Digital Services Act25 Sep 2026
Detected guidance relating to Digital Services Act: “Fifth Roundtable with Civil Society Organisations and Researchers on the implementation of the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Digital Services Act25 Sep 2026
Detected guidance relating to Digital Services Act: “European Board for Digital Services adopts good practices to notify suspected criminal offences under the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Framework to be determined23 Sep 2026
Detected enforcement from EDPB: “The Irish Data Protection Commission fines Google 403 000 000 EUR following Inquiry into Google’s processing of location data”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
Framework to be determined22 Sep 2026
Detected guidance from EDPB: “Guidelines 3/2025 on the interplay between the DSA and the GDPR”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
Framework to be determined21 Sep 2026
Detected guidance from EDPB: “EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
GDPR21 Sep 2026
Detected enforcement relating to GDPR: “Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: No direct compliance change follows from this enforcement action against a platform. Review it for enforcement context and note any implications relevant to your services.
Legal status: EU guidance · Jurisdiction: EU
Cyber Resilience Act11 Sep 2026
Detected guidance relating to Cyber Resilience Act: “The CRA Single Reporting Platform is launched”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
GDPR3 Sep 2026
Detected caselaw relating to GDPR: “Judgment of the Court (First Chamber) of 3 September 2026. — A et autres v Latvijas Republikas Saeima. — Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing of personal data – Article 6 – Lawfulness of processing – Company law – Directive (EU) 2017/1132 – Article 14 – Documents and particulars to be disclosed – Concept of ‘persons who take part in the administration, supervision or control of a company’ – Making available to the public personal data relating to the shareholders of public limited liability companies – Minority shareholders. — Case C-798/24.”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this ruling for implications on your AI systems' legal basis and record the outcome in your compliance dossier.
Legal status: Case law · Jurisdiction: EU
Digital Services Act31 Aug 2026
Detected guidance relating to Digital Services Act: “Commission designates ChatGPT, Reddit, Roblox under Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
AI Act22 Aug 2026
Detected guidance relating to AI Act: “Dialogue on the AI Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: National guidance or authority · Jurisdiction: NL
Cyber Resilience Act22 Aug 2026
Detected guidance relating to Cyber Resilience Act: “Technical Competence Requirements for CRA Notified Bodies”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Cyber Resilience Act22 Aug 2026
Detected guidance relating to Cyber Resilience Act: “SME CRA Survey Report”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Framework to be determined22 Aug 2026
Detected guidance from ENISA: “Procurement guidelines for the cybersecurity of hospitals and healthcare providers”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
NIS222 Aug 2026
Detected guidance relating to NIS2: “NIS2 Technical Implementation Guidance”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your incident-reporting or resilience obligations and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Framework to be determined22 Aug 2026
Detected guidance from EDPB: “Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
GDPR22 Aug 2026
Detected guidance relating to GDPR: “Guidelines 02/2024 on Article 48 GDPR”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your personal-data processing and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Cyber Resilience Act22 Aug 2026
Detected guidance relating to Cyber Resilience Act: “Commission publishes new guidance to support timely Cyber Resilience Act implementation”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
AI Act22 Aug 2026Art. 50
Detected guidance relating to AI Act: “Guidelines on transparency obligations for providers and deployers of AI systems”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
AI Act17 Aug 2026
Detected law relating to AI Act: “Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Text with EEA relevance)”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: Legislation · Jurisdiction: EU
AI Act17 Aug 2026
Detected guidance relating to AI Act: “AI Omnibus enters into force”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
AI Act3 Aug 2026Art. 53, Art. 55
Detected guidance relating to AI Act: “Fourth GPAI Signatory Taskforce meeting”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
AI Act31 Jul 2026Art. 50
European Commission communication marking the start of enforcement of the AI Act from 2 August 2026 — including the Article 50 transparency obligations for chatbots and AI-generated content and the general-purpose AI (GPAI) obligations. See the primary source for scope and detail.
What to do: If you operate chatbots, generate AI content or provide/deploy general-purpose AI, confirm your Article 50 transparency measures and GPAI obligations are in place — they now apply.
Legal status: EU guidance · Jurisdiction: EU
AI Act31 Jul 2026Art. 50(2), Art. 50(4)
European Commission announcement of strong stakeholder backing for the Code of Practice on the transparency of AI-generated content, which supports the Article 50 marking and disclosure obligations. See the primary source for detail.
What to do: If you generate or deploy AI-generated content, review the Code of Practice as a route to demonstrate compliance with the Article 50 transparency duties.
Legal status: EU guidance · Jurisdiction: EU
GDPR27 Jul 2026Art. 2, Art. 5, Art. 6, Art. 9, Art. 10
Court of Justice (Grand Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): material scope (Article 2), the principles relating to processing and its lawfulness (Articles 5 and 6), the concept of data concerning health (Article 9) and personal data relating to criminal convictions (Article 10). See the primary source for the Court's operative findings.
What to do: If you process health data or data on criminal convictions under the GDPR, read this ruling against your lawful-basis and special-category analysis and record whether any change is needed.
Legal status: Case law · Jurisdiction: EU
GDPR27 Jul 2026
Court of Justice (Fifth Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): its scope where information on criminal convictions is made available to the public online in return for remuneration, and reconciling the right to protection of personal data with the right to freedom of expression and information. See the primary source for the Court's operative findings.
What to do: If your service publishes personal data, including data on criminal convictions, weigh this ruling against your data-protection and freedom-of-expression balancing and record whether any change is needed.
Legal status: Case law · Jurisdiction: EU
Cyber Resilience Act27 Jul 2026
European Commission guidance to help businesses implement the Cyber Resilience Act (Regulation (EU) 2024/2847). See the primary source for the full guidance.
What to do: If you make products with digital elements in scope of the CRA, read this guidance against your implementation plan and record whether any change is needed.
Legal status: EU guidance · Jurisdiction: EU
Digital Services Act24 Jul 2026
Preliminary finding by the European Commission that TikTok breaches the Digital Services Act by failing to ensure safe accounts for minors. This is a preliminary finding, not a final decision; TikTok can respond before the Commission concludes. See the primary source for details.
What to do: If you operate an online platform under the DSA, note this enforcement direction on the safety of minors and review your own measures.
Legal status: Other or unclassified · Jurisdiction: EU
GDPR23 Jul 2026Art. 33
The EDPB adopted a common data breach notification template to harmonise GDPR Article 33 breach notifications across the EU.
What to do: If you process personal data, align your breach-notification process with the common template. Review the primary source.
Legal status: EU guidance · Jurisdiction: EU
GDPR23 Jul 2026
Detected guidance relating to GDPR: “EDPB calls for legal basis for cross-regulatory information sharing”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your personal-data processing and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Digital Services Act23 Jul 2026
Detected guidance relating to Digital Services Act: “Commission accepts X's corrective measures to terminate breaches of the DSA”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Digital Services Act23 Jul 2026
Detected guidance relating to Digital Services Act: “Commission accepts X’s action plan to comply with Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
AI Act21 Jul 2026
Commission Implementing Regulation (EU) 2026/1755 sets detailed procedural arrangements for how the Commission conducts certain proceedings under the AI Act (Regulation (EU) 2024/1689). Published in the Official Journal.
What to do: Relevant if the Commission may open proceedings on your AI systems. Note the procedural rules and review the primary source.
Legal status: Legislation · Jurisdiction: EU
AI Act20 Jul 2026Art. 50
Detected guidance relating to ai act: “Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Digital Services Act20 Jul 2026
Detected enforcement relating to Digital Services Act: “Commission fines AliExpress €550 million for breaching the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: No direct compliance change follows from this enforcement action against a platform. Review it for DSA enforcement context and note any implications relevant to your services.
Legal status: Other or unclassified · Jurisdiction: EU
GDPR17 Jul 2026Art. 6, Art. 9(2)
On 8 July 2026 the EDPB published guidance on when data counts as anonymous and how the GDPR applies to web scraping used to train generative AI. Data is anonymous only if individuals cannot be singled out, linked across records, or inferred - and that assessment can differ per recipient. Scraping personal data must respect purpose limitation, transparency, accuracy and data minimisation, and special-category data still needs both an Article 6 lawful basis and an Article 9(2) exception. The anonymisation and web-scraping guidelines are open for public consultation until 30 October 2026 and may still change; the accompanying blockchain guidelines were adopted in final form.
What to do: If you train or fine-tune generative AI on scraped or web-sourced data, document the Article 6 lawful basis and confirm no special-category data is used without an Article 9(2) exception. Re-test any data you treat as anonymised against the singling-out, linkability and inference criteria. Keep records of purpose limitation, source reliability (timestamps), accuracy validation and data-minimisation measures for your scraping pipeline.
Legal status: EU guidance · Jurisdiction: EU
NIS29 Jul 2026
An enforcement action related to NIS2/cybersecurity regulation: “Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity”. See the primary source for the authoritative text.
What to do: No direct action for your own systems — this is an enforcement step against a Member State, not a new obligation. Note it for awareness only.
Legal status: Other or unclassified · Jurisdiction: EU
NIS29 Jul 2026
ENISA published NIS2 implementation guidance: NIS2 Technical Implementation Guidance plus a companion on cybersecurity roles and skills for essential and important entities.
What to do: If you are an essential or important entity under NIS2, use this guidance to shape your implementation. Review the primary source.
Legal status: EU guidance · Jurisdiction: EU
AI Act9 Jul 2026Art. 50(2), Art. 50(4)
The Commission published a Code of Practice on marking and labelling AI-generated content. It supports the Article 50 transparency obligations: machine-readable marking and detectability of synthetic content by providers (Art. 50(2)) and disclosure/labelling of AI-generated or manipulated content by deployers (Art. 50(4)).
What to do: If you provide or deploy generative AI, review this Code against your Article 50(2) marking duty (providers) and your Article 50(4) disclosure duty (deployers) and record how you meet them.
Legal status: EU guidance · Jurisdiction: EU
AI Act2 Feb 2025
The ban on AI emotion recognition in the workplace and education applies since 2 February 2025 (Art. 5 AI Act). Enforcement is still nascent — no major formal case yet. Fines for prohibited practices are the highest in the regulation.
What to do: Confirm no system implements an Art. 5 prohibited practice; the penalty ceiling is up to EUR 35 million or 7 percent of worldwide turnover.
Legal status: EU guidance · Jurisdiction: EU
ECHR / fundamental rights5 Feb 2020
The SyRI welfare-fraud risk system breaches Article 8 ECHR: insufficiently transparent and not proportionate. Use prohibited.
What to do: If you run automated risk-profiling on individuals, test it against fundamental-rights safeguards (proportionality, transparency); the court struck down SyRI for lacking them.
Legal status: Case law · Jurisdiction: Netherlands
GDPR1 Dec 2021
Years of unlawful and discriminatory processing of applicants' (dual) nationality for childcare benefits; nationality wrongly used as a risk indicator.
What to do: Review automated profiling for unlawful or discriminatory use of personal data; ensure necessity, proportionality and a clear lawful basis.
Legal status: National guidance or authority · Jurisdiction: Netherlands
GDPR3 Sep 2024
Unlawful database of billions of facial images scraped from the internet for facial recognition, without a valid legal basis; processing of biometric personal data.
What to do: Do not use facial-recognition data obtained by untargeted scraping; where you process biometric data, confirm a valid basis and carry out a DPIA.
Legal status: National guidance or authority · Jurisdiction: Netherlands
GDPR20 Dec 2024
ChatGPT trained on personal data without a valid legal basis, breach of transparency duties, failure to report a data breach (March 2023) and missing age verification.
What to do: If you process personal data through a generative-AI service, verify your lawful basis, your transparency notice to users, and any age checks.
Legal status: National guidance or authority · Jurisdiction: Italy
AI Act19 Nov 2025Art. 6, Annex III
Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. The binding high-risk application dates are 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
What to do: Re-baseline affected systems and contracts against Regulation (EU) 2026/1744, keep non-high-risk workstreams on their applicable dates, and preserve the decision trail from before entry into force.
Legal status: EU guidance · Jurisdiction: EU
AI Act10 Jul 2025art. 53, art. 55
Voluntary code of practice for providers of general-purpose AI models (Art. 53/55), with three chapters: transparency, copyright and safety/security. Signatories (incl. Anthropic, Google, Microsoft, OpenAI, IBM) use it to demonstrate compliance; Meta did not sign.
What to do: If you build on a general-purpose AI model, obtain and keep the provider transparency and copyright information you rely on (Art. 53), and check whether your provider signed the Code.
Legal status: EU guidance · Jurisdiction: EU
AI Act4 Feb 2025art. 5
The Commission's official guidance on the prohibited practices (Art. 5): manipulation, exploitation of vulnerabilities, social scoring, untargeted facial scraping, emotion recognition at work/education, biometric categorisation and certain real-time biometric identification. Non-binding; the CJEU has the final say.
What to do: Check that none of your AI systems fall under the Art. 5 prohibitions (e.g. social scoring, untargeted facial scraping, emotion recognition at work or school); record that assessment.
Legal status: EU guidance · Jurisdiction: EU