Skip to content

Regulatory changelog

What changed in EU digital regulation

A dated, sourced log of EU digital regulation — the AI Act, GDPR, NIS2, DORA, the Data Act, the Cyber Resilience Act and the DSA — covering law, guidance, enforcement and case-law. Every entry links to its primary source.

Coverage last updated 25 Sep 2026 · 46 changes tracked
Digital Services Act25 Sep 2026

Fifth Roundtable with Civil Society Organisations and Researchers on the implementation of the Digital…

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to Digital Services Act: “Fifth Roundtable with Civil Society Organisations and Researchers on the implementation of the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
Digital Services Act25 Sep 2026

European Board for Digital Services adopts good practices to notify suspected criminal offences under the…

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to Digital Services Act: “European Board for Digital Services adopts good practices to notify suspected criminal offences under the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
Framework to be determined23 Sep 2026

The Irish Data Protection Commission fines Google 403 000 000 EUR following Inquiry into Google’s processing…

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected enforcement from EDPB: “The Irish Data Protection Commission fines Google 403 000 000 EUR following Inquiry into Google’s processing of location data”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
Framework to be determined22 Sep 2026

Guidelines 3/2025 on the interplay between the DSA and the GDPR

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance from EDPB: “Guidelines 3/2025 on the interplay between the DSA and the GDPR”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
Framework to be determined21 Sep 2026

EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance from EDPB: “EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
GDPR21 Sep 2026

Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other…

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected enforcement relating to GDPR: “Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: No direct compliance change follows from this enforcement action against a platform. Review it for enforcement context and note any implications relevant to your services.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
Cyber Resilience Act11 Sep 2026

The CRA Single Reporting Platform is launched

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to Cyber Resilience Act: “The CRA Single Reporting Platform is launched”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: ENISA ↗
GDPR3 Sep 2026

Judgment of the Court (First Chamber) of 3 September 2026. — A et autres v Latvijas Republikas Saeima…

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected caselaw relating to GDPR: “Judgment of the Court (First Chamber) of 3 September 2026. — A et autres v Latvijas Republikas Saeima. — Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5 – Principles relating to processing of personal data – Article 6 – Lawfulness of processing – Company law – Directive (EU) 2017/1132 – Article 14 – Documents and particulars to be disclosed – Concept of ‘persons who take part in the administration, supervision or control of a company’ – Making available to the public personal data relating to the shareholders of public limited liability companies – Minority shareholders. — Case C-798/24.”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this ruling for implications on your AI systems' legal basis and record the outcome in your compliance dossier.
Legal status: Case law · Jurisdiction: EU
Official source: CJEU ↗
Digital Services Act31 Aug 2026

Commission designates ChatGPT, Reddit, Roblox under Digital Services Act

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to Digital Services Act: “Commission designates ChatGPT, Reddit, Roblox under Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act22 Aug 2026

Dialogue on the AI Act

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to AI Act: “Dialogue on the AI Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: National guidance or authority · Jurisdiction: NL
Cyber Resilience Act22 Aug 2026

Technical Competence Requirements for CRA Notified Bodies

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to Cyber Resilience Act: “Technical Competence Requirements for CRA Notified Bodies”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: ENISA ↗
Cyber Resilience Act22 Aug 2026

SME CRA Survey Report

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to Cyber Resilience Act: “SME CRA Survey Report”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: ENISA ↗
Framework to be determined22 Aug 2026

Procurement guidelines for the cybersecurity of hospitals and healthcare providers

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance from ENISA: “Procurement guidelines for the cybersecurity of hospitals and healthcare providers”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
Official source: ENISA ↗
NIS222 Aug 2026

NIS2 Technical Implementation Guidance

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to NIS2: “NIS2 Technical Implementation Guidance”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your incident-reporting or resilience obligations and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Official source: ENISA ↗
Framework to be determined22 Aug 2026

Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance from EDPB: “Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive”. Framework not yet determined — open the primary source to see which EU rules apply. Summarised automatically; not yet editorially verified.
What to do: See the primary source to determine which EU framework and obligations apply to you.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
GDPR22 Aug 2026

Guidelines 02/2024 on Article 48 GDPR

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to GDPR: “Guidelines 02/2024 on Article 48 GDPR”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your personal-data processing and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
Cyber Resilience Act22 Aug 2026

Commission publishes new guidance to support timely Cyber Resilience Act implementation

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to Cyber Resilience Act: “Commission publishes new guidance to support timely Cyber Resilience Act implementation”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act22 Aug 2026Art. 50

Guidelines on transparency obligations for providers and deployers of AI systems

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to AI Act: “Guidelines on transparency obligations for providers and deployers of AI systems”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act17 Aug 2026

Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations…

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected law relating to AI Act: “Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Text with EEA relevance)”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: Legislation · Jurisdiction: EU
AI Act17 Aug 2026

AI Omnibus enters into force

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to AI Act: “AI Omnibus enters into force”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act3 Aug 2026Art. 53, Art. 55

Fourth GPAI Signatory Taskforce meeting

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to AI Act: “Fourth GPAI Signatory Taskforce meeting”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act31 Jul 2026Art. 50

Commission starts enforcing AI Act rules and new transparency requirements on 2 August

European Commission communication marking the start of enforcement of the AI Act from 2 August 2026 — including the Article 50 transparency obligations for chatbots and AI-generated content and the general-purpose AI (GPAI) obligations. See the primary source for scope and detail.
What to do: If you operate chatbots, generate AI content or provide/deploy general-purpose AI, confirm your Article 50 transparency measures and GPAI obligations are in place — they now apply.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act31 Jul 2026Art. 50(2), Art. 50(4)

Strong backing for the Code of Practice on Transparency of AI-generated Content

European Commission announcement of strong stakeholder backing for the Code of Practice on the transparency of AI-generated content, which supports the Article 50 marking and disclosure obligations. See the primary source for detail.
What to do: If you generate or deploy AI-generated content, review the Code of Practice as a route to demonstrate compliance with the Article 50 transparency duties.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
GDPR27 Jul 2026Art. 2, Art. 5, Art. 6, Art. 9, Art. 10

Judgment of the Court (Grand Chamber) of 14 July 2026. — AR and Others v Österreichische Datenschutzbehörde…

Court of Justice (Grand Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): material scope (Article 2), the principles relating to processing and its lawfulness (Articles 5 and 6), the concept of data concerning health (Article 9) and personal data relating to criminal convictions (Article 10). See the primary source for the Court's operative findings.
What to do: If you process health data or data on criminal convictions under the GDPR, read this ruling against your lawful-basis and special-category analysis and record whether any change is needed.
Legal status: Case law · Jurisdiction: EU
GDPR27 Jul 2026

Judgment of the Court (Fifth Chamber) of 9 July 2026. — ND v Legal Newsdesk Sweden AB, anciennement…

Court of Justice (Fifth Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): its scope where information on criminal convictions is made available to the public online in return for remuneration, and reconciling the right to protection of personal data with the right to freedom of expression and information. See the primary source for the Court's operative findings.
What to do: If your service publishes personal data, including data on criminal convictions, weigh this ruling against your data-protection and freedom-of-expression balancing and record whether any change is needed.
Legal status: Case law · Jurisdiction: EU
Cyber Resilience Act27 Jul 2026

Commission publishes new guidance to support businesses' implementation of the Cyber Resilience Act

European Commission guidance to help businesses implement the Cyber Resilience Act (Regulation (EU) 2024/2847). See the primary source for the full guidance.
What to do: If you make products with digital elements in scope of the CRA, read this guidance against your implementation plan and record whether any change is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
Digital Services Act24 Jul 2026

Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for…

Preliminary finding by the European Commission that TikTok breaches the Digital Services Act by failing to ensure safe accounts for minors. This is a preliminary finding, not a final decision; TikTok can respond before the Commission concludes. See the primary source for details.
What to do: If you operate an online platform under the DSA, note this enforcement direction on the safety of minors and review your own measures.
Legal status: Other or unclassified · Jurisdiction: EU
Official source: European Commission ↗
GDPR23 Jul 2026

EDPB calls for legal basis for cross-regulatory information sharing

Detected guidance relating to GDPR: “EDPB calls for legal basis for cross-regulatory information sharing”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your personal-data processing and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
Digital Services Act23 Jul 2026

Commission accepts X's corrective measures to terminate breaches of the DSA

Detected guidance relating to Digital Services Act: “Commission accepts X's corrective measures to terminate breaches of the DSA”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
Digital Services Act23 Jul 2026

Commission accepts X’s action plan to comply with Digital Services Act

Detected guidance relating to Digital Services Act: “Commission accepts X’s action plan to comply with Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act21 Jul 2026

Commission Implementing Regulation (EU) 2026/1755 of 20 July 2026 on detailed arrangements for the conduct of…

Commission Implementing Regulation (EU) 2026/1755 sets detailed procedural arrangements for how the Commission conducts certain proceedings under the AI Act (Regulation (EU) 2024/1689). Published in the Official Journal.
What to do: Relevant if the Commission may open proceedings on your AI systems. Note the procedural rules and review the primary source.
Legal status: Legislation · Jurisdiction: EU
AI Act20 Jul 2026Art. 50

Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems

Detected guidance relating to ai act: “Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗ · v20 Jul 2026
Digital Services Act20 Jul 2026

Commission fines AliExpress €550 million for breaching the Digital Services Act

Detected enforcement relating to Digital Services Act: “Commission fines AliExpress €550 million for breaching the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: No direct compliance change follows from this enforcement action against a platform. Review it for DSA enforcement context and note any implications relevant to your services.
Legal status: Other or unclassified · Jurisdiction: EU
Official source: European Commission ↗ · v20 Jul 2026
GDPR17 Jul 2026Art. 6, Art. 9(2)

EDPB: how the GDPR applies to web scraping and anonymisation for generative AI

On 8 July 2026 the EDPB published guidance on when data counts as anonymous and how the GDPR applies to web scraping used to train generative AI. Data is anonymous only if individuals cannot be singled out, linked across records, or inferred - and that assessment can differ per recipient. Scraping personal data must respect purpose limitation, transparency, accuracy and data minimisation, and special-category data still needs both an Article 6 lawful basis and an Article 9(2) exception. The anonymisation and web-scraping guidelines are open for public consultation until 30 October 2026 and may still change; the accompanying blockchain guidelines were adopted in final form.
What to do: If you train or fine-tune generative AI on scraped or web-sourced data, document the Article 6 lawful basis and confirm no special-category data is used without an Article 9(2) exception. Re-test any data you treat as anonymised against the singling-out, linkability and inference criteria. Keep records of purpose limitation, source reliability (timestamps), accuracy validation and data-minimisation measures for your scraping pipeline.
Legal status: EU guidance · Jurisdiction: EU
Official source: EDPB ↗
NIS29 Jul 2026

Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose…

An enforcement action related to NIS2/cybersecurity regulation: “Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity”. See the primary source for the authoritative text.
What to do: No direct action for your own systems — this is an enforcement step against a Member State, not a new obligation. Note it for awareness only.
Legal status: Other or unclassified · Jurisdiction: EU
Official source: European Commission ↗
NIS29 Jul 2026

Supporting NIS2 implementation through actionable guidance

ENISA published NIS2 implementation guidance: NIS2 Technical Implementation Guidance plus a companion on cybersecurity roles and skills for essential and important entities.
What to do: If you are an essential or important entity under NIS2, use this guidance to shape your implementation. Review the primary source.
Legal status: EU guidance · Jurisdiction: EU
Official source: ENISA ↗
AI Act9 Jul 2026Art. 50(2), Art. 50(4)

Commission publishes Code of Practice on marking and labelling AI-generated content

The Commission published a Code of Practice on marking and labelling AI-generated content. It supports the Article 50 transparency obligations: machine-readable marking and detectability of synthetic content by providers (Art. 50(2)) and disclosure/labelling of AI-generated or manipulated content by deployers (Art. 50(4)).
What to do: If you provide or deploy generative AI, review this Code against your Article 50(2) marking duty (providers) and your Article 50(4) disclosure duty (deployers) and record how you meet them.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗
AI Act2 Feb 2025

Prohibition (no formal case yet)

The ban on AI emotion recognition in the workplace and education applies since 2 February 2025 (Art. 5 AI Act). Enforcement is still nascent — no major formal case yet. Fines for prohibited practices are the highest in the regulation.
What to do: Confirm no system implements an Art. 5 prohibited practice; the penalty ceiling is up to EUR 35 million or 7 percent of worldwide turnover.
Legal status: EU guidance · Jurisdiction: EU
Official source: EC / national authorities ↗ · v2 Feb 2025
ECHR / fundamental rights5 Feb 2020

SyRI (Nederlandse staat)

The SyRI welfare-fraud risk system breaches Article 8 ECHR: insufficiently transparent and not proportionate. Use prohibited.
What to do: If you run automated risk-profiling on individuals, test it against fundamental-rights safeguards (proportionality, transparency); the court struck down SyRI for lacking them.
Legal status: Case law · Jurisdiction: Netherlands
Official source: District Court of The Hague ↗ · v5 Feb 2020
GDPR1 Dec 2021

Belastingdienst

Years of unlawful and discriminatory processing of applicants' (dual) nationality for childcare benefits; nationality wrongly used as a risk indicator.
What to do: Review automated profiling for unlawful or discriminatory use of personal data; ensure necessity, proportionality and a clear lawful basis.
Legal status: National guidance or authority · Jurisdiction: Netherlands
Official source: Dutch DPA (AP) ↗ · v1 Dec 2021
GDPR3 Sep 2024

Clearview AI

Unlawful database of billions of facial images scraped from the internet for facial recognition, without a valid legal basis; processing of biometric personal data.
What to do: Do not use facial-recognition data obtained by untargeted scraping; where you process biometric data, confirm a valid basis and carry out a DPIA.
Legal status: National guidance or authority · Jurisdiction: Netherlands
Official source: Dutch DPA (AP) ↗ · v3 Sep 2024
GDPR20 Dec 2024

OpenAI (ChatGPT)

ChatGPT trained on personal data without a valid legal basis, breach of transparency duties, failure to report a data breach (March 2023) and missing age verification.
What to do: If you process personal data through a generative-AI service, verify your lawful basis, your transparency notice to users, and any age checks.
Legal status: National guidance or authority · Jurisdiction: Italy
Official source: Garante (IT) ↗ · v20 Dec 2024
AI Act19 Nov 2025Art. 6, Annex III

Digital Omnibus — high-risk deferral

Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. The binding high-risk application dates are 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
What to do: Re-baseline affected systems and contracts against Regulation (EU) 2026/1744, keep non-high-risk workstreams on their applicable dates, and preserve the decision trail from before entry into force.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Union ↗ · v19 Nov 2025
AI Act10 Jul 2025art. 53, art. 55

GPAI Code of Practice

Voluntary code of practice for providers of general-purpose AI models (Art. 53/55), with three chapters: transparency, copyright and safety/security. Signatories (incl. Anthropic, Google, Microsoft, OpenAI, IBM) use it to demonstrate compliance; Meta did not sign.
What to do: If you build on a general-purpose AI model, obtain and keep the provider transparency and copyright information you rely on (Art. 53), and check whether your provider signed the Code.
Legal status: EU guidance · Jurisdiction: EU
Official source: AI Office / European Commission ↗ · v10 Jul 2025
AI Act4 Feb 2025art. 5

Guidelines on prohibited AI practices

The Commission's official guidance on the prohibited practices (Art. 5): manipulation, exploitation of vulnerabilities, social scoring, untargeted facial scraping, emotion recognition at work/education, biometric categorisation and certain real-time biometric identification. Non-binding; the CJEU has the final say.
What to do: Check that none of your AI systems fall under the Art. 5 prohibitions (e.g. social scoring, untargeted facial scraping, emotion recognition at work or school); record that assessment.
Legal status: EU guidance · Jurisdiction: EU
Official source: European Commission ↗ · v4 Feb 2025