Law / Changes / Map / European Union
Software law in the European Union, on a map
How software law came to bind across the European Union, from into the coming years. When a law of the Union starts, every member state flashes and the law joins the table under the EU flag; each member state's own law colours the country and joins the table under it. Press Play, or move the slider to a date. The rest of the world is on the world map.
The date the map shows
From to in 15 months By this date: 30 laws of the Union in force and 22 not yet in force; 375 national laws in force in 27 of 27 member states, and 4 not yet in force.
- Not yet in force: enacted, and it starts to bind after the date shown or after today
- In force: started to bind since
- no law of its own on the map by this date
- Flash: a law of the Union starts to bind in every member state
Every law on the map
431 laws in 28 places, the Union first, each with the dates the map places it on: the day it started to bind, from on, as its own page gives it; the changes the Software Law Tracker lists since ; and the start dates the LexLint law library holds up to .
-
European Union 52 laws- GDPR Article 22, Automated Individual Decision-MakingIn force from
- GDPR Article 9, Special Categories of Personal Data Including Biometric DataIn force from
- GDPR Articles 12-21, Data Subject RightsIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Articles 51-59, 68-76 and 77-84, Supervisory Authorities, Penalties and RemediesIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- General Data Protection Regulation (GDPR), Comprehensive RegimeIn force from
- Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market (DSM Directive), Articles 15 and 4In force from
- Audiovisual Media Services Directive (AVMSD), Articles 6a and 28bIn force from
- DSM Directive, Article 4 (text-and-data-mining exception and rights reservation)In force from
- Digital Services Act (DSA), Articles 33, 38 and 39 (Very large online platforms and search engines)In force from
- Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking)In force from
- Digital Services Act, Article 37 (independent audit of very large online platforms and search engines)In force from
- Digital Services Act (DSA), Article 16 (Notice and action mechanisms)In force from
- Digital Services Act (DSA), Article 28 (Online protection of minors)In force from
- Digital Services Act (DSA), Articles 4 to 10 (Liability of providers of intermediary services and orders)In force from
- European Digital Identity Regulation (eIDAS2)In force from
- NIS2 Directive, Cybersecurity Risk-Management MeasuresIn force from
- NIS2 Directive, Reporting ObligationsIn force from
- DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301In force from
- DORA, Articles 28-30 (ICT Third-Party Risk Management)In force from
- AI Act, Article 4 (AI literacy)In force from
- AI Act, Article 5 (prohibited AI practices)In force from
- Commission Guidelines on the protection of minors under Article 28(4) DSAIn force from
- AI Act, Article 53 (obligations for providers of general-purpose AI models)In force from
- AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk)In force from
- Commission Recommendation (EU) 2026/1035 on a common framework for EU wide age verification technologiesIn force from
- AI Act, Article 4a (processing of special categories of personal data for bias detection and correction)Enacted In force from
- AI Act, Article 5(1)(ba) and (bb) (AI-generated non-consensual intimate imagery and child sexual abuse material)Enacted Starts
- AI Act, Article 10 (data and data governance)Amended Starts
- AI Act, Article 12 (record-keeping)Amended Starts
- AI Act, Article 14 (human oversight)Amended Starts
- AI Act, Article 15 (accuracy, robustness and cybersecurity)Amended Starts
- AI Act, Article 19 (automatically generated logs)Amended Starts
- AI Act, Article 21(2) (competent authority access to automatically generated logs)Amended Starts
- AI Act, Article 26(6) (deployer log-keeping)Amended Starts
- AI Act, Article 50 (transparency obligations for AI systems and synthetic content)Amended In force from
- AI Act, Article 73 (reporting of serious incidents)Amended Starts
- AI Act, Article 86 (right to explanation of individual decision-making)Amended Starts
- AI Act, Article 9 (risk management system)Amended Starts
- Cyber Resilience Act, Manufacturer Reporting ObligationsIn force from
- AI Act, Article 57 (national AI regulatory sandboxes)Starts
- AI Act, Article 25 (responsibilities along the AI value chain)Starts
- AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring)Starts
- AI Act, Article 26(10) (post-remote biometric identification authorisation)Starts
- AI Act, Article 26(11) (informing individuals subject to an Annex III decision)Starts
- AI Act, Article 26(7) (informing workers before workplace use)Starts
- AI Act, Article 26(8) (public-authority deployer registration)Starts
- AI Act, Article 26(9) (using Article 13 information for a data protection impact assessment)Starts
- AI Act, Article 27 (fundamental rights impact assessment)Starts
- AI Act, Article 6(3) and (4) (narrow-task derogation from Annex III high-risk classification)Starts
- Cyber Resilience Act, Essential Requirements and Manufacturer ObligationsStarts
-
Austria 14 laws- Datenschutzgesetz (DSG), Data Protection ActIn force from
- GDPR Article 22, Automated Decision-Making in AustriaIn force from
- GDPR Article 82 and Datenschutzbehörde Enforcement in AustriaIn force from
- GDPR Article 9, Special Categories of Personal Data Including Biometric Data, as Applied in AustriaIn force from
- GDPR Articles 12-21 and DSG Section 4, Data Subject Rights in AustriaIn force from
- GDPR Articles 33-34, Breach Notification in AustriaIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from AustriaIn force from
- UrhG Section 42h(6), Text-and-Data-Mining Opt-Out for AggregationIn force from
- UrhG Section 42h, Text-and-Data-Mining ExceptionIn force from
- UrhG Section 76f, Press-Publisher Neighbouring RightIn force from
- UWG Section 1, General Unfair Commercial Practices ClauseIn force from
- StGB Section 207a(4)(4), Computer-Generated and Altered Child Sexual Abuse MaterialIn force from
- Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management MeasuresIn force from
- Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting ObligationsIn force from
-
Belgium 16 laws- Act of 3 December 2017, GBA/APD and Litigation ChamberIn force from
- Code de Droit Économique Article XVII.37, 10 degrees/1, Collective Redress for GDPR ClaimsIn force from
- GDPR Article 22, Automated Decision-Making in BelgiumIn force from
- GDPR Articles 12-21 and Act of 30 July 2018 Title 5, Data Subject Rights and Action en Cessation in BelgiumIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V and Act Article 222, 4, Cross-Border Transfer RestrictionsIn force from
- Act of 30 July 2018 Article 9 and GBA/APD Biometric Recommendation and EnforcementIn force from
- Act of 30 July 2018 Articles 8-10, Special-Category Processing GroundsIn force from
- Act of 30 July 2018 Title 6 Chapter II, Criminal SanctionsIn force from
- Act of 30 July 2018 on the Protection of Natural Persons with regard to Personal DataIn force from
- Act of 30 July 2018 Article 10/1, Recorded Commercial CommunicationsIn force from
- Code de droit économique, article XI.190, 20°, exception de fouille de textes et de donnéesIn force from
- Code de droit économique, article XI.216/2, droit voisin des éditeurs de presseIn force from
- Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and GovernanceIn force from
- Loi du 26 avril 2024, Significant-Incident Notification ObligationsIn force from
- Code pénal, Livre II, articles 524 à 527, accès non autorisé dans un système informatiqueIn force from
-
Bulgaria 12 laws- GDPR Article 22, Automated Decisions in BulgariaIn force from
- GDPR Articles 12-21 and Personal Data Protection Act Articles 37a-37v, Data Subject Rights in BulgariaIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- KZLD Enforcement and GDPR Article 82In force from
- Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD)In force from
- Radio and Television Act (ZRT), Arts. 17a and 19d, Protection of Minors and Video-Sharing Platform Age VerificationIn force from
- Copyright and Neighbouring Rights Act (ZAPSP), Arts. 26e, 26zh and 26k, Text-and-Data-Mining Exception for Crawling and TrainingIn force from
- Copyright and Neighbouring Rights Act (ZAPSP), Arts. 26e, 26zh and 26k, Text-and-Data-Mining Exception for News AggregationIn force from
- Copyright and Neighbouring Rights Act (ZAPSP), Arts. 90d and 90zh, Press Publisher RightIn force from
- Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS)In force from
- Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)In force from
-
Croatia 13 laws- AZOP Enforcement and GDPR Article 82In force from
- Act on the Implementation of the General Data Protection RegulationIn force from
- Croatian Act Articles 21-23, Biometric Data by SectorIn force from
- GDPR Article 22, Right Against Automated Individual Decision-MakingIn force from
- GDPR Articles 12-21, Data Subject Rights in CroatiaIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Zakon o autorskom pravu i srodnim pravima, Pravo nakladnika informativnih publikacija (Arts. 165-166, 170-172)In force from
- Zakon o autorskom pravu i srodnim pravima, Text and Data Mining Exceptions (Arts. 187-188)In force from
- Zakon o elektroničkim medijima, Minor Protection and Video-Sharing-Platform Age Verification (Arts. 24, 96)In force from
- Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and GovernanceIn force from
- Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting ObligationsIn force from
- Kazneni zakon Article 215a, Endangering Life and Property by an Artificial Intelligence SystemIn force from
-
Cyprus 10 laws- GDPR Articles 33-34, Breach Notification in CyprusIn force from
- GDPR Articles 82-83 and ODPC Enforcement in CyprusIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from CyprusIn force from
- GDPR Article 22 and Law 125(I)/2018 Article 31, Decisions About a Person in CyprusIn force from
- GDPR Article 9 and Law 125(I)/2018, Genetic and Biometric Data in CyprusIn force from
- GDPR Articles 12-21 and Law 125(I)/2018 Article 11, Data Subject Rights in CyprusIn force from
- Law 125(I)/2018, Cyprus GDPR SupplementIn force from
- Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and GovernanceIn force from
- Security of Networks and Information Systems Law, Incident Notification ObligationsIn force from
- Security of Networks and Information Systems Law, Radio Equipment Cybersecurity RequirementsIn force from
-
Czech Republic 15 laws- GDPR Article 22, Automated Decisions in the Czech RepublicIn force from
- GDPR Article 9, Special Categories Including Biometric DataIn force from
- GDPR Articles 12-21 and Act No. 110/2019 Sb. Section 11, Data Subject Rights in the Czech RepublicIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Act on Personal Data ProcessingIn force from
- Act No. 132/2010 Coll., Section 6a, Age Verification for On-Demand Audiovisual Media ServicesIn force from
- Act No. 242/2022 Coll., Protection Measures Including Age Verification for Video-Sharing Platform ServicesIn force from
- Autorský zákon Section 87b, Press Publisher Neighbouring RightIn force from
- Autorský zákon Sections 39c-39d, Text and Data Mining Exception Bearing on News IndexingIn force from
- Autorský zákon Sections 39c-39d, Text and Data Mining Exception for Automated AnalysisIn force from
- UOOU Enforcement, GDPR Article 82, and the Act on Collective Civil Court ProceedingIn force from
- Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident NotificationIn force from
- Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security MeasuresIn force from
- Criminal Code Section 191a, Non-Consensual Identity-Based Pornographic DepictionIn force from
-
Denmark 14 laws- Danish Data Protection Act (Databeskyttelsesloven)In force from
- GDPR Article 22, Automated Decisions in DenmarkIn force from
- GDPR Article 9, Special Categories of Personal Data as Applied in DenmarkIn force from
- GDPR Articles 12-21 and 23, Data Subject Rights as Applied in DenmarkIn force from
- GDPR Articles 33-34, Breach Notification in DenmarkIn force from
- GDPR Articles 82-83 and Datatilsynet Enforcement in DenmarkIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from DenmarkIn force from
- Straffeloven Section 263, Unauthorized Access to a Data SystemIn force from
- Radio- og fjernsynsloven Sections 51a-51c, Video-Sharing Platform Minor ProtectionIn force from
- Ophavsretsloven Section 69a, Press Publisher RightIn force from
- Ophavsretsloven Sections 11b-11c, Text and Data Mining ExceptionIn force from
- NIS 2-loven, Cybersecurity Risk-Management Measures and RegistrationIn force from
- NIS 2-loven, Significant-Incident Reporting and Recipient-Notice DutiesIn force from
- Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 EnforcementIn force from
-
Estonia 12 laws- GDPR Article 22, Automated Decisions in EstoniaIn force from
- GDPR Article 9, Special Categories of Personal Data as Applied in EstoniaIn force from
- GDPR Articles 15-21, Data Subject Rights as Applied in EstoniaIn force from
- GDPR Articles 33-34, Breach Notification in EstoniaIn force from
- GDPR Articles 82-83 and AKI Enforcement in EstoniaIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from EstoniaIn force from
- Personal Data Protection Act (Isikuandmete kaitse seadus)In force from
- Autoriõiguse seadus (Copyright Act) Section 73-2, Rights of a Press Publication PublisherIn force from
- Autoriõiguse seadus (Copyright Act) Sections 19-1 and 19-2, Text and Data Mining ExceptionIn force from
- Meediateenuste seadus (Media Services Act) Section 19-1, Protection of Minors on a Video-Sharing PlatformIn force from
- Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber IncidentIn force from
- Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body DutiesIn force from
-
Finland 14 laws- GDPR Article 22, Automated Decisions in FinlandIn force from
- Data Protection Act (Tietosuojalaki)In force from
- GDPR Article 9 and Data Protection Act Section 6, Special Categories in FinlandIn force from
- GDPR Articles 15-21 and Data Protection Act Sections 21 and 33-34, Data Subject Rights in FinlandIn force from
- GDPR Articles 33-34, Breach Notification in FinlandIn force from
- GDPR Articles 82-83 and Data Protection Act Section 24, Enforcement in FinlandIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from FinlandIn force from
- Rikoslaki Chapter 20, Distribution and Possession of an Image Depicting a Child Sexually, Including Realistic DepictionsIn force from
- Tekijanoikeuslaki Section 13b, Text-and-Data-Mining Reproduction ExceptionIn force from
- Tekijanoikeuslaki Section 50, Press Publication Publisher RightIn force from
- Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and GovernanceIn force from
- Kyberturvallisuuslaki, Significant-Incident Reporting ObligationsIn force from
- Laki eräiden tekoälyjärjestelmien valvonnasta, Act on the Supervision of Certain Artificial Intelligence SystemsIn force from
- Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience ActIn force from
-
France 17 laws- Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident NotificationIn force from
- Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security RequirementsIn force from
- CNIL Enforcement, GDPR Article 83 and Code Pénal Articles 226-16 to 226-22-2In force from
- GDPR Article 22, Right Against Automated Individual Decision-MakingIn force from
- GDPR Article 9 Special Categories, as Implemented by Loi 78-17 Article 6In force from
- GDPR Articles 12-21 and Loi 78-17 Article 49, Data Subject Rights in FranceIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Loi Informatique et Libertés, GDPR-Aligned Comprehensive Regime (Data Processing, Data Files and Individual Liberties Act)In force from
- CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001)In force from
- Loi 78-17 Articles 48 and 51 II, Rights of Minors in FranceIn force from
- CPI Articles L218-1 to L218-5, Press Publisher and News Agency Neighbouring RightIn force from
- CPI Article L122-5-3, Text and Data Mining ExceptionIn force from
- Loi n° 2022-309 du 3 mars 2022 (loi Cyberscore), Cybersecurity Audit and Disclosure DutyIn force from
- Loi n° 2024-449 du 21 mai 2024 visant à sécuriser et réguler l'espace numérique (SREN, Law No. 2024-449 of 21 May 2024 on securing and regulating the digital space), articles 1 and 2 (age verification for access to pornographic content)In force from
- Délibération n° 2024-20 du 9 octobre 2024 de l'Arcom relative au référentiel technique de vérification de l'âge pour l'accès aux contenus pornographiques (Arcom Deliberation No. 2024-20 of 9 October 2024 on the technical reference framework for age verification for access to pornographic content)In force from
- Arrêté du 26 février 2025 désignant les services établis dans un autre État membre de l'Union européenne soumis aux articles 10 et 10-1 de la loi n° 2004-575 du 21 juin 2004 (Ministerial order of 26 February 2025 designating services established in another EU member state subject to the age verification regime)In force from
-
Germany 16 laws- Bundesdatenschutzgesetz (BDSG), Federal Data Protection ActIn force from
- GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in GermanyIn force from
- GDPR Article 82, BDSG Sections 41-43, and BfDI and Landesdatenschutzbehörden Enforcement in GermanyIn force from
- GDPR Article 9 and BDSG Section 26(3), Special Categories and Employment Biometric Data in GermanyIn force from
- GDPR Articles 12-21 and BDSG Sections 34 and 35, Data Subject Rights in GermanyIn force from
- GDPR Articles 33-34, Breach Notification in GermanyIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from GermanyIn force from
- Jugendschutzgesetz (JuSchG, Youth Protection Act), Section 24a, Vorsorgemassnahmen (provider precautionary measures)In force from
- Presseverleger-Leistungsschutzrecht (Press Publisher Neighbouring Right)In force from
- Text und Data Mining (General Text and Data Mining Exception)In force from
- Text und Data Mining fuer Zwecke der wissenschaftlichen Forschung (Text and Data Mining for Scientific Research)In force from
- Gesetz gegen den unlauteren Wettbewerb, Documentation of Consent to Telephone AdvertisingIn force from
- Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, Protection of Privacy in Terminal EquipmentIn force from
- BSI-Gesetz (BSIG), Incident NotificationIn force from
- BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important EntitiesIn force from
- Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion ActIn force from
-
Greece 15 laws- GDPR Article 22, Automated Decisions in GreeceIn force from
- GDPR Article 9 and Law 4624/2019, Special Categories in GreeceIn force from
- GDPR Articles 33-34, Breach Notification in GreeceIn force from
- GDPR Articles 82-83 and HDPA Enforcement in GreeceIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from GreeceIn force from
- Penal Code Article 370C (370Γ), Violation of Computer Data and Program SecretsIn force from
- Penal Code Article 370D (370Δ), Access to an Information System in Breach of a Prohibition or Security MeasureIn force from
- GDPR Articles 12-21 and 23 and Law 4624/2019 Article 27, Data Subject Rights and Employment in GreeceIn force from
- Law 4624/2019, Greek GDPR Implementation Law (Nomos 4624/2019, N. 4624/2019)In force from
- Law 4779/2021 Article 32, Video-Sharing Platform and Social Network Minor Protection DutiesIn force from
- Law 2121/1993 Article 51B, Press Publisher Neighbouring RightIn force from
- Law 2121/1993 Articles 21A-21B, Text and Data Mining ExceptionIn force from
- Law 5160/2024, Cybersecurity Risk-Management Measures and GovernanceIn force from
- Law 5160/2024, Significant-Incident Reporting ObligationsIn force from
- Law 5321/2026, National AI Act Implementation LawIn force from
-
Hungary 9 laws- GDPR Article 22, Automated Decisions in HungaryIn force from
- GDPR Articles 12-21 and Infotv. Sections 23 and 25, Data Subject Rights in HungaryIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Infotörvény Definitions, Biometric and Special-Category DataIn force from
- Infotörvény Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018In force from
- Szjt. Section 35/A, Text and Data Mining ExceptionIn force from
- Szjt. Sections 82/A-82/C, Press Publisher's RightIn force from
- Cybersecurity Act, Incident Notification and Cybersecurity FineIn force from
- Cybersecurity Act, Risk-Management MeasuresIn force from
-
Ireland 19 laws- Criminal Justice (Offences Relating to Information Systems) Act 2017In force from
- Data Protection Act 2018In force from
- Data Protection Act 2018, section 31 (digital age of consent)In force from
- GDPR Article 22 and Data Protection Act 2018 Section 57, Automated Decision-Making in IrelandIn force from
- GDPR Article 82, Data Protection Act 2018 Section 117, and DPC Enforcement in IrelandIn force from
- GDPR Article 9 and Data Protection Act 2018 Section 46, Special Categories and Employment Biometric Data in IrelandIn force from
- GDPR Articles 12-21 and Data Protection Act 2018 Sections 60-61, Data Subject Rights in IrelandIn force from
- GDPR Articles 33-34, Breach Notification in IrelandIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from IrelandIn force from
- European Union (NIS) Regulations 2018, Incident NotificationIn force from
- European Union (NIS) Regulations 2018, Security RequirementsIn force from
- Harassment, Harmful Communications and Related Offences Act 2020, Intimate Image OffencesIn force from
- European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021, Press Publisher RightIn force from
- Text and Data Mining Exceptions, Copyright and Related Rights Act 2000 ss. 53A-53BIn force from
- Online Safety and Media Regulation Act 2022 (No. 41 of 2022)In force from
- DPC Guidance: AI, Large Language Models and Data ProtectionIn force from
- Online Safety Code, Part B (age assurance for pornography and violent content)In force from
- European Union (Artificial Intelligence) (Designation) Regulations 2025In force from
- Regulation of Artificial Intelligence Act 2026Enacted In force from
-
Italy 20 laws- GDPR Article 22 and the Garante's OpenAI/ChatGPT EnforcementIn force from
- GDPR Article 82 and Azione di Classe (Codice di Procedura Civile Art. 840-bis)In force from
- GDPR Article 9 Special Categories and Codice Privacy Article 167(2)In force from
- GDPR Articles 12-21 and Codice Articles 2-undecies and 2-terdecies, Data Subject Rights in ItalyIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Codice Privacy (Personal Data Protection Code), as Amended for GDPR AlignmentIn force from
- Codice in materia di protezione dei dati personali (Data Protection Code), Art. 2-quinquies, minimum age for social media consentIn force from
- Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data PrescriptionsIn force from
- Legge sul Diritto d'Autore Art. 43-bis, Press Publisher Neighbouring RightIn force from
- Legge sul Diritto d'Autore Artt. 70-ter and 70-quater, Text-and-Data-Mining ExceptionsIn force from
- Decreto-legge 15 settembre 2023, n. 123 (Decreto Caivano, Youth Hardship Decree), Art. 13-bis, converted by Legge 13 novembre 2023, n. 159In force from
- Codice Penale Art. 615-quater, Illicit Possession or Distribution of Access DevicesIn force from
- Codice Penale Art. 615-ter, Unauthorized Access to a Computer or Telematic SystemIn force from
- Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident NotificationIn force from
- Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management MeasuresIn force from
- Codice Penale Art. 612-quater, Illicit Dissemination of AI-Generated or AI-Altered ContentIn force from
- Legge 132/2025 Art. 20, National AI Authorities (AgID and ACN)In force from
- Legge 132/2025, Sector Human-Oversight and Disclosure Duties (Artt. 4, 11, 13)In force from
- Delibera AGCOM n. 96/25/CONS dell'8 aprile 2025 (technical and process rules for age verification)In force from
-
Latvia 17 laws- GDPR Article 22, Automated Decisions in LatviaIn force from
- GDPR Articles 15-21, Data Subject Rights as Applied in LatviaIn force from
- GDPR Articles 33-34, Breach Notification in LatviaIn force from
- GDPR Articles 82-83 and DVI Enforcement in LatviaIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from LatviaIn force from
- Personal Data Processing Law (Fizisko personu datu apstrādes likums)In force from
- Personal Data Processing Law Article 25(2), Special Categories in LatviaIn force from
- Elektronisko plašsaziņas līdzekļu likums, Article 23.6, Video-Sharing Platform Minor Protection MeasuresIn force from
- Elektronisko plašsaziņas līdzekļu likums, Articles 23(4) and 24(9)-(10.1), Restricted Access Control for Content Harmful to MinorsIn force from
- Autortiesību likums Article 21.1, Text and Data Mining Exception (News Indexing and Aggregation)In force from
- Autortiesību likums Article 21.1, Text and Data Mining Exception (Scraping and AI Training)In force from
- Autortiesību likums Article 53.1, Press Publisher Online Rights (DSM Article 15 Transposition)In force from
- Autortiesību likums Chapter IX, Sui Generis Database RightIn force from
- Krimināllikums Sections 90.1 and 90.2, Criminalization of Deepfake Election and State-Appointment DisinformationIn force from
- Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and RemediationIn force from
- Nacionālās kiberdrošības likums, Cybersecurity Risk-Management MeasuresIn force from
- Nacionālās kiberdrošības likums, Incident NotificationIn force from
-
Lithuania 15 laws- GDPR Article 22, Automated Decisions in LithuaniaIn force from
- GDPR Article 9, Special Categories of Personal Data as Applied in LithuaniaIn force from
- GDPR Articles 15-21, Data Subject Rights as Applied in LithuaniaIn force from
- GDPR Articles 33-34, Breach Notification in LithuaniaIn force from
- GDPR Articles 82-83 and VDAI Enforcement in LithuaniaIn force from
- GDPR Chapter V and VDAI Article 46(3) Authorization, Cross-Border Transfer from LithuaniaIn force from
- Law on Legal Protection of Personal DataIn force from
- Law on the Protection of Minors against the Detrimental Effect of Public Information, Arts. 4 and 7 (Content Classification and Age-Restricted Access)In force from
- Copyright Act Art. 21, Quotation ExceptionIn force from
- Copyright Act Art. 57-1, Electronic Press Publishers' RightIn force from
- Copyright Act Arts. 22-1 and 22-2, Text and Data Mining ExceptionsIn force from
- Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident NotificationIn force from
- Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management MeasuresIn force from
- Criminal Code Art. 309(2), Dealing in Child Sexual Abuse Material Including Simulated DepictionsIn force from
- Criminal Code Arts. 196-198 and 198-1, Computer Misuse and Unauthorised Access OffensesIn force from
-
Luxembourg 9 laws- GDPR Article 22, Automated Decisions as Applied in LuxembourgIn force from
- GDPR Article 9, Special Categories of Personal Data as Applied in LuxembourgIn force from
- GDPR Articles 12-21 and Loi du 1er août 2018 Article 63, Data Subject Rights in LuxembourgIn force from
- GDPR Articles 33-34, Breach Notification in LuxembourgIn force from
- GDPR Articles 82-83 and CNPD Enforcement in LuxembourgIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from LuxembourgIn force from
- Act of 1 August 2018 on the Organisation of the CNPD and the General Data Protection FrameworkIn force from
- Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident NotificationIn force from
- Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important EntitiesIn force from
-
Malta 14 laws- Data Protection Act, Chapter 586 of the Laws of MaltaIn force from
- GDPR Article 22, Automated Decisions in MaltaIn force from
- GDPR Article 9 and Cap. 586, Genetic, Biometric and Health Data Research Processing in MaltaIn force from
- GDPR Articles 12-21 and Cap. 586, Data Subject Rights in MaltaIn force from
- GDPR Articles 33-34, Breach Notification in MaltaIn force from
- GDPR Articles 82-83 and IDPC Enforcement in MaltaIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from MaltaIn force from
- Gaming Authorisations and Compliance Directive, Notification of Information Security BreachesIn force from
- Copyright and Related Rights in the Digital Single Market Regulations, Text and Data Mining ExceptionsIn force from
- Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025)In force from
- Artificial Intelligence Regulations, 2025 (L.N. 226 of 2025)In force from
- Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Risk-Management Measures for Essential and Important EntitiesIn force from
- Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Significant-Incident Reporting to the National CSIRTIn force from
- Cyber Resilience Regulations, MDIA Designation under the Cyber Resilience ActEnacted Starts
-
Netherlands 14 laws- AP Enforcement, GDPR Article 82 and the WAMCA Collective-Action RegimeIn force from
- GDPR Article 22 and UAVG Article 40, Automated Decisions in the NetherlandsIn force from
- GDPR Articles 12-21 and UAVG Articles 41 and 43, Data Subject Rights in the NetherlandsIn force from
- GDPR Articles 33-34 and UAVG Article 42, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- UAVG Article 29, Biometric-Data Exception for Authentication or SecurityIn force from
- UAVG Articles 30-33 and 46, Health, Criminal-Conviction, and National-ID-Number DataIn force from
- Uitvoeringswet Algemene verordening gegevensbescherming (UAVG), GDPR Implementation ActIn force from
- Auteurswet, artt. 15n and 15o, Text and Data Mining ExceptionsIn force from
- Wet op de naburige rechten, Article 7b, Press Publisher Online RightIn force from
- Wetboek van Strafrecht, art. 252, Sexual Imagery of an Apparent Minor (Virtual Child Sexual Abuse Material)In force from
- Wetboek van Strafrecht, art. 138ab, Computervredebreuk (Computer Trespass)In force from
- Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and GovernanceIn force from
- Cyberbeveiligingswet, Significant-Incident Reporting ObligationsIn force from
-
Poland 13 laws- Act on the Protection of Personal Data of 10 May 2018In force from
- GDPR Article 22, Automated Decisions in PolandIn force from
- GDPR Article 9, Act Article 107(2), and Kodeks Pracy Article 22(1b), Biometric DataIn force from
- GDPR Articles 12-21 and Act of 10 May 2018 Articles 92-97, Data Subject Rights in PolandIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- UODO Enforcement, GDPR Article 82, and Act Articles 98, 101-108In force from
- Ustawa o radiofonii i telewizji, Video-Sharing Platform Minor Protection DutiesIn force from
- Ustawa o prawie autorskim i prawach pokrewnych, Text-and-Data-Mining ExceptionsIn force from
- Ustawa o prawie autorskim, Press Publisher Neighbouring RightIn force from
- Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem InformacjiEnacted Starts
- Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów PoważnychEnacted Starts
- Ustawa o systemach sztucznej inteligencji, Act on Artificial Intelligence SystemsEnacted In force from
-
Portugal 13 laws- CNPD Deliberacao 2019/494, Disapplication of Lei 58/2019 Provisions in PortugalIn force from
- GDPR Article 22, Automated Decisions in PortugalIn force from
- GDPR Article 9, Special Categories of Personal Data as Applied in PortugalIn force from
- GDPR Articles 33-34, Breach Notification in PortugalIn force from
- GDPR Chapter V, Cross-Border Transfer of Personal Data from PortugalIn force from
- GDPR Articles 12-21 and Lei n.o 58/2019, Data Subject Rights in PortugalIn force from
- Lei n.o 58/2019, Portuguese GDPR Implementation Law (Lei de Execução do RGPD)In force from
- Video-Sharing Platform Age Verification DutyIn force from
- CDADC Article 188.º-A, Press Publisher Online RightsIn force from
- CDADC Text and Data Mining ExceptionIn force from
- CDADC Text and Data Mining Opt-Out for News AggregationIn force from
- Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and GovernanceIn force from
- Regime Jurídico da Cibersegurança, Significant-Incident Reporting ObligationsIn force from
-
Romania 12 laws- Cod penal, Art. 374, Pornografia infantilă (Child Pornography, Including Simulated or Computer-Generated Depictions of Minors)In force from
- ANSPDCP Enforcement and GDPR Article 82In force from
- GDPR Article 22, Automated Decisions in RomaniaIn force from
- GDPR Articles 12-21 and Legea nr. 190/2018 Article 8, Data Subject Rights in RomaniaIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Law No. 190/2018 on Measures for the Implementation of Regulation (EU) 2016/679In force from
- Legea nr. 8/1996 privind dreptul de autor și drepturile conexe, art. 36^1-36^2, Text and Data Mining Exceptions, inserted by Legea nr. 69/2022In force from
- Legea nr. 8/1996 privind dreptul de autor și drepturile conexe, art. 94^1, Press Publisher Neighbouring Right, inserted by Legea nr. 69/2022In force from
- Legea nr. 504/2002 (Legea audiovizualului), art. 39, Minors Protection in Television, Radio, and On-Demand Audiovisual Media ServicesIn force from
- Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management MeasuresIn force from
- Ordonanța de urgență nr. 155/2024, Incident NotificationIn force from
-
Slovakia 12 laws- Act on the Protection of Personal DataIn force from
- GDPR Article 22, Automated Decisions in SlovakiaIn force from
- GDPR Articles 12-21, Data Subject Rights in SlovakiaIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Office for Personal Data Protection Enforcement and GDPR Article 82In force from
- Autorský zákon, Press Publisher RightIn force from
- Autorský zákon, TDM ExceptionIn force from
- Autorský zákon, TDM Exception (Aggregation)In force from
- Media Services Act, Video-Sharing Platform Public-Protection MeasuresIn force from
- Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability NotificationIn force from
- Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management MeasuresIn force from
-
Slovenia 13 laws- GDPR Article 22, Automated Decisions in SloveniaIn force from
- GDPR Articles 12-21 and ZVOP-2 Articles 11 and 69, Data Subject Rights in SloveniaIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- Informacijski pooblaščenec Enforcement, GDPR Article 82, and ZVOP-2 Articles 114-116In force from
- Zakon o avdiovizualnih medijskih storitvah (ZAvMS), Art. 38.b, Video-Sharing Platform Protective Measures for MinorsIn force from
- Zakon o avtorski in sorodnih pravicah (ZASP), Art. 139.a, Media PublicationsIn force from
- Zakon o avtorski in sorodnih pravicah (ZASP), Arts. 57.a-57.b, Text and Data MiningIn force from
- ZVOP-2 Chapter 4 (Articles 81-84) and Article 80, Biometric and Genetic DataIn force from
- Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection ActIn force from
- Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification ObligationsIn force from
- Zakon o izvajanju uredbe (EU) o določitvi harmoniziranih pravil o umetni inteligenci (ZIUDHPUI), AKOS Designation as AI Act Competent AuthorityIn force from
- Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and GovernanceStarts
-
Spain 16 laws- AEPD Enforcement, GDPR Article 82 and LOPDGDD Título IXIn force from
- GDPR Articles 33-34 and LOPDGDD Article 69, Breach NotificationIn force from
- LOPDGDD Título VI, International Transfers, Layered on GDPR Chapter VIn force from
- Real Decreto-ley 12/2018, Incident Notification ObligationIn force from
- Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service ProvidersIn force from
- GDPR Article 22 and LOPDGDD Article 11(2), Automated Decisions in SpainIn force from
- GDPR Article 9 and AEPD Biometric Guidance, Special CategoriesIn force from
- LOPDGDD Título III and Título X, Data-Subject and Digital RightsIn force from
- Ley Orgánica 3/2018 (LOPDGDD), GDPR-Aligned Comprehensive RegimeIn force from
- Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD, Organic Law 3/2018 on personal data protection and digital rights guarantee), Art. 7In force from
- Ley Orgánica 8/2021, de 4 de junio, de protección integral a la infancia y la adolescencia frente a la violencia (LOPIVI, Organic Law 8/2021 on the comprehensive protection of children and adolescents against violence)In force from
- Estatuto de los Trabajadores Article 64.4.d), Algorithmic Management Works Council Information RightIn force from
- RDL 24/2021 Article 67, Text and Data Mining ExceptionIn force from
- RDL 24/2021 Article 67, Text and Data Mining ExceptionIn force from
- TRLPI Article 129 bis, Press Publisher and News Agency Online RightsIn force from
- TRLPI Article 32, Citation, Press-Review, and Aggregation-Service ExceptionIn force from
-
Sweden 15 laws- Dataskyddslagen (Data Protection Act), GDPR-Complementing ProvisionsIn force from
- GDPR Article 22, Automated Decisions in SwedenIn force from
- GDPR Article 9, Dataskyddslagen Chapter 3, and the IMY Skelleftea Facial-Recognition DecisionIn force from
- GDPR Articles 12-21 and Dataskyddslagen Chapter 5, Data Subject Rights in SwedenIn force from
- GDPR Articles 33-34, Breach NotificationIn force from
- GDPR Chapter V, Cross-Border Transfer RestrictionsIn force from
- IMY Enforcement, GDPR Article 82, Dataskyddslagen Chapter 6-7, and Group ProceedingsIn force from
- Kamerabevakningslagen (Camera Surveillance Act)In force from
- Brottsbalken 16 kap. 10 a-10 b §§, Child Pornography Offence (Barnpornografibrott)In force from
- Radio- och tv-lagen 9 a kap., Video-Sharing Platform Protection of MinorsIn force from
- Upphovsrättslagen 15 a-15 c §§, Text and Data Mining ExceptionIn force from
- Upphovsrättslagen 48 b-48 d §§, Press Publisher Neighbouring RightIn force from
- Cybersäkerhetslag, Cybersecurity Risk-Management MeasuresIn force from
- Cybersäkerhetslag, Incident NotificationIn force from
- Brottsbalken 4 kap. 9 c §, Unauthorized Computer Access (Dataintrång)In force from
1 law starts to bind after , past the slider's last stop, so the map does not place it:
- AI Act, Article 111(2) (2030 compliance deadline for public-authority-intended systems), European Union, starts
5 more laws are enacted with no start date on record, so the map cannot place them on the slider. Each is marked not yet in force on its own LexLint page.
58 laws in force started to bind before , the slider's first day, so the map does not draw them.
35 laws are in force with no start date on record, so the map cannot place them on the slider.
7 laws now blocked by a court or no longer in force have no dated change on record, so the map cannot say when they stopped binding and does not draw them.
This map reports changes in the law, drawn from the official record that each law's LexLint page, and each change on the tracker, cites. It is not legal advice.