EU data, AI and cybersecurity regulations
GDPR, the AI Act, DORA, NIS2, the Data Act, the Cyber Resilience Act and the rest of the EU digital rulebook.
1 jurisdictions with tracked laws. Tap one to open it.
15 regulations
Add to calendar
- EU AI Act
European Union
AmendedAIBiometricsNext: Dec 2, 2026 New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
- Product Liability Directive
European Union
EnactedAICybersecurityNext: Dec 9, 2026 Transposition deadline; old PLD repealed
- eIDAS 2 / EU Digital Identity Wallet
European Union
EnactedPrivacyData access and sharingNext: Dec 24, 2026 Member States must provide EU Digital Identity Wallets
- EU Data Act
European Union
In forceData access and sharingPrivacyNext: Jan 12, 2027 Cloud switching charges abolished
- European Health Data Space (EHDS)
European Union
EnactedHealth dataPrivacyNext: Mar 26, 2027 EHDS general application date
- GDPR
European Union
AmendedPrivacyBreach notificationNext: Apr 2, 2027 GDPR Procedural Regulation applies
- NIS2
European Union
AmendedCybersecurityBreach notificationNext: Apr 17, 2027 Next biennial entity notification
- Cyber Resilience Act
European Union
EnactedCybersecurityBreach notificationNext: Dec 11, 2027 CRA fully applies
- Data Governance Act
European Union
AmendedData access and sharingPrivacyEffective Jun 23, 2022
- Digital Markets Act
European Union
In forceData access and sharingPrivacyEffective Nov 1, 2022
- Digital Omnibus (data/GDPR)
European Union
ProposedPrivacyData access and sharing - Digital Services Act
European Union
In forceOnline safetyChildrenEffective Nov 16, 2022
- DORA
European Union
In forceCybersecurityFinancialEffective Jan 16, 2023
- ePrivacy Directive (cookie law)
European Union
AmendedPrivacyBreach notificationEffective Jul 31, 2002
- EU-US Data Privacy Framework
European Union
In forcePrivacyData residencyEffective Jul 10, 2023
Upcoming deadlines
December 20263 deadlines
- EU AI ActEuropean Union
New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).
- Product Liability DirectiveEuropean Union
Transposition deadline; old PLD repealed
Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Member States must provide EU Digital Identity Wallets
Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).
January 20271 deadline
- EU Data ActEuropean Union
Cloud switching charges abolished
Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).
March 20271 deadline
- European Health Data Space (EHDS)European Union
EHDS general application date
The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).
April 20272 deadlines
August 20271 deadline
- EU AI ActEuropean Union
Legacy GPAI models must comply; national AI sandboxes operational
Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).
September 20271 deadline
- EU Data ActEuropean Union
Unfair-terms rules extend to older long-term contracts
Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).
October 20271 deadline
December 20273 deadlines
- EU AI ActEuropean Union
High-risk obligations apply to Annex III systems
Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.
- Cyber Resilience ActEuropean Union
CRA fully applies
All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Private relying parties must accept wallets
Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).
June 20281 deadline
- Cyber Resilience ActEuropean Union
Legacy type-examination certificates expire
EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).
August 20281 deadline
- EU AI ActEuropean Union
High-risk obligations apply to Annex I product-embedded systems
Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.
September 20282 deadlines
- Cyber Resilience ActEuropean Union
Report on single reporting platform
Commission report assessing the single reporting platform's effectiveness (Art 70(2)).
- EU Data ActEuropean Union
Commission evaluation
Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).
March 20291 deadline
- European Health Data Space (EHDS)European Union
Primary use for first data categories; secondary use framework applies
Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.
August 20301 deadline
- EU AI ActEuropean Union
Public-authority high-risk systems must comply
Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).
December 20302 deadlines
- Cyber Resilience ActEuropean Union
First CRA evaluation
Commission evaluation and review report, then every four years (Art 70(1)).
March 20311 deadline
- European Health Data Space (EHDS)European Union
Primary use for second data categories; EHR systems in service; extra secondary-use categories
Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.
March 20351 deadline
- European Health Data Space (EHDS)European Union
Third-country participation in secondary use
Art 75(5) applies from 26 Mar 2035.
Past deadlines
September 20262 deadlines
- EU Data ActEuropean Union
Access-by-design for new connected products
Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.
- Cyber Resilience ActEuropean Union
Vulnerability and incident reporting obligations apply
Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).
August 20262 deadlines
- Digital Services ActEuropean Union
ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs
Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.
- EU AI ActEuropean Union
General application: transparency obligations, GPAI fines, most other rules
The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.
July 20261 deadline
June 20261 deadline
- Cyber Resilience ActEuropean Union
Conformity assessment body provisions apply
Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).
May 20261 deadline
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Legacy qualified trust service providers conformity report
QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.
January 20261 deadline
November 20252 deadlines
October 20251 deadline
- EU-US Data Privacy FrameworkEuropean Union
Latombe appeal lodged at the Court of Justice
Latombe appealed the General Court judgment to the Court of Justice on points of law (reported as Case C-703/25 P); the DPF stays valid while it is pending.
September 20254 deadlines
- Data Governance ActEuropean Union
Legacy data intermediaries must comply
Entities that were already providing data intermediation services on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).
- EU Data ActEuropean Union
Member States notify penalty rules
Member States had to notify the Commission of their penalty rules (Art 40(2)).
- EU Data ActEuropean Union
Data Act applies
Most obligations apply, including user data access and sharing (Chapters II-III), cloud switching (Chapter VI) and interoperability; Chapter IV unfair terms apply to contracts concluded after this date (Art 50).
- EU-US Data Privacy FrameworkEuropean Union
General Court upholds DPF (Latombe v Commission)
General Court dismissed Philippe Latombe's action for annulment (Case T-553/23) and confirmed the US offered adequate protection when the decision was adopted.
August 20251 deadline
- EU AI ActEuropean Union
GPAI, governance, notified bodies and penalties apply
Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).
July 20251 deadline
April 20252 deadlines
- DORAEuropean Union
First registers of information submitted to the ESAs
Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.
March 20251 deadline
- European Health Data Space (EHDS)European Union
EHDS enters into force
Regulation (EU) 2025/327, published 5 Mar 2025, enters into force on the twentieth day following publication.
February 20251 deadline
January 20252 deadlines
- NIS2European Union
Digital infrastructure entities submit registration data
DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).
December 20243 deadlines
- eIDAS 2 / EU Digital Identity WalletEuropean Union
First wallet implementing acts enter into force
Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 (adopted 28 Nov 2024, published 4 Dec 2024) enter into force. This starts the wallet deadline clocks in Arts 5a and 5f.
- Cyber Resilience ActEuropean Union
CRA enters into force
Entered into force on the twentieth day after publication in the OJ on 20 Nov 2024 (Art 71(1)).
- Product Liability DirectiveEuropean Union
New PLD enters into force
Directive entered into force on the twentieth day after publication in the OJ on 18 Nov 2024 (Art 23).
November 20241 deadline
- NIS2European Union
Implementing Regulation 2024/2690 enters into force
Commission Implementing Regulation (EU) 2024/2690 (published 18 Oct 2024) sets technical risk-management measures and significant-incident thresholds for DNS, TLD, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers.
October 20242 deadlines
August 20241 deadline
May 20241 deadline
- eIDAS 2 / EU Digital Identity WalletEuropean Union
eIDAS 2 enters into force
Regulation (EU) 2024/1183 entered into force on the twentieth day after publication on 30 Apr 2024 (Art 2).
March 20241 deadline
- Digital Markets ActEuropean Union
Gatekeeper compliance deadline (first designations)
First-wave gatekeepers had to comply with Arts 5-7 obligations and submit compliance reports six months after the 6 Sep 2023 designation.
February 20241 deadline
- Digital Services ActEuropean Union
DSA applies to all intermediary services
Full application to all providers of intermediary services (Art 93(2)).
January 20242 deadlines
- EU Data ActEuropean Union
Reduced switching charges period begins
From 11 Jan 2024 to 12 Jan 2027, data processing providers may charge only reduced switching fees, capped at costs directly linked to switching (Art 29(2)-(3)).
- EU Data ActEuropean Union
Data Act enters into force
Entered into force on the twentieth day after publication in the OJ on 22 Dec 2023 (Art 50).
September 20232 deadlines
- Digital Markets ActEuropean Union
First six gatekeepers designated
Commission designated Alphabet, Amazon, Apple, ByteDance, Meta and Microsoft (22 core platform services). They had six months to fully comply.
July 20231 deadline
- EU-US Data Privacy FrameworkEuropean Union
DPF adequacy decision adopted and effective
Commission adopted Implementing Decision (EU) 2023/1795, effective on notification to Member States; EU-US transfers to DPF-certified organisations may proceed without additional safeguards.
May 20231 deadline
- Digital Markets ActEuropean Union
DMA applies
DMA becomes applicable; undertakings meeting thresholds must notify the Commission within two months (Arts 3(3), 54).
April 20231 deadline
- Digital Services ActEuropean Union
First VLOP/VLOSE designations
Commission designated the first 19 very large online platforms and search engines (e.g. Amazon Store, Facebook, Google Search, TikTok, X). Obligations apply four months after notification.