stillholds EU digital compliance

What is covered

Four instruments today, chosen because they share a fact base and land on the same solutions. Three done properly beat ten done thinly, and thin is what a reader notices first.

The instruments #

InstrumentReferenceRulesWeakest check
Artificial Intelligence Act Regulation (EU) 2024/168921corroborated
Cyber Resilience Act Regulation (EU) 2024/28479corroborated
General Data Protection Regulation Regulation (EU) 2016/67911corroborated
NIS2 Directive
A directive: binds through national law
Directive (EU) 2022/25555corroborated
Data Act Regulation (EU) 2023/28548corroborated
Digital Services Act Regulation (EU) 2022/206512corroborated
Digital Operational Resilience Act Regulation (EU) 2022/25546corroborated
European Accessibility Act
A directive: binds through national law
Directive (EU) 2019/8826corroborated

Back to top

Dates that bind #

Every date this ruleset knows, across all four instruments, in order. Dates moved by an amending instrument are marked.

DateWhat happensInstrument
2018-05-25AppliesGeneral Data Protection Regulation
2019-06-07Published in the Official JournalEuropean Accessibility Act
2022-06-28Member States were required to transpose itEuropean Accessibility Act
2022-11-16Enters into forceDigital Services Act
2023-01-16Enters into forceNIS2 Directive
2023-01-16Enters into forceDigital Operational Resilience Act
2023-08-25Applies to designated very large platforms and search enginesDigital Services Act
2024-01-11Enters into forceData Act
2024-02-17Applies to all intermediary servicesDigital Services Act
2024-08-01Enters into forceArtificial Intelligence Act
2024-10-17Member States were required to transpose itNIS2 Directive
2024-12-10Enters into forceCyber Resilience Act
2025-01-17AppliesDigital Operational Resilience Act
2025-02-02Prohibitions and AI literacy applyArtificial Intelligence Act
2025-06-28Obligations apply to products and services placed on the market from this dateEuropean Accessibility Act
2025-08-02General-purpose model obligations, governance and penalties applyArtificial Intelligence Act
2025-09-12Applies: data access, switching and interoperability obligationsData Act
2026-08-02Transparency obligations apply and enforcement beginsArtificial Intelligence Act
2026-09-11Reporting obligations for actively exploited vulnerabilities applyCyber Resilience Act
2026-09-12Access by design applies to connected products placed on the market from this dateData Act
2026-12-02Marking applies to systems already on the market; new prohibitions apply
This date was moved by an amending instrument.
Artificial Intelligence Act
2027-01-12Switching charges prohibited entirelyData Act
2027-09-12Unfair terms provisions reach contracts concluded before 12 September 2025Data Act
2027-12-02High-risk obligations apply to Annex III systems
This date was moved by an amending instrument.
Artificial Intelligence Act
2027-12-11The remaining obligations applyCyber Resilience Act
2028-08-02High-risk obligations apply to Annex I systems
This date was moved by an amending instrument.
Artificial Intelligence Act
2030-06-28Transitional period ends for services under earlier contractsEuropean Accessibility Act

Back to top

Where instruments meet #

The part rarely written down: obligations from different instruments that must be reconciled rather than run in parallel. Each fires on a combination of facts, never on one instrument alone.

Two conformity assessments under one CE marking

AI Act Articles 43 and 48 · CRA Articles 32 and 30

A product carrying digital elements and an AI safety component must satisfy both regimes and affix a single CE marking. Plan one technical file and one assessment route rather than two projects that meet at the end.

One incident, three reporting duties on different clocks

GDPR Articles 33 and 34 · NIS2 Article 23 · AI Act Article 73

The same event can require an early warning within 24 hours, a personal data notification within 72, and a serious incident report under the AI Act, to different authorities. One runbook, one decision tree, one owner; the Data Omnibus proposes a single entry point but has not been adopted.

A data protection impact assessment and a fundamental rights impact assessment

GDPR Article 35 · AI Act Article 27

Two assessments with overlapping evidence and different questions. The AI Act permits building on an existing data protection assessment rather than repeating it; the fundamental rights questions are additional, not a subset.

Automated decisions meet AI Act transparency

GDPR Article 22 · AI Act Articles 26(11) and 86

A person subject to an automated decision has rights under both: meaningful information about the logic, and an explanation of the role the system played. The two duties are satisfied together or not at all.

Product security requirements and processing security

CRA Annex I · GDPR Article 32

The CRA sets requirements for the product; Article 32 sets them for the processing. Evidence for one is usually evidence for the other, and a single control set mapped to both saves the second audit.

A directive and a regulation in the same programme

NIS2 Article 41

The regulations bind identically across the Union; NIS2 binds as each Member State transposed it. A single compliance programme therefore has one part that travels and one part that does not, and the second must be checked per country.

DORA displaces NIS2 for a financial entity's ICT risk

DORA Article 1(2) · NIS2 Article 4

Where DORA covers the same ground, it applies as the more specific law and NIS2's corresponding duties do not stack on top. That is a reason to map the two rather than run two programmes, and a reason not to assume the NIS2 obligation has simply vanished: the displacement is provision by provision, not wholesale.

Advertising transparency meets lawful processing

DSA Articles 26 and 28 · GDPR Articles 6, 9 and 22

The DSA requires an advertisement to be identifiable and its targeting parameters disclosed; the GDPR governs whether that targeting may happen at all. Special-category profiling is prohibited under both, and disclosing unlawful targeting does not make it lawful.

Data sharing under the Data Act meets data protection

Data Act Articles 4, 5 and 1(5) · GDPR Articles 6 and 20

A user's right to have product data sent to a third party is not itself a lawful basis for processing anyone else's personal data caught up in it. Where the data set mixes personal and non-personal data, both regimes apply to the same transfer.

Cloud switching rights meet financial exit strategies

Data Act Chapter VI · DORA Articles 28 to 30

Both regimes reach the same cloud contract from opposite directions: one gives the customer a right to leave, the other requires the financial customer to have a documented exit strategy and specific contractual terms. One contract review satisfies both if it is scoped that way; two separate ones usually contradict each other.

Accessibility requirements meet AI transparency duties

EAA Annex I · AI Act Article 50(1)

Telling a person they are speaking to an AI system only counts if they can perceive the notice. A disclosure delivered in a way that fails the accessibility requirements satisfies neither instrument.

A consumer platform is covered twice over

DSA Article 14 · EAA Annex I

The DSA requires terms in plain, intelligible language; the Accessibility Act requires the interface delivering them to be perceivable and operable. Plain language in an inaccessible interface fails the second test while passing the first.

An AI system inside a regulated product

AI Act Article 6(1) · CRA Article 12

Being a product with digital elements does not by itself make the AI high-risk, and being high-risk does not by itself trigger the CRA. Check both routes separately; they share a technical file but not a test.

Back to top

Proposed, not law #

Tracked so that a plan is not built on a proposal. None of the following binds anyone today.

The Data Omnibus would amend the GDPR, ePrivacy, NIS2, DORA and the Data Act

General Data Protection Regulation · proposed 2025-11-19

Still in negotiation as of August 2026 and not law. Reported changes include single-click consent, a moratorium on re-prompting, a longer breach notification window and a single incident reporting point. Plan against the obligations that are in force today.

The Data Omnibus proposes streamlined incident reporting through a single entry point

NIS2 Directive · proposed 2025-11-19

Would let one report satisfy notifications under NIS2, the GDPR and DORA. Not adopted; report separately until it is.

The Digital Omnibus proposes exemptions from the switching regime for custom-made services and a lighter regime for smaller providers

Data Act · proposed 2025-11-19

Reported as covering custom-made services other than infrastructure services for contracts concluded before 12 September 2025. Not adopted; the obligations above apply as they stand.

The Data Omnibus proposes a single entry point for incident reporting across DORA, NIS2 and the GDPR

Digital Operational Resilience Act · proposed 2025-11-19

Still in negotiation. Report separately until it is adopted.

Back to top

What is not covered #

Eight instruments are encoded. Sectoral regimes that need their own expert, medical devices, machinery and automotive among them, are deliberately out of scope rather than thinly covered, as are the ePrivacy rules, which are mid-reform. The next candidates are the Machinery Regulation for products already caught by the CRA, and the ePrivacy regime once the Data Omnibus settles it.

If an instrument is not listed on this page, this service says nothing about it, and silence here is not a finding that it does not apply to you.

Back to top