Legislation & Acts

NIS2 Becomes Dutch Law: What Changes on 15 August 2026

The Netherlands will implement the Cyberbeveiligingswet (Cbw) on 15 August 2026, enforcing the NIS2 Directive to enhance cybersecurity for over 8,000 organisations across various sectors. Key responsibilities include registration, risk analysis, incident reporting, and management accountability, aimed at strengthening overall cyber resilience and integrating security measures into governance.

France’s SREN Law Regulates Cloud Lock-In

France’s SREN law treats cloud exit as a market rule: switching fees, portability, interoperability and contract transparency are no longer matters that customers can safely postpone until migration day. Law 2024-449 on securing and regulating the digital space was published…

eIDAS 2.0 Changes Europe’s Identity Architecture

The European Digital Identity Framework is not simply a government login application. It creates a cross-border trust architecture for wallets, credentials and the organisations that request them. Regulation (EU) 2024/1183—the updated eIDAS framework—applied from 20 May 2024. It requires Member…

The Digital Services Act Is an Incident-Response Framework for Platforms

The Digital Services Act, applicable from 17 February 2024, regulates intermediary services within the EU, imposing varying obligations based on service type and size. It mandates effective notice, classification, and moderation workflows while ensuring transparency in automated decision-making. Large platforms are held to higher standards, requiring systemic risk assessments and accountability measures.