European Digital Regulation: The Alphabet Soup Update



The European Union isn’t slowing down: It keeps adding to what is already one of the most comprehensive digital regulatory frameworks in the world. For U.S. technology companies with European customers, employees, or operations, ignorance is not a viable compliance strategy. Here is a snapshot of five areas (and their acronyms) that should be on everybody’s radar.

GDPR: Vulnerabilities in the transatlantic Data Privacy Framework

For personal data to flow freely (and legally) from the EU to jurisdictions beyond, the General Data Protection Regulation (GDPR) requires either an adequate level of protection at the destination (as determined by the European Commission), or extra precautions. The EU–U.S. Data Privacy Framework (DPF) provides that adequate level of protection for transatlantic transfers. To benefit from it, a U.S. company must annually certify its compliance, and it must be subject to the investigatory and enforcement powers of the FTC or the DoT.

The European Commission’s adequacy decision expressly relies on the FTC’s structural independence and describes the hallmarks of that independence: Senate-confirmed commissioners, fixed seven-year terms, and removal only for cause. The SCOTUS decision in Trump v. Slaughter, which allowed removal of a commissioner without cause, has raised concerns regarding the basis of the DPF. While no formal action has been taken to disband the DPF, notorious privacy activist Max Schrems has already threatened litigation. Companies should watch developments carefully and explore other options, such as a Europrivacy certification.

Data Act: Unlock your data (and your annual subscriptions)

The EU Data Act (DA) has been live since 12 September 2025. Its two headline obligations concern data access in IoT, as well as switching of cloud services providers. On access, the regulation ensures that users of connected products (like smart appliances), can obtain and reshare with third parties the raw data generated by their use. These rules apply to manufacturers and service providers regardless of where they are established, as long as they serve the EU market.

On the cloud services side, the DA facilitates switching between data-processing service providers and provides for the gradual withdrawal of switching charges. From 12 January 2027, providers may no longer impose any switching charges at all; until then, charges must not exceed costs directly linked to the switching process. Cloud providers also cannot exclude early termination rights in annual subscriptions, meaning customers can now walk whenever they want. Providers are allowed to charge reasonable early termination fees, but the jury is still out on what “reasonable” is in this context.

The EU AI Act: Transparency obligations are now live

The EU AI Act is essentially product safety legislation, as it aims to encourage safe and trustworthy AI systems across the EU single market while ensuring respect for fundamental rights. It follows a risk-based approach: the higher the potential harm, the stricter the rules. Some use cases are already banned because they are deemed to pose unacceptable risks; for other high-use cases, the recently adopted AI Omnibus regulation has pushed out compliance deadlines to the end of 2027 and beyond.

However, transparency obligations have come live on 2 August 2026. AI systems designed to interact with humans (such as chatbots) must disclose that the user is interacting with AI, and providers of generative AI tools must mark their output in a machine-readable format (such as meta-tags). Deployers of such AI systems have their own transparency obligations. While slightly less wide in scope, they do require human-readable disclosures at the time a user interacts with the content.

Cybersecurity: Direct and indirect obligations

Multiple overlapping frameworks govern EU cybersecurity law. The Network and Information Security Directive 2 (NIS2) is a common cybersecurity framework requiring risk-management measures and incident reporting in critical sector. It mandates supply-chain security measures, meaning that even vendors not directly in scope will be swept in through customer contracts flowing down certain reporting obligations. Similar concerns exist with the Digital Operational Resilience Act (DORA), which directly applies to financial institutions – but indirectly forces service providers catering to such customers to commit to reporting and remediation, as well as supporting the switch to other providers.

Finaly, the Cyber Resilience Act (CRA), which comes into full force on 11 December 2027, will require “smart” products (i.e. physical products with digital elements) to be secure by design, resilient against cyber threats, and capable of ongoing protection throughout their life cycle. Certain vulnerability reporting obligations however are imminent, going live on 11 September 2026. Non-EU software makers selling to EU markets are fully in scope

What Is Coming: The Digital Fairness Act and the Digital Omnibus

Two more legislative waves are on the horizon. Any day now, we are expecting the draft of a Digital Fairness Act (DFA), which will update consumer protections in the digital world by tackling dark patterns, manipulative design, problematic influencer marketing, and difficult-to-cancel digital subscriptions and auto-renewals.

The Digital Omnibus is a broader simplification exercise. Initially debuted alongside the AI Omnibus, but currently delayed, it aims to amend the GDPR, the Data Act, NIS2, and the ePrivacy Directive, while repealing the Platform-to-Business Regulation, the Data Governance Act, and the Open Data Directive. The stated aim is to bring immediate relief to businesses and public authorities while maintaining strong fundamental rights protections – but it remains to be seen whether this goal can be attained.