All Changes

EU Regulatory Changes

19 changes tracked across 21 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board has published the agenda for the IAPP Global Summit 2026, serving as a key forward-looking resource on the operationalization of the EU AI Act. This agenda outlin...
Read analysis →
Patrick Montagner: Banking supervision in a fragmented credit market: interconnections matter
In an interview published on 24 March 2026, ECB Supervisory Board member Patrick Montagner outlined evolving supervisory expectations regarding risk management in a fragmented credit market. The fo...
Read analysis →
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board (EDPB) has published its agenda for the IAPP Global Summit 2026, highlighting key regulatory priorities. This agenda signals the EDPB's focus on the operational c...
Read analysis →
EDPB-EDPS Joint Opinion 4/2026 on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 ...
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on the proposed Cybersecurity Act 2 and amendments to the NIS 2 Directive. This opinion provid...
Read analysis →
EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data
The EDPB and EDPS have issued a joint opinion endorsing the European Commission's draft implementing acts for the NIS2 Directive. This opinion supports measures designed to standardize and clarify ...
Read analysis →
CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR
The European Data Protection Board (EDPB) has launched its 2026 Coordinated Enforcement Framework (CEF) action, focusing on the practical application of GDPR transparency and information obligation...
Read analysis →
DORA – Register of Information collection – Update
The CSSF has published an update regarding the collection of information for the DORA Register. This involves the formal issuance of templates and technical specifications that financial entities m...
Read analysis →
ESMA consults on post-trade risk reduction services under EMIR 3
ESMA has launched a public consultation on proposed technical standards for post-trade risk reduction (PTRR) services under the revised EMIR framework (EMIR 3). This initiative, developed within th...
Read analysis →
ESMA sets out clearing thresholds under EMIR 3
ESMA has published its final report setting the clearing thresholds under the updated EMIR 3 framework, which is part of the broader DORA regulatory initiative. This establishes the quantitative le...
Read analysis →
How does ENISA cooperate with users of the EU Cybersecurity Reserve? Who decides which entity should benefit from ser...
ENISA has published operational details on the cooperation framework for the EU Cybersecurity Reserve, a key mechanism established under the NIS2 Directive. The update clarifies the process for req...
Read analysis →
Claudia Buch: AMLA and ECB Banking Supervision: strengthening cooperation
In a February 2026 speech, ECB supervisory chair Claudia Buch outlined enhanced cooperation between the future Anti-Money Laundering Authority (AMLA) and ECB Banking Supervision. The key change is ...
Read analysis →
DORA – Submission timeframe for register of information for third-country branches of credit institutions having thei...
The CSSF has published a communication specifying the submission timeframe for a key DORA requirement. It mandates that third-country branches of credit institutions, whose head office is outside t...
Read analysis →
How could a cybersecurity company join the EU Cybersecurity Reserve?
ENISA has published guidance on the process for cybersecurity companies to join the newly established EU Cybersecurity Reserve. This voluntary pool of trusted private sector incident response servi...
Read analysis →
How will the EU Cybersecurity Reserve be funded?
ENISA has published guidance clarifying the funding mechanism for the new EU Cybersecurity Reserve, a key operational capability established under the NIS2 Directive. The Reserve is designed to pro...
Read analysis →
Does the EU Cybersecurity Reserve only provide incident reponse and initial recovery actions?
ENISA has published a clarification on the scope of assistance available from the EU Cybersecurity Reserve. This operational tool, established under the NIS2 Directive, is confirmed to provide supp...
Read analysis →
Is any non-EU country eligible to receive support from the EU Cybersecurity Reserve?
ENISA has published a clarification confirming that non-EU countries are eligible to receive support from the EU Cybersecurity Reserve. This operational detail stems from the NIS2 Directive and the...
Read analysis →
The EBA publishes follow-up Report on ICT risk assessment under the Supervisory Review and Evaluation Process
The European Banking Authority (EBA) has published a follow-up report on integrating Information and Communication Technology (ICT) risk into the Supervisory Review and Evaluation Process (SREP). T...
Read analysis →
Making GDPR compliance easier through new initiatives: a key focus of the EDPB work programme 2026-2027
The European Data Protection Board (EDPB) has published its strategic work programme for 2026-2027, formally establishing a core objective of simplifying GDPR compliance. This represents a signific...
Read analysis →
EDPB Report on the public consultation on helpful templates for organisations to facilitate their GDPR compliance
The European Data Protection Board (EDPB) has published a report summarizing the feedback from its public consultation on proposed GDPR compliance templates. This report details stakeholder input o...
Read analysis →