stillholds EU digital compliance

Verification

A rule is only as good as the reading behind it. Every rule carries a record of what was read, at one of three strengths, and this page reproduces all of them from the rules themselves rather than from a summary that could drift.

How strength is graded #

LevelMeansMay be relied onRules
official textRead against the text as published in the Official Journal, or the consolidated version on EUR-LexYes, subject to your own judgement19
official guidanceConfirmed against a European Commission page or official guidance, not against the text itselfAs a strong starting point6
corroboratedConfirmed across independent professional sources; the wording has not been readAs a starting point only53
uncheckedEncoded from working knowledgeNo. The build reports these, and none currently exist.0

A pack's strength is computed from its weakest rule rather than declared, because an average would hide exactly the rule a reader needs to know about.

Back to top

Artificial Intelligence Act #

Regulation (EU) 2024/1689 · 21 rules · official source

RuleProvisionFromCheckedWhat was read
Social scoring leading to detrimental treatmentArticle 5(1)(c)2025-02-02 official textOJ text, recital 31 (social scoring leading to detrimental or disproportionate treatment) (2026-08-06)
Predicting offending from profiling or traits aloneArticle 5(1)(d)2025-02-02 official textOJ text, recital 42 (prediction based solely on profiling or personality traits) (2026-08-06)
Untargeted scraping of facial imagesArticle 5(1)(e)2025-02-02 official textOJ text, recital 43 (untargeted scraping of facial images from the internet or CCTV) (2026-08-06)
Emotion inference in the workplace or educationArticle 5(1)(f)2025-02-02 official textOJ text, recital 44 (emotion inference in the workplace and education, excluding medical and safety uses) (2026-08-06)
Biometric categorisation inferring sensitive attributesArticle 5(1)(g)2025-02-02 official textOJ text, recital 30, and recital 40 which cites Article 5(1) first subparagraph point (g) (2026-08-06)
Real-time remote biometric identification in public spaces for law enforcementArticle 5(1)(h)2025-02-02 official textOJ text, recitals 32 to 38, and recital 40 which cites Article 5(1) first subparagraph point (h) (2026-08-06)
Subliminal or manipulative techniques distorting behaviourArticle 5(1)(a)2025-02-02 official textOJ text, recital 29 (subliminal and manipulative techniques materially distorting behaviour) (2026-08-06)
Exploiting vulnerabilities of age, disability or circumstanceArticle 5(1)(b)2025-02-02 official textOJ text, recital 29 (exploitation of vulnerabilities of age, disability or social or economic situation) (2026-08-06)
Generating non-consensual intimate imagery of identifiable peopleArticle 5, as amended2026-12-02 corroboratedRegulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read (2026-08-06)
Generating child sexual abuse material, or lacking safeguards against itArticle 5, as amended2026-12-02 corroboratedRegulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read (2026-08-06)
High-risk: falls within an Annex III areaArticle 6(2) and Annex III2027-12-02 official textOJ text, recitals 54 to 62 (the eight Annex III areas); the deferred date is from Regulation (EU) 2026/1744 (2026-08-06)
Annex III area, with the Article 6(3) derogation claimedArticle 6(3)2027-12-02 official textOJ text, recital 53 (all four Article 6(3) conditions, the documentation duty and EU database registration) (2026-08-06)
The derogation is unavailable because the system profiles peopleArticle 6(3), final subparagraph2027-12-02 official textOJ text, recital 53 (profiling within the meaning of Article 4(4) GDPR removes the derogation) (2026-08-06)
High-risk as a regulated product or its safety componentArticle 6(1) and Annex I2028-08-02 official textOJ text, recitals 50 and 51 (products under Union harmonisation legislation with third-party assessment) (2026-08-06)
Tell people they are interacting with an AI systemArticle 50(1)2026-08-02 corroboratedArticle 50 transparency obligations confirmed as applying from 2 August 2026 across the Commission's reporting and several law firms; the wording of Article 50(1) is not yet read (2026-08-06)
Mark synthetic content in a machine-readable wayArticle 50(2)2026-08-02 corroboratedDeferral to 2026-12-02 for systems already on the market, confirmed across the same sources (2026-08-06)
Inform people exposed to emotion recognition or biometric categorisationArticle 50(3)2026-08-02 corroboratedArticle 50(3) as reported consistently; wording not yet read (2026-08-06)
Disclose deep fakes and AI-generated text on matters of public interestArticle 50(4)2026-08-02 corroboratedArticle 50(4) as reported consistently; wording not yet read (2026-08-06)
General-purpose model documentation, downstream information, copyright policy and training-content summaryArticle 532025-08-02 corroboratedChapter V obligations applying from 2 August 2025, reported consistently; Article 53 wording not yet read (2026-08-06)
Systemic-risk evaluation, adversarial testing, incident reporting and cybersecurityArticles 51 and 552025-08-02 corroboratedArticles 51 and 55 with the 10^25 floating point operation presumption, reported consistently; wording not yet read (2026-08-06)
AI literacy: ensure staff dealing with the system are sufficiently competentArticle 42025-02-02 official textOJ text, recital 20 (AI literacy for providers, deployers and affected persons) (2026-08-06)

Back to top

Cyber Resilience Act #

Regulation (EU) 2024/2847 · 9 rules · official source

RuleProvisionFromCheckedWhat was read
Report actively exploited vulnerabilities and severe incidents to ENISA and the CSIRTArticle 142026-09-11 official guidancehttps://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act (2026-08-06)
Essential cybersecurity requirements in design, development and productionArticle 13 and Annex I2027-12-11 official guidancehttps://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06)
Vulnerability handling, including a coordinated disclosure policy and security updatesAnnex I Part II2027-12-11 official guidancehttps://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06)
Software bill of materials covering top-level dependenciesAnnex I Part II(1)2027-12-11 official guidancehttps://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06)
Conformity assessment, EU declaration of conformity and CE markingArticles 32, 28 and 302027-12-11 official guidancehttps://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06)
Define and publish the support period, at least five years unless the expected use is shorterArticle 13(8)2027-12-11 corroboratedCommission summary describes the support period; the five year default and the Article 13(8) reference are not yet confirmed against the text (2026-08-06)
Verify the manufacturer's conformity assessment and marking before placing on the marketArticle 192027-12-11 corroboratedCommission summary describes importer duties; the Article 19 number is not yet confirmed against the text (2026-08-06)
Act with due care in relation to the requirements when making a product availableArticle 202027-12-11 corroboratedCommission summary describes distributor duties; the Article 20 number is not yet confirmed against the text (2026-08-06)
Open-source software outside a commercial activity is treated differentlyArticle 2 and Recitals2027-12-11 official guidancehttps://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06)

Back to top

General Data Protection Regulation #

Regulation (EU) 2016/679 · 11 rules · official source

RuleProvisionFromCheckedWhat was read
Identify and record a lawful basis for each purposeArticle 62018-05-25 corroboratedArticle index reproductions of Regulation (EU) 2016/679 (gdpr-info.eu and others), consistent on Article 6 (2026-08-06)
Establish an Article 9 condition before processing special categoriesArticle 92018-05-25 corroboratedArticle index reproductions, consistent on Article 9 for special categories (2026-08-06)
Inform people at collection, in clear and accessible termsArticles 13 and 142018-05-25 corroboratedArticle index reproductions, consistent on Articles 13 and 14 (2026-08-06)
Maintain a record of processing activitiesArticle 302018-05-25 official textEUR-Lex text: Article 30 named as the record of processing activities; the Article 30(5) exemption for organisations under 250 people is conditional as encoded (2026-08-06)
Carry out a data protection impact assessment before startingArticle 352018-05-25 official textEUR-Lex text: Article 36(1) refers to 'a data protection impact assessment under Article 35', confirming both the duty and its numbering (2026-08-06)
Automated decisions with legal or similarly significant effects need a basis, safeguards and human interventionArticle 222018-05-25 corroboratedArticle index reproductions, consistent on Article 22 for automated individual decision-making (2026-08-06)
A written processing agreement with every processorArticle 282018-05-25 corroboratedArticle index reproductions, consistent on Article 28 for processor contracts (2026-08-06)
Security appropriate to the risk, and the ability to demonstrate itArticle 322018-05-25 corroboratedArticle index reproductions, consistent on Article 32 for security of processing (2026-08-06)
Notify a personal data breach to the authority within 72 hours where it is likely to result in riskArticles 33 and 342018-05-25 official textEUR-Lex text of Regulation (EU) 2016/679: Article 33(1) read verbatim, including the 72 hour limit and the risk qualifier (2026-08-06)
A transfer mechanism, and a transfer impact assessment where requiredChapter V2018-05-25 corroboratedArticle index reproductions, consistent on Chapter V, Articles 44 to 50 (2026-08-06)
Designate a data protection officerArticle 372018-05-25 corroboratedArticle index reproductions, consistent on Article 37 for designation of the data protection officer (2026-08-06)

Back to top

NIS2 Directive #

Directive (EU) 2022/2555 · 5 rules · official source

RuleProvisionFromCheckedWhat was read
Your obligations are those of the transposing national law, not the directive itselfArticle 412024-10-18 corroboratedTransposition deadline of 17 October 2024 corroborated widely; as of mid-2026 transposition remains uneven and the Commission has referred several Member States to the Court of Justice, which is exactly why this pack refuses to assert a national obligation (2026-08-06)
Register with the competent national authorityArticle 3(4)2024-10-18 corroboratedArticle 3(4) requires Member States to establish lists of essential and important entities with information submitted by them; note that Article 27 imposes a separate registry duty on certain digital entity types, which this pack does not yet distinguish (2026-08-06)
Risk management measures: policies, incident handling, continuity, supply chain, cryptography and access controlArticle 212024-10-18 corroboratedMultiple independent analyses of Directive (EU) 2022/2555, consistent on Article 21 for risk management measures (2026-08-06)
Early warning within 24 hours, notification within 72 hours, final report within one monthArticle 232024-10-18 corroboratedMultiple independent analyses, consistent on Article 23 and the 24 hour, 72 hour and one month structure (2026-08-06)
Management bodies approve the measures and can be held personally liableArticle 202024-10-18 corroboratedMultiple independent analyses, consistent on Article 20 for management approval, oversight, training and personal liability (2026-08-06)

Back to top

Data Act #

Regulation (EU) 2023/2854 · 8 rules · official source

RuleProvisionFromCheckedWhat was read
Design connected products so that the data they generate is accessible to the user by defaultArticle 32026-09-12 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: connected products placed on the market after 12 September 2026 must be designed so that data is accessible by default (2026-08-09)
Make product and related service data available to the user, and to a third party at the user's requestArticles 4 and 52025-09-12 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read (2026-08-09)
Remove switching charges: reduced until 12 January 2027, prohibited from that dateArticle 292025-09-12 official textEUR-Lex text read on 2026-08-09: Article 29 read verbatim. From 12 January 2027 no switching charges; reduced charges permitted from 11 January 2024 until then, capped at costs directly incurred (2026-08-09)
Contractual terms enabling a customer to switch provider, run several in parallel, or move on premisesChapter VI, Articles 23 to 312025-09-12 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: Chapter VI, Articles 23 to 31, requires contractual terms enabling switching to another provider or to on-premises infrastructure (2026-08-09)
Functional equivalence for infrastructure services, and open interfaces for other data processing servicesChapter VIII2025-09-12 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: functional equivalence for infrastructure services, open interfaces for others (2026-08-09)
Publish the jurisdiction your infrastructure sits under, and the safeguards against unlawful international governmental accessArticle 322025-09-12 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: publish the jurisdiction of the ICT infrastructure and the measures against unlawful governmental access to non-personal data (2026-08-09)
Unilaterally imposed unfair data terms do not bind the other party, and this reaches older contracts from 12 September 2027Article 132025-09-12 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: unfairly imposed data-sharing terms are not binding; extends to pre-existing contracts from 12 September 2027 (2026-08-09)
Where the data is personal, the GDPR continues to apply alongside this RegulationArticle 1(5)2025-09-12 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: the Data Act covers personal and non-personal data and does not displace the GDPR (2026-08-09)

Back to top

Digital Services Act #

Regulation (EU) 2022/2065 · 12 rules · official source

RuleProvisionFromCheckedWhat was read
Terms and conditions in plain language, machine readable, with changes notifiedArticle 142024-02-17 official textEUR-Lex text read on 2026-08-09: Article 14 read. Terms in clear, plain, intelligible, user-friendly and unambiguous language, publicly available and machine readable, with significant changes notified; where a service is directed at or predominantly used by minors, the conditions must be explained so minors can understand (2026-08-09)
A point of contact for authorities and for users, and a legal representative if you are not established in the UnionArticles 11 to 132024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: single points of contact for authorities and for recipients, and a legal representative where not established in the Union (2026-08-09)
Notice and action mechanism for illegal content, easy to access and electronicArticle 162024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: Article 16 requires easy-to-access, user-friendly electronic notice mechanisms for illegal content (2026-08-09)
A statement of reasons for every restriction, published to the Commission's database by online platformsArticles 17 and 24(5)2024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: a statement of reasons for each restriction, submitted to the Commission database for online platforms (2026-08-09)
Internal complaint handling, free and electronic, open for at least six monthsArticle 202024-02-17 official textEUR-Lex text read on 2026-08-09: Article 20(1) read. Online platforms must give access to an effective internal complaint-handling system, electronically and free of charge, for at least six months after the decision (2026-08-09)
Out-of-court dispute settlement available to users, and cooperation with trusted flaggersArticles 21 and 222024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read (2026-08-09)
Interfaces that deceive or manipulate a user's ability to decide freely are prohibitedArticle 252024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: Article 25 prohibits interface design that deceives, manipulates or distorts users' ability to make free decisions (2026-08-09)
Advertising identifiable in real time, with the payer and the main targeting parameters shown, and no targeting on special categoriesArticle 262024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: advertising must be identifiable, with the payer and the main targeting parameters disclosed; profiling on special categories is prohibited (2026-08-09)
No advertising based on profiling where you know the recipient is a minorArticle 28(2)2024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: no advertising based on profiling where the platform is aware the recipient is a minor (2026-08-09)
Know your business customer: obtain and verify trader details before allowing them to sellArticles 30 to 322024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: marketplaces must obtain and check trader identification before allowing use of the service (2026-08-09)
Micro and small enterprises are excluded from the platform-specific obligationsArticle 192024-02-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: Article 19 excludes micro and small enterprises from the platform-specific obligations in Section 3 (2026-08-09)
Systemic risk assessment and mitigation, independent audit, ad repository and researcher accessArticles 34 to 402023-08-25 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: systemic risk assessment and mitigation, independent audit, advertisement repository and researcher data access for designated very large platforms (2026-08-09)

Back to top

Digital Operational Resilience Act #

Regulation (EU) 2022/2554 · 6 rules · official source

RuleProvisionFromCheckedWhat was read
The management body carries final responsibility for ICT risk, and must be able to show itArticle 52025-01-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: the management body bears final responsibility for ICT risk management (2026-08-09)
An ICT risk management framework: identify, protect, detect, respond, recover and learnArticles 6 to 162025-01-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: an ICT risk management framework covering protection, detection, response, recovery and learning (2026-08-09)
Classify ICT incidents and report major ones to your competent authorityArticles 17 to 232025-01-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: classification of ICT-related incidents and reporting of major incidents to the competent authority (2026-08-09)
A resilience testing programme, with threat-led penetration testing where you are significantArticles 24 to 272025-01-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: a digital operational resilience testing programme, with threat-led penetration testing for significant entities (2026-08-09)
A register of ICT third-party arrangements, mandatory contract terms, and a documented exit strategy for eachArticles 28 to 302025-01-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: a register of information on contractual arrangements with ICT third-party providers, and mandatory contractual terms including exit strategies (2026-08-09)
If designated critical, an ICT provider to the financial sector comes under direct EU oversightArticles 31 to 442025-01-17 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: critical ICT third-party providers are subject to an EU oversight framework (2026-08-09)

Back to top

European Accessibility Act #

Directive (EU) 2019/882 · 6 rules · official source

RuleProvisionFromCheckedWhat was read
Your obligations are those of the transposing national law, not the directive itselfArticle 302025-06-28 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: a directive transposed by all Member States, with enforcement from 28 June 2025 and penalties set nationally (2026-08-09)
Meet the functional accessibility requirements; EN 301 549 gives a presumption of conformityAnnex I2025-06-28 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: Annex I sets functional accessibility requirements; conformity with the harmonised standard EN 301 549 creates a presumption of conformity (2026-08-09)
Publish how the service meets the accessibility requirements, and keep it currentArticle 13 and Annex V2025-06-28 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: service providers must publish information on how the service meets the accessibility requirements (2026-08-09)
Microenterprises providing services are exempt, but not microenterprises making or distributing covered productsArticle 4(5)2025-06-28 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: microenterprises providing services are exempt; microenterprises manufacturing or distributing covered products are not (2026-08-09)
The disproportionate burden defence must be assessed, documented and periodically reviewed, not merely assertedArticle 142025-06-28 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: a disproportionate burden defence exists, and must be assessed, documented and re-assessed (2026-08-09)
Services provided under contracts concluded before 28 June 2025 have until 28 June 2030Article 322025-06-28 corroboratedCorroborated across independent professional sources on 2026-08-09; wording not read: service contracts concluded before 28 June 2025 may continue until 28 June 2030 at the latest (2026-08-09)

Back to top

The reading log #

Every session, what was read, what it settled, and what it did not. Sorted newest first. A verification log that records only successes is a marketing page, so the last two columns carry as much weight as the first.

DateInstrumentWhat was readStrengthSettled
2026-08-09 Regulation (EU) 2023/2854
data-act
EUR-Lex text for Article 29, and Commission-adjacent professional analysis for the rest
eur-lex.europa.eu/eli/reg/2023/2854/oj/eng
official text 3
2026-08-09 Regulation (EU) 2022/2065
dsa
EUR-Lex text for Articles 14 and 20, and professional sources for the tiered duties
eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2065
official text 4
2026-08-09 Regulation (EU) 2022/2554
dora
Professional sources and a published reproduction of Article 64
Corroboration only; the EUR-Lex text has not been read
corroborated 3
2026-08-09 Directive (EU) 2019/882
eaa
Professional sources across several jurisdictions
Corroboration only; the directive text has not been read
corroborated 4
2026-08-06 Regulation (EU) 2024/1689
ai-act
Official Journal text, English, recitals 1 to 72
eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202401689
official text 5
2026-08-06 Regulation (EU) 2024/2847
cra
European Commission pages for the Cyber Resilience Act, including the legislative summary
digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
official guidance 4
2026-08-06 Regulation (EU) 2016/679
gdpr
EUR-Lex text, Articles 30, 33 and 36 in the passages quoted
eur-lex.europa.eu/eli/reg/2016/679/oj/eng
official text 3
2026-08-06 Directive (EU) 2022/2555
nis2
Multiple independent professional analyses, consistent throughout
Corroboration only; the directive text has not been read
corroborated 4
2026-08-06 Regulation (EU) 2024/1689 and 2026/1744
ai-act
Commission reporting and several independent law firms on the Digital Omnibus amendments
Corroboration only
corroborated 5

Regulation (EU) 2023/2854 2026-08-09 · official text

SettledOn what basis
Article 29, switching chargesRead verbatim: no switching charges from 12 January 2027, reduced charges permitted before that and capped at costs directly incurred
Application datesIn force 11 January 2024, applies 12 September 2025, access by design for products placed on the market from 12 September 2026
Chapter VI and Chapter VIIISwitching and interoperability duties on providers of data processing services, corroborated consistently

Also found
The unfair terms provisions reach contracts concluded before 12 September 2025 from 12 September 2027, which is the kind of retrospective date organisations miss.

Not settled
The wording of Articles 3, 4, 5, 13, 23 to 28, 30, 31 and 32. Only Article 29 was read.

Regulation (EU) 2022/2065 2026-08-09 · official text

SettledOn what basis
Article 14, terms and conditionsRead: plain, intelligible, machine-readable terms, changes notified, and explained so minors can understand where a service is directed at them
Article 20, internal complaintsRead: free, electronic complaint handling open for at least six months after the decision
The tier structureIntermediary, hosting, online platform, marketplace and very large platform duties, corroborated consistently
Article 19Micro and small enterprises are excluded from the platform-specific obligations

Also found
Article 25 prohibits deceptive interface design, and Article 28(2) prohibits profiling-based advertising to known minors. Both are encoded as such.

Not settled
The wording of Articles 11 to 13, 16, 17, 21, 22, 25, 26, 28 and 30 to 40.

Regulation (EU) 2022/2554 2026-08-09 · corroborated

SettledOn what basis
Application dateApplies from 17 January 2025, per Article 64
The five pillarsGovernance, ICT risk management, incident reporting, resilience testing and third-party risk, corroborated consistently
Oversight of critical providersAn EU oversight framework reaches ICT providers designated critical to the financial sector

Also found
DORA operates as the more specific law where it covers the same ground as NIS2, which is now encoded as an overlap rather than left for the reader to discover.

Not settled
Every article number in this pack. None of the text has been read.

Directive (EU) 2019/882 2026-08-09 · corroborated

SettledOn what basis
Application dateObligations apply from 28 June 2025, after transposition due 28 June 2022
ScopeConsumer e-commerce, banking, e-books, electronic communications, audiovisual media, transport ticketing, and certain terminals and consumer hardware
Microenterprise carve-outMicroenterprises providing services are exempt; those manufacturing or distributing covered products are not
Technical routeEN 301 549, which incorporates WCAG at level AA, gives a presumption of conformity with the functional requirements

Also found
Services under contracts concluded before 28 June 2025 have until 28 June 2030, and enforcement has already begun in several Member States.

Not settled
All article numbers, the exact wording of Annex I, and the disproportionate burden test in Article 14. As a directive, the binding text is each national transposition rather than this one.

Regulation (EU) 2024/1689 2026-08-06 · official text

SettledOn what basis
Eight prohibited practicesRecitals 29, 30, 31, 32 to 38, 42, 43 and 44, each matching the encoded rule
The Article 6(3) derogationRecital 53 states all four conditions in the same terms, confirms that profiling removes it, and confirms the documentation and EU database duties
The eight Annex III areasRecitals 54 to 62
The Annex I routeRecitals 50 and 51
AI literacyRecital 20

Also found
Recital 40 cites Article 5(1) first subparagraph points (g) and (h), confirming this pack's lettering for biometric categorisation and real-time remote biometric identification.

Not settled
The enacting wording of Articles 5, 6, 9 to 15, 17, 26, 27, 43, 47 to 50, 53, 55, 72 and 73. Recitals state the substance; articles state the obligation. EUR-Lex records the consolidated version as 27 July 2026, which is the Omnibus amendment, and that consolidated text has not been read.

Regulation (EU) 2024/2847 2026-08-06 · official guidance

SettledOn what basis
Entry into force10 December 2024
Article 14 reportingApplies from 11 September 2026, ahead of everything else
The remaining obligationsApply from 11 December 2027
Open-source stewardsTreated distinctly from manufacturers, the boundary turning on commercial activity

Also found
Two facts found but not yet encoded: Chapter IV on notified bodies applies from 11 June 2026, and Article 69(3) extends the reporting duty to products already on the market.

Not settled
Article numbers for importer and distributor duties, and the five-year support period in Article 13(8), which the summary describes without numbering.

Regulation (EU) 2016/679 2026-08-06 · official text

SettledOn what basis
Article 33(1)Read verbatim: notification without undue delay and, where feasible, not later than 72 hours, unless the breach is unlikely to result in a risk
Article 35Confirmed through Article 36(1), which refers to a data protection impact assessment under Article 35
Article 30Confirmed as the record of processing activities, with the exemption for organisations under 250 people being conditional rather than absolute, as this pack encodes it

Also found
Articles 6, 9, 13, 14, 22, 28, 32, 37 and Chapter V corroborated across independent faithful reproductions of the article index. Numbering is consistent everywhere it appears.

Not settled
The wording of those eight, which has not been read.

Directive (EU) 2022/2555 2026-08-06 · corroborated

SettledOn what basis
Article 21Risk management measures
Article 23Early warning within 24 hours, notification within 72, final report within one month
Article 20Management approval, oversight, training and personal liability
Article 41Transposition, deadline 17 October 2024

Also found
Transposition remains uneven across the Union in mid-2026, with several Member States referred to the Court of Justice. That is precisely why this pack raises a caution rather than asserting a national obligation.

Not settled
The registration duty is more complicated than the pack states: Article 3(4) requires Member States to keep lists with information submitted by entities, while Article 27 imposes a separate registry duty on certain digital entity types. The pack does not yet distinguish them.

Regulation (EU) 2024/1689 and 2026/1744 2026-08-06 · corroborated

SettledOn what basis
Article 50 transparencyApplies from 2 August 2026
Article 50(2) markingDeferred to 2 December 2026 for systems already on the market
Annex III high riskDeferred from 2 August 2026 to 2 December 2027
Annex I high riskDeferred to 2 August 2028
Two new prohibitionsNon-consensual intimate imagery and child sexual abuse material, from 2 December 2026

Also found
Consistent across the Commission's own reporting and four independent firms.

Not settled
None of it read in the consolidated text, which is the next task for this pack.

Back to top

The procedure #

How a reading session is conducted and recorded, so that a future session, by anyone, reaches the same standard as the last one.

#StepWhat it means in practice
1Read the provisionIn the official text. Not a summary of it, and not a reproduction of it on somebody else's site.
2Update the rule's recordLevel, date, and what was read, in enough detail that another person could repeat the reading and land in the same place.
3Add a session to the logFour things: what was read, what it settled and on what basis, what was found incidentally, and what it did not settle. The last is not optional; a log recording only successes is a marketing page.
4Raise the ruleset versionA published ruleset is immutable, and the build refuses to alter one.
5Run the buildThe integrity gate refuses a rule without a check record; replay parity refuses a snapshot that no longer reproduces the live ruleset.

Standing rules

Back to top

What is outstanding #

In the order it should be done. A reader deciding whether to rely on a rule wants to know what is coming as much as what has been done.

PackNext readingWhy it matters
doraArticles 5 to 30 and 64 in the official textEvery article number rests on corroboration alone
eaaArticles 4, 13, 14, 30 to 32 and Annex I, then the Polish transposing actA directive binds through national law, and no national text has been read
data-actArticles 3, 4, 5, 13, 23 to 28 and 32Only Article 29 has been read
dsaArticles 16, 17, 25, 26, 28 and 30Only Articles 14 and 20 have been read
ai-actArticles 50, 53 and 55, then the high-risk duties in Articles 9 to 15, 26 and 27Twenty-one rules rest on recitals or corroboration rather than the enacting text
gdprArticles 6, 9, 13, 14, 22, 28, 32 and 37Eight rules are corroborated by numbering alone
craArticles 13, 14, 19, 20 and 71; encode Chapter IV from 11 June 2026 and Article 69(3)Three article numbers unconfirmed, two known facts unencoded
nis2Articles 3, 20, 21, 23, 27 and 41Nothing read; and Article 3(4) must be separated from the Article 27 registry

Back to top