EU Cyber Resilience Act enters into force
The CRA introduces mandatory cybersecurity requirements for products with digital elements sold in the EU.
Insights for the EU, the EEA, and the rest of Europe.
The CRA introduces mandatory cybersecurity requirements for products with digital elements sold in the EU.
EU Member States were required to bring NIS2 into national law by today; Belgium’s NIS2 law applies from 18 October 2024.
Italy’s Legislative Decree 138/2024 transposes the NIS2 Directive, extending cyber security obligations across many sectors.
Switzerland adds certified US organisations to its list of adequate countries, allowing transfers under the Swiss–US Data Privacy Framework.
The first legally binding international AI treaty opens for signature, with the UK, EU and US among the first signatories.
The Dutch data protection authority fines Uber €290 million for transferring European drivers’ data to the US without adequate safeguards.
The world’s first comprehensive AI law enters into force, with obligations phasing in from February 2025.
UN Regulations 155 and 156 become mandatory for all new vehicles registered in the EU, extending beyond new vehicle types.
Amendments to Türkiye’s KVKK introduce standard contracts for cross-border transfers of personal data.
France’s SREN law introduces cloud market rules and sovereign cloud requirements for sensitive public sector data.
The revised EU eIDAS Regulation introduces European Digital Identity Wallets and new trust services.
TISAX assessments commissioned from 1 April 2024 must use version 6.0 of the VDA Information Security Assessment catalogue.