant AI systems which present a riskEven a compliant system may be required to be withdrawn where it presents a risk to health, safety or fundamental rights.
- Formal non-complianceCovers formal breaches such as improperly affixed CE marking, or a missing declaration of conformity, technical documentation or registration.
- Union AI testing support structuresThe Commission designates testing support structures that provide independent technical or scientific advice.
- Right to lodge a complaint with a market surveillance authorityAny person may lodge a complaint about an infringement of this Regulation with the relevant market surveillance authority.
- Right to explanation of individual decision-makingA person subject to an Annex III high-risk decision producing legal or similarly significant adverse effects may obtain clear and meaningful explanations of the AI system’s role in that decision.
- Reporting of infringements and protection of reporting personsWhistleblower protection under the Union’s reporting directive applies to people reporting infringements of this Regulation.
- Enforcement of obligations of providers of general-purpose AI modelsThe Commission holds exclusive powers, exercised through the AI Office, to supervise and enforce the obligations on providers of general-purpose AI models.
- Monitoring actionsThe AI Office may act to monitor effective implementation and compliance by providers of general-purpose AI models, including in response to alerts from the scientific panel.
- Alerts of systemic risks by the scientific panelThe scientific panel may issue a qualified alert to the AI Office where a model poses a concrete, identifiable systemic risk.
- Power to request documentation and informationThe Commission may require providers of general-purpose AI models to supply documentation and any information needed to assess compliance.
- Power to conduct evaluationsThe AI Office may evaluate general-purpose AI models, including through access to the model, to assess compliance or investigate systemic risks.
- Power to request measuresThe Commission may require providers to take measures, implement mitigation, or restrict, withdraw or recall a model from the market.
- Procedural rights of economic operators of the general-purpose AI modelThe Union market surveillance rules on rights of defence apply, giving providers of general-purpose AI models access to the file and the right to be heard.
Chapter X — Codes of conduct and guidelines Arts. 95–96
- Codes of conduct for voluntary application of specific requirementsEncourages voluntary codes of conduct applying high-risk-style requirements to AI systems that are not high-risk.
- Guidelines from the Commission on the implementation of this RegulationThe Commission shall develop guidelines on practical implementation, including on the requirements, the prohibitions and the transparency obligations.
Chapter XI — Delegation of power and committee procedure Arts. 97–98
- Exercise of the delegationSets out the conditions and duration of the Commission’s delegated powers, which are subject to revocation and objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
Chapter XII — Penalties Arts. 99–101
- PenaltiesPenalties must be effective, proportionate and dissuasive. Prohibited practices attract up to 35 million euro or 7% of global turnover, most other breaches 15 million euro or 3%, and misleading information 7.5 million euro or 1%.
- Administrative fines on Union institutions, bodies, offices and agenciesThe European Data Protection Supervisor may fine Union institutions, bodies and agencies up to 1.5 million euro for prohibited practices and 750,000 euro for other breaches.
- Fines for providers of general-purpose AI modelsThe Commission may fine providers of general-purpose AI models up to 3% of their global annual turnover or 15 million euro, whichever is higher.
Chapter XIII — Final provisions Arts. 102–113
- Amendment to Regulation (EC) No 300/2008Aligns civil aviation security rules with this Regulation’s requirements for AI safety components.
- Amendment to Regulation (EU) No 167/2013Aligns the approval rules for agricultural and forestry vehicles with this Regulation.
- Amendment to Regulation (EU) No 168/2013Aligns the approval rules for two- and three-wheel vehicles and quadricycles with this Regulation.
- Amendment to Directive 2014/90/EUAligns the marine equipment rules with this Regulation.
- Amendment to Directive (EU) 2016/797Aligns the rail interoperability rules with this Regulation.
- Amendment to Regulation (EU) 2018/858Aligns the motor vehicle approval rules with this Regulation.
- Amendments to Regulation (EU) 2018/1139Aligns the civil aviation rules with this Regulation.
- Amendment to Regulation (EU) 2019/2144Aligns the vehicle general safety rules with this Regulation.
- Amendment to Directive (EU) 2020/1828Adds this Regulation to the instruments covered by representative actions for the protection of consumers.
- AI systems already placed on the market or put into service and general-purpose AI models already placed on the marketTransitional rules. General-purpose AI models placed on the market before 2 August 2025 must comply by 2027. Legacy high-risk systems are caught only on significant design change, with a 2030 deadline for public-authority systems.
- Evaluation and reviewThe Commission must assess annually whether Annex III and the transparency list need amending, and report periodically on evaluation and review.
- Entry into force and applicationThe Regulation entered into force on 1 August 2024 and applies from 2 August 2026, with the prohibitions from 2 February 2025 and the general-purpose AI rules from 2 August 2025.
Read every post tagged EU AI Act →
Digital Services Act Regulation (EU) 2022/2065
Chapter I — General Provisions Arts. 1–3
- Subject matterSets harmonised rules for a safe, predictable and trusted online environment, and for intermediary services in the internal market.
- ScopeApplies to intermediary services offered to users established or located in the Union, whatever the provider’s place of establishment.
- DefinitionsDefines the Regulation’s terms, including intermediary service, illegal content, online platform, recipient and trader.
Chapter II — Liability of Providers of Intermediary Services Arts. 4–10
- ‘Mere conduit’A provider that only transmits information is not liable for it, provided it does not initiate the transmission, select the receiver, or modify the content.
- ‘Caching’Automatic, intermediate and temporary storage is exempt from liability where the provider does not modify the information and acts expeditiously once content is removed at source.
- HostingA hosting provider is not liable for stored information unless it has actual knowledge of illegal activity and fails to act expeditiously to remove or disable it.
- Voluntary own-initiative investigations and legal complianceProviders do not lose their liability exemption merely because they carry out voluntary own-initiative investigations or take measures to comply with the law.
- No general monitoring or active fact-finding obligationsNo general obligation may be imposed on providers to monitor what they transmit or store, or actively to seek facts indicating illegal activity.
- Orders to act against illegal contentOn receiving an order from a national authority, providers must inform the issuing authority of the effect given to it, and orders must meet minimum content conditions.
- Orders to provide informationSets the conditions for national orders requiring a provider to supply specific information about one or more individual recipients.
Chapter III — Due Diligence Obligations for a Transparent and Safe Online Environment Arts. 11–48
- Points of contact for Member States’ authorities, the Commission and the BoardProviders must designate a single electronic point of contact for authorities and state the languages it works in.
- Points of contact for recipients of the serviceProviders must offer a point of contact allowing users to communicate directly and rapidly, by means that are not solely automated.
- Legal representativesProviders without an establishment in the Union must designate a legal representative in a Member State where they offer services.
- Terms and conditionsTerms must set out any restrictions on user content in clear, plain and intelligible language, and be applied diligently, objectively and proportionately with regard to fundamental rights.
- Transparency reporting obligations for providers of intermediary servicesProviders must publish at least annual, machine-readable reports on their content moderation, including orders received and action taken.
- Notice and action mechanismsHosting providers must operate easy, electronic mechanisms allowing anyone to notify them of content believed to be illegal.
- Statement of reasonsUsers must receive a clear, specific statement of reasons for any restriction imposed on their content, account or monetisation.
- Notification of suspicions of criminal offencesWhere a hosting provider suspects a criminal offence involving a threat to life or safety, it must promptly inform law enforcement.
- Exclusion for micro and small enterprisesThe online-platform obligations in this Section do not apply to micro or small enterprises, subject to a transition where a platform loses that status.
- Internal complaint-handling systemPlatforms must give users a free, electronic internal complaint mechanism against moderation decisions, for at least six months after the decision.
- Out-of-court dispute settlementUsers may bring moderation disputes to a certified out-of-court dispute settlement body, without prejudice to going to court.
- Trusted flaggersNotices from entities awarded trusted-flagger status by a Digital Services Coordinator must be given priority and processed without undue delay.
- Measures and protection against misusePlatforms must suspend, after warning, users who frequently post manifestly illegal content and complainants who frequently file unfounded notices.
- Transparency reporting obligations for providers of online platformsPlatforms must additionally report disputes, suspensions, and their average monthly active users.
- Online interface design and organisationPlatforms must not design, organise or operate their interfaces in a way that deceives, manipulates or materially distorts users’ ability to make free decisions.
- Advertising on online platformsEach advertisement must be clearly identifiable as such, with the payer and the main parameters used to target it disclosed; targeting on sensitive data is prohibited.
- Recommender system transparencyPlatforms must set out in their terms, in plain language, the main parameters of their recommender systems and any options to change them.
- Online protection of minorsPlatforms accessible to minors must put in place appropriate measures for their privacy, safety and security, and must not profile minors for advertising.
- Exclusion for micro and small enterprisesThe trader-related obligations in this Section do not apply to micro or small enterprises, with a transition where that status is lost.
- Traceability of tradersPlatforms allowing distance contracts must obtain and make best efforts to verify identifying information about traders before allowing them to sell.
- Compliance by designPlatform interfaces must be designed so traders can meet their pre-contractual, compliance and product-safety information duties.
- Right to informationWhere a platform learns an illegal product or service was offered, it must inform affected consumers of the trader’s identity and the remedies available.
- Very large online platforms and very large online search enginesSets the designation mechanism for services reaching at least 45 million average monthly Union users, triggering the additional obligations in this Section.
- Risk assessmentDesignated services must diligently assess systemic risks arising from their design and use, including illegal content, fundamental rights, civic discourse and public health.
- Mitigation of risksDesignated services must put in place reasonable, proportionate and effective mitigation measures tailored to the risks identified.
- Crisis response mechanismThe Commission may, acting on a Board recommendation, require designated services to take specific action during a serious threat to public security or health.
- Independent auditDesignated services must submit to at least annual independent audits of their compliance, at their own expense.
- Recommender systemsDesignated services must offer at least one recommender option not based on profiling.
- Additional online advertising transparencyDesignated services must maintain a public, searchable repository of the advertisements they present, retained for a year.
- Data access and scrutinyDesignated services must give the Digital Services Coordinator and vetted researchers access to data needed to monitor systemic risks.
- Compliance functionDesignated services must maintain an independent compliance function with sufficient authority, standing and resources.
- Transparency reporting obligationsDesignated services must publish transparency reports every six months, including moderation resources and audit results.
- Supervisory feeThe Commission charges designated services an annual fee to cover its supervisory costs, capped by reference to their global income.
- StandardsThe Commission supports and promotes voluntary standards for notices, ad repositories, auditing, interoperability and minor protection.
- Codes of conductThe Commission and the Board encourage voluntary codes of conduct at Union level to contribute to the proper application of the Regulation.
- Codes of conduct for online advertisingEncourages codes of conduct to bring further transparency to the online advertising value chain, beyond the Regulation’s own requirements.
- Codes of conduct for accessibilityEncourages codes of conduct to ensure services are accessible to persons with disabilities, consistent with Union accessibility law.
- Crisis protocolsThe Board may recommend that the Commission initiate voluntary crisis protocols for extraordinary circumstances affecting public security or health.
Chapter IV — Implementation, Cooperation, Penalties and Enforcement Arts. 49–88
- Competent authorities and Digital Services CoordinatorsEach Member State must designate competent authorities and one Digital Services Coordinator responsible for supervision and enforcement.
- Requirements for Digital Services CoordinatorsCoordinators must act impartially, transparently and independently, with adequate technical, financial and human resources.
- Powers of Digital Services CoordinatorsCoordinators hold investigative powers, including inspections and information requests, and enforcement powers including fines and interim measures.
- PenaltiesMember States must lay down effective, proportionate and dissuasive penalties, capped at 6% of global annual turnover for the most serious breaches.
- Right to lodge a complaintUsers may complain to the Digital Services Coordinator of their Member State about any alleged infringement by a provider.
- CompensationUsers have the right to seek compensation from providers for damage or loss suffered from a breach of the Regulation.
- Activity reportsCoordinators must publish annual reports on their activity, including complaints received and orders issued.
- CompetencesAllocates supervisory competence to the Member State of the provider’s main establishment, with the Commission exclusively supervising designated services.
- Mutual assistanceCoordinators and the Commission must cooperate closely and give each other assistance in applying the Regulation consistently.
- Cross-border cooperation among Digital Services CoordinatorsSets the procedure by which a Coordinator may request another to assess and act on a suspected infringement.
- Referral to the CommissionWhere a request goes unanswered or a Coordinator disagrees with the assessment, the matter may be referred to the Commission.
- Joint investigationsCoordinators may run joint investigations, coordinated by the Coordinator of establishment, with the Commission’s support.
- European Board for Digital ServicesEstablishes the Board as an independent advisory group of Digital Services Coordinators.
- Structure of the BoardSets the Board’s composition, chairing by the Commission, meeting arrangements and rules of procedure.
- Tasks of the BoardThe Board supports coordination, issues opinions and recommendations, and assists in supervising designated services.
- Development of expertise and capabilitiesThe Commission, with the Member States, develops the expertise and capabilities needed to supervise designated services, including algorithmic assessment.
- Enforcement of obligations of providers of very large online platforms and of very large online search enginesConfirms the Commission’s exclusive powers to supervise and enforce the additional obligations on designated services.
- Initiation of proceedings by the Commission and cooperation in investigationOnce the Commission opens proceedings, national Coordinators lose competence over the same conduct.
- Requests for informationThe Commission may require providers, and other relevant persons, to supply information within a set period.
- Power to take interviews and statementsThe Commission may interview any person consenting to be interviewed for the purpose of collecting information about an investigation.
- Power to conduct inspectionsThe Commission may inspect premises, examine records in any form, seal premises, and ask for explanations.
- Interim measuresWhere there is urgency due to the risk of serious damage to users, the Commission may order interim measures.
- CommitmentsThe Commission may make commitments offered by a provider binding, and reopen proceedings if they are not honoured.
- Monitoring actionsThe Commission may order a provider to give access to and explain its databases and algorithms, and may appoint external experts and auditors.
- Non-complianceThe Commission may adopt a non-compliance decision where a designated service breaches the Regulation, interim measures or commitments.
- FinesThe Commission may fine a provider up to 6% of global annual turnover for infringement, or 1% for supplying incorrect or misleading information.
- Enhanced supervision of remedies to address infringements of obligations laid down in Section 5 of Chapter IIIWhere systemic-risk obligations are breached, the Commission may require an action plan and independent audit of its implementation.
- Periodic penalty paymentsThe Commission may impose periodic penalties of up to 5% of average daily global turnover to compel compliance.
- Limitation period for the imposition of penaltiesThe Commission’s power to impose penalties is subject to a five-year limitation period, interrupted by investigative action.
- Limitation period for the enforcement of penaltiesThe Commission’s power to enforce penalties already imposed is subject to a five-year limitation period.
- Right to be heard and access to the fileBefore an adverse decision, providers must be heard and given access to the file, subject to business secrets and confidentiality.
- Publication of decisionsThe Commission publishes its decisions, having regard to the legitimate interest of parties in protecting confidential information.
- Review by the Court of Justice of the European UnionThe Court has unlimited jurisdiction to review decisions imposing fines or periodic penalty payments.
- Requests for access restrictions and cooperation with national courtsWhere an infringement persists and causes serious harm, the Commission may ask the Coordinator of establishment to seek a court-ordered access restriction.
- Implementing acts relating to Commission interventionEmpowers the Commission to adopt implementing acts on the practical arrangements for its proceedings.
- Professional secrecyInformation collected under the Regulation is covered by professional secrecy and may only be used for the purpose for which it was gathered.
- Information sharing systemEstablishes a reliable, secure electronic system for communication between Coordinators, the Commission and the Board.
- RepresentationUsers may mandate a qualified body to exercise their rights under the Regulation on their behalf.
- Exercise of the delegationSets the conditions and duration of the Commission’s delegated powers, subject to revocation and objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
Chapter V — Final Provisions Arts. 89–93
- Amendments to Directive 2000/31/ECDeletes the e-Commerce Directive’s liability provisions, which this Regulation replaces.
- Amendment to Directive (EU) 2020/1828Adds this Regulation to the instruments covered by representative actions for consumers.
- ReviewThe Commission must evaluate the Regulation and report, on designation thresholds and the Board’s functioning, and thereafter every five years.
- Anticipated application to providers of very large online platforms and of very large online search enginesThe additional obligations on designated services applied from four months after their designation, ahead of the Regulation’s general application date.
- Entry into force and applicationEntered into force on 16 November 2022 and applies in full from 17 February 2024, with designation-related provisions applying earlier.
Read every post tagged Digital Services Act →
Cyber Resilience Act Regulation (EU) 2024/2847
Chapter I — General Provisions Arts. 1–12
- Subject matterSets cybersecurity requirements for the design, development and production of products with digital elements placed on the Union market.
- ScopeApplies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.
- DefinitionsDefines product with digital elements, remote data processing, manufacturer, vulnerability, incident, support period and other terms.
- Free movementMember States may not impede the making available of products that comply with this Regulation.
- Procurement or use of products with digital elementsMember States may impose additional cybersecurity requirements when procuring or using products, for national security or defence purposes.
- Requirements for products with digital elementsProducts may only be made available if they meet the essential cybersecurity requirements in Annex I and are supplied without known exploitable vulnerabilities.
- Important products with digital elementsLists the important product categories, which face stricter conformity assessment — including password managers, VPNs, firewalls and network monitoring.
- Critical products with digital elementsLists the critical product categories, for which the Commission may require European cybersecurity certification — including smart meter gateways and hardware security modules.
- Stakeholder consultationThe Commission must consult stakeholders, including industry, SMEs, open-source communities and consumer bodies, when applying the Regulation.
- Enhancing skills in a cyber resilient digital environmentMember States must promote cybersecurity skills, training and awareness, including for SMEs and open-source developers.
- General product safetyThe General Product Safety Regulation applies to products with digital elements as regards risks not covered here.
- High-risk AI systemsProducts that are also high-risk AI systems under the AI Act are presumed to meet its cybersecurity requirement where they comply with this Regulation — the CRA-to-AI-Act bridge.
Chapter II — Obligations of Economic Operators and Provisions in Relation to Free and Open-source Software Arts. 13–26
- Obligations of manufacturersManufacturers must ensure products meet the essential requirements, assess cybersecurity risks, and provide security updates for the support period, normally at least five years.
- Reporting obligations of manufacturersManufacturers must notify actively exploited vulnerabilities and severe incidents to the CSIRT and ENISA — an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days.
- Voluntary reportingManufacturers and other operators may voluntarily notify vulnerabilities, incidents, cyber threats and near misses.
- Establishment of a single reporting platformENISA establishes a single reporting platform so a single notification reaches all the relevant authorities.
- Other provisions related to reportingSets further rules on reporting, including dissemination of notifications and the grounds for delaying circulation.
- Authorised representativesManufacturers may appoint an authorised representative in the Union by written mandate to carry out specified tasks.
- Obligations of importersImporters may only place products on the market that comply, carry the CE marking, and come with the required documentation.
- Obligations of distributorsDistributors must verify the CE marking and documentation and must not make a non-compliant product available.
- Cases in which obligations of manufacturers apply to importers and distributorsAn importer or distributor becomes subject to the manufacturer’s obligations if it markets the product under its own name or substantially modifies it.
- Other cases in which obligations of manufacturers applySubstantial modification of a product already on the market triggers a fresh conformity assessment.
- Identification of economic operatorsEconomic operators must identify, on request, who supplied them and to whom they supplied a product, for ten years.
- Obligations of open-source software stewardsOpen-source software stewards must put in place a documented cybersecurity policy and cooperate with market surveillance authorities, under a lighter regime than manufacturers.
- Security attestation of free and open-source softwareProvides for voluntary security attestation of free and open-source software, so downstream manufacturers can rely on it.
- GuidanceThe Commission must issue guidance to help operators apply the Regulation, with particular attention to SMEs and open-source.
Chapter III — Conformity of the Product with Digital Elements Arts. 27–34
- Presumption of conformityProducts conforming to harmonised standards, common specifications or European cybersecurity certification schemes are presumed to meet the corresponding requirements.
- EU declaration of conformityManufacturers must draw up an EU declaration of conformity stating that the essential requirements have been met.
- General principles of the CE markingSets out the general principles governing the CE marking on products with digital elements.
- Rules and conditions for affixing the CE markingThe CE marking must be affixed visibly, legibly and indelibly before the product is placed on the market.
- Technical documentationManufacturers must draw up technical documentation before placing the product on the market and keep it for ten years or the support period.
- Conformity assessment procedures for products with digital elementsSets which conformity assessment route applies: internal control for most products, third-party involvement for important and critical categories.
- Support measures for microenterprises and small and medium-sized enterprises, including start-upsMember States must support SMEs and start-ups with awareness, training, testing facilities and reduced conformity assessment fees.
- Mutual recognition agreementsThe Union may conclude mutual recognition agreements with third countries on conformity assessment.
Chapter IV — Notification of Conformity Assessment Bodies Arts. 35–51
- NotificationMember States must notify the Commission of the bodies authorised to carry out third-party conformity assessment.
- Notifying authoritiesEach Member State must designate a notifying authority responsible for assessing and monitoring conformity assessment bodies.
- Requirements relating to notifying authoritiesNotifying authorities must be objective and impartial, and must not offer the services that notified bodies provide.
- Information obligation on notifying authoritiesNotifying authorities must inform the Commission of their assessment and monitoring procedures.
- Requirements relating to notified bodiesNotified bodies must be independent, competent, impartial and confidential, adequately insured, and follow documented procedures.
- Presumption of conformity of notified bodiesBodies conforming to relevant harmonised standards are presumed to meet the requirements for notified bodies.
- Subsidiaries of and subcontracting by notified bodiesNotified bodies remain fully responsible for tasks performed by subsidiaries or subcontractors.
- Application for notificationConformity assessment bodies apply to the notifying authority with evidence of their competence.
- Notification procedureSets the procedure by which notifying authorities notify bodies to the Commission and the other Member States.
- Identification numbers and lists of notified bodiesThe Commission assigns each notified body an identification number and publishes the list.
- Changes to notificationsGoverns suspension, restriction or withdrawal of a notification, and the fate of the certificates concerned.
- Challenge of the competence of notified bodiesThe Commission may investigate and require corrective action where it doubts a notified body’s competence.
- Operational obligations of notified bodiesNotified bodies must carry out assessments proportionately, avoiding unnecessary burden, particularly for SMEs.
- Appeal against decisions of notified bodiesNotified bodies must provide an appeal procedure against their decisions.
- Information obligation on notified bodiesNotified bodies must inform their notifying authority of certificates refused, suspended or withdrawn.
- Exchange of experienceThe Commission provides for the exchange of experience between the Member States’ notifying authorities.
- Coordination of notified bodiesThe Commission ensures coordination and cooperation between notified bodies through a sectoral group.
Chapter V — Market Surveillance and Enforcement Arts. 52–60
- Market surveillance and control of products with digital elements in the Union marketMarket surveillance authorities supervise products under the Market Surveillance Regulation, with ENISA supporting the analysis of reported incidents.
- Access to data and documentationMarket surveillance authorities may require access to the data and documentation needed to assess conformity, including source code where necessary.
- Procedure at national level concerning products with digital elements presenting a significant cybersecurity riskWhere a product presents a significant cybersecurity risk, authorities must evaluate it and require corrective action, withdrawal or recall.
- Union safeguard procedureWhere a national measure is contested, the Commission evaluates it and decides whether it is justified.
- Procedure at Union level concerning products with digital elements presenting a significant cybersecurity riskThe Commission may itself evaluate products presenting a significant cybersecurity risk where Union-level action is needed.
- Compliant products with digital elements which present a significant cybersecurity riskEven a compliant product may be required to be withdrawn where it nonetheless presents a significant cybersecurity risk.
- Formal non-complianceCovers formal breaches such as improperly affixed CE marking, or missing declaration of conformity or technical documentation.
- Joint activities of market surveillance authoritiesMarket surveillance authorities may agree joint activities, including with manufacturers, to promote compliance.
- SweepsAuthorities may conduct simultaneous coordinated control actions — sweeps — on particular categories of product.
Chapter VI — Delegated Powers and Committee Procedure Arts. 61–62
- Exercise of the delegationSets the conditions and duration of the Commission’s delegated powers, subject to revocation and objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
Chapter VII — Confidentiality and Penalties Arts. 63–65
- ConfidentialityAuthorities must respect the confidentiality of information obtained, in particular trade secrets and source code.
- PenaltiesPenalties reach up to 15 million euro or 2.5% of global annual turnover for breach of the essential requirements.
- Representative actionsAdds this Regulation to the instruments covered by representative actions for consumers.
Chapter VIII — Transitional and Final Provisions Arts. 66–71
- Amendment to Regulation (EU) 2019/1020Amends the Market Surveillance Regulation to add this Regulation to its annex.
- Amendment to Directive (EU) 2020/1828Amends the Representative Actions Directive to cover this Regulation.
- Amendment to Regulation (EU) No 168/2013Amends Regulation (EU) No 168/2013 on two- and three-wheel vehicles to account for this Regulation.
- Transitional provisionsProducts placed on the market before the application date are only caught if substantially modified afterwards.
- Evaluation and reviewThe Commission must evaluate and report on the Regulation by 11 December 2030 and every four years thereafter.
- Entry into force and applicationEntered into force on 10 December 2024; the reporting obligations apply from 11 September 2026 and the Regulation in full from 11 December 2027.
Read every post tagged Cyber Resilience Act →
DORA Regulation (EU) 2022/2554
Chapter I — General Provisions Arts. 1–4
- Subject matterSets uniform requirements for the security of network and information systems supporting the business processes of financial entities.
- ScopeApplies across the financial sector — banks, insurers, investment firms, crypto-asset service providers and more — and to their critical ICT providers.
- DefinitionsDefines digital operational resilience, ICT risk, ICT-related incident, major incident, critical ICT third-party service provider and other terms.
- Proportionality principleRequirements apply proportionately to the entity’s size, overall risk profile, and the nature and complexity of its services.
Chapter II — ICT Risk Management Arts. 5–16
- Governance and organisationThe management body bears final responsibility for ICT risk, must approve strategy and budget, and must keep its knowledge current.
- ICT risk management frameworkEntities must maintain a sound, documented ICT risk management framework, reviewed at least yearly and after major incidents.
- ICT systems, protocols and toolsICT systems must be reliable, of sufficient capacity, and technologically resilient to handle peak conditions and stress.
- IdentificationEntities must identify and classify all ICT-supported business functions, assets and dependencies, and review that inventory regularly.
- Protection and preventionEntities must apply policies and tools ensuring resilience, continuity and availability — including authentication, encryption and network segmentation.
- DetectionEntities must have mechanisms to detect anomalous activity promptly, with multiple layers of control and defined alert thresholds.
- Response and recoveryEntities must maintain a dedicated ICT business continuity policy and response and recovery plans, tested at least annually.
- Backup policies and procedures, restoration and recovery procedures and methodsEntities must maintain backup policies and restoration procedures, with backup systems physically and logically segregated from source systems.
- Learning and evolvingEntities must gather information on vulnerabilities and incidents, conduct post-incident reviews, and feed the lessons back into the framework.
- CommunicationEntities must have crisis communication plans and a designated person responsible for communicating with the public and clients.
- Further harmonisation of ICT risk management tools, methods, processes and policiesThe European Supervisory Authorities develop technical standards further harmonising ICT risk management tools and processes.
- Simplified ICT risk management frameworkSmaller and less interconnected entities may apply a simplified ICT risk management framework.
Chapter III — ICT-related Incident Management, Classification and Reporting Arts. 17–23
- ICT-related incident management processEntities must define, establish and implement a process to detect, manage and notify ICT-related incidents, with early warning indicators.
- Classification of ICT-related incidents and cyber threatsIncidents must be classified against criteria including clients affected, duration, geographical spread, data losses and economic impact.
- Reporting of major ICT-related incidents and voluntary notification of significant cyber threatsMajor incidents must be reported to the competent authority via an initial, an intermediate and a final report; significant cyber threats may be notified voluntarily.
- Harmonisation of reporting content and templatesThe ESAs develop common templates and content requirements so incident reporting is consistent across the sector.
- Centralisation of reporting of major ICT-related incidentsProvides for a possible single EU Hub centralising the reporting of major incidents, subject to a feasibility report.
- Supervisory feedbackCompetent authorities must acknowledge receipt and may provide feedback, guidance and anonymised information on similar threats.
- Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutionsExtends the incident regime to operational and security payment-related incidents for credit, payment and e-money institutions.
Chapter IV — Digital Operational Resilience Testing Arts. 24–27
- General requirements for the performance of digital operational resilience testingEntities must establish a risk-based digital operational resilience testing programme as an integral part of the ICT risk framework.
- Testing of ICT tools and systemsTesting must cover vulnerability assessments, network security assessments, gap analyses, source code reviews and penetration testing, at least annually.
- Advanced testing of ICT tools, systems and processes based on TLPTSignificant entities must carry out threat-led penetration testing on live production systems at least every three years.
- Requirements for testers for the carrying out of TLPTTesters must be of the highest suitability and reputability, technically capable, certified, and covered by professional indemnity insurance.
Chapter V — Managing of ICT Third-party Risk Arts. 28–44
- General principlesEntities remain fully responsible for compliance when using ICT third-party providers, and must maintain a register of information on all contractual arrangements.
- Preliminary assessment of ICT concentration risk at entity levelBefore contracting, entities must assess whether the arrangement would create ICT concentration risk or difficult-to-unwind dependency.
- Key contractual provisionsContracts must include mandatory terms on service descriptions, data locations, access and audit rights, exit strategies and notice periods.
- Designation of critical ICT third-party service providersThe ESAs designate ICT third-party providers as critical based on systemic impact, substitutability and interconnectedness.
- Structure of the Oversight FrameworkEstablishes the Oversight Framework, with an Oversight Forum and a Lead Overseer appointed for each critical provider.
- Tasks of the Lead OverseerThe Lead Overseer assesses whether the critical provider has comprehensive, sound and effective rules to manage the risk it poses.
- Operational coordination between Lead OverseersLead Overseers coordinate their work through a joint examination team drawing on staff from the ESAs and competent authorities.
- Powers of the Lead OverseerThe Lead Overseer may request information, conduct investigations and inspections, issue recommendations, and impose periodic penalty payments.
- Exercise of the powers of the Lead Overseer outside the UnionSets how the Lead Overseer exercises its powers in respect of a critical provider’s facilities located outside the Union.
- Request for informationThe Lead Overseer may require critical providers to supply all information necessary to carry out its duties.
- General investigationsThe Lead Overseer may conduct general investigations of critical providers, including examining records and taking statements.
- InspectionsThe Lead Overseer may conduct on-site inspections at any business premises of a critical provider.
- Ongoing oversightThe Lead Overseer conducts ongoing oversight, adopting an annual oversight plan for each critical provider.
- Harmonisation of conditions enabling the conduct of the oversight activitiesThe ESAs develop technical standards specifying the information and the detailed conditions for oversight activities.
- Follow-up by competent authoritiesCompetent authorities must follow up on the Lead Overseer’s recommendations and may require entities to suspend or terminate arrangements.
- Oversight feesCritical providers pay fees covering the Lead Overseer’s oversight costs, proportionate to their turnover.
- International cooperationProvides for cooperation arrangements with third-country authorities on ICT third-party risk in the financial sector.
Chapter VI — Information-sharing Arrangements Art. 45
- Information-sharing arrangements on cyber threat information and intelligenceFinancial entities may exchange cyber threat information and intelligence within trusted communities, subject to safeguards.
Chapter VII — Competent Authorities Arts. 46–56
- Competent authoritiesDesignates which authority supervises which category of financial entity for the purposes of the Regulation.
- Cooperation with structures and authorities established by Directive (EU) 2022/2555Financial supervisors must cooperate with the NIS2 authorities, CSIRTs and the Cooperation Group.
- Cooperation between authoritiesThe ESAs, competent authorities and other Union bodies must cooperate closely and exchange information.
- Financial cross-sector exercises, communication and cooperationProvides for Union-level cross-sector exercises and crisis communication involving public authorities and financial entities.
- Administrative penalties and remedial measuresCompetent authorities must have supervisory, investigatory and sanctioning powers, and may impose administrative penalties and remedial measures.
- Exercise of the power to impose administrative penalties and remedial measuresSets the criteria for determining the type and level of administrative penalties, including gravity, duration and cooperation.
- Criminal penaltiesMember States may lay down criminal penalties instead of administrative ones for certain infringements.
- Notification dutiesMember States must notify the Commission and the ESAs of the laws implementing this Chapter.
- Publication of administrative penaltiesCompetent authorities must publish administrative penalties, in anonymised form where publication would be disproportionate.
- Professional secrecyAll persons working for competent authorities are bound by professional secrecy in respect of confidential information.
- Data ProtectionAny processing of personal data under the Regulation must comply with the GDPR and be limited to what is necessary.
Chapter VIII — Delegated Acts Art. 57
- Exercise of the delegationSets the conditions and duration of the Commission’s delegated powers, subject to revocation and objection.
Chapter IX — Transitional and Final Provisions Arts. 58–64
- Review clauseThe Commission must review the Regulation, including the appropriateness of extending it and the Oversight Framework’s functioning.
- Amendments to Regulation (EC) No 1060/2009Amends the Credit Rating Agencies Regulation to align its ICT requirements with this Regulation.
- Amendments to Regulation (EU) No 648/2012Amends EMIR to align its ICT and business continuity requirements with this Regulation.
- Amendments to Regulation (EU) No 909/2014Amends the Central Securities Depositories Regulation to align its ICT requirements.
- Amendments to Regulation (EU) No 600/2014Amends MiFIR to align its systems resilience requirements with this Regulation.
- Amendment to Regulation (EU) 2016/1011Amends the Benchmarks Regulation to align its ICT requirements.
- Entry into force and applicationEntered into force on 16 January 2023 and applies from 17 January 2025.
Digital Markets Act Regulation (EU) 2022/1925
Chapter I — Subject Matter, Scope and Definitions Arts. 1–2
- Subject matter and scopeSets harmonised rules ensuring contestable and fair markets in the digital sector where gatekeepers are present.
- DefinitionsDefines gatekeeper, core platform service, end user, business user, online search engine, and other key terms.
Chapter II — Gatekeepers Arts. 3–4
- Designation of gatekeepersAn undertaking is designated a gatekeeper where it has significant impact on the internal market, operates an important gateway, and holds an entrenched position — presumed by turnover and user thresholds.
- Review of the status of gatekeeperThe Commission must review designations regularly and may reassess, amend or repeal them where the underlying facts change.
Chapter III — Practices of Gatekeepers That Limit Contestability or Are Unfair Arts. 5–15
- Obligations for gatekeepersCore obligations: no combining personal data across services without consent, no most-favoured-nation clauses, freedom for business users to steer to their own offers, and no forced use of the gatekeeper’s identification or payment services.
- Obligations for gatekeepers susceptible of being further specified under Article 8Further obligations open to specification: no self-preferencing in ranking, allowing uninstalling and third-party app stores, permitting sideloading, and giving business users access to their performance data.
- Obligation for gatekeepers on interoperability of number-independent interpersonal communications servicesGatekeepers running number-independent messaging services must make basic functionalities interoperable with other providers on request.
- Compliance with obligations for gatekeepersGatekeepers must ensure and demonstrate compliance, and the Commission may specify the measures required by decision.
- SuspensionThe Commission may suspend an obligation where compliance would jeopardise the economic viability of the gatekeeper’s Union operations.
- Exemption for grounds of public health and public securityThe Commission may exempt a gatekeeper from an obligation on grounds of public health or public security.
- ReportingGatekeepers must report their compliance measures within six months of designation and update the report annually.
- Updating obligations for gatekeepersThe Commission may adopt delegated acts updating the obligations where a practice limits contestability or is unfair in the same way.
- Anti-circumventionGatekeepers must not degrade services, or use behavioural or contractual techniques, to circumvent the obligations.
- Obligation to inform about concentrationsGatekeepers must inform the Commission of any concentration involving digital or data-collection services, regardless of merger thresholds.
- Obligation of an auditGatekeepers must submit an independently audited description of consumer-profiling techniques used across their services.
Chapter IV — Market Investigation Arts. 16–19
- Opening of a market investigationThe Commission may open a market investigation to designate gatekeepers, examine systematic non-compliance, or look at new services and practices.
- Market investigation for designating gatekeepersSets the procedure for a market investigation designating a gatekeeper, or one that does not yet meet all thresholds.
- Market investigation into systematic non-complianceWhere a gatekeeper has systematically infringed and further entrenched its position, the Commission may impose behavioural or structural remedies.
- Market investigation into new services and new practicesThe Commission may investigate whether services should be added to the list of core platform services, or whether new practices should be caught.
Chapter V — Investigative, Enforcement and Monitoring Powers Arts. 20–43
- Opening of proceedingsThe Commission may open proceedings with a view to adopting a non-compliance, remedy or specification decision.
- Requests for informationThe Commission may require undertakings to supply information, including access to databases and algorithms, within a set period.
- Power to carry out interviews and take statementsThe Commission may interview any person consenting to be interviewed for the purpose of collecting information.
- Powers to conduct inspectionsThe Commission may conduct on-site inspections, examine records, take copies, seal premises and ask for explanations.
- Interim measuresIn cases of urgency due to the risk of serious and irreparable damage to business or end users, the Commission may order interim measures.
- CommitmentsThe Commission may make commitments offered by a gatekeeper binding, and reopen proceedings if they are not honoured.
- Monitoring of obligations and measuresThe Commission takes the measures needed to monitor effective implementation, and may appoint external experts and auditors.
- Information by third partiesThird parties, including business users and competitors, may inform national authorities or the Commission of gatekeeper practices.
- Compliance functionGatekeepers must establish an independent compliance function with sufficient authority, resources and direct reporting to management.
- Non-complianceThe Commission may adopt a non-compliance decision setting out the infringement and the measures required to end it.
- FinesFines reach up to 10% of global annual turnover, or 20% for a repeated infringement of the same obligation.
- Periodic penalty paymentsThe Commission may impose periodic penalties of up to 5% of average daily global turnover to compel compliance.
- Limitation periods for the imposition of penaltiesThe Commission’s power to impose penalties is subject to limitation periods of three or five years, depending on the infringement.
- Limitation periods for the enforcement of penaltiesThe Commission’s power to enforce penalties already imposed is subject to a five-year limitation period.
- Right to be heard and access to the fileBefore an adverse decision, the undertaking must be heard and given access to the file, subject to business secrets.
- Annual reportingThe Commission must report annually to the Parliament and the Council on the enforcement of the Regulation.
- Professional secrecyInformation collected under the Regulation is covered by professional secrecy and may only be used for the purpose for which it was gathered.
- Cooperation with national authoritiesThe Commission and national authorities must cooperate and coordinate their enforcement actions.
- Cooperation and coordination with national competent authorities enforcing competition rulesSets out coordination with national competition authorities, which may investigate gatekeeper conduct under national competition law.
- Cooperation with national courtsNational courts applying the Regulation may ask the Commission for information or an opinion, and must avoid conflicting decisions.
- The high-level groupEstablishes a high-level group of European regulatory bodies and networks to advise the Commission.
- Request for a market investigationThree or more Member States may request the Commission to open a market investigation.
- Representative actionsAdds the Regulation to the representative actions regime, so qualified entities can act for consumers.
- Reporting of breaches and protection of reporting personsWhistleblower protection under Directive (EU) 2019/1937 applies to reporting infringements of this Regulation.
Chapter VI — Final Provisions Arts. 44–54
- Publication of decisionsThe Commission publishes its decisions, having regard to the legitimate interest in protecting confidential information.
- Review by the Court of JusticeThe Court of Justice has unlimited jurisdiction to review decisions imposing fines or periodic penalty payments.
- Implementing provisionsThe Commission may adopt implementing acts on the practical arrangements for proceedings under the Regulation.
- GuidelinesThe Commission may issue guidelines on the application of the Regulation to help gatekeepers comply.
- StandardisationStandardisation bodies may be asked to develop standards facilitating compliance, particularly on interoperability.
- Exercise of the delegationSets the conditions and duration of the Commission’s delegated powers, subject to revocation and objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
- Amendment to Directive (EU) 2019/1937Amends the Whistleblower Directive to cover reporting under this Regulation.
- Amendment to Directive (EU) 2020/1828Adds this Regulation to the instruments covered by representative actions for consumers.
- ReviewThe Commission must evaluate the Regulation and report, and thereafter every three years.
- Entry into force and applicationEntered into force on 1 November 2022 and applies from 2 May 2023.
Read every post tagged Digital Markets Act →
Data Act Regulation (EU) 2023/2854
Chapter I — General Provisions Arts. 1–2
- Subject matter and scopeSets harmonised rules on access to and use of data generated by connected products and related services, and on switching between cloud services.
- DefinitionsDefines data, connected product, related service, data holder, data recipient, user, and data processing service.
Chapter II — Business to Consumer and Business to Business Data Sharing Arts. 3–7
- Obligation to make product data and related service data accessible to the userConnected products and related services must be designed so that the data they generate is accessible to the user by default, easily and securely.
- The rights and obligations of users and data holders with regard to access, use and making available product data and related service dataWhere data is not directly accessible, the data holder must make it available to the user without undue delay, free of charge, and may not use non-personal data to compete with the user.
- Right of the user to share data with third partiesThe user may require the data holder to share the data with a third party of the user’s choosing, on the same terms.
- Obligations of third parties receiving data at the request of the userThird parties may only process the data for the purposes agreed with the user, must not profile them, and must not pass the data to gatekeepers.
- Scope of business-to-consumer and business-to-business data sharing obligationsMicroenterprises and small enterprises acting as data holders are exempt from the access obligations in this Chapter.
Chapter III — Obligations for Data Holders Obliged to Make Data Available Pursuant to Union Law Arts. 8–12
- Conditions under which data holders make data available to data recipientsWhere Union law obliges a data holder to make data available, it must do so on fair, reasonable, non-discriminatory and transparent terms.
- Compensation for making data availableCompensation agreed between data holder and recipient must be non-discriminatory and reasonable, and cost-based where the recipient is an SME.
- Dispute settlementMember States must make certified dispute settlement bodies available for disagreements over data access and compensation.
- Technical protection measures on the unauthorised use or disclosure of dataData holders may apply technical protection measures, but not to hinder the user’s rights; misuse of unlawfully obtained data triggers remedies.
- Scope of obligations for data holders obliged pursuant to Union law to make data availableClarifies that this Chapter’s conditions apply only where another Union act obliges a data holder to make data available.
Chapter IV — Unfair Contractual Terms Related to Data Access and Use Between Enterprises Art. 13
- Unfair contractual terms unilaterally imposed on another enterpriseA contractual term on data access unilaterally imposed on another enterprise is not binding if it is unfair, with a blacklist and a greylist of terms.
Chapter V — Making Data Available to Public Sector Bodies, the Commission, the European Central Bank and Union Bodies on the Basis of an Exceptional Need Arts. 14–22
- Obligation to make data available on the basis of an exceptional needData holders must make data available to public sector bodies and Union institutions where an exceptional need is demonstrated.
- Exceptional need to use dataExceptional need exists to respond to a public emergency, or where the lack of data prevents a public body from fulfilling a specific task in the public interest.
- Relationship with other obligations to make data available to public sector bodies, the Commission, the European Central Bank and Union bodiesPreserves other Union and national obligations to make data available to public bodies for statistical or reporting purposes.
- Requests for data to be made availableRequests must be proportionate, specify the data needed and the purpose, be publicly available online, and state the retention period.
- Compliance with requests for dataData holders must comply without undue delay, and may decline or seek modification of a request on stated grounds.
- Obligations of public sector bodies, the Commission, the European Central Bank and Union bodiesPublic bodies may not use the data for other purposes, must delete it once the need ends, and must keep it secure.
- Compensation in cases of an exceptional needData must be supplied free of charge in a public emergency; otherwise the holder is entitled to compensation covering the cost plus a reasonable margin.
- Sharing of data obtained in the context of an exceptional need with research organisations or statistical bodiesPublic bodies may share data obtained under an exceptional need with research organisations or statistical bodies carrying out compatible tasks.
- Mutual assistance and cross-border cooperationSets the cross-border cooperation and mutual assistance arrangements between authorities handling exceptional-need requests.
Chapter VI — Switching Between Data Processing Services Arts. 23–31
- Removing obstacles to effective switchingProviders of data processing services must remove commercial, technical, contractual and organisational obstacles to switching to another provider.
- Scope of the technical obligationsClarifies which technical switching obligations apply to which categories of data processing service.
- Contractual terms concerning switchingContracts must set out a maximum transition period of 30 days, a 30-day minimum retrieval period, and an exhaustive list of exportable data.
- Information obligation of providers of data processing servicesProviders must give customers clear information about available switching procedures, formats and any assistance.
- Obligation of good faithAll parties must cooperate in good faith to make switching effective, timely and secure.
- Contractual transparency obligations on international access and transferProviders must publish where their infrastructure is located and set out the measures taken against unlawful international access to non-personal data.
- Gradual withdrawal of switching chargesSwitching charges were to be reduced and then withdrawn entirely from 12 January 2027, leaving only cost-based early-termination charges.
- Technical aspects of switchingSets the interoperability and functional-equivalence obligations that make switching technically possible.
- Specific regime for certain data processing servicesCertain services whose main features are largely bespoke, or supplied for testing, benefit from a lighter regime.
Chapter VII — Unlawful International Governmental Access and Transfer of Non-personal Data Art. 32
- International governmental access and transferProviders must take all reasonable measures to prevent international governmental access to non-personal data that would conflict with Union or Member State law.
Chapter VIII — Interoperability Arts. 33–36
- Essential requirements regarding interoperability of data, of data sharing mechanisms and services, as well as of common European data spacesSets essential requirements for the interoperability of data, data-sharing mechanisms and common European data spaces.
- Interoperability for the purposes of in-parallel use of data processing servicesProviders must ensure interoperability for the in-parallel use of several data processing services.
- Interoperability of data processing servicesOpen interoperability specifications and harmonised standards for data processing services are to be developed and published.
- Essential requirements regarding smart contracts for executing data sharing agreementsSmart contracts used to execute data sharing agreements must be robust, safely terminable, archivable and access-controlled.
Chapter IX — Implementation and Enforcement Arts. 37–42
- Competent authorities and data coordinatorsMember States must designate competent authorities and a data coordinator to enforce the Regulation.
- Right to lodge a complaintNatural and legal persons may lodge a complaint with the competent authority of their Member State.
- Right to an effective judicial remedyAffected parties have the right to an effective judicial remedy against decisions of competent authorities.
- PenaltiesMember States lay down effective, proportionate and dissuasive penalties; GDPR fines apply where personal data is involved.
- Model contractual terms and standard contractual clausesThe Commission develops non-binding model contractual terms for data access and standard clauses for cloud contracts.
- Role of the EDIBThe European Data Innovation Board advises and assists the Commission on the consistent application of the Regulation.
Chapter X — Sui Generis Right Under Directive 96/9/ec Art. 43
- Databases containing certain dataThe sui generis database right does not apply to databases containing data obtained from or generated by connected products, closing an obstacle to data access.
Chapter XI — Final Provisions Arts. 44–50
- Other Union legal acts governing rights and obligations on data access and usePreserves other Union acts governing data access and use, which continue to apply alongside this Regulation.
- Exercise of the delegationSets the conditions and duration of the Commission’s delegated powers, subject to revocation and objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
- Amendment to Regulation (EU) 2017/2394Adds this Regulation to the Consumer Protection Cooperation Regulation’s annex.
- Amendment to Directive (EU) 2020/1828Adds this Regulation to the instruments covered by representative actions for consumers.
- Evaluation and reviewThe Commission must evaluate the Regulation and report to the Parliament, the Council and the Economic and Social Committee.
- Entry into force and applicationEntered into force on 11 January 2024 and applies from 12 September 2025, with the design obligations applying later.
Read every post tagged Data Act →
NIS2 Directive Directive (EU) 2022/2555
Chapter I — General Provisions Arts. 1–6
- Subject matterLays down measures to achieve a high common level of cybersecurity across the Union, replacing the original NIS Directive.
- ScopeApplies to public and private entities in the sectors listed in the Annexes that qualify as medium-sized or larger, with sector-specific exceptions.
- Essential and important entitiesSplits entities into essential and important, which determines how intensively they are supervised and how large the fines can be.
- Sector-specific Union legal actsWhere a sector-specific Union act imposes at least equivalent cybersecurity duties, that act applies instead of the corresponding NIS2 provisions.
- Minimum harmonisationMember States may adopt stricter national requirements than the minimum set here.
- DefinitionsDefines network and information system, cybersecurity, incident, near miss, significant incident and other core terms.
Chapter II — Coordinated Cybersecurity Frameworks Arts. 7–13
- National cybersecurity strategyEach Member State must adopt a national cybersecurity strategy setting objectives, governance and policies, and review it regularly.
- Competent authorities and single points of contactMember States must designate cybersecurity competent authorities and a single point of contact exercising a liaison function.
- National cyber crisis management frameworksMember States must adopt a national plan for responding to large-scale cybersecurity incidents and crises, and designate crisis management authorities.
- Computer security incident response teams (CSIRTs)Each Member State must designate one or more CSIRTs, adequately resourced, covering all sectors within scope.
- Requirements, technical capabilities and tasks of CSIRTsCSIRTs must ensure high availability, secure premises and business continuity, and carry out incident monitoring, early warning, response and risk analysis.
- Coordinated vulnerability disclosure and a European vulnerability databaseMember States must designate a CSIRT as coordinator for vulnerability disclosure; ENISA develops and maintains a European vulnerability database.
- Cooperation at national levelCompetent authorities, single points of contact and CSIRTs within a Member State must cooperate with each other and with law enforcement and data protection authorities.
Chapter III — Cooperation at Union and International Level Arts. 14–19
- Cooperation GroupEstablishes the Cooperation Group to support strategic cooperation and information exchange between Member States.
- CSIRTs networkEstablishes the CSIRTs network to promote swift and effective operational cooperation between national CSIRTs.
- European cyber crisis liaison organisation network (EU-CyCLONe)Establishes EU-CyCLONe to support the coordinated management of large-scale cybersecurity incidents and crises at operational level.
- International cooperationThe Union may conclude international agreements with third countries or international organisations on cybersecurity cooperation.
- Report on the state of cybersecurity in the UnionENISA must adopt a biennial report on the state of cybersecurity in the Union, including a cybersecurity index.
- Peer reviewsThe Cooperation Group establishes methodology for voluntary peer reviews of Member States’ cybersecurity policies.
Chapter IV — Cybersecurity Risk-management Measures and Reporting Obligations Arts. 20–25
- GovernanceManagement bodies must approve the cybersecurity risk-management measures, oversee implementation, can be held liable, and must follow training.
- Cybersecurity risk-management measuresEntities must take appropriate, proportionate technical, operational and organisational measures — covering risk analysis, incident handling, business continuity, supply chain security, encryption, access control and multi-factor authentication.
- Union level coordinated security risk assessments of critical supply chainsThe Cooperation Group, with the Commission and ENISA, may carry out coordinated security risk assessments of critical ICT supply chains.
- Reporting obligationsSignificant incidents must be reported to the CSIRT: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.
- Use of European cybersecurity certification schemesMember States may require entities to use ICT products certified under European cybersecurity certification schemes.
- StandardisationMember States must promote the use of European and international standards relevant to network and information security.
Chapter V — Jurisdiction and Registration Arts. 26–28
- Jurisdiction and territorialityEntities generally fall under the jurisdiction of the Member State where they are established, with specific rules for DNS, cloud and digital providers.
- Registry of entitiesENISA maintains a registry of certain digital infrastructure and digital service entities, based on information supplied by Member States.
- Database of domain name registration dataTLD registries and domain registration service providers must collect and maintain accurate registration data and give lawful access to legitimate requesters.
Chapter VI — Information Sharing Arts. 29–30
- Cybersecurity information-sharing arrangementsEntities may exchange relevant cybersecurity information among themselves on a voluntary basis, including threats, vulnerabilities and indicators of compromise.
- Voluntary notification of relevant informationMember States must allow entities, including those outside the Directive’s scope, to notify significant incidents, cyber threats and near misses voluntarily.
Chapter VII — Supervision and Enforcement Arts. 31–37
- General aspects concerning supervision and enforcementCompetent authorities must supervise and enforce the Directive, and cooperate with data protection authorities where an incident involves personal data.
- Supervisory and enforcement measures in relation to essential entitiesEssential entities face ex ante and ex post supervision: on-site inspections, security audits, scans, information requests and access to evidence.
- Supervisory and enforcement measures in relation to important entitiesImportant entities face only ex post supervision, triggered by evidence or an indication of non-compliance.
- General conditions for imposing administrative fines on essential and important entitiesFines reach at least 10 million euro or 2% of global annual turnover for essential entities, and 7 million euro or 1.4% for important entities.
- Infringements entailing a personal data breachWhere an infringement also involves a personal data breach, the cybersecurity authority must inform the data protection authority, which may fine instead.
- PenaltiesMember States must lay down effective, proportionate and dissuasive penalties for infringements of the national transposing rules.
- Mutual assistanceCompetent authorities must assist each other across borders, including through joint supervisory action.
Chapter VIII — Delegated and Implementing Acts Arts. 38–39
- Exercise of the delegationSets the conditions and duration of the Commission’s delegated powers, subject to revocation and objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
Chapter IX — Final Provisions Arts. 40–46
- ReviewThe Commission must review the functioning of the Directive periodically and report to the Parliament and the Council.
- TranspositionMember States had to transpose the Directive into national law by 17 October 2024.
- Amendment of Regulation (EU) No 910/2014Amends the eIDAS Regulation to align trust service provider security requirements with this Directive.
- Amendment of Directive (EU) 2018/1972Amends the European Electronic Communications Code, moving telecoms security requirements into this Directive.
- RepealRepeals the original NIS Directive (EU) 2016/1148 with effect from 18 October 2024.
- Entry into forceThe Directive entered into force on the twentieth day following its publication in the Official Journal.
- AddresseesThe Directive is addressed to the Member States.
Read every post tagged NIS2 Directive →
Data Governance Act Regulation (EU) 2022/868
Chapter I — General Provisions Arts. 1–2
- Subject matter and scopeSets conditions for re-using certain protected public sector data, a notification regime for data intermediation services, and a framework for data altruism.
- DefinitionsDefines data, re-use, data holder, data user, data intermediation service, data altruism and metadata.
Chapter II — Re-use of Certain Categories of Protected Data Held by Public Sector Bodies Arts. 3–9
- Categories of dataCovers public sector data protected by commercial or statistical confidentiality, intellectual property, or personal data protection.
- Prohibition of exclusive arrangementsExclusive arrangements over the re-use of public sector data are prohibited, save where justified for a service in the public interest.
- Conditions for re-useRe-use conditions must be non-discriminatory, proportionate and objectively justified, and preserve the protected nature of the data.
- FeesFees for re-use must be transparent, non-discriminatory and limited to the costs incurred, with reductions for SMEs, start-ups and research.
- Competent bodiesMember States must designate competent bodies to assist public sector bodies with re-use requests.
- Single information pointsEach Member State must run a single information point directing re-users to available datasets and their conditions.
- Procedure for requests for re-useRe-use requests must be decided within two months, with reasons given and a right of challenge.
Chapter III — Requirements Applicable to Data Intermediation Services Arts. 10–15
- Data intermediation servicesSets out the three categories of data intermediation service subject to the notification regime.
- Notification by data intermediation services providersProviders must notify the competent authority before starting, and may then declare themselves a recognised data intermediation service provider in the Union.
- Conditions for providing data intermediation servicesIntermediaries must be structurally separate from other services, act neutrally, may not use the data for their own ends, and must apply fair, transparent, non-discriminatory terms.
- Competent authorities for data intermediation servicesMember States must designate authorities to monitor data intermediation services, meeting independence requirements.
- Monitoring of complianceAuthorities monitor compliance, may require information, and can require an intermediary to cease providing the service.
- ExceptionsThe regime does not apply to services that only intermediate copyright-protected content.
Chapter IV — Data Altruism Arts. 16–25
- National arrangements for data altruismMember States may put in place policies and arrangements to support voluntary data sharing for objectives of general interest.
- Public registers of recognised data altruism organisationsEach Member State must keep a public register of recognised data altruism organisations.
- General requirements for registrationRegistration requires a not-for-profit legal person, operating on a functionally separate basis, pursuing objectives of general interest.
- Registration of recognised data altruism organisationsSets the registration procedure and the information an applicant must provide.
- Transparency requirementsRegistered organisations must keep records of data use and publish annual activity reports.
- Specific requirements to safeguard rights and interests of data subjects and data holders with regard to their dataOrganisations must inform data subjects and data holders of the general-interest purposes, any third-country processing, and must not use the data for other ends.
- RulebookThe Commission adopts delegated acts setting a rulebook on information requirements, security and interoperability for data altruism.
- Competent authorities for the registration of data altruism organisationsMember States must designate authorities responsible for the registration of data altruism organisations.
- Monitoring of complianceAuthorities monitor compliance and may require an organisation to remedy a breach or be removed from the register.
- European data altruism consent formThe Commission adopts a European data altruism consent form, allowing consent to be collected and withdrawn in a uniform way.
Chapter V — Competent Authorities and Procedural Provisions Arts. 26–28
- Requirements relating to competent authoritiesCompetent authorities must be legally distinct and functionally independent, and exercise their powers impartially and transparently.
- Right to lodge a complaintNatural and legal persons may lodge a complaint with the relevant competent authority.
- Right to an effective judicial remedyAny affected party has the right to an effective judicial remedy against a decision of a competent authority.
Chapter VI — European Data Innovation Board Arts. 29–30
- European Data Innovation BoardEstablishes the European Data Innovation Board as a Commission expert group with Member State and stakeholder representation.
- Tasks of the European Data Innovation BoardThe Board advises on cross-sector standardisation, interoperability, and consistent practice for intermediation and data altruism.
Chapter VII — International Access and Transfer Art. 31
- International access and transferPublic sector bodies, intermediaries and altruism organisations must take safeguards against unlawful international access to non-personal data, mirroring the GDPR’s transfer logic.
Chapter VIII — Delegation and Committee Procedure Arts. 32–33
- Exercise of the delegationSets the conditions and duration of the Commission’s delegated powers, subject to revocation and objection.
- Committee procedureThe Commission is assisted by a committee within the meaning of the Union’s comitology rules.
Chapter IX — Final and Transitional Provisions Arts. 34–38
- PenaltiesMember States lay down effective, proportionate and dissuasive penalties, taking account of the nature and duration of the infringement.
- Evaluation and reviewThe Commission must evaluate the Regulation and report to the Parliament and the Council.
- Amendment to Regulation (EU) 2018/1724Amends the Single Digital Gateway Regulation to add the single information points.
- Transitional arrangementsExisting data intermediation providers had until 24 September 2025 to comply with the notification obligations.
- Entry into force and applicationEntered into force on 23 June 2022 and applies from 24 September 2023.
Read every post tagged Data Governance Act →
Copyright in the Digital Single Market Directive (EU) 2019/790
Chapter I — General Provisions Arts. 1–2
- Subject matter and scopeSets rules adapting Union copyright to the digital and cross-border environment, alongside the existing copyright directives.
- DefinitionsDefines research organisation, cultural heritage institution, text and data mining, press publication and online content-sharing service provider.
Chapter II — Measures to Adapt Exceptions and Limitations to the Digital and Cross-border Environment Arts. 3–7
- Text and data mining for the purposes of scientific researchResearch organisations and cultural heritage institutions may mine text and data from works they lawfully access, for scientific research, and this cannot be contracted away.
- Exception or limitation for text and data miningA general text-and-data-mining exception applies to anyone with lawful access, but rightholders may expressly reserve their rights — the basis of the AI training opt-out.
- Use of works and other subject matter in digital and cross-border teaching activitiesPermits digital use of works for illustration in teaching, under the responsibility of an educational establishment and on secure networks.
- Preservation of cultural heritageCultural heritage institutions may copy works permanently in their collections for preservation purposes.
- Common provisionsContract terms overriding these exceptions are unenforceable, and the exceptions interact with technological protection measures.
Chapter III — Measures to Improve Licensing Practices and Ensure Wider Access to Content Arts. 8–14
- Use of out-of-commerce works and other subject matter by cultural heritage institutionsCultural heritage institutions may make out-of-commerce works in their collections available, under a collective licence or a fallback exception.
- Cross-border usesLicences granted under the out-of-commerce regime may cover use in any Member State.
- Publicity measuresRightholders must be given a permanent, public information portal at EU level at least six months before out-of-commerce use begins.
- Stakeholder dialogueMember States must consult stakeholders regularly on the practical operation of the out-of-commerce provisions.
- Collective licensing with an extended effectAllows collective licences with an extended effect, binding rightholders who have not mandated the collecting society, with safeguards and an opt-out.
- Negotiation mechanismMember States must provide an impartial body to assist negotiations where parties cannot agree on licensing audiovisual works for video-on-demand.
- Works of visual art in the public domainFaithful reproductions of visual works whose copyright has expired are not themselves protected, so public-domain art stays in the public domain.
Chapter IV — Measures to Achieve a Well-functioning Marketplace for Copyright Arts. 15–23
- Protection of press publications concerning online usesGives press publishers a two-year related right over online use of their publications by information society services; hyperlinks and very short extracts are excluded.
- Claims to fair compensationMember States may provide that publishers share in the fair compensation paid for uses under an exception.
- Use of protected content by online content-sharing service providersContent-sharing platforms perform an act of communication to the public and must seek authorisation, or make best efforts to obtain it and to prevent re-uploads — with complaint and redress mechanisms.
- Principle of appropriate and proportionate remunerationAuthors and performers are entitled to appropriate and proportionate remuneration when they license or transfer their exclusive rights.
- Transparency obligationAuthors and performers must receive regular, up-to-date information on how their works are exploited and what revenue they generate.
- Contract adjustment mechanismWhere remuneration turns out disproportionately low compared with the revenues generated, authors and performers may claim additional, fair remuneration.
- Alternative dispute resolution procedureDisputes on transparency and contract adjustment may be submitted to a voluntary alternative dispute resolution procedure.
- Right of revocationAuthors and performers may revoke a licence or transfer of an exclusive right where the work is not being exploited.
- Common provisionsContract terms preventing compliance with the remuneration, transparency and revocation provisions are unenforceable.
Chapter V — Final Provisions Arts. 24–32
- Amendments to Directives 96/9/EC and 2001/29/ECAmends the Database Directive and the InfoSoc Directive to align them with this Directive.
- Relationship with exceptions and limitations provided for in other directivesMember States may adopt broader exceptions for the uses covered here, compatible with the earlier directives.
- Application in timeApplies to all works still protected on 7 June 2021, without prejudice to acts concluded and rights acquired before that date.
- Transitional provisionTransparency and contract-adjustment obligations apply to existing contracts from 7 June 2022.
- Protection of personal dataAny processing of personal data under this Directive must comply with the ePrivacy Directive and the GDPR.
- TranspositionMember States had to transpose the Directive into national law by 7 June 2021.
- ReviewThe Commission must review the Directive and report, in particular on the press publishers’ right and the platform provisions.
- Entry into forceThe Directive entered into force on the twentieth day following its publication in the Official Journal.
- AddresseesThe Directive is addressed to the Member States.
Read every post tagged Copyright in the Digital Single Market →

