The laws, and what they mean in practice

Privacy, AI and cybersecurity laws that shape digital trust work, from the GDPR to every US state privacy law. Each entry says who it applies to, who enforces it and when, in plain words, with the sources. Free for everyone.

Regulatory Watch follows new rules, enforcement and court decisions as they happen.

European Union 12

In force

GDPR

The global reference point for privacy law: lawful bases, principles, rights, accountability, breach notice within 72 hours, transfer rules and fines up to 4 percent of worldwide turnover.

Since 25 May 2018 · Guide in progress
In force

EU AI Act

Risk-based AI regulation with obligations assigned by role: prohibited practices, high-risk requirements, transparency duties and rules for general-purpose models.

Since 1 Aug 2024 · Guide in progress
In force

ePrivacy Directive

The source of EU cookie consent and electronic marketing rules, alongside the GDPR.

See details · Guide in progress
In force

NIS2

Cybersecurity risk management, management accountability and staged incident reporting starting with an early warning within 24 hours.

See details · Guide in progress
In force

DORA

ICT risk management, incident reporting, resilience testing and a register of ICT third-party arrangements for the financial sector.

Since 17 Jan 2025
In force

Data Act

Rights for users to access and share data from connected products, and rules making it easier to switch cloud providers.

Since 12 Sep 2025
In force

DSA

Content moderation, transparency, a ban on ads targeted using sensitive data or at minors based on profiling, and risk assessments for very large platforms.

Since 17 Feb 2024
In force

DMA

Limits on how gatekeepers combine personal data across services without consent, among other conduct rules.

Since 2 May 2023
In force

CRA

Security requirements across the life of hardware and software products, with vulnerability handling and reporting duties.

Since 10 Dec 2024
In force

DGA

Rules for neutral data intermediaries and for re-using protected public sector data.

Since 24 Sep 2023
In force

EHDS

Patients' access to and control of electronic health data across the EU, and a framework for secondary use of health data.

Since 26 Mar 2025
In force

EU-US DPF

An adequacy decision letting personal data flow to self-certified US companies without standard contractual clauses.

Since 10 Jul 2023

This library explains laws for practitioners. It is not legal advice, and laws change: check the sources on each page and take advice from counsel before acting.