Skip to content
Jurisdiction ยท 15 regulations

European Union: data, AI and cyber laws

15 regulations in European Union that affect companies handling data: Cyber Resilience Act, DORA, Data Governance Act, Digital Markets Act, Digital Omnibus (data/GDPR), Digital Services Act, EU AI Act, EU Data Act, EU-US Data Privacy Framework, European Health Data Space (EHDS), GDPR, NIS2, Product Liability Directive, eIDAS 2 / EU Digital Identity Wallet, ePrivacy Directive (cookie law). Part of EU.

  • EU AI Act

    European Union

    AmendedAIBiometrics

    Next: Dec 2, 2026 New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

  • EnactedAICybersecurity

    Next: Dec 9, 2026 Transposition deadline; old PLD repealed

  • EnactedPrivacyData access and sharing

    Next: Dec 24, 2026 Member States must provide EU Digital Identity Wallets

  • EU Data Act

    European Union

    In forceData access and sharingPrivacy

    Next: Jan 12, 2027 Cloud switching charges abolished

  • EnactedHealth dataPrivacy

    Next: Mar 26, 2027 EHDS general application date

  • GDPR

    European Union

    AmendedPrivacyBreach notification

    Next: Apr 2, 2027 GDPR Procedural Regulation applies

  • NIS2

    European Union

    AmendedCybersecurityBreach notification

    Next: Apr 17, 2027 Next biennial entity notification

  • Cyber Resilience Act

    European Union

    EnactedCybersecurityBreach notification

    Next: Dec 11, 2027 CRA fully applies

  • Data Governance Act

    European Union

    AmendedData access and sharingPrivacy

    Effective Jun 23, 2022

  • Digital Markets Act

    European Union

    In forceData access and sharingPrivacy

    Effective Nov 1, 2022

  • ProposedPrivacyData access and sharing

  • Digital Services Act

    European Union

    In forceOnline safetyChildren

    Effective Nov 16, 2022

  • DORA

    European Union

    In forceCybersecurityFinancial

    Effective Jan 16, 2023

  • AmendedPrivacyBreach notification

    Effective Jul 31, 2002

  • In forcePrivacyData residency

    Effective Jul 10, 2023

Upcoming deadlines

December 20263 deadlines

  1. EU AI Act

    New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

    New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).

    Compliance deadlinein 2 monthsSource
  2. Transposition deadline; old PLD repealed

    Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).

    Transitionin 3 monthsSource
  3. Member States must provide EU Digital Identity Wallets

    Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).

    Compliance deadlinein 3 monthsSource

January 20271 deadline

  1. EU Data Act

    Cloud switching charges abolished

    Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).

    Compliance deadlinein 4 monthsSource

March 20271 deadline

  1. EHDS general application date

    The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).

    Takes effectin 6 monthsSource

April 20272 deadlines

  1. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource
  2. NIS2

    Next biennial entity notification

    Competent authorities notify the Commission and Cooperation Group of the number of essential and important entities, repeated every two years after 17 Apr 2025 (Art 3(5)).

    Reportingin 7 monthsSource

August 20271 deadline

  1. EU AI Act

    Legacy GPAI models must comply; national AI sandboxes operational

    Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).

    Compliance deadlinein 10 monthsSource

September 20271 deadline

  1. EU Data Act

    Unfair-terms rules extend to older long-term contracts

    Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).

    Compliance deadlinein 12 monthsSource

October 20271 deadline

  1. NIS2

    Commission review of NIS2

    Commission must review the functioning of NIS2 and report to Parliament and Council, then every 36 months (Art 40).

    Reportingin 13 monthsSource

December 20273 deadlines

  1. EU AI Act

    High-risk obligations apply to Annex III systems

    Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.

    Compliance deadlinein 14 monthsSource
  2. Cyber Resilience Act

    CRA fully applies

    All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).

    Compliance deadlinein 15 monthsSource
  3. Private relying parties must accept wallets

    Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).

    Compliance deadlinein 15 monthsSource

June 20281 deadline

  1. Cyber Resilience Act

    Legacy type-examination certificates expire

    EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).

    Sunsetin 21 monthsSource

August 20281 deadline

  1. EU AI Act

    High-risk obligations apply to Annex I product-embedded systems

    Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.

    Compliance deadlinein 22 monthsSource

September 20282 deadlines

  1. Cyber Resilience Act

    Report on single reporting platform

    Commission report assessing the single reporting platform's effectiveness (Art 70(2)).

    Reportingin 24 monthsSource
  2. EU Data Act

    Commission evaluation

    Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).

    Reportingin 24 monthsSource

March 20291 deadline

  1. Primary use for first data categories; secondary use framework applies

    Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.

    Compliance deadlinein 2.5 yearsSource

August 20301 deadline

  1. EU AI Act

    Public-authority high-risk systems must comply

    Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).

    Compliance deadlinein 3.9 yearsSource

December 20302 deadlines

  1. Cyber Resilience Act

    First CRA evaluation

    Commission evaluation and review report, then every four years (Art 70(1)).

    Reportingin 4.2 yearsSource
  2. EU AI Act

    Large-scale EU IT systems must comply

    AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).

    Compliance deadlinein 4.3 yearsSource

March 20311 deadline

  1. Primary use for second data categories; EHR systems in service; extra secondary-use categories

    Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.

    Compliance deadlinein 4.5 yearsSource

March 20351 deadline

  1. Third-country participation in secondary use

    Art 75(5) applies from 26 Mar 2035.

    Takes effectin 8.5 yearsSource

Past deadlines

September 20262 deadlines

  1. EU Data Act

    Access-by-design for new connected products

    Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.

    Compliance deadline12 days agoSource
  2. Cyber Resilience Act

    Vulnerability and incident reporting obligations apply

    Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).

    Reporting13 days agoSource

August 20262 deadlines

  1. Digital Services Act

    ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs

    Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.

    Enforcement24 days agoSource
  2. EU AI Act

    General application: transparency obligations, GPAI fines, most other rules

    The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.

    Takes effect53 days agoSource

July 20261 deadline

  1. EU AI Act

    Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 (adopted 8 July 2026, OJ 24 July 2026) enters into force on the third day after publication. Amended Articles 102 to 110 apply from this date (new Art 113(d)).

    Transition59 days agoSource

June 20261 deadline

  1. Cyber Resilience Act

    Conformity assessment body provisions apply

    Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).

    Takes effect3 months agoSource

May 20261 deadline

  1. Legacy qualified trust service providers conformity report

    QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.

    Compliance deadline4 months agoSource

January 20261 deadline

  1. GDPR

    GDPR Procedural Regulation enters into force

    Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.

    Transition9 months agoSource

November 20252 deadlines

  1. GDPR

    GDPR Procedural Regulation adopted

    Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.

    Transition10 months agoSource
  2. DORA

    First critical ICT third-party providers designated

    The ESAs published the first list of 19 critical ICT third-party providers (including AWS, Google Cloud and Microsoft), which now come under direct EU oversight.

    Enforcement10 months agoSource

October 20251 deadline

  1. Latombe appeal lodged at the Court of Justice

    Latombe appealed the General Court judgment to the Court of Justice on points of law (reported as Case C-703/25 P); the DPF stays valid while it is pending.

    Enforcement11 months agoSource

September 20254 deadlines

  1. Data Governance Act

    Legacy data intermediaries must comply

    Entities that were already providing data intermediation services on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).

    Compliance deadline12 months agoSource
  2. EU Data Act

    Member States notify penalty rules

    Member States had to notify the Commission of their penalty rules (Art 40(2)).

    Reporting12 months agoSource
  3. EU Data Act

    Data Act applies

    Most obligations apply, including user data access and sharing (Chapters II-III), cloud switching (Chapter VI) and interoperability; Chapter IV unfair terms apply to contracts concluded after this date (Art 50).

    Takes effect12 months agoSource
  4. General Court upholds DPF (Latombe v Commission)

    General Court dismissed Philippe Latombe's action for annulment (Case T-553/23) and confirmed the US offered adequate protection when the decision was adopted.

    Enforcement13 months agoSource

August 20251 deadline

  1. EU AI Act

    GPAI, governance, notified bodies and penalties apply

    Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).

    Takes effect14 months agoSource

July 20251 deadline

  1. DORA

    TLPT regulatory technical standards enter into force

    Commission Delegated Regulation (EU) 2025/1190 (published 18 June 2025) sets criteria for which financial entities must run threat-led penetration testing, plus methodology and tester requirements.

    Takes effect15 months agoSource

April 20252 deadlines

  1. DORA

    First registers of information submitted to the ESAs

    Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.

    Reporting17 months agoSource
  2. NIS2

    Member States establish entity lists

    Member States had to establish lists of essential and important entities and notify the Commission of entity numbers (Art 3(3) and (5)). Repeated every two years.

    Reporting17 months agoSource

March 20251 deadline

  1. EHDS enters into force

    Regulation (EU) 2025/327, published 5 Mar 2025, enters into force on the twentieth day following publication.

    Takes effect18 months agoSource

February 20251 deadline

  1. EU AI Act

    Prohibited practices and AI literacy apply

    Chapters I and II apply, including the Article 5 bans on prohibited AI practices and the Article 4 AI literacy duty (Art 113(a)).

    Takes effect20 months agoSource

January 20252 deadlines

  1. NIS2

    Digital infrastructure entities submit registration data

    DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).

    Reporting20 months agoSource
  2. DORA

    DORA applies

    All DORA obligations (ICT risk management, incident reporting, testing, third-party risk, register of information) apply from 17 Jan 2025 (Art 64).

    Takes effect20 months agoSource

December 20243 deadlines

  1. First wallet implementing acts enter into force

    Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 (adopted 28 Nov 2024, published 4 Dec 2024) enter into force. This starts the wallet deadline clocks in Arts 5a and 5f.

    Takes effect21 months agoSource
  2. Cyber Resilience Act

    CRA enters into force

    Entered into force on the twentieth day after publication in the OJ on 20 Nov 2024 (Art 71(1)).

    Takes effect21 months agoSource
  3. New PLD enters into force

    Directive entered into force on the twentieth day after publication in the OJ on 18 Nov 2024 (Art 23).

    Takes effect22 months agoSource

November 20241 deadline

  1. NIS2

    Implementing Regulation 2024/2690 enters into force

    Commission Implementing Regulation (EU) 2024/2690 (published 18 Oct 2024) sets technical risk-management measures and significant-incident thresholds for DNS, TLD, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers.

    Takes effect23 months agoSource

October 20242 deadlines

  1. NIS2

    National NIS2 measures apply; NIS1 repealed

    Member States apply their NIS2 measures from 18 Oct 2024 and Directive (EU) 2016/1148 (NIS1) is repealed (Arts 41(1), 44).

    Takes effect23 months agoSource
  2. NIS2

    Transposition deadline

    Member States had to adopt and publish national transposing measures by 17 Oct 2024 (Art 41(1)).

    Transition23 months agoSource

August 20241 deadline

  1. EU AI Act

    AI Act enters into force

    Regulation (EU) 2024/1689 enters into force twenty days after publication on 12 July 2024 (Art 113).

    Takes effect2.1 years agoSource

May 20241 deadline

  1. eIDAS 2 enters into force

    Regulation (EU) 2024/1183 entered into force on the twentieth day after publication on 30 Apr 2024 (Art 2).

    Takes effect2.3 years agoSource

March 20241 deadline

  1. Digital Markets Act

    Gatekeeper compliance deadline (first designations)

    First-wave gatekeepers had to comply with Arts 5-7 obligations and submit compliance reports six months after the 6 Sep 2023 designation.

    Compliance deadline2.5 years agoSource

February 20241 deadline

  1. Digital Services Act

    DSA applies to all intermediary services

    Full application to all providers of intermediary services (Art 93(2)).

    Takes effect2.6 years agoSource

January 20242 deadlines

  1. EU Data Act

    Reduced switching charges period begins

    From 11 Jan 2024 to 12 Jan 2027, data processing providers may charge only reduced switching fees, capped at costs directly linked to switching (Art 29(2)-(3)).

    Transition2.7 years agoSource
  2. EU Data Act

    Data Act enters into force

    Entered into force on the twentieth day after publication in the OJ on 22 Dec 2023 (Art 50).

    Takes effect2.7 years agoSource

September 20232 deadlines

  1. Data Governance Act

    DGA applies

    All DGA rules apply (Art 38).

    Takes effect3 years agoSource
  2. Digital Markets Act

    First six gatekeepers designated

    Commission designated Alphabet, Amazon, Apple, ByteDance, Meta and Microsoft (22 core platform services). They had six months to fully comply.

    Enforcement3 years agoSource

July 20231 deadline

  1. DPF adequacy decision adopted and effective

    Commission adopted Implementing Decision (EU) 2023/1795, effective on notification to Member States; EU-US transfers to DPF-certified organisations may proceed without additional safeguards.

    Takes effect3.2 years agoSource

May 20231 deadline

  1. Digital Markets Act

    DMA applies

    DMA becomes applicable; undertakings meeting thresholds must notify the Commission within two months (Arts 3(3), 54).

    Takes effect3.4 years agoSource

April 20231 deadline

  1. Digital Services Act

    First VLOP/VLOSE designations

    Commission designated the first 19 very large online platforms and search engines (e.g. Amazon Store, Facebook, Google Search, TikTok, X). Obligations apply four months after notification.

    Enforcement3.4 years agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.