Skip to content

EU data, AI and cybersecurity regulations

GDPR, the AI Act, DORA, NIS2, the Data Act, the Cyber Resilience Act and the rest of the EU digital rulebook.

FewerMore laws

1 countries and blocs with tracked laws (US states on the US map). Tap one to open it.

25 of 25 regulations

Upcoming deadlines

DateRegulation
in 7 weeksCCD2

National rules apply

in 2 monthsEU AI Act

New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

in 2 monthsEU Platform Work Directive

Transposition deadline

in 2 monthsEU PLD

Transposition deadline; old PLD repealed

in 2 monthseIDAS 2

Member States must provide EU Digital Identity Wallets

in 3 monthsEU Data Act

Cloud switching charges abolished

in 4 monthsEU Cyber Solidarity Act

First Commission evaluation

in 4 monthsEU DSA

DSA SME impact report

in 6 monthsEU EHDS

EHDS general application date

in 6 monthsGDPR

GDPR Procedural Regulation applies

in 6 monthsNIS2

Next biennial entity notification

in 10 monthsEU AI Act

Legacy GPAI models must comply; national AI sandboxes operational

in 11 monthsEU Data Act

Unfair-terms rules extend to older long-term contracts

in 1 yearNIS2

Commission review of NIS2

in 1 yearEU AI Act

High-risk obligations apply to Annex III systems

in 1 yearEU CRA

CRA fully applies

in 1 yeareIDAS 2

Private relying parties must accept wallets

in 1 yearEU CSAM Interim Regulation

Commission implementation report

in 1 yearEU CSAM Interim Regulation

Interim derogation expires

in 1 yearEU CRA

Legacy type-examination certificates expire

in 1 yearEU AI Act

High-risk obligations apply to Annex I product-embedded systems

in 1 yearEU CRA

Report on single reporting platform

in 1 yearEU Data Act

Commission evaluation

in 2 yearsEU EHDS

Primary use for first data categories; secondary use framework applies

in 3 yearsEU AI Act

Public-authority high-risk systems must comply

in 4 yearsEU CRA

First CRA evaluation

in 4 yearsEU AI Act

Large-scale EU IT systems must comply

in 4 yearsEU EHDS

Primary use for second data categories; EHR systems in service; extra secondary-use categories

in 8 yearsEU EHDS

Third-country participation in secondary use

Past deadlines

DateRegulation
2 weeks agoEU Data Act

Access-by-design for new connected products

2 weeks agoEU CRA

Vulnerability and incident reporting obligations apply

3 weeks agoEU DSA

ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs

5 weeks agoEU e-Evidence Package

e-Evidence Regulation applies

7 weeks agoEU AI Act

General application: transparency obligations, GPAI fines, most other rules

8 weeks agoEU CSAM Interim Regulation

New interim regulation enters into force

2 months agoEU AI Act

Digital Omnibus on AI enters into force

3 months agoEU CRA

Conformity assessment body provisions apply

4 months agoeIDAS 2

Legacy qualified trust service providers conformity report

4 months agoEU DMA

DMA first review

5 months agoEU CSAM Interim Regulation

Previous interim regulation expires

7 months agoEU e-Evidence Package

Legal representatives Directive transposition

8 months agoEU Cybersecurity Act

Cybersecurity Act 2 proposed

8 months agoTTPA

Member States notify sanction rules

8 months agoGDPR

GDPR Procedural Regulation enters into force

8 months agoEU DSA

DSA first harmonised transparency reporting cycle

10 months agoGDPR

GDPR Procedural Regulation adopted

10 months agoCCD2

Transposition deadline

10 months agoDORA

First critical ICT third-party providers designated

10 months agoEU DSA

DSA review report on VLOP scope and interplay

11 months agoEU-US DPF

Latombe appeal lodged at the Court of Justice

11 months agoEU DSA

DSA delegated act on researcher data access in force

11 months agoTTPA

TTPA applies

1 year agoEU DGA

Legacy data intermediaries must comply

1 year agoEU Data Act

Member States notify penalty rules

1 year agoEU Data Act

Data Act applies

1 year agoEU-US DPF

General Court upholds DPF (Latombe v Commission)

1 year agoEU AI Act

GPAI, governance, notified bodies and penalties apply

1 year agoDORA

TLPT regulatory technical standards enter into force

1 year agoEU DSA

DSA transparency report templates mandatory

1 year agoDORA

First registers of information submitted to the ESAs

1 year agoNIS2

Member States establish entity lists

1 year agoEU EHDS

EHDS enters into force

1 year agoEU Cyber Solidarity Act

Cyber Solidarity Act enters into force

1 year agoEU AI Act

Prohibited practices and AI literacy apply

1 year agoNIS2

Digital infrastructure entities submit registration data

1 year agoDORA

DORA applies

1 year agoInteroperable Europe Act

Interoperability assessments mandatory

1 year agoeIDAS 2

First wallet implementing acts enter into force

1 year agoEU CRA

CRA enters into force

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.