EU Digital and Data Legislation Tracker
Below you’ll find the overview of the most important EU laws that regulate the digital realm. Such as the AI Act, Cybersecurity Act and Data Act. A handy legislation tracker for each modern-day legal data & AI professional.
Powered by Digibeetle
The table below is a limited view of what Digibeetle offers. Don’t miss the opportunity to save time on research and supercharge your decision-making process with Digibeetle. Unlock the full potential of our intuitive search, referenced and curated documents.
EU Digital and Data Legislation Tracker (Updated)
Last update: 06 October 2026
Powered by
| Abbreviation | Title | Stage | Type | Object(s) | Addressees | Entry into force | Application/transposition |
|---|---|---|---|---|---|---|---|
| GreenData4All | GreenData4All Directive |
2 Council stage |
Data | Geospatial environmental data and access to environmental information | Public sector bodies holding environmental spatial data | 0Unknown | 0Unknown |
| EBW | European Business Wallet Regulation |
2 Council stage |
Data | Digital identity, secure data exchange, data protection | Businesses, public sector bodies | 0Unknown | 0Unknown |
| EU Space Act | EU Space Act |
2 Council stage |
Space technology | Rules for safe, resilient and sustainable space activities | Launch operators, spacecraft operators, space service providers | 0Unknown | 0Unknown |
| CSAM Interim Extension | Regulation extending the interim CSAM derogation (2021/1232) |
4 Trilogue / Negotiations |
Online services | Extension of the period of application of the interim derogation from the ePrivacy framework allowing providers to voluntarily detect, report and remove child sexual abuse material in online communications pending adoption of the permanent CSAM | Providers of interpersonal electronic communications services, online platforms | 0Unknown | 0Unknown |
| PSR | Payment Services Regulation |
3 EP stage |
Payments & e-money | Compliance and operations rules for payment and e-money services | Payment services, e-money services | 0Unknown | 0Unknown |
| PSD3 | Third Payment Services Directive |
3 EP stage |
Payments & e-money | authorisation, prudential oversight, and supervision of payment and e-money institutions | Payment services, e-money services | 0Unknown | 0Unknown |
| EBA | European Biotech Act |
3 EP stage |
Product | Health biotechnology | Providers of health biotechnology products and services | 0Unknown | 0Unknown |
| DNA | Digital Networks Act |
2 Council stage |
Electronic communications | Electronic communications networks and services | Providers of electronic communications networks and services | 0Unknown | 0Unknown |
| NIS2 simplification | NIS2 Simplification Directive |
2 Council stage |
Cybersecurity | Simplification of NIS2 and alignment with Cybersecurity Act 2 | NIS2 addressees, European Digital Identity Wallets, European Business Wallets, small mid-cap enterprises | 0Unknown | 0Unknown |
| CSA2 | Cybersecurity Act 2 |
2 Council stage |
Cybersecurity | ENISA, ICT products, ICT services, ICT processes, European cybersecurity certification schemes | ENISA, operators of essential services, digital service providers | 0Unknown | 0Unknown |
| MDR/IVDR reform | MDR/IVDR simplification Regulation |
3 EP stage |
Product | Medical devices, in vitro diagnostic devices, clinical/non-clinical data | Manufacturers | 0Unknown | 0Unknown |
| FiDA Regulation | Financial Data Access Regulation |
2 Council stage |
Data | Personal data, customer data | Financial institutions, financial information service providers | 0Unknown | 0Unknown |
| Omnibus IV | Small Mid-Caps Regulation (Omnibus IV) |
3 EP stage |
Data, anti-dumping, anti-subsidy, prospectus, batteries, f-gas | Extending regulatory simplification to SMCs | Small mid-cap enterprises (SMC) | 0Unknown | 0Unknown |
| Digital Omnibus on AI | Digital Omnibus on AI |
6 Published |
Product | AI systems | AI Act addressees, micro, small and medium-sized enterprises (SME), small mid-cap enterprises (SMC) | 2026-7-27 | 2026-7-27 |
| Digital Omnibus (data rules) | Digital Omnibus (Data rules) |
3 EP stage |
Data | Personal data, Data | Controllers, processors, data subjects | 0Unknown | 0Unknown |
| AI Act | Artificial Intelligence Act |
6 Published |
Product | AI systems, General-Purpose AI models, General-Purpose AI systems, | Providers, downstream providers, deployers, importers, distributors, affected persons | 2024-8-1 | 2024-8-2 |
| EHDSR | European Health Data Space Regulation |
6 Published |
Data | Personal data, data, health data | Patients, data holders | 2025-3-26 | 2027-3-26 |
| AILD | AI Liability Directive |
7 Withdrawn |
Product, liability | AI systems | Providers, users, claimants, defendants | 0Unknown | 0Unknown |
| PLD | Product Liability Directive 2024/2853 |
6 Published |
Product, liability | Products | Member States, manufacturer, importers, distributors, economic operators, online platforms | 2024-12-9 | 2026-12-9 |
| PWD | Platform Work Directive |
6 Published |
Data | Platform workers’ data | Platforms, platform workers | 2024-12-1 | 2026-12-2 |
| Combating Gender-Based Violence Directive | Directive on Combating Violence Against Women and Domestic Violence |
6 Published |
Anti-cyber violence | Online cybercrimes, cyber stalking, cyber harassment, deepfakes, non-consensual sharing of materials | Member States, victims | 2024-6-13 | 2027-6-14 |
| GDPREPR | GDPR Enforcement Procedural Rules Regulation |
6 Published |
Enforcement | GDPR enforcement | Supervisory authorities, EDPB | 0Unknown | 0Unknown |
| CRA | Cyber Resilience Act |
6 Published |
Cybersecurity | Products with digital elements | Economic operators, manufacturers, importers, distributors, consumers | 2024-12-10 | 2027-12-11 |
| TTPAR | Transparency and Targeting of Political Advertising Regulation |
6 Published |
Advertising | Political advertising | Providers, sponsors, controllers, voters | 2024-4-9 | 2024-4-9 |
| GDPR | General Data Protection Regulation |
6 Published |
Data | Personal data | Controllers, processors, data subjects | 2016-5-24 | 2018-5-25 |
| CSoldA | Cyber Solidarity Act |
6 Published |
Cybersecurity | Cyber threats | Cross-border SOC, public bodies, entities operating in critical or highly critical sectors, trusted providers | 2025-2-4 | 2025-2-4 |
| EUDPR | Data Protection Regulation for EU institutions |
6 Published |
Data | Personal data, operational personal data | EU institutions | 2018-12-11 | 2018-12-11 |
| LED | Law Enforcement Directive |
6 Published |
Data | Personal data | Law enforcement authorities | 2016-5-5 | 2018-5-6 |
| DGA | Data Governance Act |
6 Published |
Fair digital market, data | Data, non-personal data | Data subjects, data holders, data users, data intermediation services, data altruism organisations, public sector bodies | 2022-6-23 | 2023-9-24 |
| Data Act | Data Act |
6 Published |
Fair digital market, data | Data, metadata, personal data, non-personal data | Users, data holders, data recipients | 2024-1-11 | 2025-9-12 |
| DSA | Digital Services Act |
6 Published |
Online services | Information society services, illegal content, advertisements, recommender systems | Consumers, traders, intermediary services, online platforms, online search engines, VLOPs, VLOSEs | 2022-11-16 | 2024-2-17 |
| DMA | Digital Markets Act |
6 Published |
Fair digital market | Core platform services | Gatekeepers, business users, end users | 2022-11-1 | 2023-5-2 |
| IEA | Interoperable Europe Act |
6 Published |
Cross-border interoperability | Trans-European digital public services, data | EU entities and bodies regulating or manging trans-European digital public services | 2024-4-11 | 2024-7-11 |
| NIS2 | NIS2 Directive |
6 Published |
Cybersecurity | Cyber threat, ICT products, ICT services, ICT processes | Member States, (critical) entities | 2023-1-16 | 2024-10-17 |
| CSA | Cybersecurity Act |
6 Published |
Cybersecurity | ENISA, ICT products, ICT services, ICT processes, European cybersecurity certification schemes | ENISA, operators of essential services, digital service providers | 2019-6-27 | 2021-6-28 |
| DORA | Digital Operational Resilience Act |
6 Published |
Cybersecurity, finance | Network and Information Systems | Financial entities, ICT third-party service providers | 2023-1-16 | 2025-1-25 |
| ePR | ePrivacy Regulation |
7 Withdrawn |
Telecom | Electronic communications services, electronic communications data, emails, direct marketing communications | End-users, electronic communications services providers | 0Unknown | 0Unknown |
| ATD | Access to documents Regulation |
6 Published |
Transparency | Public access to European Parliament, Council and Commission documents | European Parliament, Council and Commission | 2001-6-3 | 2001-12-3 |
| ADT reform | Revision of Access to Documents Regulation |
7 Withdrawn |
Transparency | Broader transparency obligations, wider definition of “document” | EU institutions | 0Unknown | 0Unknown |
| MSR | Market Surveillance and Compliance of Products Regulation |
6 Published |
Enforcement | Products | Market surveillance authorities, manufacturers, importers, distributors, fulfilment service providers, economic operators, information society service providers, end users | 2019-7-15 | 2021-1-1 |
| EU Digital Travel App | EU Digital Travel Application Regulation |
4 Trilogue / Negotiations |
Digital identity | EU-operated mobile application enabling electronic submission of travel data and use of digital travel credentials at external EU borders; amends Schengen Borders Code and eu-LISA rules | Member States, border control authorities, eu-LISA, EU citizens and third-country national travellers | 0Unknown | 0Unknown |
| CADA | Cloud and AI Development Act |
2 Council stage |
AI, cloud | Framework of measures to strengthen Europe’s cloud and AI ecosystem: data centre capacity, cloud infrastructure investment, AI compute access for providers and public sector, and industrial AI deployment support | Cloud service providers, AI developers, public sector bodies, Member States | 0Unknown | 0Unknown |
| EUDPR Reform | EUDPR Reform Regulation |
2 Council stage |
Data | Reform of the data protection framework for EU institutions, bodies, offices and agencies; extension to law enforcement, police cooperation and judicial cooperation contexts; amends Regulation (EU) 2018/1725 (EUDPR) | EU institutions, bodies, offices and agencies; European Data Protection Supervisor | 0Unknown | 0Unknown |
| Chips Act 2.0 | Chips Act 2.0 |
2 Council stage |
Semiconductors | Framework to strengthen the EU semiconductor ecosystem: chip design capacity, manufacturing pilot lines, supply chain monitoring, crisis management, and security-of-supply measures; repeals the 2023 Chips Act | Semiconductor manufacturers, chip designers, Member States, supply chain operators, competent authorities | 0Unknown | 0Unknown |
| Omnibus IV Directive | Small Mid-Caps Directive (Omnibus IV) |
3 EP stage |
Cybersecurity, fair digital market | Extension of SME mitigating measures to small mid-cap enterprises and further simplification; amends Directive 2014/65/EU (MiFID II) and Directive (EU) 2022/2557 on the resilience of critical entities | Member States, small mid-cap enterprises, investment firms, critical entities | 0Unknown | 0Unknown |
| Product Digitalisation Regulation | Product Rules Digitalisation and Common Specifications Regulation |
3 EP stage |
Product | Digitalisation of product compliance requirements across Union harmonisation legislation: electronic instructions for use, digital declarations of conformity, digital EC conformity marking and common specifications; amends Regulations (EU) No 765/2008, 2016/424, 2016/425, 2016/426, 2023/1230, 2023/1542 and 2024/1781 | Manufacturers, importers, distributors, economic operators, notified bodies, market surveillance authorities | 0Unknown | 0Unknown |
| Product Digitalisation Directive | Product Rules Digitalisation and Common Specifications Directive |
3 EP stage |
Product | Digitalisation of product compliance documentation across 13 harmonisation directives: electronic instructions for use, digital declarations of conformity and common specifications; amends Directives 2000/14/EC, 2011/65/EU, 2013/53/EU and the 2014 product directives | Member States, manufacturers, importers, distributors, economic operators, notified bodies | 0Unknown | 0Unknown |
| ePrivacy Derogation Extension Regulation | Temporary Derogation from the ePrivacy Directive to Combat Online Child Sexual Abuse |
6 Published |
Online services | Temporary and strictly limited rules derogating from certain obligations in Directive 2002/58/EC, allowing providers of number-independent interpersonal communications services to process personal and other data to the extent strictly necessary to detect online child sexual abuse, report it and remove child sexual abuse material from their services, while excluding scanning of audio communications; extends and amends Regulation (EU) 2021/1232, whose previous derogation was due to expire on 3 April 2026 | Providers of number-independent interpersonal communications services, Member States, users/data subjects | 2026-7-31 | 2026-7-31 |
| Europol Reform | Europol Regulation Reform |
3 EP stage |
Data | Reform of Europol’s mandate and data processing powers; amends Regulation (EU) 2018/1726 and Regulation (EU) 2024/982; repeals Regulation (EU) 2016/794 | Europol, Member States law enforcement authorities, eu-LISA | 0Unknown | 0Unknown |
| Eurojust Reform | Eurojust Regulation Reform |
3 EP stage |
Data | Reform of Eurojust’s mandate on criminal justice cooperation and case-related data processing; repeals Regulation (EU) 2018/1727 | Eurojust, Member States judicial authorities | 0Unknown | 0Unknown |
| EU KIDS Act | EU Keeping Internet Digital Spaces Accountable and Trustworthy Act |
1 Commission proposal |
Online services, data | Protection of minors in digital spaces, age verification and safety-by-design obligations for online services, data protection and content moderation safeguards for children | Providers of online platforms and digital services accessible to minors, Member States | 0Unknown | 0Unknown |
| ESSPASS | European Social Security Pass Regulation |
1 Commission proposal |
Digital identity, data | Digitalisation of social security coordination and cross-border exchange of social security data via the European Social Security Pass | Member State social security institutions, posted workers, employers | 0Unknown | 0Unknown |
* indicates an estimated date
PS: We have more laws in scope, so stay tuned for updates
Featured customers
Tame the information overload
No more: “where did I read that again?” or “wasn’t there a case about that?”. Tame the information overload and join Digibeetle.
- Curated.
- Referenced.
- Updated daily.