Law / European Union

European Union

The European Union has 27 member states Each member state has law of its own, on a page of its own. All 27 are listed below.

37 of 44 named instruments researched to a stage, across all six areas of law we track: 27 in force, 9 enacted but not yet in force and 1 proposed. As of 21 September 2026.

When they take effect36 of 37 carry a date, 1 does not. Earlier is before 2015.
Before 2015: 2 instruments (2 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 2 instruments (2 in force) 2020: 1 instrument (1 in force) ’20 2021: 2 instruments (2 in force) 2022: 0 instruments 2023: 2 instruments (2 in force) 2024: 4 instruments (4 in force) 2025: 4 instruments (4 in force) ’25 2026: 4 instruments (4 in force) 2027: 9 instruments (9 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blockedcourt decision

  1. AI law 14
  2. Privacy law 7
  3. Scraping law 1
  4. Cybersecurity law 5
  5. Age gating law 5
  6. News aggregation law 5

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

What is unusual here

Positions this jurisdiction holds that few others do, measured across every jurisdiction we score on the same question.

Text and data mining opt-out

Under Article 4(3) of the Copyright in the Digital Single Market Directive a rightholder's reservation of text and data mining rights has to be expressed by machine-readable means for content made publicly available online, so whether a crawler may mine a page turns on a signal it can read rather than on a term stated only in that site's conditions of use.

1 of 216 jurisdictions scored

AI law14 instruments, 6 in force, 8 enacted but not yet in force

Research summary (587 words)

The EU AI Act (Regulation (EU) 2024/1689) supplies the core duties recorded here.

Article 50 requires disclosure of AI interaction, machine-readable marking of synthetic output, and labeling of deepfakes and AI-generated public-interest text, effective 2 August 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) left it largely untouched, adding only a four-month transition, to 2 December 2026, for the machine-readable marking sub-duty on generative systems already on the market before 2 August 2026.

Article 53 requires providers of general-purpose AI models to publish a training-content summary, adopt a copyright-compliance policy honoring Text and Data Mining opt-outs, and, for a model carrying systemic risk, test for and report serious incidents, effective 2 August 2025.

Article 55 adds a second, separate incident-reporting duty on a different bound party: a provider of a general-purpose AI model the Commission has classified as carrying systemic risk must keep track of, document, and report relevant information about serious incidents and corrective measures to the AI Office, and as appropriate to national competent authorities, without undue delay, effective 2 August 2025.

That duty states no number of days and no explicit moment it runs from; the day counts a signatory provider works to sit in the AI Office's General-Purpose AI Code of Practice rather than in the Regulation.

Article 73 requires providers of high-risk AI systems, and deployers who identify one, to report a serious incident to the market surveillance authority of the Member State where it occurred, on a clock of 15 days in the ordinary case, 10 days where the incident caused a person's death, and 2 days for a widespread infringement or an incident causing a serious and irreversible disruption to critical infrastructure, effective on the Regulation's general 2 August 2026 application date; the Digital Omnibus left Article 73's own text and clocks unchanged, and its deferral of Chapter III's high-risk-system obligations to 2027 and 2028 does not reach Article 73, which sits in Chapter IX, though the Omnibus did add a narrow Article 75 derogation redirecting the report to the AI Office, on the same clocks, for providers under the AI Office's own exclusive supervisory competence.

Articles 9, 10, 14 and 15 add the core Chapter III, Section 2 duties for a high-risk AI system itself: risk management, training data governance, human oversight, and accuracy, robustness and cybersecurity, each deferred by the same Digital Omnibus schedule to 2 December 2027 for a system classified high-risk under Article 6(2) and Annex III and to 2 August 2028 for one classified under Article 6(1) and Annex I. A narrower, platform-side duty sits in Digital Services Act Article 35(1)(k): very large online platforms and search engines must, as one item on an illustrative list of systemic-risk mitigation measures, consider making manipulated content that appreciably resembles real persons or events distinguishable through prominent markings.

The Political Advertising Regulation (Regulation (EU) 2024/900) is excluded here: its labeling duties concern ad sponsorship and targeting, not AI generation.

Digital Services Act Article 37 is carried here as the audit machinery over that platform-side duty and the rest of Chapter III: a designated very large online platform or search engine must submit to an independent audit at its own expense at least once a year, and the audit report and the provider's implementation report both go to the Digital Services Coordinator of establishment and the Commission and are then published. Article 37 is not itself an AI law; it is how compliance with the obligations that include Article 35(1)(k) is checked.

AI governance

AI Act, Article 12 (record-keeping)

Regulation (EU) 2024/1689, Article 12official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

High-risk AI systems must be technically capable of automatically recording events, in logs, over the system's lifetime. The logging capability must enable recording of events relevant to identifying a risk under Article 79(1) or a substantial modification, to supporting the post-market monitoring required by Article 72, and to the deployer monitoring required by Article 26(5).

For a remote biometric identification system, one of the Annex III use cases classified as high-risk under Article 6(2), the logs must at minimum record the start and end date and time of each use, the reference database checked against the input data, the input data for which a search produced a match, and the identity of the natural persons who verified the results under Article 14(5); this minimum contents list does not extend to high-risk systems generally.

Article 12 does not itself set how long a log must be kept or who may demand access to one: retention is Article 19's duty for a provider and Article 26(6)'s for a deployer, and access is Article 21(2)'s. Article 12 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI Act, Article 19 (automatically generated logs)

Regulation (EU) 2024/1689, Article 19official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of a high-risk AI system must keep the logs the system automatically generates under Article 12(1), to the extent those logs are under the provider's control. The logs must be kept for a period appropriate to the system's intended purpose, at least six months, unless a different period is required under other Union or national law, in particular data-protection law.

A provider that is a financial institution subject to internal-governance requirements under Union financial services law satisfies this duty by keeping the logs as part of the documentation that law already requires it to maintain.

Article 19 sits in Chapter III, Section 3, so like Article 12 it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI Act, Article 21(2) (competent authority access to automatically generated logs)

Regulation (EU) 2024/1689, Article 21(2)official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

Upon a reasoned request from a competent authority, a provider of a high-risk AI system must give that authority access to the logs automatically generated by the system under Article 12(1), to the extent the logs are under the provider's control. Any information a competent authority obtains under Article 21, including through this access, is subject to the confidentiality obligations of Article 78.

Article 21(2) is the access half of the record-keeping duty: Article 12 requires the logging capability to exist and Article 19 requires a provider to keep the logs, while Article 21(2) is what lets a competent authority reach them.

Article 21 sits in Chapter III, Section 3, so it takes effect on the same schedule as Articles 12, 19 and 26(6): 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI Act, Article 26(6) (deployer log-keeping)

Regulation (EU) 2024/1689, Article 26(6)official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

A deployer of a high-risk AI system must keep the logs the system automatically generates, to the extent the logs are under the deployer's control, for a period appropriate to the system's intended purpose, at least six months, unless a different period is required under other Union or national law, in particular data-protection law.

A deployer that is a financial institution subject to internal-governance requirements under Union financial services law satisfies this duty by maintaining the logs as part of the documentation that law already requires it to keep. Article 26(6) is the deployer-side counterpart of Article 19: the two provisions state the same retention period, of a deployer and a provider respectively, in nearly identical wording.

Article 26 sits in Chapter III, Section 3, so like Articles 12, 19 and 21 it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk)

Regulation (EU) 2024/1689, Article 55official consolidated Official Journal text, EUR-Lex

In force since 2 August 2025. Binds public and private bodies.

What this law does

Article 55 binds providers of general-purpose AI models that the Commission has classified as carrying systemic risk, in addition to the disclosure and copyright duties Article 53 places on every general-purpose AI model provider. A model is presumed to carry systemic risk when its training used more than 10^25 floating-point operations. The Commission may also designate a model this way on the basis of equivalent capabilities or impact.

Those providers must perform model evaluation using standardised, state-of-the-art protocols, including adversarial testing to identify and mitigate systemic risks. They must also assess and mitigate the systemic risks their model may pose at Union level, including where those risks originate.

They must keep track of, document, and report to the AI Office, and as appropriate to national competent authorities, without undue delay, relevant information about serious incidents involving their model and any corrective measures. And they must maintain an adequate level of cybersecurity protection for the model and its physical infrastructure.

The reporting duty names no fixed number of days and no explicit moment the clock runs from; it states only that the report must be made without undue delay. Article 73's reporting duty for high-risk AI systems sets a general ceiling of 15 days running from when the provider becomes aware of the incident. That ceiling tightens to 10 days where the incident caused a person's death.

It tightens to 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure. 'Serious incident' is defined once, in Article 3, point (49), for the whole Regulation, as an incident or malfunctioning that leads to a person's death or serious harm to health, a serious and irreversible disruption of critical infrastructure, an infringement of Union law protecting fundamental rights, or serious harm to property or the environment.

That definition is written for an AI system, a term the Regulation defines in Article 3, point (1). A general-purpose AI model is a separate defined term in the same Article. Article 55 supplies no definition of a serious incident keyed to a model rather than a system. A provider may rely on an AI Office code of practice, or a harmonised standard once one is published, to demonstrate compliance with these duties, and must show an alternative adequate means of compliance if it relies on neither.

Article 113's third paragraph, point (b), applies Chapter V, which contains Article 55, from 2 August 2025, a year ahead of the Regulation's general application date. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) left that point unchanged, replacing only points (a) and (c) and adding point (d). A provider whose model was already on the market before that date has until 2 August 2027 to come into compliance.

What it requires

Digital Services Act, Article 37 (independent audit of very large online platforms and search engines)

Regulation (EU) 2022/2065, Article 37, supplemented by Commission Delegated Regulation (EU) 2024/436official consolidated Official Journal text, EUR-Lex

In force since 25 August 2023. Binds private bodies.

EEA incorporation pending.

What this law does

Article 37 requires a Commission-designated very large online platform or very large online search engine, one with 45,000,000 or more average monthly active recipients in the Union, to commission an independent audit, at its own expense and at least once a year, of its compliance with the whole of Chapter III's due diligence obligations, not only the AI-relevant systemic-risk mitigation measure for generated and manipulated content in Article 35(1)(k), and with any codes of conduct or crisis protocols it has undertaken.

Article 37 is not itself an AI-facing duty; it is the audit machinery that sits over a body of obligations that happens to include the AI-relevant ones.

The auditing organisation must be independent of the provider and free of conflicts of interest, must not have supplied non-audit services to the provider in the twelve months before or after the audit, must not have audited the same provider for more than ten consecutive years, and may not be paid on a result-contingent basis; Commission Delegated Regulation (EU) 2024/436 supplements Article 37 with procedural rules on selecting and cooperating with the auditor, scoping the audit period, and drawing up the audit report and audit implementation report on the Regulation's own templates.

The audit report must name the provider and the auditor, describe the elements audited and the methodology, summarise the findings, list third parties consulted, and reach an audit opinion of 'positive', 'positive with comments', or 'negative'; where the opinion is not positive, the provider must adopt, within one month, an audit implementation report describing the measures it took or its reasons for not taking them.

The provider must transmit both reports to its Digital Services Coordinator of establishment and the Commission without undue delay, and make them public, in a version stripped of confidential information where necessary, at the latest three months after receiving the audit report.

Article 37 sits, like Article 35, in Chapter III Section 5 (Articles 33 to 43), so Article 92's anticipated-application rule applies to it too: the obligation binds a designated very large online platform or search engine from four months after the Commission's notification of that designation, where that date precedes the Regulation's general application date of 17 February 2024.

The Commission's first designations took effect on 25 April 2023 for platforms including Facebook, Instagram, TikTok, and X, so the audit duty began applying to that cohort from 25 August 2023.

What it requires

AI risk obligations

AI Act, Article 10 (data and data governance)

Regulation (EU) 2024/1689, Article 10official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of a high-risk AI system that uses techniques involving the training of AI models must develop it on training, validation and testing data sets that meet the quality criteria in paragraphs 2, 3 and 4 of Article 10 and in Article 4a(1), whenever such data sets are used.

Those data sets must be subject to data governance and management practices appropriate to the system's intended purpose, covering the provider's design choices, how the data was collected and, for personal data, why it was originally collected, data-preparation operations such as annotation, labelling, cleaning, updating, enrichment and aggregation, the assumptions made about what the data measures and represents, an assessment of whether the needed data sets are available, sufficient in quantity and suitable, examination for biases likely to affect health and safety, harm fundamental rights or lead to prohibited discrimination, especially where one operation's outputs become a later operation's inputs, measures to detect, prevent and mitigate any bias found, and identification of data gaps or shortcomings that would prevent compliance, with how they will be addressed.

The data sets must be relevant, sufficiently representative, as free of errors and as complete as possible for the intended purpose, with statistical properties appropriate to the persons or groups the system is intended to be used on, and must take into account the specific geographic, contextual, behavioural or functional setting the system is intended to be used in, to the extent the intended purpose requires it; where the system does not use training techniques, these criteria apply only to its testing data set.

The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) deleted Article 10(5), which had let a provider exceptionally process special categories of personal data to detect and correct bias. That same permission now sits in a new Article 4a, which also reaches a deployer of a high-risk AI system and a provider or deployer of any other AI system or model.

Article 10 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI Act, Article 14 (human oversight)

Regulation (EU) 2024/1689, Article 14official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of a high-risk AI system must design and develop it, including its human-machine interface, so that a natural person can effectively oversee it while it is in use. Human oversight must aim to prevent or minimise the risks to health, safety or fundamental rights that may emerge when the system is used as intended or under reasonably foreseeable misuse, in particular where those risks persist despite the other Section 2 requirements.

The oversight measures must be commensurate with the system's risks, level of autonomy and context of use, built into the system before it is placed on the market or put into service, identified for the deployer to implement, or both, and the system must be provided to the deployer so that the assigned overseers can understand its capacities and limitations, monitor its operation, remain aware of the tendency to over-rely on its output, correctly interpret that output, decide not to use it or to disregard, override or reverse it, and intervene in or halt its operation through a stop mechanism.

For a remote biometric identification system under Annex III point 1(a), the oversight measures must ensure that no action or decision is taken on the identification result unless it has been separately verified and confirmed by at least two natural persons with the necessary competence, training and authority, except where the system serves law enforcement, migration, border control or asylum and Union or national law treats the two-person requirement as disproportionate.

A deployer of a high-risk AI system must separately assign that human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.

Article 14 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI Act, Article 15 (accuracy, robustness and cybersecurity)

Regulation (EU) 2024/1689, Article 15official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of a high-risk AI system must design and develop it to achieve an appropriate level of accuracy, robustness and cybersecurity, performing consistently in those respects throughout its lifecycle. The system's accuracy levels and metrics must be declared in its accompanying instructions of use.

The system must be as resilient as possible to errors, faults or inconsistencies, including those arising from its interaction with people or other systems, through technical and organisational measures, and a system that continues to learn after deployment must be developed to eliminate or reduce as far as possible the risk of biased outputs feeding back into future operations, with mitigation measures for any feedback loop that remains.

The system must be resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting vulnerabilities, with technical solutions appropriate to the circumstances and the risk, including, where appropriate, measures against data poisoning, model poisoning, adversarial examples or model evasion, and confidentiality attacks.

A high-risk AI system that meets the essential cybersecurity requirements of the Cyber Resilience Act (Regulation (EU) 2024/2847) and whose declaration of conformity under that Regulation demonstrates the level of cybersecurity Article 15 requires is deemed to comply with Article 15's cybersecurity requirement, though no such presumption covers accuracy or robustness.

Article 15 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI Act, Article 73 (reporting of serious incidents)

Regulation (EU) 2024/1689, Article 73official consolidated Official Journal text, EUR-Lex

In force 52 days, effective 2 August 2026. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of high-risk AI systems placed on the EU market must report a serious incident to the market surveillance authority of the Member State where it occurred. The report is due immediately after the provider establishes a causal link between the AI system and the incident, or the reasonable likelihood of one, and in any event not later than 15 days after becoming aware of it.

For a widespread infringement or a serious incident causing a serious and irreversible disruption to critical infrastructure, the report is due immediately and not later than 2 days after becoming aware of it. Where the incident caused a person's death, the report is due immediately after the provider or deployer establishes, or suspects, a causal relationship, but not later than 10 days after becoming aware of it.

Where necessary for timely reporting, the provider, or deployer where applicable, may file an initial report that is incomplete, followed by a complete report. A deployer who identifies a serious incident must immediately inform the provider first, then the importer or distributor and the market surveillance authority, and reports directly under the same rules if the provider cannot be reached.

After reporting, the provider must without delay carry out the necessary investigations, including a risk assessment of the incident and corrective action, must cooperate with the competent authorities, and must not run any investigation that alters the AI system in a way that could affect a later evaluation of the causes before telling those authorities.

Where the provider of an Annex III high-risk system is already subject to Union instruments laying down equivalent reporting obligations, notification is limited to incidents that infringe obligations under Union law intended to protect fundamental rights.

Where the high-risk AI system is, or is a safety component of, a device covered by Regulation (EU) 2017/745 or (EU) 2017/746, notification is limited to that same class of incident and goes to the national competent authority the Member State where the incident occurred chose for that purpose, rather than to its market surveillance authority.

The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) inserted a new Article 75(1a) requiring a narrow set of providers under the AI Office's own exclusive supervisory competence, meaning a general-purpose AI model integrated into the provider's own system or a system built into a Commission-designated very large online platform or search engine, to report a serious incident to the AI Office instead, with Article 73(2) to (9) applying in the same way.

The Digital Omnibus deferred a separate block, the obligations in Sections 1, 2 and 3 of Chapter III, to 2 December 2027 and 2 August 2028, which does not include Article 73's own Chapter IX reporting duty.

What it requires

AI Act, Article 9 (risk management system)

Regulation (EU) 2024/1689, Article 9official consolidated Official Journal text, EUR-Lex

In force in 435 days, effective 2 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of a high-risk AI system must establish, implement, document and maintain a risk management system for it, run as a continuous process across the system's whole lifecycle with regular review and updating, covering the identification and analysis of known and reasonably foreseeable risks to health, safety or fundamental rights, the estimation and evaluation of risks under intended use and reasonably foreseeable misuse, the evaluation of other risks surfaced by post-market monitoring, and the adoption of targeted risk management measures for the risks identified.

Those measures must bring residual risk, per hazard and overall, to an acceptable level, first by eliminating or reducing risk through design and development where technically feasible, then by mitigating what cannot be eliminated, then by providing required information and, where appropriate, deployer training, taking the deployer's likely expertise and context of use into account.

The system must be tested throughout development and, in any event, before it is placed on the market or put into service, against pre-defined metrics and probabilistic thresholds, to confirm the measures work and the system performs consistently for its intended purpose, and testing may draw on real-world testing under Article 60.

A provider must also consider whether the system is likely to adversely affect persons under 18 or other vulnerable groups when implementing this process, and a provider already bound by an internal risk-management regime under other Union law, for example as a manufacturer of a device under Annex I harmonisation legislation, may combine this risk management system with the existing one rather than running two.

Article 9 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

What it requires

AI training data

AI Act, Article 53 (obligations for providers of general-purpose AI models)

Regulation (EU) 2024/1689, Article 53official consolidated Official Journal text, EUR-Lex

In force since 2 August 2025. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of general-purpose AI models must draw up and keep up to date the model's technical documentation for the AI Office and national competent authorities, make information and documentation available to providers who intend to integrate the model into their own AI systems, put in place a policy to comply with Union copyright law and in particular to identify and comply with a reservation of rights expressed under Article 4(3) of Directive (EU) 2019/790, and draw up and make publicly available a sufficiently detailed summary of the content used for training, following a template provided by the AI Office.

Paragraph 2 exempts models released under a free and open-source licence from the first two duties only, and not at all where the model carries systemic risk, so the copyright policy and the training-content summary bind every provider of a general-purpose model. Article 113(b) applies Chapter V, which contains this Article, from 2 August 2025, a year ahead of the Regulation's general application date.

What it requires

AI transparency

AI Act, Article 50 (transparency obligations for AI systems and synthetic content)

Regulation (EU) 2024/1689, Article 50official consolidated Official Journal text, EUR-Lex

In force 52 days, effective 2 August 2026. Binds public and private bodies.

EEA incorporation pending.

What this law does

Providers of AI systems that interact directly with people must ensure users are informed they are dealing with an AI system unless obvious from context, and providers of generative AI must mark synthetic audio, image, video, or text output in a machine-readable, detectable format.

Deployers of emotion-recognition or biometric-categorization systems must inform exposed individuals, and deployers of deepfakes or AI-generated public-interest text must disclose the artificial origin unless the content underwent human review with editorial responsibility. The Article reaches providers and deployers outside the EU whose system's output is used in the EU.

A four-month transition, to 2 December 2026, applies only to the machine-readable marking sub-duty for generative systems already on the market before 2 August 2026, added by the Digital Omnibus on AI.

What it requires

Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking)

Regulation (EU) 2022/2065, Article 35(1)(k)official consolidated regulation text, EUR-Lex

In force since 25 August 2023. Binds private bodies.

EEA incorporation pending.

What this law does

As one of the listed, non-exhaustive systemic-risk mitigation measures a designated very large online platform or search engine may adopt, the provider should ensure that generated or manipulated content resembling real persons, objects, places, or events, and that would falsely appear authentic, is distinguishable through prominent markings when presented on the platform, alongside an easy-to-use flagging function.

This is materially narrower than AI Act Article 50: it binds only Commission-designated very large online platforms (VLOPs) and very large online search engines (VLOSEs) as a risk-mitigation option, not every provider or publisher as a freestanding labeling mandate.

Article 92 provides that this Regulation applies to a provider of a very large online platform or search engine designated under Article 33(4) from four months after the Commission's notification of that designation, where the notification date is earlier than 17 February 2024, the Regulation's general application date.

The Commission's first designation decisions under Article 33(4) took effect on 25 April 2023 for platforms including Facebook, Instagram, TikTok, and X, so this Article's obligations began applying to that cohort from 25 August 2023, four months later.

What it requires

Privacy law7 instruments, 6 in force, 1 proposed

Research summary (175 words)

The European Union's privacy posture is a single comprehensive regime, the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679, applicable since 25 May 2018), which binds both private and public controllers and processors on lawful basis, purpose limitation, data subject rights, cross border transfer, breach notification and supervisory enforcement.

Biometric data, including voiceprints and faceprints derived through technical processing for unique identification, is a special category under Article 9 carrying a default prohibition, and no dedicated biometric statute exists alongside it.

The regime does not carve out publicly available personal data in general: the sole public availability exception in Article 9 requires the data subject themselves to have made the data public, so an identifier a controller derives from a public photo or recording stays fully covered, as confirmed by 2024 and 2025 enforcement against Clearview AI in four Member States.

A European Commission proposal to amend the GDPR, the Digital Omnibus (COM(2025) 837, published 19 November 2025), remains under negotiation between the European Parliament and the Council as of the date shown and had not passed either chamber.

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

Applies in the EEA since 2018.

What this law does

Article 33(1) requires the controller to notify the competent supervisory authority without undue delay, and where feasible within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to risk individuals' rights and freedoms, and a processor must notify its controller without undue delay.

Article 34 requires notice to affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless the exposed data was rendered unintelligible, for example by strong encryption, or the controller has since eliminated the high risk.

What it requires

Comprehensive regime

Digital Omnibus Regulation Proposal, GDPR and ePrivacy Reform

COM(2025) 837 finalEuropean Commission legislative proposal text, EUR-Lex

Proposed: draft of 19 November 2025. In committee, dated 27 July 2026, as of 12 September 2026. Binds public and private bodies.

A proposal, not yet EU law, so there is nothing yet for the EEA Joint Committee to incorporate.

What this law does

This proposal has not been enacted and does not currently bind. Published by the European Commission on 19 November 2025, it would amend the General Data Protection Regulation (GDPR) alongside the ePrivacy Directive, NIS2 and other digital legislation to fold cookie consent into the GDPR, raise and simplify the breach notification threshold, ease processing record and impact assessment duties, and adjust the Article 22 automated decision safeguards.

It remains in the ordinary legislative procedure as of the date shown, with the Council still circulating compromise texts and several of the Commission's central proposals under active negotiation; most observers do not expect adoption before late 2026 at the earliest.

What it requires

General Data Protection Regulation (GDPR), Comprehensive Regime

Regulation (EU) 2016/679Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

Applies in the EEA since 2018.

What this law does

Establishes the lawful basis, purpose limitation, and controller and processor accountability framework for processing personal data of people in the EU. Article 6(1) requires one of six lawful bases for any processing, Articles 24-28 allocate duties between controllers, joint controllers and processors, and the Regulation applies extraterritorially to any controller or processor offering goods or services to, or monitoring, people in the EU (Article 3).

It binds public authorities as well as private sector controllers, though Article 83(7) lets Member States decide whether administrative fines apply to their own public bodies.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-50Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

Applies in the EEA since 2018.

What this law does

Chapter V bars any transfer of personal data outside the EEA unless the European Commission has issued an adequacy decision (Article 45), the transfer is covered by an appropriate safeguard such as Standard Contractual Clauses or Binding Corporate Rules together with a transfer impact assessment under the Court of Justice's Schrems II judgment (Case C-311/18, 16 July 2020), or a narrow Article 49 derogation applies.

Most transfers to the United States currently rely on the EU-US Data Privacy Framework, found adequate by Commission Implementing Decision (EU) 2023/1795. The General Court upheld that adequacy decision at first instance in Latombe v Commission (Case T-553/23, 3 September 2025). An appeal against that judgment is pending before the Court of Justice as Case C-703/25 P, with no hearing date set as of the date shown.

What it requires

Data subject rights

GDPR Articles 12-22, Data Subject Rights

Regulation (EU) 2016/679, Arts. 12-22Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

Applies in the EEA since 2018.

What this law does

Articles 12-22 give a data subject access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection (Article 21) rights against the controller, ordinarily to be honored within one month, and a right under Article 22 not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, absent a qualifying exception and safeguards including meaningful human review.

The Court of Justice held in SCHUFA (Case C-634/21, 7 December 2023) that an automated credit score a third party relies on to make its own decision falls within Article 22 even though the scoring entity is not the final decision maker.

What it requires

Enforcement supervision

GDPR Articles 51-59, 68-76 and 77-84, Supervisory Authorities, Penalties and Remedies

Regulation (EU) 2016/679, Arts. 51-59, 68-76, 77-84Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

Applies in the EEA since 2018.

What this law does

Each Member State designates an independent supervisory authority (Article 51) with investigative and corrective powers, including orders and bans on processing (Article 58); cross border cases route through a lead authority under the one stop shop mechanism (Articles 56, 60-63), coordinated by the European Data Protection Board (Articles 68-76).

Article 83 sets administrative fines up to the higher of EUR 20,000,000 or 4 percent of global annual turnover for infringements of the core provisions, and up to the higher of EUR 10,000,000 or 2 percent for other provisions.

Article 82(1) arms a direct private right of action, letting any person who suffered material or non-material damage claim compensation from the controller or processor, though the Court of Justice held actual, if not necessarily serious, damage must be shown rather than the mere fact of infringement (UI v Österreichische Post, Case C-300/21, 4 May 2023). Article 80 lets a not for profit body pursue a complaint or judicial remedy on a data subject's behalf.

The Representative Actions Directive (EU) 2020/1828 separately lists Regulation (EU) 2016/679 in its Annex I, letting a qualified entity bring a representative action for collective consumer redress over a General Data Protection Regulation (GDPR) infringement. The Dutch, Italian and French data protection authorities each took enforcement action against Clearview AI over the same underlying conduct, the Netherlands imposing EUR 30.5 million in a decision dated 16 May 2024.

The Hellenic Data Protection Authority separately fined Clearview EUR 20,000,000 for the same conduct, illustrating Article 83 penalties applied to biometric data drawn from public sources.

What it requires

Sensitive categories

GDPR Article 9, Special Categories of Personal Data Including Biometric Data

Regulation (EU) 2016/679, Art. 9Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

Applies in the EEA since 2018.

What this law does

Article 9(1) prohibits processing special categories of personal data, including biometric data processed for the purpose of uniquely identifying a person, unless a listed Article 9(2) exception applies, most commonly explicit consent.

Article 4(14) defines biometric data as data from specific technical processing of physical, physiological or behavioural characteristics, with the statute's own examples (facial images, fingerprint data) stated as non-exhaustive, so the same definition reaches a voiceprint once a system derives an identification capable template from audio, even though the text never uses the word voice.

Recital 51 confirms an ordinary photograph is not itself biometric data and only becomes covered when processed through a specific technical means allowing unique identification, so a faceprint a controller derives from one, even from a publicly available photograph, is newly covered special category data; the General Data Protection Regulation (GDPR) text does not separately discuss audio recordings.

The Dutch data protection authority fined Clearview AI EUR 30.5 million (decision dated 16 May 2024, publicly announced 3 September 2024) for building a facial recognition database from photographs scraped off the public internet without an Article 9 basis.

The Dutch decision itself catalogs parallel GDPR enforcement against Clearview by other Member State authorities on the same underlying conduct, including the Italian Garante (decision dated 10 February 2022) and the French CNIL (decision dated 17 October 2022). The Hellenic Data Protection Authority separately fined Clearview EUR 20,000,000 for the same conduct on 13 July 2022.

What it requires

Scraping law1 instrument, 1 in force

Research summary (128 words)

Coverage here is limited to one dimension of EU scraping law, the text-and-data-mining exceptions in the Copyright in the Digital Single Market Directive; the rest is not yet characterised. Article 3 gives research organisations and cultural heritage institutions an exception for mining works they lawfully access for scientific research, and Article 7(1) makes any contrary contractual provision unenforceable.

Article 4 gives everyone else the same permission for lawfully accessible works, but only where the rightholder has not expressly reserved the use, and it is absent from the Article 7(1) list, so a contract can displace it. The database sui generis right in Directive 96/9/EC, the computer-misuse rules in Directive 2013/40/EU, and personal data under Regulation (EU) 2016/679 all bear on scraping in the EU and are unresearched here.

Copyright and text and data mining (TDM)

DSM Directive, Article 4 (text-and-data-mining exception and rights reservation)

Directive (EU) 2019/790, Article 4official consolidated Official Journal text, EUR-Lex

In force since 7 June 2021. Binds public and private bodies.

EEA incorporation pending.

What this law does

Article 4 requires Member States to provide an exception or limitation for reproductions and extractions of lawfully accessible works for the purposes of text and data mining, and paragraph 2 permits retaining those copies for as long as the mining requires.

Unlike the Article 3 exception, which is confined to research organisations and cultural heritage institutions acting for scientific research, Article 4 is limited by neither purpose nor actor, and recital 18 records that mining techniques are widely used by private and public entities alike, including for the development of new applications and technologies.

Paragraph 3 makes the exception conditional on the rightholder not having expressly reserved the use in an appropriate manner, which the Article illustrates as machine-readable means for content made publicly available online, so a reservation removes the exception rather than merely signalling a preference. Article 7(1) renders contractual override unenforceable for Articles 3, 5 and 6 but does not list Article 4.

What it requires

Cybersecurity law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (321 words)

The European Union's product-security and cyber-resilience posture rests on two instruments with different duty-bearers. The Cyber Resilience Act (Regulation (EU) 2024/2847) sets essential cybersecurity requirements and vulnerability-handling duties for a manufacturer placing a product with digital elements on the EU market, with its main obligations applying from 11 December 2027 and its vulnerability and incident reporting duties applying earlier, from 11 September 2026.

The NIS2 Directive (Directive (EU) 2022/2555) sets cybersecurity risk-management and incident-reporting duties for essential and important entities, including public administration bodies and the digital providers named in its Annex II, and has applied since 18 October 2024.

Personal-data breach notification to a supervisory authority and to the affected person is separate law, General Data Protection Regulation (GDPR) Articles 33 and 34, which sits in the privacy topic rather than here even where one incident triggers both regimes. Because NIS2 is a directive rather than a directly applicable regulation, its duties reach a covered entity only through the transposing law of the Member State where that entity is established, and the depth and penalty tiers of that transposition vary by Member State.

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) carries the financial sector's own incident clock, recorded below.

Article 19 requires a financial entity to report a major ICT-related incident to its designated competent authority, and Commission Delegated Regulation (EU) 2025/301 supplies the periods the Article itself does not state: an initial notification within four hours of classifying the incident as major and no later than 24 hours from becoming aware of it, an intermediate report within 72 hours of that notification, and a final report within one month of the intermediate report.

An ICT third-party service provider is not a financial entity under Article 2(2) and carries no Article 19 duty of its own, only a contractual duty to assist the financial entity it serves, or a delegated one where that entity outsources the reporting task and stays responsible for it.

Product security requirements

Cyber Resilience Act, Essential Requirements and Manufacturer Obligations

Regulation (EU) 2024/2847, Art. 13 and Annex IOfficial Journal text, EUR-Lex, Regulation (EU) 2024/2847

In force in 444 days, effective 11 December 2027. Binds public and private bodies.

EEA incorporation pending.

What this law does

Article 13 requires a manufacturer placing a product with digital elements on the EU market to design, develop and produce it in accordance with the essential cybersecurity requirements of Annex I, Part I, which include shipping without known exploitable vulnerabilities, a secure default configuration, protection against unauthorised access, encryption of data at rest and in transit, data minimisation, and resilience against denial-of-service and other attacks.

Annex I, Part II requires the manufacturer to identify and document vulnerabilities, including through a software bill of materials, remediate them without delay, operate a coordinated vulnerability disclosure policy, and provide security updates free of charge for a support period the manufacturer must set at not less than five years, or the product's expected use time if shorter, keeping each update available for ten years after release or for the remainder of the support period, whichever is longer.

The Regulation does not reach free and open source software that its manufacturer does not monetise, and its remote data processing requirements reach only a processing solution the manufacturer designed the product to need in order to perform one of its own functions, not a service the product could operate without.

Article 65 makes Directive (EU) 2020/1828 on representative actions apply to an infringement of this Regulation that harms, or may harm, the collective interests of consumers, letting a qualified consumer-protection entity, not an individual consumer, bring that action.

What it requires

Sector security regimes

NIS2 Directive, Cybersecurity Risk-Management Measures

Directive (EU) 2022/2555, Art. 21Official Journal text, EUR-Lex, Directive (EU) 2022/2555

In force since 18 October 2024. Binds public and private bodies.

EEA incorporation pending.

What this law does

Article 21 requires each Member State to ensure that essential and important entities, defined by the Annex I and Annex II sector lists together with a medium-enterprise size threshold set under Article 2, take appropriate and proportionate technical, operational and organisational measures to manage the cybersecurity risks to the network and information systems they use, based on an all-hazards approach covering at least risk analysis and information system security, incident handling, business continuity, supply chain security, security in system acquisition and maintenance, the effectiveness of the measures, basic cyber hygiene and training, cryptography, human resources security and access control, and multi-factor or continuous authentication.

Annex II names online marketplaces, online search engines and social networking services platforms among the digital providers this duty reaches once they cross the medium-enterprise size threshold, and Annex I separately reaches public administration entities of central and regional government.

An entity not established in the Union that offers such a service within it must designate a representative in a Member State where it offers the service, and falls under that Member State's jurisdiction for this duty.

What it requires

Vulnerability and incident reporting

Cyber Resilience Act, Manufacturer Reporting Obligations

Regulation (EU) 2024/2847, Art. 14Official Journal text, EUR-Lex, Regulation (EU) 2024/2847

In force 12 days, effective 11 September 2026. Binds public and private bodies.

EEA incorporation pending.

What this law does

Article 14 requires a manufacturer to notify any actively exploited vulnerability or severe incident affecting a product with digital elements to the CSIRT designated as coordinator for its main establishment and simultaneously to ENISA, through the single reporting platform established under Article 16.

For a vulnerability, the manufacturer submits an early warning within 24 hours of becoming aware, a fuller vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the same 24-hour early warning and 72-hour incident notification apply, followed by a final report within one month of the incident notification.

After becoming aware of either, the manufacturer must inform the affected users of the product, and where appropriate all users, of the vulnerability or incident and of any risk mitigation or corrective measures they can take. Article 65 makes Directive (EU) 2020/1828 on representative actions apply to an infringement of this Regulation that harms, or may harm, the collective interests of consumers, letting a qualified consumer-protection entity, not an individual consumer, bring that action.

What it requires

DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301

Regulation (EU) 2022/2554, Article 19Official Journal text, EUR-Lex, Regulation (EU) 2022/2554, supplemented by Commission Delegated Regulation (EU) 2025/301

In force since 17 January 2025. Binds private bodies.

What this law does

Regulation (EU) 2022/2554 (DORA) is the financial sector's own digital operational resilience regime, and Article 19 sets its major ICT-related incident reporting duty, read here together with Commission Delegated Regulation (EU) 2025/301, which Article 20 required to specify the report content and time limits Article 19 itself leaves open.

Article 19 requires a financial entity listed in Article 2(1), points (a) to (t), such as a credit institution, payment institution, investment firm, insurance or reinsurance undertaking, or crypto-asset service provider, to report a major ICT-related incident to the competent authority designated for it under Article 46.

Article 2(1) also names ICT third-party service providers as point (u), but Article 2(2) confines the defined term financial entities to points (a) to (t), so Article 19's own reporting duty does not bind an ICT third-party service provider directly. A financial entity may instead outsource the Article 19 reporting task to a third-party service provider while remaining fully responsible for fulfilling it.

Separately, every contract for the use of ICT services must oblige the provider to assist the financial entity, at no additional cost or at a pre-agreed cost, when an ICT incident related to that service occurs, and a contract covering a critical or important function carries further terms on top of that baseline.

The duty runs through three stages under Article 19(4): an initial notification, an intermediate report once the incident's status or handling changes significantly or new information becomes available, and a final report once the root cause analysis is complete and the actual impact figures are known.

Commission Delegated Regulation (EU) 2025/301 supplies the clock Article 20 left to be specified: the initial notification is due as early as possible and in any case within four hours of classifying the incident as major, and no later than 24 hours from becoming aware of it. Where classification of an incident as major happens more than 24 hours after the financial entity became aware of it, the initial notification is instead due within four hours of that later classification.

The intermediate report is due at the latest within 72 hours of the initial notification, updated without undue delay whenever the incident's status changes or normal activity is recovered. The final report is due no later than one month after the intermediate report, or, where the entity filed an updated one, after the latest updated intermediate report.

A financial entity unable to meet one of these deadlines must tell the competent authority without undue delay and before the deadline itself lapses, explaining the reason for the delay. A deadline that falls on a weekend or a bank holiday moves to noon of the next working day.

That extension does not apply to an initial notification or an intermediate report from a credit institution, a central counterparty, a trading venue operator, or an entity identified as essential or important under the NIS2 Directive. Notifying a significant cyber threat under Article 19(2) is voluntary, made only where the financial entity itself judges the threat relevant to the financial system, service users, or clients.

Where a major ICT-related incident has an impact on the financial interests of clients, Article 19(3) requires the financial entity to inform those clients without undue delay as soon as it becomes aware of the incident, describing the incident and the mitigation measures taken. For a significant cyber threat, Article 19(3) requires the financial entity to inform a potentially affected client of protection measures it could take, where applicable.

Unlike the Cyber Resilience Act's and the NIS2 Directive's own fine tiers, DORA leaves the amount of an administrative penalty for a breach of Article 19 to each Member State's own law, requiring only that the penalty be effective, proportionate, and dissuasive. DORA applies from 17 January 2025.

Commission Delegated Regulation (EU) 2025/301, which supplies the four-hour, 24-hour, 72-hour, and one-month figures above, entered into force on 12 March 2025, 54 days after DORA's own application date, closing the gap during which Article 19's reporting duty applied without a specified clock.

What it requires

NIS2 Directive, Reporting Obligations

Directive (EU) 2022/2555, Art. 23Official Journal text, EUR-Lex, Directive (EU) 2022/2555

In force since 18 October 2024. Binds public and private bodies.

EEA incorporation pending.

What this law does

Article 23 requires each Member State to ensure that an essential or important entity notifies its CSIRT, or the competent authority where applicable, of any incident that has a significant impact on the provision of its services, on a three-stage clock: an early warning within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours, and, unless already provided, a final report no later than one month after the incident notification.

Where appropriate, the entity must also notify, without undue delay, the recipients of its services that a significant incident is likely to adversely affect, and must communicate to service recipients potentially affected by a significant cyber threat any measures or remedies they can take. An incident is significant where it has caused or is capable of causing severe operational disruption or financial loss to the entity, or considerable material or non-material damage to another person.

What it requires

Age gating law5 instruments, 5 in force

Research summary (208 words)

The European Union addresses age gating for minors mainly through Article 28 of the Digital Services Act (Digital Services Act (DSA)), which requires online platforms accessible to minors to put in place appropriate and proportionate protection measures and bans targeted advertising based on profiling of minors, applicable since 17 February 2024 (and from 25 August 2023 for designated very large platforms and search engines).

The European Commission's July 2025 guidelines under Article 28(4) DSA set non-binding but Commission enforced benchmarks, recommending age verification or estimation for high risk services such as pornography and gambling and requiring default private settings for minors' accounts.

The Audiovisual Media Services Directive requires video sharing platforms and audiovisual media providers to take appropriate measures, including age verification tools, to protect minors from harmful content, and is the legal basis several national regulators, including France's Arcom, rely on to require pornography age checks; member states had to transpose these provisions by 19 September 2020 and specific enforcement actions live in national jurisdiction files, not here.

Looking ahead, the Commission's April 2026 recommendation on a common EU age verification framework, building on the European Digital Identity Wallet regulation, asks member states to deploy the EU age verification solution, standalone or integrated into national wallets, by 31 December 2026.

Adult content age verification (AV)

Audiovisual Media Services Directive (AVMSD), Articles 6a and 28b

Directive 2010/13/EU, as amended by Directive (EU) 2018/1808, Articles 6a and 28bofficial directive text, EUR-Lex

In force since 19 September 2020. Binds private bodies.

Applies in the EEA since 2025.

What this law does

Requires member states to ensure audiovisual media services and video sharing platforms take appropriate measures, such as age verification tools, parental controls, and restricted broadcast times, so that content that may impair minors' physical, mental, or moral development is not normally seen or heard by them, with the strictest measures required for the most harmful content such as gratuitous violence and pornography.

Also bars processing minors' personal data for profiling or behaviourally targeted advertising. Member states had to transpose the 2018 amendments by 19 September 2020; national regulators, including France's Arcom, cite this directive as the legal basis for requiring pornography age verification, with specific national enforcement actions recorded in each jurisdiction's own file rather than here.

Note and primary source

Commission Recommendation (EU) 2026/1035 on a common framework for EU wide age verification technologies

Commission Recommendation (EU) 2026/1035 of 29 April 2026, OJ L, 2026/1035, 8.5.2026official Commission Recommendation, published in the Official Journal, EUR-Lex

In force 5 months, effective 29 April 2026. Binds government bodies.

Non-binding Commission guidance, which the EEA Joint Committee has not taken up.

What this law does

Non-binding recommendation asking member states to submit an implementation plan by 30 June 2026 and to make available, by 31 December 2026, a privacy preserving EU age verification solution built on the Commission's open source age verification blueprint, either as a standalone app or integrated into a national European Digital Identity Wallet, letting a user prove they exceed an age threshold such as 18 without revealing other personal data.

Encourages member states to cooperate through the European Board for Digital Services and with data protection authorities to define a forthcoming EU Age Verification Scheme with lists of trusted proof of age providers, and to engage with the Commission before enacting national age verification laws so the internal market does not fragment.

Note and primary source

Age-appropriate design code

Commission Guidelines on the protection of minors under Article 28(4) DSA

Commission Guidelines pursuant to Article 28(4) of Regulation (EU) 2022/2065, C(2025) 6826, OJ C, C/2025/5519, 10.10.2025official Commission guidelines, published in the Official Journal, EUR-Lex

In force since 14 July 2025. Binds private bodies.

Non-binding Commission guidance, which the EEA Joint Committee has not taken up.

What this law does

Non-binding guidelines the European Commission adopted and published on 14 July 2025, later carried in the Official Journal, setting benchmark measures for compliance with Article 28(1) Digital Services Act (DSA): recommending age verification for high risk services such as pornography and gambling, age estimation by independently audited third parties for medium risk services, and rejecting self declaration as insufficient.

The guidelines also call for minors' accounts to default to private settings, with geolocation, autoplay, and push notifications disabled and recommender systems adjusted to limit exposure to harmful content. The Commission uses the guidelines, which apply to platforms accessible to minors other than micro and small enterprises, to assess Article 28 compliance and inform enforcement, though following them does not itself guarantee compliance.

Note and primary source

App store age verification (AV)

European Digital Identity Regulation (eIDAS2)

Regulation (EU) 2024/1183, amending Regulation (EU) No 910/2014 (eIDAS)official regulation text, EUR-Lex

In force since 20 May 2024. Binds public and private bodies.

EEA incorporation pending.

What this law does

Establishes the legal framework for European Digital Identity Wallets, requiring each member state to provide at least one wallet to its citizens, residents, and businesses, and creating qualified and non qualified electronic attestations of attributes that can include a person's age, so a user can prove they exceed an age threshold without revealing their date of birth or full identity.

Adopted 11 April 2024, published in the Official Journal 30 April 2024, and entered into force 20 May 2024; member states must make a wallet available by 6 December 2026. This device level wallet credential is the framework the Commission's age verification solution is designed to integrate with.

Note and primary source

Social media and minors

Digital Services Act (DSA), Article 28 (Online protection of minors)

Regulation (EU) 2022/2065, Article 28official regulation text, EUR-Lex

In force since 17 February 2024. Binds private bodies.

EEA incorporation pending.

What this law does

Requires providers of online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security for minors on their service, and bans presenting advertisements based on profiling using a minor's personal data when the provider is aware with reasonable certainty the recipient is a minor. Providers are not required to process additional personal data solely to determine a user's age.

The Digital Services Act (DSA) applied to designated very large online platforms and search engines from 25 August 2023, and to all other in scope providers from 17 February 2024.

Note and primary source

News aggregation law5 instruments, 5 in force

Research summary (218 words)

EU news-aggregation law is anchored by two copyright directives and a growing body of CJEU case law. The InfoSoc Directive (2001/29/EC) established the EU-wide reproduction right that governs snippet copyright; the Infopaq judgment (C-5/08, 2009) confirmed that even an 11-word extract can be protected if it reflects the author's own intellectual creation.

Directive (EU) 2019/790 (Digital Single Market (DSM) Directive) is the dominant instrument: Article 15 grants press publishers a new neighbouring right against online platforms, with explicit carve-outs for bare hyperlinking and 'very short extracts,' while Article 4 creates a general text-and-data-mining exception that rightholders may block by a machine-readable reservation.

Two member-state predecessors to Article 15 (Germany's 2013 Leistungsschutzrecht and Spain's 2014 AEDE levy) both failed: the German law was declared inapplicable by the CJEU in C-299/17 (2019) for failure to notify under Directive 98/34/EC, while Spain's mandatory non-waivable levy prompted Google to shutter Google News in Spain until DSM transposition in 2021.

On inline framing, the CJEU ruled in VG Bild-Kunst (C-392/19, 2021) that embedding constitutes communication to the public where the rightsholder has adopted technical measures against framing. The EU has no 'hot news' misappropriation doctrine or statutory bargaining code analogous to Australia's News Media Bargaining Code; Article 15 DSM is the closest functional equivalent, requiring licensing negotiations between platforms and publisher collectives in each member state.

Linking and framing

VG Bild-Kunst v Stiftung Preussischer Kulturbesitz

Case C-392/19, judgment of 9 March 2021EUR-Lex / CURIA

Decided 9 March 2021 by the Court of Justice of the European Union. Binds public and private bodies.

A Court of Justice judgment, which the EEA Agreement does not incorporate, though the EFTA Court follows it for acts the Agreement does.

What this court held

The CJEU (Grand Chamber) held that embedding a third-party copyright-protected work via inline framing constitutes a 'communication to the public' under Art. 3(1) of the InfoSoc Directive (and therefore requires authorisation) where the rightsholder has adopted or required technical measures restricting framing.

Although the case concerned thumbnail images rather than news text, it directly constrains news aggregators that display publisher content through iframes or embedded widgets: a rightsholder's machine-readable anti-framing signal (e.g. X-Frame-Options header or technical restriction in licence conditions) must be respected, or the embedding constitutes infringement.

Note and primary source

Press publishers' right

Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market (DSM Directive), Articles 15 and 4

Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019, OJ L 130, 17.5.2019, pp. 92-119EUR-Lex

In force since 7 June 2019. Binds public and private bodies.

EEA incorporation pending.

What this law does

Article 15 creates an EU-wide neighbouring right for press publishers against online information-society service providers, enabling them to demand remuneration for the online use of press publications; the right explicitly excludes bare hyperlinking and 'very short extracts', leaving the precise scope of the snippet carve-out to member-state implementation and future litigation, and does not apply to private or non-commercial use.

Article 4 establishes a general exception for text and data mining for purposes beyond scientific research (Art. 3), which any rightsholder may override by a machine-readable reservation of rights, making it the primary EU opt-out mechanism for AI training and news-crawler scraping. The Directive entered into force 7 June 2019 with a transposition deadline of 7 June 2021; all EU member states have now transposed it, replacing earlier failed ancillary-copyright experiments in Germany and Spain.

Note and primary source

VG Media Gesellschaft zur Verwertung der Urheber- und Leistungsschutzrechte von Medienunternehmen mbH v Google LLC

Case C-299/17, judgment of 12 September 2019EUR-Lex / CURIA

Decided 12 September 2019 by the Court of Justice of the European Union. Binds public and private bodies.

A Court of Justice judgment, which the EEA Agreement does not incorporate, though the EFTA Court follows it for acts the Agreement does.

What this court held

The CJEU (Fourth Chamber) ruled that Germany's Leistungsschutzrecht (sections 87f-87h UrhG) constituted a 'technical regulation' within the meaning of Directive 98/34/EC requiring prior notification to the European Commission; because Germany had not notified the draft law, the provision was inapplicable and unenforceable against individuals with retroactive effect.

The ruling nullified the German ancillary copyright for press publishers from its 2013 entry into force and reinforced momentum for the harmonised EU-level approach that became Digital Single Market (DSM) Art. 15.

Note and primary source

Snippet reproduction

Directive 2001/29/EC on the harmonisation of certain aspects of copyright and related rights in the information society (InfoSoc Directive)

Directive 2001/29/EC of the European Parliament and of the Council of 22 May 2001, OJ L 167, 22.6.2001, pp. 10-19EUR-Lex

In force since 22 June 2001. Binds public and private bodies.

Applies in the EEA since 2005.

What this law does

Harmonises the reproduction right (Art. 2) and the right of communication to the public (Art. 3) across EU member states, establishing the copyright baseline under which news snippets and cached copies are assessed.

The mandatory temporary-copies safe harbour (Art. 5(1)) and the optional quotation exception (Art. 5(3)(d)) define the outer limits of lawful short-extract reproduction by news aggregators; member states must implement Art. 5 exceptions strictly and may not create additional exceptions beyond the exhaustive list.

Note and primary source

Infopaq International A/S v Danske Dagblades Forening

Case C-5/08, judgment of 16 July 2009EUR-Lex / CURIA

Decided 16 July 2009 by the Court of Justice of the European Union. Binds public and private bodies.

A Court of Justice judgment, which the EEA Agreement does not incorporate, though the EFTA Court follows it for acts the Agreement does.

What this court held

The CJEU (Fourth Chamber) held that an 11-word extract from a newspaper article can be protected by copyright under Art. 2 of the InfoSoc Directive if it reflects the author's own intellectual creation, the standard that now governs all snippet reproduction across EU member states. The Court also found that Infopaq's media-monitoring data-capture process did not qualify for the transient-copy exemption (Art. 5(1)) because the printing step was not transient. This ruling is the foundational EU authority on the copyright status of news snippets used by aggregators.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.