Where the Cyber Resilience Act and the AI Act apply to the same product, which obligations duplicate, which conflict, and how to build one compliance programme instead of two.
ENISA’s Single Reporting Platform goes live on 11 September 2026. What it does, who registers, what the 24-hour clock actually requires, and what you can prepare before the URL is published.
What the EU Cyber Resilience Act is, when it takes effect, and why Brexit does not put UK software and hardware companies outside its scope.
What Annex I actually requires, why the September 2026 reporting deadline makes SBOMs urgent before they are legally mandatory, and how to build a compliant component inventory.
From 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe security incidents to ENISA reporting platform (SRP) and their national CSIRT under Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847). The CRA vulnerability reporting cascade runs on three deadlines: a 24-hour early…
What the Data (Use and Access) Act 2025 changed, where the two regimes now differ, and what dual compliance actually requires. This guide reflects the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and the European Commission’s adequacy decisions as at August 2026.
In GDPR, DPA is the Data Processing Agreement. Under Article 28 GDPR, a controller may only use a processor that provides sufficient guarantees, and the relationship must be governed by a written contract. That contract is the Data Processing Agreement, usually shortened to DPA. Most organisations have DPAs in place. Fewer have DPAs that would…
A practical legal guide to the Digital Operational Resilience Act (Regulation (EU) 2022/2554)
PCI compliance refers to adherence to the Payment Card Industry Data Security Standard (PCI DSS), a set of security requirements that applies to any organisation that stores, processes, or transmits payment card data. In the UK, PCI compliance is not a statutory legal obligation in the way that GDPR is, but it is a contractual…
A practical legal guide for manufacturers of connected products navigating Regulation (EU) 2023/2854 The EU Data Act has applied since 12 September 2025. It creates binding obligations for manufacturers of connected products and related service providers, covering data access rights, data sharing obligations, contractual fairness requirements, and cloud switching obligations. For IoT device manufacturers specifically,…