GDPR and DPA are two terms that appear together constantly in UK data protection compliance, and they are regularly confused. GDPR refers to the General Data Protection Regulation, the EU’s primary data protection law. DPA has two distinct meanings depending on context: it can refer to the Data Protection Act 2018, the UK statute that…
A practical legal guide to the Digital Operational Resilience Act (Regulation (EU) 2022/2554) DORA, the Digital Operational Resilience Act, is an EU regulation that entered into application on 17 January 2025. It establishes a binding framework for digital operational resilience across the EU financial sector, covering ICT risk management, incident reporting, operational resilience testing, third-party…
PCI compliance refers to adherence to the Payment Card Industry Data Security Standard (PCI DSS), a set of security requirements that applies to any organisation that stores, processes, or transmits payment card data. In the UK, PCI compliance is not a statutory legal obligation in the way that GDPR is, but it is a contractual…
A practical legal guide for manufacturers of connected products navigating Regulation (EU) 2023/2854 The EU Data Act has applied since 12 September 2025. It creates binding obligations for manufacturers of connected products and related service providers, covering data access rights, data sharing obligations, contractual fairness requirements, and cloud switching obligations. For IoT device manufacturers specifically,…
By Yuliia Habriiel, Regulatory Lawyer. Last reviewed 12 August 2026, against the AI Act as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI). EU AI Act compliance requires between six and twenty-five documents, depending on your role and your risk tier. Every organisation using AI needs the same six baseline records: an AI system inventory,…
FRAND prohibits exploitative contracts, caps compensation costs for SMEs, and stops market incumbents from discriminating against competitors seeking data access.
July 2026 is the month AI compliance stopped being a European planning exercise and became a global operational reality simultaneously across multiple binding regimes. The question is no longer whether regulation is coming. It is whether your compliance infrastructure was built for one framework or for the world as it actually is. EU: Digital Omnibus…
Last updated: 29 July 2026 Summary The EU AI Act applies to anyone who develops, sells, or uses an AI system whose output reaches the EU market, regardless of where that company is based. It catches four main actors: providers (who build or sell the system), deployers (who use it in their own operations), importers,…
The most common assumption among UK, US, Canadian, and Swiss businesses encountering the EU AI Act for the first time is that territorial scope follows establishment. If you are not incorporated in an EU member state, the Act does not apply to you. This assumption is incorrect, and acting on it creates material regulatory and…
The short answer: yes. Brexit moved UK companies outside the EU’s regulatory perimeter. The EU AI Act treats UK companies as third-country providers — subject to the same extraterritorial obligations as US, Indian, or Canadian companies the moment their AI systems reach EU users. There is no special post-Brexit status, no UK-EU AI Act equivalence…