Directive 2011/83/EU of the European Parliament and of th...
Official EU publication (2026-09-27): Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights, amending Coun...
Source-linked regulatory updates from CNIL, Garante, ICO, AEPD, EDPB, and major EU supervisory authorities. Sourced from official authority publications.
Last updated
343
Total updates indexed
12
Sources indexed
8
Regulation areas
27
EU member states
342 decisions (showing latest 30)
Official EU publication (2026-09-27): Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights, amending Coun...
Official EU publication (2026-09-27): Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consume...
ESMA has officially authorised EuroCTP as the Consolidated Tape Provider (CTP) for shares and ETFs under the MiFIR framework. SMEs operating in financial services must now align their market data reporting and consumptio…
ESMA has issued guidance regarding the conclusion of the MiCA transitional period and the publication of the first annual report on major ICT-related incidents under DORA (Regulation (EU) 2022/2554). SMEs operating in th…
The European Supervisory Authorities have published joint guidance calling for enhanced governance and risk-based supervision to mitigate ICT and cyber risks stemming from frontier AI models in financial services. Financ…
The ESAs have proposed amendments to Delegated Regulation (EU) 2016/2251 to simplify bilateral margin requirements under EMIR. This initiative aims to remove the obligation for counterparties below the €8 billion thresho…
ESMA is hosting a conference focusing on the European Single Access Point (ESAP) and the simplification of regulatory reporting requirements. SMEs in the financial sector must prepare for upcoming data integration mandat…
The European Securities and Markets Authority announces the go-live of weekly commodity derivatives position reporting starting 3 September 2026 under XML schema version v2.0, impacting data processing and regulatory sub…
ESMA has launched a consultation on new RTS/ITS under EMIR 3 to standardize reporting of clearing activities at third-country CCPs. SMEs acting as clearing members or clients must prepare for new data submission requirem…
ESMA has established a Memorandum of Understanding with SEBI to facilitate the recognition of Indian Central Counterparties (CCPs) under EMIR Art. 25. This enables EU clearing members to resume operations with Indian CCP…
ESMA has released a package of updated guidelines and RTS under the Prospectus Regulation to align with the Listing Act. These measures aim to simplify disclosure requirements and provide a standardized framework for pro…
The European Securities and Markets Authority published its risk monitoring report for 2026, warning that optimistic valuations in technology and AI sectors mask significant geopolitical and operational vulnerabilities. …
The EDPB adopted new guidelines establishing a five-step methodology for national DPAs to impose administrative fines alongside other corrective powers under GDPR Art. 58 and Art. 83. Additionally, final guidelines on th…
The EBA published final Guidelines on the management of third-party risk under DORA, delivering a more proportionate framework alongside Q&As on resolution reporting and templates. SMEs providing financial technology ser…
The European Commission is hosting the Data Union Conference on January 12, 2027, focusing on the upcoming Digital Omnibus to simplify EU data rules, reduce administrative burdens, and enhance data access for AI under th…
The CNIL plenary session agenda serves as a regulatory signal for upcoming enforcement priorities under GDPR Art. 57 and 58. SMEs should monitor these sessions to anticipate changes in supervisory focus regarding data pr…
The EU KIDS Act mandates that digital service providers implement age-appropriate safety by design, shifting the burden of proof to the provider. SMEs must now verify user age and ensure services are safe for minors unde…
The EU KIDS Act mandates a harmonized age threshold of 15 for autonomous account creation on social networking and video-sharing platforms. This proposal aims to mitigate risks to minors by standardizing protection level…
The European Parliament has confirmed Thomas Gstädtner as the new Executive Director of the European Banking Authority (EBA). This leadership change signals potential shifts in regulatory enforcement priorities regarding…
The EDPS clarifies that Secure Multi-Party Computation (SMPC) is a privacy-enhancing technology but does not exempt controllers from GDPR Art. 5(1)(f) integrity and confidentiality obligations. SMEs must ensure that cryp…
The EBA has released updated validation rules for quarterly reporting frameworks under DORA and related financial regulations. SMEs in the financial sector must integrate these technical standards into their automated re…
The French CNIL sanctioned EXTIA for failing to process data erasure requests under GDPR Art. 17 and failing to provide timely transparency under Art. 12. This case highlights the critical necessity for SMEs to maintain …
The BfDI mandates enhanced transparency and genuine opt-out mechanisms for the electronic patient record (ePA) as pseudonymized medication data becomes available for research under GDPR Art. 6 and Art. 9. SMEs in the hea…
Depuis le 1er septembre 2026, la réforme relative à la facturation électronique entre entreprises est entrée en vigueur. La CNIL aide les entreprises à comprendre les enjeux et à assurer la sécurité des données traitées.
The CNIL plenary session agenda serves as a compliance signal for upcoming regulatory enforcement priorities under GDPR Art. 57 and Art. 58. SMEs should monitor these sessions to anticipate shifts in supervisory focus re…
The CNIL has released 'Au-delà de l’écran' (Tome 2), providing educational guidance on digital privacy risks including deepfakes and social engineering. This resource serves as a compliance signal for SMEs to integrate a…
The EBA has issued a formal response regarding the European Commission's decision not to adopt draft amending technical standards on prior permission under DORA. This regulatory friction creates uncertainty for SMEs rega…
The French data protection authority CNIL fined EXTIA 300000 EUR on July 21, 2026, for failing to comply with data subject rights, specifically violating GDPR Art. 17 regarding the right to erasure. SMEs must ensure auto…
The CNIL sanctioned Hôpital Privé de la Loire for violating GDPR Art. 32 and Art. 34 due to inadequate authentication, lack of access controls, and failure to notify affected third parties during a massive health data br…
The European Personnel Selection Office (EPSO) has initiated a recruitment drive for AD 8 level administrators specializing in AI and Cybersecurity. This signals an imminent increase in regulatory oversight and enforceme…
Italy's Garante and France's CNIL issue the highest volume of enforcement decisions annually. Ireland's DPC handles many Big Tech cases due to EU headquarters presence — including the record €1.2 billion Meta fine (2023). The Spanish AEPD and Dutch AP are most active against smaller organisations and public bodies.
GDPR Article 83 sets maximum fines at €20 million or 4% of global annual turnover — whichever is higher. Tier 1 infringements (e.g. insufficient legal basis, data subject rights violations) carry up to €10 million or 2% of turnover. Tier 2 infringements (e.g. unlawful processing, international transfers) carry the full €20 million / 4% ceiling.
EU AI Act enforcement is phased: prohibited AI practices banned from February 2, 2025; GPAI model rules from August 2, 2025; high-risk AI system obligations from August 2, 2026. National market surveillance authorities handle enforcement; the European AI Office oversees general-purpose AI models above 10^25 FLOPs.
NIS2 (Directive 2022/2555) required EU member state transposition by October 17, 2024. Essential entities face fines up to €10 million or 2% of global turnover; important entities up to €7 million or 1.4% of turnover. National CSIRTs and competent authorities handle enforcement. Management board members can be held personally liable for repeated non-compliance.
Every Monday: the week's top EU enforcement actions, curated by regulation and authority. Free for all EuroComply users.
Sign in or create a free account to subscribe to weekly enforcement alerts.
Data sourced from official EU supervisory authority publications. For informational purposes only. Not legal advice. Editorial policy