Regingada Radar

What moved in EU digital regulation — source, affected corpus nodes, a neutral orientation note.

DSA

DSA — clarification on points of contact (Art. 11)

Concerns the authority-facing point of contact under Art. 11 DSA and its public information.

  • dsa_art_11 Points of contact for authorities
  • dsa_art_11_1 Art. 11(1) — Designation of contact point
  • dsa_art_11_2 Art. 11(2) — Public information
published EUR-Lex / DSA ↗

AI Act

AI Act — prohibited practices (Chapter II)

Relates to the catalogue of prohibited AI practices under Chapter II of the AI Act.

  • aiact_ch_2 Chapter II — Prohibited AI Practices
  • aiact_root Regulation (EU) 2024/1689 — AI Act
published EUR-Lex / AI Act ↗
GDPR

GDPR — Data Protection Impact Assessment (Art. 35)

Concerns the thresholds and mandatory elements of the DPIA under Art. 35 GDPR.

  • gdpr_art_35 GDPR Art. 35 — Data Protection Impact Assessment (DPIA)
published EUR-Lex / GDPR ↗

CN/PIPL

China — Beijing: data export negative list of the two zones (2025 edition)

Three Beijing authorities published the 2025 edition of the data export negative list for the Beijing free trade zone and the services opening-up demonstration zone, together with administrative measures, on 11 May 2026; it covers 9 sectors, 67 business scenarios and 612 data fields and extends the mechanism city-wide.

EU relevance Concerns data transfers from China to recipients in the EU; for data outside the negative list the mechanism provides simplified export routes.

    CN/PIPL

    China — amendment to the Cybersecurity Law (CSL) adopted

    The Standing Committee of the National People's Congress adopted the amendment to the Cybersecurity Law on 28 October 2025 (Presidential Order No. 61); the amended law is in force since 1 January 2026, including a new provision on the promotion and safety supervision of artificial intelligence and revised legal-liability rules.

    EU relevance Touches EU companies operating networks or IT systems in China that fall within the scope of the Chinese Cybersecurity Law.

      applicable from gov.cn / 主席令第六十一号 ↗
      CN/PIPL

      China — PIPL certification route for data exports (CAC/SAMR measures)

      The Cyberspace Administration (CAC) and the market regulator (SAMR) published the measures on certification of data exports under the PIPL on 17 October 2025; they are in force since 1 January 2026 and cover the scenarios eligible for export certification, the duties of certification bodies and a three-year certificate validity.

      EU relevance Concerns data transfers from China to recipients in the EU, for which PIPL certification is one of the available export routes.

        applicable from CAC / 网信办 ↗

        CN/PIPL

        China — enforcement case: data transfer to overseas headquarters penalised

        On 18 September 2025 the Ministry of Public Security published six enforcement cases from the 2025 special campaign (护网-2025), including a penalty against a multinational fashion company in Shanghai that had transferred user data to its overseas headquarters without an export legal basis (security assessment, standard contract or certification) and without separate consent.

        EU relevance Touches EU groups with Chinese subsidiaries: intra-group data transfers from China to an EU headquarters fall under the PIPL export rules.

          published 公安部 / 江苏网信网 ↗

          Weekly digest

          The curated changes as a weekly email digest — double opt-in, unsubscribe anytime (RFC 8058). Sign-up in preparation.