{
  "version": "v0.8.2",
  "updated": "2026-08-09",
  "facts": [
    {
      "id": "role",
      "section": "Your position",
      "label": "What is your relationship to the solution?",
      "multi": true,
      "help": "More than one can be true, and different instruments bind different roles.",
      "options": [
        {
          "id": "provider",
          "label": "We build it, or place it on the market under our name"
        },
        {
          "id": "deployer",
          "label": "We use it under our own authority"
        },
        {
          "id": "manufacturer",
          "label": "We manufacture a product with digital elements"
        },
        {
          "id": "importer",
          "label": "We bring it into the Union from outside"
        },
        {
          "id": "distributor",
          "label": "We make it available without being provider or importer"
        },
        {
          "id": "controller",
          "label": "We decide why and how personal data is processed"
        },
        {
          "id": "processor",
          "label": "We process personal data on someone else's instructions"
        }
      ]
    },
    {
      "id": "euMarket",
      "section": "Your position",
      "label": "Is it placed on the Union market, or used by people in the Union?",
      "boolean": true
    },
    {
      "id": "size",
      "section": "Your position",
      "label": "How large is the organisation?",
      "options": [
        {
          "id": "micro",
          "label": "Fewer than 10 people"
        },
        {
          "id": "small",
          "label": "Fewer than 50 people"
        },
        {
          "id": "medium",
          "label": "Fewer than 250 people"
        },
        {
          "id": "large",
          "label": "250 or more"
        }
      ]
    },
    {
      "id": "nature",
      "section": "What it is",
      "label": "What kind of solution is it?",
      "multi": true,
      "options": [
        {
          "id": "software-service",
          "label": "Software delivered as a service"
        },
        {
          "id": "product-digital-elements",
          "label": "A product with digital elements placed on the market"
        },
        {
          "id": "connected-product",
          "label": "A connected product that generates data in use"
        },
        {
          "id": "related-service",
          "label": "A related service: software governing how a connected product works"
        },
        {
          "id": "ai-system",
          "label": "An AI system"
        },
        {
          "id": "gpai-model",
          "label": "A general-purpose AI model"
        },
        {
          "id": "intermediary",
          "label": "An intermediary service, such as a network or caching service"
        },
        {
          "id": "hosting-service",
          "label": "A hosting service storing information provided by users"
        },
        {
          "id": "online-platform",
          "label": "An online platform that stores and publishes user content"
        },
        {
          "id": "marketplace",
          "label": "An online marketplace where traders sell to consumers"
        },
        {
          "id": "data-processing-service",
          "label": "A data processing service: cloud or edge computing"
        }
      ]
    },
    {
      "id": "lifecycle",
      "section": "What it is",
      "label": "Was it placed on the market before 2 August 2026?",
      "help": "This exact date matters for the AI Act's transparency transition. Other instruments use different cut-offs, and each says so in its own finding.",
      "options": [
        {
          "id": "already",
          "label": "Already on the market before 2 August 2026"
        },
        {
          "id": "new",
          "label": "From 2 August 2026 onwards"
        }
      ]
    },
    {
      "id": "openSource",
      "section": "What it is",
      "label": "Is it free and open-source software outside a commercial activity?",
      "boolean": true
    },
    {
      "id": "personalData",
      "section": "Data",
      "label": "Does it process personal data?",
      "boolean": true
    },
    {
      "id": "specialCategories",
      "section": "Data",
      "label": "Does it process special categories, such as health, biometrics or beliefs?",
      "boolean": true
    },
    {
      "id": "profiling",
      "section": "Data",
      "label": "Does it profile people, or decide about them automatically?",
      "boolean": true
    },
    {
      "id": "significantEffects",
      "section": "Data",
      "label": "Do those automated decisions have legal or similarly significant effects for the person?",
      "boolean": true,
      "help": "Refusing credit, rejecting a job application, or ending a service, as opposed to segmenting a mailing list."
    },
    {
      "id": "largeScaleSpecialCategories",
      "section": "Data",
      "label": "Is processing special categories at large scale a core activity of the organisation?",
      "boolean": true,
      "help": "The main thing the organisation does, rather than incidental processing such as employee health records."
    },
    {
      "id": "largeScaleMonitoring",
      "section": "Data",
      "label": "Does it monitor people systematically at large scale?",
      "boolean": true
    },
    {
      "id": "transfersOutsideEu",
      "section": "Data",
      "label": "Is personal data transferred outside the Union?",
      "boolean": true
    },
    {
      "id": "aiPurpose",
      "section": "If it uses AI",
      "label": "Does the AI do any of these?",
      "options": [
        {
          "id": "none",
          "label": "None of these"
        },
        {
          "id": "social-scoring",
          "label": "Scores people socially, leading to detrimental treatment"
        },
        {
          "id": "crime-prediction",
          "label": "Predicts offending from profiling or traits alone"
        },
        {
          "id": "face-scraping",
          "label": "Builds facial recognition databases by untargeted scraping"
        },
        {
          "id": "emotion-inference",
          "label": "Infers emotions of people"
        },
        {
          "id": "biometric-categorisation-sensitive",
          "label": "Infers sensitive attributes biometrically"
        },
        {
          "id": "realtime-remote-biometric-id",
          "label": "Identifies people biometrically in real time in public spaces"
        },
        {
          "id": "ncii",
          "label": "Generates intimate imagery of identifiable people without consent"
        },
        {
          "id": "csam",
          "label": "Can generate child sexual abuse material"
        }
      ]
    },
    {
      "id": "aiTechniques",
      "section": "If it uses AI",
      "label": "Does it use manipulative techniques?",
      "multi": true,
      "options": [
        {
          "id": "subliminal",
          "label": "Subliminal, manipulative or deceptive techniques"
        },
        {
          "id": "vulnerability",
          "label": "Exploits vulnerabilities of age, disability or circumstance"
        }
      ]
    },
    {
      "id": "aiUseCase",
      "section": "If it uses AI",
      "label": "What does it decide or support?",
      "options": [
        {
          "id": "none",
          "label": "None of these"
        },
        {
          "id": "biometrics",
          "label": "Biometric identification, categorisation or emotion recognition"
        },
        {
          "id": "critical-infrastructure",
          "label": "Safety of critical infrastructure"
        },
        {
          "id": "education",
          "label": "Access to education, assessment or proctoring"
        },
        {
          "id": "employment",
          "label": "Recruitment, evaluation, allocation, monitoring or termination"
        },
        {
          "id": "essential-services",
          "label": "Essential services, creditworthiness, insurance pricing or triage"
        },
        {
          "id": "law-enforcement",
          "label": "Law enforcement"
        },
        {
          "id": "migration",
          "label": "Migration, asylum or border control"
        },
        {
          "id": "justice-democracy",
          "label": "Justice or democratic processes"
        }
      ]
    },
    {
      "id": "aiDerogation",
      "section": "If it uses AI",
      "label": "If it falls in one of those areas, which is true?",
      "multi": true,
      "help": "Article 6(3) of the AI Act. It never applies where the system profiles people.",
      "options": [
        {
          "id": "narrow-procedural",
          "label": "A narrow procedural task only"
        },
        {
          "id": "improves-prior-human",
          "label": "Improves a completed human activity"
        },
        {
          "id": "detects-patterns-no-replace",
          "label": "Detects patterns without replacing human assessment"
        },
        {
          "id": "preparatory",
          "label": "A preparatory task"
        }
      ]
    },
    {
      "id": "annexOneProduct",
      "section": "If it uses AI",
      "label": "Is it a safety component of a regulated product needing third-party assessment?",
      "boolean": true
    },
    {
      "id": "gpaiSystemicRisk",
      "section": "If it uses AI",
      "label": "Does the model exceed the systemic-risk compute threshold?",
      "boolean": true
    },
    {
      "id": "interactsWithPeople",
      "section": "Behaviour",
      "label": "Does it interact directly with people?",
      "boolean": true
    },
    {
      "id": "generatesSyntheticContent",
      "section": "Behaviour",
      "label": "Does it generate synthetic audio, image, video or text?",
      "boolean": true
    },
    {
      "id": "emotionOrBiometricCategorisation",
      "section": "Behaviour",
      "label": "Does it recognise emotions or categorise people biometrically?",
      "boolean": true
    },
    {
      "id": "publishesDeepFakesOrPublicInterestText",
      "section": "Behaviour",
      "label": "Do you publish deep fakes, or AI text informing the public on matters of public interest?",
      "boolean": true
    },
    {
      "id": "consumerFacing",
      "section": "Behaviour",
      "label": "Is it offered to consumers?",
      "boolean": true
    },
    {
      "id": "platformAds",
      "section": "Behaviour",
      "label": "Does the platform show advertising?",
      "boolean": true
    },
    {
      "id": "minorsDirected",
      "section": "Behaviour",
      "label": "Is it directed at minors, or predominantly used by them?",
      "boolean": true
    },
    {
      "id": "veryLargePlatform",
      "section": "Behaviour",
      "label": "Has it been designated a very large online platform or search engine?",
      "boolean": true
    },
    {
      "id": "eaaService",
      "section": "Sector",
      "label": "Is it one of these consumer products or services?",
      "help": "The categories the European Accessibility Act covers.",
      "options": [
        {
          "id": "none",
          "label": "None of these"
        },
        {
          "id": "ecommerce",
          "label": "E-commerce"
        },
        {
          "id": "banking",
          "label": "Consumer banking"
        },
        {
          "id": "ebooks",
          "label": "E-books or dedicated reading software"
        },
        {
          "id": "telecoms",
          "label": "Electronic communications"
        },
        {
          "id": "av-media",
          "label": "Audiovisual media services"
        },
        {
          "id": "transport",
          "label": "Transport information or e-ticketing"
        },
        {
          "id": "terminals",
          "label": "Self-service terminals, payment terminals or consumer computing hardware"
        }
      ]
    },
    {
      "id": "financialEntity",
      "section": "Sector",
      "label": "Is the organisation a regulated financial entity?",
      "boolean": true
    },
    {
      "id": "ictProviderToFinance",
      "section": "Sector",
      "label": "Do you provide ICT services to financial entities?",
      "boolean": true
    },
    {
      "id": "sector",
      "section": "Sector",
      "label": "Which sector does it serve?",
      "options": [
        {
          "id": "general",
          "label": "General commercial"
        },
        {
          "id": "finance",
          "label": "Financial services"
        },
        {
          "id": "health",
          "label": "Health"
        },
        {
          "id": "energy",
          "label": "Energy or utilities"
        },
        {
          "id": "transport",
          "label": "Transport"
        },
        {
          "id": "digital-infrastructure",
          "label": "Digital infrastructure, cloud or managed services"
        },
        {
          "id": "water",
          "label": "Drinking water or waste water"
        },
        {
          "id": "waste",
          "label": "Waste management"
        },
        {
          "id": "manufacturing",
          "label": "Manufacturing, chemicals or food"
        },
        {
          "id": "postal",
          "label": "Postal or courier services"
        },
        {
          "id": "space",
          "label": "Space"
        },
        {
          "id": "public",
          "label": "Public body"
        },
        {
          "id": "education",
          "label": "Education"
        }
      ]
    },
    {
      "id": "essentialOrImportantEntity",
      "section": "Sector",
      "label": "Is the organisation an essential or important entity under national cybersecurity law?",
      "boolean": true,
      "help": "Both categories carry the same core duties; they differ in supervision, not in what must be done."
    }
  ],
  "packs": [
    {
      "id": "ai-act",
      "title": "Artificial Intelligence Act",
      "instrument": "Regulation (EU) 2024/1689",
      "amendedBy": [
        {
          "id": "omnibus-ai",
          "title": "Regulation (EU) 2026/1744 (Digital Omnibus on AI)",
          "inForce": "2026-07-27"
        }
      ],
      "source": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
      "version": "v0.5.0",
      "reads": [
        "role",
        "euMarket",
        "nature",
        "lifecycle",
        "aiPurpose",
        "aiTechniques",
        "aiUseCase",
        "aiDerogation",
        "profiling",
        "annexOneProduct",
        "gpaiSystemicRisk",
        "interactsWithPeople",
        "generatesSyntheticContent",
        "emotionOrBiometricCategorisation",
        "publishesDeepFakesOrPublicInterestText"
      ],
      "gate": "(f) => f.euMarket === true && (f.nature || []).some((n) => [\"ai-system\", \"gpai-model\"].includes(n))",
      "rules": [
        {
          "id": "aia-p-social-scoring",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 31 (social scoring leading to detrimental or disproportionate treatment)"
          },
          "severity": "prohibited",
          "title": "Social scoring leading to detrimental treatment",
          "provision": "Article 5(1)(c)",
          "since": "2025-02-02",
          "when": "(f) => f.aiPurpose === \"social-scoring\""
        },
        {
          "id": "aia-p-crime-prediction",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 42 (prediction based solely on profiling or personality traits)"
          },
          "severity": "prohibited",
          "title": "Predicting offending from profiling or traits alone",
          "provision": "Article 5(1)(d)",
          "since": "2025-02-02",
          "when": "(f) => f.aiPurpose === \"crime-prediction\""
        },
        {
          "id": "aia-p-face-scraping",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 43 (untargeted scraping of facial images from the internet or CCTV)"
          },
          "severity": "prohibited",
          "title": "Untargeted scraping of facial images",
          "provision": "Article 5(1)(e)",
          "since": "2025-02-02",
          "when": "(f) => f.aiPurpose === \"face-scraping\""
        },
        {
          "id": "aia-p-emotion",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 44 (emotion inference in the workplace and education, excluding medical and safety uses)"
          },
          "severity": "prohibited",
          "title": "Emotion inference in the workplace or education",
          "provision": "Article 5(1)(f)",
          "since": "2025-02-02",
          "when": "(f) => f.aiPurpose === \"emotion-inference\" && [\"employment\", \"education\"].includes(f.aiUseCase)"
        },
        {
          "id": "aia-p-biocat",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 30, and recital 40 which cites Article 5(1) first subparagraph point (g)"
          },
          "severity": "prohibited",
          "title": "Biometric categorisation inferring sensitive attributes",
          "provision": "Article 5(1)(g)",
          "since": "2025-02-02",
          "when": "(f) => f.aiPurpose === \"biometric-categorisation-sensitive\""
        },
        {
          "id": "aia-p-rbi",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recitals 32 to 38, and recital 40 which cites Article 5(1) first subparagraph point (h)"
          },
          "severity": "prohibited",
          "title": "Real-time remote biometric identification in public spaces for law enforcement",
          "provision": "Article 5(1)(h)",
          "since": "2025-02-02",
          "when": "(f) => f.aiPurpose === \"realtime-remote-biometric-id\" && f.aiUseCase === \"law-enforcement\""
        },
        {
          "id": "aia-p-subliminal",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 29 (subliminal and manipulative techniques materially distorting behaviour)"
          },
          "severity": "prohibited",
          "title": "Subliminal or manipulative techniques distorting behaviour",
          "provision": "Article 5(1)(a)",
          "since": "2025-02-02",
          "when": "(f) => (f.aiTechniques || []).includes(\"subliminal\")"
        },
        {
          "id": "aia-p-vulnerability",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 29 (exploitation of vulnerabilities of age, disability or social or economic situation)"
          },
          "severity": "prohibited",
          "title": "Exploiting vulnerabilities of age, disability or circumstance",
          "provision": "Article 5(1)(b)",
          "since": "2025-02-02",
          "when": "(f) => (f.aiTechniques || []).includes(\"vulnerability\")"
        },
        {
          "id": "aia-p-ncii",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Regulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read"
          },
          "severity": "prohibited",
          "title": "Generating non-consensual intimate imagery of identifiable people",
          "provision": "Article 5, as amended",
          "since": "2026-12-02",
          "addedBy": "omnibus-ai",
          "when": "(f) => f.aiPurpose === \"ncii\""
        },
        {
          "id": "aia-p-csam",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Regulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read"
          },
          "severity": "prohibited",
          "title": "Generating child sexual abuse material, or lacking safeguards against it",
          "provision": "Article 5, as amended",
          "since": "2026-12-02",
          "addedBy": "omnibus-ai",
          "when": "(f) => f.aiPurpose === \"csam\""
        },
        {
          "id": "aia-hr-annexiii",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recitals 54 to 62 (the eight Annex III areas); the deferred date is from Regulation (EU) 2026/1744"
          },
          "severity": "high-risk",
          "title": "High-risk: falls within an Annex III area",
          "provision": "Article 6(2) and Annex III",
          "since": "2027-12-02",
          "deferredBy": "omnibus-ai",
          "when": "(f) => f.aiUseCase && f.aiUseCase !== \"none\" && !((f.aiDerogation || []).length && f.profiling !== true)",
          "note": "Deferred from 2 August 2026 by Regulation (EU) 2026/1744. Preparation is expected to be under way rather than starting then."
        },
        {
          "id": "aia-hr-derogation",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 53 (all four Article 6(3) conditions, the documentation duty and EU database registration)"
          },
          "severity": "note",
          "title": "Annex III area, with the Article 6(3) derogation claimed",
          "provision": "Article 6(3)",
          "since": "2027-12-02",
          "when": "(f) => f.aiUseCase && f.aiUseCase !== \"none\" && (f.aiDerogation || []).length > 0 && f.profiling !== true",
          "note": "Relying on the derogation requires a documented assessment before placing on the market, and registration in the EU database. It never applies where the system profiles people."
        },
        {
          "id": "aia-hr-profiling",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 53 (profiling within the meaning of Article 4(4) GDPR removes the derogation)"
          },
          "severity": "high-risk",
          "title": "The derogation is unavailable because the system profiles people",
          "provision": "Article 6(3), final subparagraph",
          "since": "2027-12-02",
          "when": "(f) => f.aiUseCase && f.aiUseCase !== \"none\" && (f.aiDerogation || []).length > 0 && f.profiling === true"
        },
        {
          "id": "aia-hr-annexi",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recitals 50 and 51 (products under Union harmonisation legislation with third-party assessment)"
          },
          "severity": "high-risk",
          "title": "High-risk as a regulated product or its safety component",
          "provision": "Article 6(1) and Annex I",
          "since": "2028-08-02",
          "deferredBy": "omnibus-ai",
          "when": "(f) => f.annexOneProduct === true",
          "note": "Sits alongside the existing product legislation rather than replacing it."
        },
        {
          "id": "aia-t-interaction",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article 50 transparency obligations confirmed as applying from 2 August 2026 across the Commission's reporting and several law firms; the wording of Article 50(1) is not yet read"
          },
          "severity": "obligation",
          "title": "Tell people they are interacting with an AI system",
          "provision": "Article 50(1)",
          "since": "2026-08-02",
          "when": "(f) => f.interactsWithPeople === true && (f.role || []).includes(\"provider\")"
        },
        {
          "id": "aia-t-marking",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Deferral to 2026-12-02 for systems already on the market, confirmed across the same sources"
          },
          "severity": "obligation",
          "title": "Mark synthetic content in a machine-readable way",
          "provision": "Article 50(2)",
          "since": "2026-08-02",
          "sinceIfAlreadyOnMarket": "2026-12-02",
          "deferredBy": "omnibus-ai",
          "when": "(f) => f.generatesSyntheticContent === true && (f.role || []).includes(\"provider\")"
        },
        {
          "id": "aia-t-emotion-notice",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article 50(3) as reported consistently; wording not yet read"
          },
          "severity": "obligation",
          "title": "Inform people exposed to emotion recognition or biometric categorisation",
          "provision": "Article 50(3)",
          "since": "2026-08-02",
          "when": "(f) => f.emotionOrBiometricCategorisation === true && (f.role || []).includes(\"deployer\")"
        },
        {
          "id": "aia-t-deepfake",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article 50(4) as reported consistently; wording not yet read"
          },
          "severity": "obligation",
          "title": "Disclose deep fakes and AI-generated text on matters of public interest",
          "provision": "Article 50(4)",
          "since": "2026-08-02",
          "when": "(f) => f.publishesDeepFakesOrPublicInterestText === true && (f.role || []).includes(\"deployer\")"
        },
        {
          "id": "aia-g-docs",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Chapter V obligations applying from 2 August 2025, reported consistently; Article 53 wording not yet read"
          },
          "severity": "obligation",
          "title": "General-purpose model documentation, downstream information, copyright policy and training-content summary",
          "provision": "Article 53",
          "since": "2025-08-02",
          "when": "(f) => (f.nature || []).includes(\"gpai-model\") && (f.role || []).includes(\"provider\")"
        },
        {
          "id": "aia-g-systemic",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Articles 51 and 55 with the 10^25 floating point operation presumption, reported consistently; wording not yet read"
          },
          "severity": "obligation",
          "title": "Systemic-risk evaluation, adversarial testing, incident reporting and cybersecurity",
          "provision": "Articles 51 and 55",
          "since": "2025-08-02",
          "when": "(f) => (f.nature || []).includes(\"gpai-model\") && (f.role || []).includes(\"provider\") && f.gpaiSystemicRisk === true"
        },
        {
          "id": "aia-literacy",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "OJ text, recital 20 (AI literacy for providers, deployers and affected persons)"
          },
          "severity": "obligation",
          "title": "AI literacy: ensure staff dealing with the system are sufficiently competent",
          "provision": "Article 4",
          "since": "2025-02-02",
          "when": "(f) => (f.nature || []).includes(\"ai-system\") && (f.role || []).some((r) => [\"provider\", \"deployer\"].includes(r))"
        }
      ],
      "obligationsIfHighRisk": {
        "provider": [
          {
            "id": "aia-o-rms",
            "title": "Risk management system across the lifecycle",
            "provision": "Article 9"
          },
          {
            "id": "aia-o-data",
            "title": "Data and data governance",
            "provision": "Article 10"
          },
          {
            "id": "aia-o-techdoc",
            "title": "Technical documentation",
            "provision": "Article 11 and Annex IV"
          },
          {
            "id": "aia-o-logging",
            "title": "Automatic event logging",
            "provision": "Article 12"
          },
          {
            "id": "aia-o-instructions",
            "title": "Instructions enabling deployers to comply",
            "provision": "Article 13"
          },
          {
            "id": "aia-o-oversight",
            "title": "Design for human oversight",
            "provision": "Article 14"
          },
          {
            "id": "aia-o-accuracy",
            "title": "Accuracy, robustness and cybersecurity",
            "provision": "Article 15"
          },
          {
            "id": "aia-o-qms",
            "title": "Quality management system",
            "provision": "Article 17"
          },
          {
            "id": "aia-o-conformity",
            "title": "Conformity assessment, declaration and CE marking",
            "provision": "Articles 43, 47 and 48"
          },
          {
            "id": "aia-o-registration",
            "title": "Registration in the EU database",
            "provision": "Article 49"
          },
          {
            "id": "aia-o-postmarket",
            "title": "Post-market monitoring and serious incident reporting",
            "provision": "Articles 72 and 73"
          }
        ],
        "deployer": [
          {
            "id": "aia-d-instructions",
            "title": "Use in accordance with the instructions",
            "provision": "Article 26(1)"
          },
          {
            "id": "aia-d-oversight",
            "title": "Competent, trained human oversight",
            "provision": "Article 26(2)"
          },
          {
            "id": "aia-d-input",
            "title": "Relevant and representative input data",
            "provision": "Article 26(4)"
          },
          {
            "id": "aia-d-monitor",
            "title": "Monitoring and serious incident reporting",
            "provision": "Article 26(5)"
          },
          {
            "id": "aia-d-logs",
            "title": "Keep the logs the system generates",
            "provision": "Article 26(6)"
          },
          {
            "id": "aia-d-workers",
            "title": "Inform workers and their representatives",
            "provision": "Article 26(7)"
          },
          {
            "id": "aia-d-fria",
            "title": "Fundamental rights impact assessment where applicable",
            "provision": "Article 27"
          },
          {
            "id": "aia-d-subjects",
            "title": "Inform people subject to decisions",
            "provision": "Article 26(11)"
          }
        ]
      },
      "timeline": [
        {
          "date": "2024-08-01",
          "label": "Enters into force",
          "provision": "Article 113"
        },
        {
          "date": "2025-02-02",
          "label": "Prohibitions and AI literacy apply",
          "provision": "Articles 4 and 5"
        },
        {
          "date": "2025-08-02",
          "label": "General-purpose model obligations, governance and penalties apply",
          "provision": "Chapter V"
        },
        {
          "date": "2026-08-02",
          "label": "Transparency obligations apply and enforcement begins",
          "provision": "Article 50"
        },
        {
          "date": "2026-12-02",
          "label": "Marking applies to systems already on the market; new prohibitions apply",
          "provision": "Articles 50(2) and 5",
          "changedBy": "omnibus-ai"
        },
        {
          "date": "2027-12-02",
          "label": "High-risk obligations apply to Annex III systems",
          "provision": "Chapter III",
          "changedBy": "omnibus-ai"
        },
        {
          "date": "2028-08-02",
          "label": "High-risk obligations apply to Annex I systems",
          "provision": "Chapter III",
          "changedBy": "omnibus-ai"
        }
      ],
      "watch": []
    },
    {
      "id": "cra",
      "title": "Cyber Resilience Act",
      "instrument": "Regulation (EU) 2024/2847",
      "source": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "version": "v0.5.0",
      "reads": [
        "role",
        "euMarket",
        "nature",
        "openSource"
      ],
      "gate": "(f) => f.euMarket === true && (f.nature || []).includes(\"product-digital-elements\") && f.openSource !== true",
      "rules": [
        {
          "id": "cra-reporting",
          "check": {
            "level": "official-summary",
            "on": "2026-08-06",
            "source": "https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act"
          },
          "severity": "obligation",
          "title": "Report actively exploited vulnerabilities and severe incidents to ENISA and the CSIRT",
          "provision": "Article 14",
          "since": "2026-09-11",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")",
          "note": "The first CRA duty to bind, ahead of the main requirements."
        },
        {
          "id": "cra-essential",
          "check": {
            "level": "official-summary",
            "on": "2026-08-06",
            "source": "https://digital-strategy.ec.europa.eu/en/policies/cra-summary"
          },
          "severity": "obligation",
          "title": "Essential cybersecurity requirements in design, development and production",
          "provision": "Article 13 and Annex I",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")"
        },
        {
          "id": "cra-vuln-handling",
          "check": {
            "level": "official-summary",
            "on": "2026-08-06",
            "source": "https://digital-strategy.ec.europa.eu/en/policies/cra-summary"
          },
          "severity": "obligation",
          "title": "Vulnerability handling, including a coordinated disclosure policy and security updates",
          "provision": "Annex I Part II",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")"
        },
        {
          "id": "cra-sbom",
          "check": {
            "level": "official-summary",
            "on": "2026-08-06",
            "source": "https://digital-strategy.ec.europa.eu/en/policies/cra-summary"
          },
          "severity": "obligation",
          "title": "Software bill of materials covering top-level dependencies",
          "provision": "Annex I Part II(1)",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")"
        },
        {
          "id": "cra-conformity",
          "check": {
            "level": "official-summary",
            "on": "2026-08-06",
            "source": "https://digital-strategy.ec.europa.eu/en/policies/cra-summary"
          },
          "severity": "obligation",
          "title": "Conformity assessment, EU declaration of conformity and CE marking",
          "provision": "Articles 32, 28 and 30",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")"
        },
        {
          "id": "cra-support",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Commission summary describes the support period; the five year default and the Article 13(8) reference are not yet confirmed against the text"
          },
          "severity": "obligation",
          "title": "Define and publish the support period, at least five years unless the expected use is shorter",
          "provision": "Article 13(8)",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")"
        },
        {
          "id": "cra-importer",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Commission summary describes importer duties; the Article 19 number is not yet confirmed against the text"
          },
          "severity": "obligation",
          "title": "Verify the manufacturer's conformity assessment and marking before placing on the market",
          "provision": "Article 19",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"importer\")"
        },
        {
          "id": "cra-distributor",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Commission summary describes distributor duties; the Article 20 number is not yet confirmed against the text"
          },
          "severity": "obligation",
          "title": "Act with due care in relation to the requirements when making a product available",
          "provision": "Article 20",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"distributor\")"
        },
        {
          "id": "cra-oss-scope",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; free and open-source software supplied outside a commercial activity is outside the scope entirely; a steward operating within a commercial context carries lighter duties than a manufacturer"
          },
          "severity": "note",
          "title": "Software supplied outside a commercial activity is outside this Regulation entirely",
          "provision": "Article 2",
          "since": "2027-12-11",
          "when": "(f) => f.openSource === true",
          "note": "This is a scope question rather than a lighter regime. Where an open-source project is supplied within a commercial activity, its steward carries duties, but they are not a manufacturer's duties. The boundary is commercial activity, and it is the fact most often assumed rather than checked."
        },
        {
          "id": "cra-techdoc",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; technical documentation demonstrating conformity with the essential requirements must be drawn up before placing the product on the market"
          },
          "severity": "obligation",
          "title": "Draw up technical documentation showing how the product meets the essential requirements",
          "provision": "Article 13 and Annex VII",
          "since": "2027-12-11",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")"
        }
      ],
      "timeline": [
        {
          "date": "2024-12-10",
          "label": "Enters into force",
          "provision": "Article 71"
        },
        {
          "date": "2026-09-11",
          "label": "Reporting obligations for actively exploited vulnerabilities apply",
          "provision": "Article 14"
        },
        {
          "date": "2027-12-11",
          "label": "The remaining obligations apply",
          "provision": "Article 71(2)"
        }
      ],
      "watch": []
    },
    {
      "id": "gdpr",
      "title": "General Data Protection Regulation",
      "instrument": "Regulation (EU) 2016/679",
      "source": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
      "version": "v0.5.0",
      "reads": [
        "role",
        "euMarket",
        "personalData",
        "specialCategories",
        "profiling",
        "significantEffects",
        "largeScaleSpecialCategories",
        "largeScaleMonitoring",
        "transfersOutsideEu",
        "size",
        "sector"
      ],
      "gate": "(f) => f.personalData === true",
      "rules": [
        {
          "id": "gdpr-lawful-basis",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions of Regulation (EU) 2016/679 (gdpr-info.eu and others), consistent on Article 6"
          },
          "severity": "obligation",
          "title": "Identify and record a lawful basis for each purpose",
          "provision": "Article 6",
          "since": "2018-05-25",
          "when": "() => true"
        },
        {
          "id": "gdpr-special",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions, consistent on Article 9 for special categories"
          },
          "severity": "obligation",
          "title": "Establish an Article 9 condition before processing special categories",
          "provision": "Article 9",
          "since": "2018-05-25",
          "when": "(f) => f.specialCategories === true"
        },
        {
          "id": "gdpr-transparency",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions, consistent on Articles 13 and 14"
          },
          "severity": "obligation",
          "title": "Inform people at collection, in clear and accessible terms",
          "provision": "Articles 13 and 14",
          "since": "2018-05-25",
          "when": "() => true"
        },
        {
          "id": "gdpr-ropa",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Article 30(5) exempts organisations under 250 people only where processing is occasional, poses no risk, and involves no special categories or criminal data. Payroll and HR are not occasional, so the exemption rarely applies"
          },
          "severity": "obligation",
          "title": "Maintain a record of processing activities",
          "provision": "Article 30",
          "since": "2018-05-25",
          "when": "() => true",
          "note": "The exemption for organisations under 250 people is conditional and narrow: processing must be occasional, unlikely to result in risk, and free of special categories. Routine payroll or HR processing is not occasional, so most organisations of any size owe this."
        },
        {
          "id": "gdpr-dpia",
          "check": {
            "level": "official-text",
            "on": "2026-08-06",
            "source": "EUR-Lex text: Article 36(1) refers to 'a data protection impact assessment under Article 35', confirming both the duty and its numbering"
          },
          "severity": "obligation",
          "title": "Carry out a data protection impact assessment before starting",
          "provision": "Article 35",
          "since": "2018-05-25",
          "when": "(f) => f.largeScaleMonitoring === true || f.largeScaleSpecialCategories === true || (f.profiling === true && f.significantEffects === true)",
          "note": "Article 35(3) names three cases: systematic and extensive automated evaluation producing legal or similarly significant effects, large-scale processing of special categories, and large-scale systematic monitoring of a publicly accessible area. They are examples of high risk rather than the whole test, and most national authorities publish their own mandatory list. Sector alone never triggers this."
        },
        {
          "id": "gdpr-automated",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions, consistent on Article 22 for automated individual decision-making"
          },
          "severity": "obligation",
          "title": "Automated decisions with legal or similarly significant effects need a basis, safeguards and human intervention",
          "provision": "Article 22",
          "since": "2018-05-25",
          "when": "(f) => f.profiling === true && f.significantEffects === true",
          "note": "Article 22 reaches decisions taken solely by automated means that produce legal or similarly significant effects. Profiling that does not decide anything of consequence, such as segmenting a mailing list, is outside it, though the rest of the Regulation still applies."
        },
        {
          "id": "gdpr-processor",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions, consistent on Article 28 for processor contracts"
          },
          "severity": "obligation",
          "title": "A written processing agreement with every processor",
          "provision": "Articles 28(3) and 28(4)",
          "since": "2018-05-25",
          "when": "(f) => (f.role || []).some((r) => [\"controller\", \"processor\"].includes(r))",
          "note": "The duty flows down the chain: a processor engaging a sub-processor must impose the same terms it accepted."
        },
        {
          "id": "gdpr-security",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions, consistent on Article 32 for security of processing"
          },
          "severity": "obligation",
          "title": "Security appropriate to the risk, and the ability to demonstrate it",
          "provision": "Article 32",
          "since": "2018-05-25",
          "when": "() => true"
        },
        {
          "id": "gdpr-breach",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Third external review, 2026-08-09; Articles 33(1) and 34 place the notification duties on the controller; Article 33(2) requires a processor to notify the controller instead"
          },
          "severity": "obligation",
          "title": "Notify a personal data breach to the authority within 72 hours where it is likely to result in risk, and tell affected people where the risk is high",
          "provision": "Articles 33(1) and 34",
          "since": "2018-05-25",
          "when": "(f) => (f.role || []).includes(\"controller\")"
        },
        {
          "id": "gdpr-breach-processor",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Third external review, 2026-08-09; Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a breach"
          },
          "severity": "obligation",
          "title": "As a processor, notify the controller without undue delay after becoming aware of a breach",
          "provision": "Article 33(2)",
          "since": "2018-05-25",
          "when": "(f) => (f.role || []).includes(\"processor\") && !(f.role || []).includes(\"controller\")",
          "note": "The processor does not notify the authority or the people affected; the controller does."
        },
        {
          "id": "gdpr-transfers",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions, consistent on Chapter V, Articles 44 to 50"
          },
          "severity": "obligation",
          "title": "A transfer mechanism, and a transfer impact assessment where required",
          "provision": "Chapter V",
          "since": "2018-05-25",
          "when": "(f) => f.transfersOutsideEu === true"
        },
        {
          "id": "gdpr-dpo",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article index reproductions, consistent on Article 37 for designation of the data protection officer"
          },
          "severity": "obligation",
          "title": "Designate a data protection officer",
          "provision": "Article 37",
          "since": "2018-05-25",
          "when": "(f) => f.sector === \"public\" || f.largeScaleMonitoring === true || f.largeScaleSpecialCategories === true",
          "note": "For a public authority the duty is unconditional. For everyone else it turns on core activities: regular and systematic monitoring at large scale, or large-scale processing of special categories, as the main thing the organisation does. Processing special categories incidentally, such as employee health records, does not trigger it, however large the organisation."
        },
        {
          "id": "gdpr-rights",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Chapter III, Articles 12 to 22, requires controllers to facilitate the exercise of data subject rights and to respond within one month"
          },
          "severity": "obligation",
          "title": "Facilitate and answer data subject requests: access, rectification, erasure, restriction, portability and objection",
          "provision": "Chapter III, Articles 12 to 22",
          "since": "2018-05-25",
          "when": "(f) => (f.role || []).includes(\"controller\")",
          "note": "One month to respond, extendable by two where the request is complex. A processor must assist the controller in meeting these."
        },
        {
          "id": "gdpr-by-design",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Article 25 requires data protection by design and by default, at the time the means of processing are determined and during processing"
          },
          "severity": "obligation",
          "title": "Data protection by design and by default, from the moment the means of processing are chosen",
          "provision": "Article 25",
          "since": "2018-05-25",
          "when": "(f) => (f.role || []).includes(\"controller\")"
        }
      ],
      "timeline": [
        {
          "date": "2018-05-25",
          "label": "Applies",
          "provision": "Article 99"
        }
      ],
      "watch": [
        {
          "id": "gdpr-omnibus",
          "title": "The Data Omnibus would amend the GDPR, ePrivacy, NIS2, DORA and the Data Act",
          "status": "proposed",
          "proposedOn": "2025-11-19",
          "note": "Still in negotiation as of August 2026 and not law. Reported changes include single-click consent, a moratorium on re-prompting, a longer breach notification window and a single incident reporting point. Plan against the obligations that are in force today."
        }
      ]
    },
    {
      "id": "nis2",
      "title": "NIS2 Directive",
      "instrument": "Directive (EU) 2022/2555",
      "source": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj",
      "version": "v0.5.0",
      "isDirective": true,
      "reads": [
        "euMarket",
        "sector",
        "size",
        "essentialOrImportantEntity"
      ],
      "gate": "(f) => f.euMarket === true &&\n    (f.essentialOrImportantEntity === true || [\"public\", \"digital-infrastructure\"].includes(f.sector) ||\n     (f.size !== \"micro\" && f.size !== \"small\")) &&\n    (f.essentialOrImportantEntity === true || [\"energy\", \"transport\", \"health\", \"digital-infrastructure\", \"public\", \"finance\", \"water\", \"waste\", \"manufacturing\", \"postal\", \"space\"].includes(f.sector))",
      "rules": [
        {
          "id": "nis2-transposition",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Transposition deadline of 17 October 2024 corroborated widely; as of mid-2026 transposition remains uneven and the Commission has referred several Member States to the Court of Justice, which is exactly why this pack refuses to assert a national obligation"
          },
          "severity": "caution",
          "title": "Your obligations are those of the transposing national law, not the directive itself",
          "provision": "Article 41",
          "since": "2024-10-18",
          "when": "() => true",
          "note": "Obligations take effect through each Member State's transposing law, which may differ in scope, timing and penalties. Transposition is uneven across the Union, and several Member States have been referred to the Court of Justice for failing to transpose."
        },
        {
          "id": "nis2-registration",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Article 3(4) requires Member States to establish lists of essential and important entities with information submitted by them; note that Article 27 imposes a separate registry duty on certain digital entity types, which this pack does not yet distinguish"
          },
          "severity": "obligation",
          "title": "Submit your registration details to the competent authority, as an essential or an important entity",
          "provision": "Articles 3(4) and 27",
          "since": "2024-10-18",
          "when": "(f) => f.essentialOrImportantEntity === true"
        },
        {
          "id": "nis2-measures",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Multiple independent analyses of Directive (EU) 2022/2555, consistent on Article 21 for risk management measures"
          },
          "severity": "obligation",
          "title": "Risk management measures, owed by essential and important entities alike: policies, incident handling, continuity, supply chain, cryptography and access control",
          "provision": "Article 21",
          "since": "2024-10-18",
          "when": "(f) => f.essentialOrImportantEntity === true"
        },
        {
          "id": "nis2-reporting",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Multiple independent analyses, consistent on Article 23 and the 24 hour, 72 hour and one month structure"
          },
          "severity": "obligation",
          "title": "Early warning within 24 hours, notification within 72 hours, final report within one month",
          "provision": "Article 23",
          "since": "2024-10-18",
          "when": "(f) => f.essentialOrImportantEntity === true"
        },
        {
          "id": "nis2-management",
          "check": {
            "level": "secondary",
            "on": "2026-08-06",
            "source": "Multiple independent analyses, consistent on Article 20 for management approval, oversight, training and personal liability"
          },
          "severity": "obligation",
          "title": "Management bodies approve the measures and can be held personally liable",
          "provision": "Article 20",
          "since": "2024-10-18",
          "when": "(f) => f.essentialOrImportantEntity === true"
        }
      ],
      "timeline": [
        {
          "date": "2023-01-16",
          "label": "Enters into force",
          "provision": "Article 45"
        },
        {
          "date": "2024-10-17",
          "label": "Member States were required to transpose it",
          "provision": "Article 41"
        }
      ],
      "watch": [
        {
          "id": "nis2-omnibus",
          "title": "The Data Omnibus proposes streamlined incident reporting through a single entry point",
          "status": "proposed",
          "proposedOn": "2025-11-19",
          "note": "Would let one report satisfy notifications under NIS2, the GDPR and DORA. Not adopted; report separately until it is."
        }
      ]
    },
    {
      "id": "data-act",
      "title": "Data Act",
      "instrument": "Regulation (EU) 2023/2854",
      "source": "https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng",
      "version": "v0.8.2",
      "reads": [
        "role",
        "euMarket",
        "nature",
        "size",
        "personalData"
      ],
      "gate": "(f) => f.euMarket === true && (f.nature || []).some((n) => [\"connected-product\", \"related-service\", \"data-processing-service\"].includes(n))",
      "rules": [
        {
          "id": "da-access-by-design",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: connected products placed on the market after 12 September 2026 must be designed so that data is accessible by default"
          },
          "severity": "obligation",
          "title": "Design connected products, and provide related services, so that the data generated is accessible to the user by default",
          "provision": "Article 3",
          "since": "2026-09-12",
          "when": "(f) => (f.nature || []).some((n) => [\"connected-product\", \"related-service\"].includes(n)) && (f.role || []).some((r) => [\"provider\", \"manufacturer\"].includes(r)) && ![\"micro\", \"small\"].includes(f.size)",
          "note": "Article 7 exempts micro and small enterprises from the Chapter II duties, including this one."
        },
        {
          "id": "da-user-access",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read"
          },
          "severity": "obligation",
          "title": "Make product and related service data available to the user, and to a third party at the user's request",
          "provision": "Articles 4 and 5",
          "since": "2025-09-12",
          "when": "(f) => (f.nature || []).some((n) => [\"connected-product\", \"related-service\"].includes(n)) && (f.role || []).some((r) => [\"provider\", \"manufacturer\"].includes(r)) && ![\"micro\", \"small\"].includes(f.size)",
          "note": "The duty falls on the data holder rather than on everyone touching the product, and micro and small enterprises are exempt under Article 7."
        },
        {
          "id": "da-switching",
          "check": {
            "level": "official-text",
            "on": "2026-08-09",
            "source": "EUR-Lex text read on 2026-08-09: Article 29 read verbatim. From 12 January 2027 no switching charges; reduced charges permitted from 11 January 2024 until then, capped at costs directly incurred"
          },
          "severity": "obligation",
          "title": "Remove switching charges: reduced until 12 January 2027, prohibited from that date",
          "provision": "Article 29",
          "since": "2025-09-12",
          "when": "(f) => (f.nature || []).includes(\"data-processing-service\") && (f.role || []).includes(\"provider\")",
          "note": "Article 29 is worded from 11 January 2024, but the Regulation only applies from 12 September 2025 under Article 50, so that is when the reduced-charge regime begins to bind. Early termination penalties remain possible; charges for the switching process itself do not."
        },
        {
          "id": "da-switching-contract",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: Chapter VI, Articles 23 to 31, requires contractual terms enabling switching to another provider or to on-premises infrastructure"
          },
          "severity": "obligation",
          "title": "Contractual terms enabling a customer to switch provider, run several in parallel, or move on premises",
          "provision": "Chapter VI, Articles 23 to 31",
          "since": "2025-09-12",
          "when": "(f) => (f.nature || []).includes(\"data-processing-service\") && (f.role || []).includes(\"provider\")"
        },
        {
          "id": "da-interop",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: functional equivalence for infrastructure services, open interfaces for others"
          },
          "severity": "obligation",
          "title": "Functional equivalence for infrastructure services, and open interfaces for other data processing services",
          "provision": "Chapter VIII",
          "since": "2025-09-12",
          "when": "(f) => (f.nature || []).includes(\"data-processing-service\") && (f.role || []).includes(\"provider\")"
        },
        {
          "id": "da-intl-access",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: publish the jurisdiction of the ICT infrastructure and the measures against unlawful governmental access to non-personal data"
          },
          "severity": "obligation",
          "title": "Publish the jurisdiction your infrastructure sits under, and take measures against unlawful international governmental access",
          "provision": "Articles 30 and 32",
          "since": "2025-09-12",
          "when": "(f) => (f.nature || []).includes(\"data-processing-service\") && (f.role || []).includes(\"provider\")"
        },
        {
          "id": "da-unfair-terms",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: unfairly imposed data-sharing terms are not binding; extends to pre-existing contracts from 12 September 2027"
          },
          "severity": "caution",
          "title": "Unilaterally imposed unfair data terms do not bind the other party, and this reaches older contracts from 12 September 2027",
          "provision": "Article 13",
          "since": "2025-09-12",
          "when": "(f) => (f.nature || []).some((n) => [\"connected-product\", \"data-processing-service\"].includes(n))"
        },
        {
          "id": "da-personal-data",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: the Data Act covers personal and non-personal data and does not displace the GDPR"
          },
          "severity": "note",
          "title": "Where the data is personal, the GDPR continues to apply alongside this Regulation",
          "provision": "Article 1(5)",
          "since": "2025-09-12",
          "when": "(f) => f.personalData === true"
        },
        {
          "id": "da-b2g",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Chapter V, Articles 14 to 22, requires a data holder to make data available to a public sector body demonstrating an exceptional need, such as a public emergency"
          },
          "severity": "obligation",
          "title": "Make data available to a public body that demonstrates an exceptional need, such as a public emergency",
          "provision": "Chapter V, Articles 14 to 22",
          "since": "2025-09-12",
          "when": "(f) => (f.nature || []).some((n) => [\"connected-product\", \"related-service\"].includes(n))"
        }
      ],
      "timeline": [
        {
          "date": "2024-01-11",
          "label": "Enters into force",
          "provision": "Article 50"
        },
        {
          "date": "2025-09-12",
          "label": "Applies: data access, switching and interoperability obligations",
          "provision": "Article 50"
        },
        {
          "date": "2026-09-12",
          "label": "Access by design applies to connected products placed on the market from this date",
          "provision": "Article 3"
        },
        {
          "date": "2027-01-12",
          "label": "Switching charges prohibited entirely",
          "provision": "Article 29"
        },
        {
          "date": "2027-09-12",
          "label": "Unfair terms provisions reach contracts concluded before 12 September 2025",
          "provision": "Article 13"
        }
      ],
      "watch": [
        {
          "id": "da-omnibus",
          "title": "The Digital Omnibus proposes exemptions from the switching regime for custom-made services and a lighter regime for smaller providers",
          "status": "proposed",
          "proposedOn": "2025-11-19",
          "note": "Reported as covering custom-made services other than infrastructure services for contracts concluded before 12 September 2025. Not adopted; the obligations above apply as they stand."
        }
      ]
    },
    {
      "id": "dsa",
      "title": "Digital Services Act",
      "instrument": "Regulation (EU) 2022/2065",
      "source": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2065",
      "version": "v0.8.2",
      "reads": [
        "role",
        "euMarket",
        "nature",
        "size",
        "platformAds",
        "minorsDirected",
        "veryLargePlatform"
      ],
      "gate": "(f) => f.euMarket === true && (f.nature || []).some((n) => [\"intermediary\", \"hosting-service\", \"online-platform\", \"marketplace\"].includes(n))",
      "rules": [
        {
          "id": "dsa-terms",
          "check": {
            "level": "official-text",
            "on": "2026-08-09",
            "source": "EUR-Lex text read on 2026-08-09: Article 14 read. Terms in clear, plain, intelligible, user-friendly and unambiguous language, publicly available and machine readable, with significant changes notified; where a service is directed at or predominantly used by minors, the conditions must be explained so minors can understand"
          },
          "severity": "obligation",
          "title": "Terms and conditions in plain language, machine readable, with changes notified",
          "provision": "Article 14",
          "since": "2024-02-17",
          "when": "() => true"
        },
        {
          "id": "dsa-contact",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: single points of contact for authorities and for recipients, and a legal representative where not established in the Union"
          },
          "severity": "obligation",
          "title": "A point of contact for authorities and for users, and a legal representative if you are not established in the Union",
          "provision": "Articles 11 to 13",
          "since": "2024-02-17",
          "when": "() => true"
        },
        {
          "id": "dsa-notice-action",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: Article 16 requires easy-to-access, user-friendly electronic notice mechanisms for illegal content"
          },
          "severity": "obligation",
          "title": "Notice and action mechanism for illegal content, easy to access and electronic",
          "provision": "Article 16",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"hosting-service\", \"online-platform\", \"marketplace\"].includes(n))"
        },
        {
          "id": "dsa-reasons",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Article 17 binds hosting services; the duty to publish to the Commission database is Article 24(5) and binds online platforms only"
          },
          "severity": "obligation",
          "title": "Give a statement of reasons to the user for every restriction",
          "provision": "Article 17",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"hosting-service\", \"online-platform\", \"marketplace\"].includes(n))"
        },
        {
          "id": "dsa-reasons-db",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Article 24(5) requires online platforms to submit statements of reasons to the Commission's public database"
          },
          "severity": "obligation",
          "title": "Submit those statements of reasons to the Commission's public database",
          "provision": "Article 24(5)",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n))"
        },
        {
          "id": "dsa-complaints",
          "check": {
            "level": "official-text",
            "on": "2026-08-09",
            "source": "EUR-Lex text read on 2026-08-09: Article 20(1) read. Online platforms must give access to an effective internal complaint-handling system, electronically and free of charge, for at least six months after the decision"
          },
          "severity": "obligation",
          "title": "Internal complaint handling, free and electronic, open for at least six months",
          "provision": "Article 20",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n)) && ![\"micro\", \"small\"].includes(f.size)"
        },
        {
          "id": "dsa-odr",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read"
          },
          "severity": "obligation",
          "title": "Out-of-court dispute settlement available to users, and cooperation with trusted flaggers",
          "provision": "Articles 21 and 22",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n)) && ![\"micro\", \"small\"].includes(f.size)"
        },
        {
          "id": "dsa-dark-patterns",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: Article 25 prohibits interface design that deceives, manipulates or distorts users' ability to make free decisions"
          },
          "severity": "prohibited",
          "title": "Interfaces that deceive or manipulate a user's ability to decide freely are prohibited",
          "provision": "Article 25",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n))"
        },
        {
          "id": "dsa-ads",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: advertising must be identifiable, with the payer and the main targeting parameters disclosed; profiling on special categories is prohibited"
          },
          "severity": "obligation",
          "title": "Advertising identifiable in real time, with the payer and the main targeting parameters shown, and no targeting on special categories",
          "provision": "Article 26",
          "since": "2024-02-17",
          "when": "(f) => f.platformAds === true && (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n))"
        },
        {
          "id": "dsa-minors",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Second external review, 2026-08-09; Article 28(2) applies wherever the platform is aware with reasonable certainty that a recipient is a minor, not only where the service is directed at minors"
          },
          "severity": "prohibited",
          "title": "No advertising based on profiling where you are aware with reasonable certainty that a recipient is a minor",
          "provision": "Article 28(2)",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n))",
          "note": "This binds general-audience platforms too. Being directed at minors adds the Article 28(1) duty to design for their privacy and safety; it is not what triggers the advertising prohibition."
        },
        {
          "id": "dsa-traders",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: marketplaces must obtain and check trader identification before allowing use of the service"
          },
          "severity": "obligation",
          "title": "Know your business customer: obtain and verify trader details before allowing them to sell",
          "provision": "Articles 30 to 32",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).includes(\"marketplace\") && ![\"micro\", \"small\"].includes(f.size)"
        },
        {
          "id": "dsa-sme-exclusion",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: Article 19 excludes micro and small enterprises from the platform-specific obligations in Section 3"
          },
          "severity": "note",
          "title": "Micro and small enterprises are excluded from the platform and marketplace obligations",
          "provision": "Articles 19 and 29",
          "since": "2024-02-17",
          "when": "(f) => [\"micro\", \"small\"].includes(f.size) && (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n))",
          "note": "Article 19 covers the platform duties in Section 3 and Article 29 covers the marketplace duties in Section 4. The hosting and intermediary duties still apply, and the exclusion does not survive designation as a very large platform."
        },
        {
          "id": "dsa-transparency-report",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Article 15 requires annual transparency reports on content moderation from all intermediary services, with additional detail for platforms"
          },
          "severity": "obligation",
          "title": "Publish an annual transparency report on your content moderation",
          "provision": "Article 15",
          "since": "2024-02-17",
          "when": "() => true"
        },
        {
          "id": "dsa-suspension",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; Article 23 requires platforms to suspend, after warning, recipients who frequently provide manifestly illegal content, and to suspend the processing of abusive notices"
          },
          "severity": "obligation",
          "title": "Suspend, after a warning, users who frequently post manifestly illegal content",
          "provision": "Article 23",
          "since": "2024-02-17",
          "when": "(f) => (f.nature || []).some((n) => [\"online-platform\", \"marketplace\"].includes(n)) && ![\"micro\", \"small\"].includes(f.size)"
        },
        {
          "id": "dsa-vlop",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: systemic risk assessment and mitigation, independent audit, advertisement repository and researcher data access for designated very large platforms"
          },
          "severity": "obligation",
          "title": "Systemic risk assessment and mitigation, independent audit, ad repository and researcher access",
          "provision": "Articles 34 to 40",
          "since": "2023-08-25",
          "when": "(f) => f.veryLargePlatform === true"
        }
      ],
      "timeline": [
        {
          "date": "2022-11-16",
          "label": "Enters into force",
          "provision": "Article 93"
        },
        {
          "date": "2023-08-25",
          "label": "Applies to designated very large platforms and search engines",
          "provision": "Article 92"
        },
        {
          "date": "2024-02-17",
          "label": "Applies to all intermediary services",
          "provision": "Article 93"
        }
      ],
      "watch": []
    },
    {
      "id": "dora",
      "title": "Digital Operational Resilience Act",
      "instrument": "Regulation (EU) 2022/2554",
      "source": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng",
      "version": "v0.8.2",
      "reads": [
        "euMarket",
        "sector",
        "size",
        "financialEntity",
        "ictProviderToFinance",
        "essentialOrImportantEntity"
      ],
      "gate": "(f) => f.euMarket === true && (f.financialEntity === true || f.ictProviderToFinance === true)",
      "rules": [
        {
          "id": "dora-dates",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "EUR-Lex ELI metadata for CELEX 32022R2554 read on 2026-08-12: date_document 2022-12-14, date_publication 2022-12-27, first_date_entry_in_force 2025-01-17"
          },
          "severity": "note",
          "title": "The obligations apply from 17 January 2025",
          "provision": "Article 64",
          "since": "2025-01-17",
          "when": "() => true",
          "note": "EUR-Lex records the first date of entry into force as 17 January 2025, which is also the application date. Commentary widely gives 16 January 2023 as entry into force, twenty days after publication on 27 December 2022. Nothing turns on the difference for a reader planning compliance, since the duties bind from January 2025 either way, but the two are stated differently by different authorities and this instrument will not pick one silently."
        },
        {
          "id": "dora-governance",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 5(2) reads that the management body shall define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework referred to in Article 6(1)"
          },
          "severity": "obligation",
          "title": "The management body carries final responsibility for ICT risk, and must be able to show it",
          "provision": "Article 5",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true && f.size !== \"micro\"",
          "note": "Article 16(1) disapplies Articles 5 to 15 for a listed set of entities, of which microenterprises are one. Being larger than a microenterprise does not by itself put you outside that list."
        },
        {
          "id": "dora-ict-risk",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 6(1) reads that financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system"
          },
          "severity": "obligation",
          "title": "A sound, comprehensive and well-documented ICT risk management framework, forming part of the overall risk management system",
          "provision": "Articles 6 to 15, with the technical standards in Delegated Regulation (EU) 2024/1774",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true",
          "note": "Article 16(1) substitutes a lighter framework for a listed set of entities, not for microenterprises alone: small and non-interconnected investment firms and small institutions for occupational retirement provision are among them. This instrument asks only about size, so check the Article 16(1) list before relying on the standard regime applying to you."
        },
        {
          "id": "dora-incidents-classify",
          "check": {
            "level": "official-summary",
            "on": "2026-08-12",
            "source": "Official Journal reference read 2026-08-12: Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024, OJ L 2024/1772 of 25.6.2024, specifies the criteria for the classification of ICT-related incidents and cyber threats, sets out materiality thresholds, and specifies the details of reports of major incidents. The thresholds themselves have not been read"
          },
          "severity": "obligation",
          "title": "Classify ICT-related incidents against the criteria, because the reporting clock starts at classification and not at detection",
          "provision": "Article 18, with Delegated Regulation (EU) 2024/1772",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true",
          "note": "The thresholds live in Delegated Regulation (EU) 2024/1772 and are reported as met where two of the six criteria are exceeded, or one where the impact is severe. That figure is corroboration, not a reading. Classification is the act that starts every deadline below, so a slow classification does not buy time; it consumes it."
        },
        {
          "id": "dora-incidents-report",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Commission Delegated Regulation (EU) 2025/301, OJ L 2025/301 of 20.2.2025, read 2026-08-12: Article 5 sets the initial notification within four hours from classification of the incident as major, and Article 5(1)(b) reads that the intermediate report is due at the latest within 72 hours from the submission of the initial notification, even where the status or the handling of the incident have not changed, with an updated intermediate report without undue delay and in any case when regular activities have been recovered. The empowerment is DORA Article 20, third subparagraph, not Article 19"
          },
          "severity": "obligation",
          "title": "Report a major incident in three stages: initial within four hours of classifying it, intermediate within 72 hours, final within one month",
          "provision": "Articles 19 and 20, with Delegated Regulation (EU) 2025/301 Article 5",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true",
          "note": "The initial notification is due as early as possible, within four hours of classification as major and in any case no later than 24 hours from becoming aware. The intermediate report follows within 72 hours of the initial notification even if nothing has changed. The final report is due no later than one month after the latest intermediate report. Forms and procedures are in Implementing Regulation (EU) 2025/302. Two points from the text that commentary tends to drop: the 72 hours run from the submission of the initial notification rather than from the incident, and an updated intermediate report is due when regular activities are recovered, so an incident lasting longer than 72 hours produces at least two intermediate reports. Article 19 requires the reports; Article 20 is the empowerment under which the deadlines were made, and a rule citing only Article 19 for a four-hour figure cites the wrong provision."
        },
        {
          "id": "dora-incidents-weekend",
          "check": {
            "level": "secondary",
            "on": "2026-08-12",
            "source": "Reported from Article 5 of Delegated Regulation (EU) 2025/301: the weekend and bank holiday extension is unavailable to credit institutions, central counterparties, operators of trading venues and entities essential or important under Directive (EU) 2022/2555. The surrounding article was read on 2026-08-12 but this paragraph was not reproduced in what was returned"
          },
          "severity": "caution",
          "title": "The weekend and bank holiday extension does not apply to you if you are also an essential or important entity under NIS2",
          "provision": "Delegated Regulation (EU) 2025/301, Article 5",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true",
          "note": "Nor to credit institutions, central counterparties or operators of trading venues, and a competent authority may withdraw it from any entity it considers significant. A four-hour clock that does not pause at a weekend is an on-call rota rather than a policy."
        },
        {
          "id": "dora-threats-voluntary",
          "check": {
            "level": "secondary",
            "on": "2026-08-12",
            "source": "Article 19(2) of Regulation (EU) 2022/2554 as reported consistently: notification of significant cyber threats is voluntary"
          },
          "severity": "note",
          "title": "Notifying a significant cyber threat is voluntary, not required",
          "provision": "Article 19(2)",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true"
        },
        {
          "id": "dora-testing-programme",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 24 establishes the testing programme; Article 24(6) reads that financial entities other than microenterprises shall ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions"
          },
          "severity": "obligation",
          "title": "A digital operational resilience testing programme, with the systems supporting critical functions tested at least yearly",
          "provision": "Articles 24 and 25",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true && f.size !== \"micro\""
        },
        {
          "id": "dora-testing-micro",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 25(3) reads that microenterprises shall perform the tests referred to in paragraph 1 by combining a risk-based approach with strategic planning of ICT testing"
          },
          "severity": "obligation",
          "title": "As a microenterprise, still test: risk-based, with strategic planning rather than a full programme",
          "provision": "Article 25(3)",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true && f.size === \"micro\"",
          "note": "An earlier version of this instrument excluded microenterprises from testing entirely. The text requires them to test proportionately, which is a lighter duty and not an absent one."
        },
        {
          "id": "dora-tlpt",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 26(1) reads that financial entities other than entities referred to in Article 16(1) first subparagraph, and other than microenterprises, which are identified in accordance with paragraph 8 third subparagraph, shall carry out at least every three years advanced testing by means of threat-led penetration testing"
          },
          "severity": "obligation",
          "title": "Threat-led penetration testing at least every three years, where the authorities identify you for it",
          "provision": "Article 26",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true && f.size === \"large\"",
          "note": "Three conditions, all in the text: not an Article 16(1) entity, not a microenterprise, and identified by the competent authority under Article 26(8). Being large does not by itself trigger it, and this instrument cannot know whether you have been identified."
        },
        {
          "id": "dora-third-party",
          "check": {
            "level": "secondary",
            "on": "2026-08-12",
            "source": "Structure corroborated on 2026-08-12 across a primary-source guide citing article ranges, the EUR-Lex record and three independent analyses: Chapter II Section 2 is Articles 6 to 15, Article 16(1) is the simplified regime, Articles 17 to 23 incidents, 24 to 27 testing, 28 to 30 third-party principles, 31 to 44 oversight, 64 application. The article text itself has still not been read."
          },
          "severity": "obligation",
          "title": "A register of ICT third-party arrangements, mandatory contract terms, and a documented exit strategy for each",
          "provision": "Articles 28 to 30",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true"
        },
        {
          "id": "dora-critical-provider",
          "check": {
            "level": "secondary",
            "on": "2026-08-12",
            "source": "Structure corroborated on 2026-08-12 across a primary-source guide citing article ranges, the EUR-Lex record and three independent analyses: Chapter II Section 2 is Articles 6 to 15, Article 16(1) is the simplified regime, Articles 17 to 23 incidents, 24 to 27 testing, 28 to 30 third-party principles, 31 to 44 oversight, 64 application. The article text itself has still not been read."
          },
          "severity": "caution",
          "title": "If designated critical, an ICT provider to the financial sector comes under direct EU oversight",
          "provision": "Articles 31 to 44",
          "since": "2025-01-17",
          "when": "(f) => f.ictProviderToFinance === true",
          "note": "Designation as critical is made by the Lead Overseer under Article 31 and is not elected. The contractual requirements in Articles 28 to 30 apply to the financial entity regardless of whether its provider is designated."
        },
        {
          "id": "dora-third-party-strategy",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 28(2) reads that financial entities, other than microenterprises, shall adopt and regularly review a strategy on ICT third-party risk, taking into account the multi-vendor strategy referred to in Article 6(9) where applicable"
          },
          "severity": "obligation",
          "title": "Adopt and regularly review a strategy on ICT third-party risk, including any multi-vendor strategy",
          "provision": "Article 28(2), with Article 6(9)",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true && f.size !== \"micro\""
        },
        {
          "id": "dora-board-training",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 5(4) reads that members of the management body shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including by following specific training on a regular basis, commensurate to the ICT risk being managed"
          },
          "severity": "obligation",
          "title": "The management body must keep its own ICT knowledge current, with regular training",
          "provision": "Article 5(4)",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true",
          "note": "A personal duty on the members, not a delegable one, and one of the few DORA obligations with no size carve-out."
        },
        {
          "id": "dora-third-party-role",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 5(3) reads that financial entities other than microenterprises shall establish a role to monitor the arrangements concluded with ICT third-party service providers, or shall designate a member of senior management as responsible for overseeing the related risk exposure and documentation"
          },
          "severity": "obligation",
          "title": "Name someone: a role monitoring ICT third-party arrangements, or a senior manager accountable for them",
          "provision": "Article 5(3)",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true && f.size !== \"micro\""
        },
        {
          "id": "dora-control-function",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 6(4) reads that entities other than microenterprises shall assign responsibility for managing and overseeing ICT risk to a control function with an appropriate level of independence, and shall ensure segregation of risk management, control and internal audit functions according to the three lines of defence model"
          },
          "severity": "obligation",
          "title": "An independent control function for ICT risk, with the three lines of defence kept separate",
          "provision": "Article 6(4)",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true && f.size !== \"micro\""
        },
        {
          "id": "dora-framework-review",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 6(5) reads that the framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents and following supervisory instructions or conclusions from testing or audit; Article 6(6) requires internal audit of the framework for entities other than microenterprises; Article 6(8) requires the framework to include a digital operational resilience strategy"
          },
          "severity": "obligation",
          "title": "Review the framework yearly, after every major incident, and include a digital operational resilience strategy",
          "provision": "Articles 6(5), 6(6) and 6(8)",
          "since": "2025-01-17",
          "when": "(f) => f.financialEntity === true",
          "note": "A microenterprise reviews periodically rather than yearly, and is outside the internal audit requirement in Article 6(6). The strategy in Article 6(8) is part of the framework rather than a separate document."
        }
      ],
      "timeline": [
        {
          "date": "2022-12-14",
          "label": "Adopted",
          "provision": "Title"
        },
        {
          "date": "2022-12-27",
          "label": "Published in the Official Journal",
          "provision": "OJ L 333"
        },
        {
          "date": "2025-01-17",
          "label": "Applies",
          "provision": "Article 64"
        }
      ],
      "watch": [
        {
          "id": "dora-omnibus",
          "title": "The Data Omnibus proposes a single entry point for incident reporting across DORA, NIS2 and the GDPR",
          "status": "proposed",
          "proposedOn": "2025-11-19",
          "note": "Still in negotiation. Report separately until it is adopted."
        }
      ]
    },
    {
      "id": "eaa",
      "title": "European Accessibility Act",
      "instrument": "Directive (EU) 2019/882",
      "source": "https://eur-lex.europa.eu/eli/dir/2019/882/oj",
      "version": "v0.8.2",
      "isDirective": true,
      "reads": [
        "role",
        "euMarket",
        "size",
        "consumerFacing",
        "eaaService",
        "nature"
      ],
      "gate": "(f) => f.euMarket === true && f.eaaService && f.eaaService !== \"none\" &&\n    (f.consumerFacing === true || f.eaaService === \"terminals\" || (f.role || []).some((r) => [\"manufacturer\", \"importer\", \"distributor\"].includes(r)))",
      "rules": [
        {
          "id": "eaa-transposition",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Directive (EU) 2019/882, L 151, 7.6.2019: the article list reads Article 29 Enforcement, Article 30 Penalties, Article 31 Transposition, Article 32 Transitional measures"
          },
          "severity": "caution",
          "title": "Your obligations are those of the transposing national law, not the directive itself",
          "provision": "Article 31, with penalties under Article 30",
          "since": "2025-06-28",
          "when": "() => true",
          "note": "All Member States have transposed it. Penalties are set nationally under Article 30 and differ by country."
        },
        {
          "id": "eaa-requirements",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 4(1) reads that Member States shall ensure, subject to Article 14, that economic operators only place on the market products and only provide services that comply with the accessibility requirements in Annex I; Article 4(2) divides those requirements between Section I for all products and Section II for products other than self-service terminals"
          },
          "severity": "obligation",
          "title": "Meet the accessibility requirements: Annex I Section I for every product, Section II for products other than self-service terminals, Sections III and IV for services",
          "provision": "Article 4(1) and (2), and Annex I",
          "since": "2025-06-28",
          "when": "(f) => !(f.size === \"micro\" && !(f.role || []).some((r) => [\"manufacturer\", \"importer\", \"distributor\"].includes(r)))"
        },
        {
          "id": "eaa-information",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corroborated across independent professional sources on 2026-08-09; wording not read: service providers must publish information on how the service meets the accessibility requirements"
          },
          "severity": "obligation",
          "title": "Publish how the service meets the accessibility requirements, and keep it current",
          "provision": "Article 13 and Annex V",
          "since": "2025-06-28",
          "when": "(f) => f.eaaService !== \"terminals\" && (f.role || []).some((r) => [\"provider\", \"deployer\"].includes(r))",
          "note": "This binds service providers. A manufacturer of a covered product owes technical documentation, conformity assessment and CE marking instead."
        },
        {
          "id": "eaa-micro",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text, Article 2(2) read: without prejudice to Article 32, this Directive applies to the listed services provided to consumers after 28 June 2025"
          },
          "severity": "note",
          "title": "Microenterprises providing services are exempt, but not microenterprises making or distributing covered products",
          "provision": "Article 4(5)",
          "since": "2025-06-28",
          "when": "(f) => f.size === \"micro\""
        },
        {
          "id": "eaa-burden",
          "check": {
            "level": "official-summary",
            "on": "2026-08-12",
            "source": "EUR-Lex legislative summary for CELEX 32019L0882 read 2026-08-12: the requirements apply provided they do not alter the basic nature of the product or service or impose a disproportionate burden, assessed against the criteria in Annex VI; the assessment is documented, kept for five years, and for a service repeated whenever it is altered or at least every five years"
          },
          "severity": "note",
          "title": "The disproportionate burden defence must be assessed, documented and periodically reviewed, not merely asserted",
          "provision": "Article 14 and Annex VI",
          "since": "2025-06-28",
          "when": "() => true",
          "note": "The criteria are in Annex VI. The assessment must be documented and kept for five years from the last time the product was made available or the service provided, repeated whenever a service is altered and in any case at least every five years, and produced to a market surveillance authority on request. An undocumented claim is not a defence."
        },
        {
          "id": "eaa-legacy-products",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text, recital 101 read: a transitional period of five years after the date of application, during which products used for the provision of a service and placed on the market before that date need not comply unless the provider replaces them"
          },
          "severity": "note",
          "title": "Products already used to provide a service have until 28 June 2030, unless you replace them sooner",
          "provision": "Article 32 and recital 101",
          "since": "2025-06-28",
          "when": "() => true",
          "note": "The five years run from the date of application. Replacing such a product during the transition brings the replacement into scope immediately, so a refresh cycle can end the transition earlier than the date suggests."
        },
        {
          "id": "eaa-legacy-terminals",
          "check": {
            "level": "official-text",
            "on": "2026-08-12",
            "source": "Official Journal text, recital 101 read: given the cost and long life-cycle of self-service terminals, terminals used in the provision of services may continue to be used until the end of their economic life"
          },
          "severity": "note",
          "title": "Self-service terminals already in use may continue until the end of their economic life",
          "provision": "Article 32 and recital 101",
          "since": "2025-06-28",
          "when": "(f) => f.eaaService === \"terminals\" || (f.role || []).includes(\"manufacturer\")",
          "note": "A separate and much longer transition from the one for other products, and the reason a terminal estate is not a five-year problem. The publisher's summary states an upper bound the pack previously lacked: no longer than twenty years after the terminal entered service. It does not extend to terminals placed on the market after the date of application."
        },
        {
          "id": "eaa-legacy-facilities",
          "check": {
            "level": "official-summary",
            "on": "2026-08-12",
            "source": "EUR-Lex legislative summary for CELEX 32019L0882 read 2026-08-12: service providers whose facilities were already lawfully in use by 28 June 2025 have a further five years, until 28 June 2030"
          },
          "severity": "note",
          "title": "Facilities already lawfully in use on 28 June 2025 have until 28 June 2030",
          "provision": "Article 32",
          "since": "2025-06-28",
          "when": "() => true",
          "note": "The publisher describes this as facilities already lawfully in use rather than as contracts concluded before the date, which is how it is often reported. The distinction matters to anyone relying on it, and Article 32 should be read before doing so."
        },
        {
          "id": "eaa-web-archive",
          "check": {
            "level": "official-summary",
            "on": "2026-08-12",
            "source": "EUR-Lex legislative summary for CELEX 32019L0882 read 2026-08-12: the Directive does not apply to certain website and mobile application content, including archives whose content is not updated or edited after 28 June 2025"
          },
          "severity": "note",
          "title": "Archived web content not updated or edited after 28 June 2025 is outside the Directive",
          "provision": "Article 2(4)",
          "since": "2025-06-28",
          "when": "(f) => (f.nature || []).some((n) => [\"software-service\", \"online-platform\", \"marketplace\"].includes(n))",
          "note": "Editing or updating archived content brings it back into scope, so this is an exclusion that a content migration can quietly remove."
        },
        {
          "id": "eaa-product-conformity",
          "check": {
            "level": "secondary",
            "on": "2026-08-09",
            "source": "Corrected after external review on 2026-08-09; as a New Legislative Framework directive, manufacturers of covered products owe technical documentation, a conformity assessment, an EU declaration of conformity and CE marking"
          },
          "severity": "obligation",
          "title": "For a covered product: technical documentation, conformity assessment, declaration of conformity and CE marking",
          "provision": "Article 7 and Annex IV",
          "since": "2025-06-28",
          "when": "(f) => (f.role || []).includes(\"manufacturer\")"
        },
        {
          "id": "eaa-importer-distributor",
          "check": {
            "level": "official-summary",
            "on": "2026-08-12",
            "source": "EUR-Lex legislative summary for CELEX 32019L0882 read 2026-08-12: Chapter III sets obligations for economic operators dealing with products: Article 7 manufacturers, Article 8 authorised representatives, Article 9 importers, Article 10 distributors, Article 11 cases in which manufacturers' obligations apply to importers and distributors"
          },
          "severity": "obligation",
          "title": "As importer or distributor: verify the CE marking, the documentation and the manufacturer's conformity before making the product available",
          "provision": "Articles 9, 10 and 11",
          "since": "2025-06-28",
          "when": "(f) => (f.role || []).some((r) => [\"importer\", \"distributor\"].includes(r))"
        }
      ],
      "timeline": [
        {
          "date": "2019-06-07",
          "label": "Published in the Official Journal",
          "provision": "Article 33"
        },
        {
          "date": "2022-06-28",
          "label": "Member States were required to transpose it",
          "provision": "Article 31"
        },
        {
          "date": "2025-06-28",
          "label": "Obligations apply to products and services placed on the market from this date",
          "provision": "Article 31"
        },
        {
          "date": "2030-06-28",
          "label": "Transitional period ends for services under earlier contracts",
          "provision": "Article 32"
        }
      ],
      "watch": []
    }
  ],
  "overlaps": [
    {
      "id": "ov-ce-double",
      "title": "Two conformity assessments under one CE marking",
      "packs": [
        "ai-act",
        "cra"
      ],
      "when": "(f, fired) => fired.has(\"aia-hr-annexi\") || (fired.has(\"cra-conformity\") && (f.nature || []).includes(\"ai-system\"))",
      "provisions": [
        "AI Act Articles 43 and 48",
        "CRA Articles 32 and 30"
      ],
      "detail": "A product carrying digital elements and an AI safety component must satisfy both regimes and affix a single CE marking. Both regimes must be satisfied before the marking is affixed. An external review states that the CRA provides for its requirements to be assessed within the AI Act procedure for high-risk systems rather than separately; that mechanism has not yet been read against the text and is recorded as unverified."
    },
    {
      "id": "ov-incident-three-clocks",
      "title": "One incident, three reporting duties on different clocks",
      "packs": [
        "gdpr",
        "nis2",
        "ai-act"
      ],
      "when": "(f, fired) => [fired.has(\"gdpr-breach\"), fired.has(\"nis2-reporting\"), fired.has(\"aia-o-postmarket\")].filter(Boolean).length >= 2",
      "provisions": [
        "GDPR Articles 33 and 34",
        "NIS2 Article 23",
        "AI Act Article 73"
      ],
      "detail": "The same event can require an early warning within 24 hours, a personal data notification within 72, and a serious incident report under the AI Act, to different authorities. The clocks run from different trigger points and the recipients differ: DORA's initial notification is due within four hours of classifying an incident as major, NIS2 asks for an early warning within twenty-four hours of becoming aware, and the GDPR allows seventy-two hours from becoming aware of a personal data breach. One event, three starting guns. The Data Omnibus proposes a single entry point, but it has not been adopted."
    },
    {
      "id": "ov-dpia-fria",
      "title": "A data protection impact assessment and a fundamental rights impact assessment",
      "packs": [
        "gdpr",
        "ai-act"
      ],
      "when": "(f, fired) => fired.has(\"gdpr-dpia\") && fired.has(\"aia-d-fria\")",
      "provisions": [
        "GDPR Article 35",
        "AI Act Article 27"
      ],
      "detail": "Two assessments with overlapping evidence and different questions. The AI Act permits building on an existing data protection assessment rather than repeating it; the fundamental rights questions are additional, not a subset."
    },
    {
      "id": "ov-article22-transparency",
      "title": "Automated decisions meet AI Act transparency",
      "packs": [
        "gdpr",
        "ai-act"
      ],
      "when": "(f, fired) => fired.has(\"gdpr-automated\") && (fired.has(\"aia-hr-annexiii\") || fired.has(\"aia-d-subjects\"))",
      "provisions": [
        "GDPR Article 22",
        "AI Act Articles 26(11) and 86"
      ],
      "detail": "A person subject to an automated decision has rights under both: meaningful information about the logic, and an explanation of the role the system played. The two duties are satisfied together or not at all."
    },
    {
      "id": "ov-cra-security-gdpr",
      "title": "Product security requirements and processing security",
      "packs": [
        "cra",
        "gdpr"
      ],
      "when": "(f, fired) => fired.has(\"cra-essential\") && fired.has(\"gdpr-security\")",
      "provisions": [
        "CRA Annex I",
        "GDPR Article 32"
      ],
      "detail": "The CRA sets requirements for the product; Article 32 sets them for the processing. The evidence that satisfies one will often be relevant to the other, but the two are assessed separately and against different criteria."
    },
    {
      "id": "ov-nis2-national",
      "title": "A directive and a regulation in the same programme",
      "packs": [
        "nis2",
        "ai-act"
      ],
      "when": "(f, fired) => fired.has(\"nis2-transposition\") && fired.size > 3",
      "provisions": [
        "NIS2 Article 41"
      ],
      "detail": "The regulations bind identically across the Union; NIS2 binds as each Member State transposed it. A single compliance programme therefore has one part that travels and one part that does not, and the second must be checked per country."
    },
    {
      "id": "ov-dora-nis2",
      "title": "DORA displaces NIS2 for a financial entity's ICT risk",
      "packs": [
        "dora",
        "nis2"
      ],
      "when": "(f, fired) => fired.has(\"dora-ict-risk\") && fired.has(\"nis2-measures\")",
      "provisions": [
        "DORA Article 1(2)",
        "NIS2 Article 4"
      ],
      "detail": "Where DORA covers the same ground, it applies as the more specific law and NIS2's corresponding duties do not stack on top. DORA is designated as the sector-specific law, and NIS2 Article 4 disapplies its requirements where such a law imposes at least equivalent ones. Whether that carve-out is total for a financial entity, or operates duty by duty, is disputed between reviewers and has not been read against DORA Article 1(2) and NIS2 Article 4."
    },
    {
      "id": "ov-dsa-gdpr-ads",
      "title": "Advertising transparency meets lawful processing",
      "packs": [
        "dsa",
        "gdpr"
      ],
      "when": "(f, fired) => fired.has(\"dsa-ads\") && fired.has(\"gdpr-lawful-basis\")",
      "provisions": [
        "DSA Articles 26 and 28",
        "GDPR Articles 6, 9 and 22"
      ],
      "detail": "The DSA requires an advertisement to be identifiable and its targeting parameters disclosed; the GDPR governs whether that targeting may happen at all. Special-category profiling is prohibited under both, and disclosing unlawful targeting does not make it lawful."
    },
    {
      "id": "ov-dataact-gdpr",
      "title": "Data sharing under the Data Act meets data protection",
      "packs": [
        "data-act",
        "gdpr"
      ],
      "when": "(f, fired) => fired.has(\"da-user-access\") && fired.has(\"gdpr-lawful-basis\")",
      "provisions": [
        "Data Act Articles 4, 5 and 1(5)",
        "GDPR Articles 6 and 20"
      ],
      "detail": "A user's right to have product data sent to a third party is not itself a lawful basis for processing anyone else's personal data caught up in it. Where the data set mixes personal and non-personal data, both regimes apply to the same transfer."
    },
    {
      "id": "ov-dataact-dora-exit",
      "title": "Cloud switching rights meet financial exit strategies",
      "packs": [
        "data-act",
        "dora"
      ],
      "when": "(f, fired) => fired.has(\"da-switching-contract\") && fired.has(\"dora-third-party\")",
      "provisions": [
        "Data Act Chapter VI",
        "DORA Articles 28 to 30"
      ],
      "detail": "Both regimes reach the same cloud contract from opposite directions: one gives the customer a right to leave, the other requires the financial customer to have a documented exit strategy and specific contractual terms. Both reach the same contract from opposite directions: one confers a right to leave, the other imposes a duty to be able to."
    },
    {
      "id": "ov-eaa-ai-transparency",
      "title": "Accessibility requirements meet AI transparency duties",
      "packs": [
        "eaa",
        "ai-act"
      ],
      "when": "(f, fired) => fired.has(\"eaa-requirements\") && fired.has(\"aia-t-interaction\")",
      "provisions": [
        "EAA Annex I",
        "AI Act Article 50(1)"
      ],
      "detail": "Telling a person they are speaking to an AI system only counts if they can perceive the notice. A disclosure delivered in a way that fails the accessibility requirements satisfies neither instrument."
    },
    {
      "id": "ov-dsa-eaa",
      "title": "A consumer platform is covered twice over",
      "packs": [
        "dsa",
        "eaa"
      ],
      "when": "(f, fired) => fired.has(\"dsa-terms\") && fired.has(\"eaa-requirements\")",
      "provisions": [
        "DSA Article 14",
        "EAA Annex I"
      ],
      "detail": "The DSA requires terms in plain, intelligible language; the Accessibility Act requires the interface delivering them to be perceivable and operable. Plain language in an inaccessible interface fails the second test while passing the first."
    },
    {
      "id": "ov-ai-in-product",
      "title": "An AI system inside a regulated product",
      "packs": [
        "ai-act",
        "cra"
      ],
      "when": "(f) => (f.nature || []).includes(\"ai-system\") && (f.nature || []).includes(\"product-digital-elements\")",
      "provisions": [
        "AI Act Article 6(1)",
        "CRA Article 12"
      ],
      "detail": "Being a product with digital elements does not by itself make the AI high-risk, and being high-risk does not by itself trigger the CRA. Check both routes separately; they share a technical file but not a test."
    }
  ]
}