<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: eurlexa</title>
    <description>The latest articles on DEV Community by eurlexa (@eurlexa).</description>
    <link>https://dev.to/eurlexa</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2709494%2Fa521243a-e29c-487c-8a46-2280458e0e94.jpg</url>
      <title>DEV Community: eurlexa</title>
      <link>https://dev.to/eurlexa</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/eurlexa"/>
    <language>en</language>
    <item>
      <title>EU AI Act Coming into Effect in February 2025</title>
      <dc:creator>eurlexa</dc:creator>
      <pubDate>Fri, 31 Jan 2025 08:20:37 +0000</pubDate>
      <link>https://dev.to/eurlexa/eu-ai-act-comming-into-effect-and</link>
      <guid>https://dev.to/eurlexa/eu-ai-act-comming-into-effect-and</guid>
      <description>&lt;p&gt;On February 2, 2025, important provisions of the EU AI Act come into effect.&lt;/p&gt;

&lt;p&gt;You can find the most recent text of the AI Act here: &lt;a href="https://www.eurlexa.com/act/en/32024R1689/present/text" rel="noopener noreferrer"&gt;https://www.eurlexa.com/act/en/32024R1689/present/text&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Anyone Who Deploys AI Can Be Fined
&lt;/h2&gt;

&lt;p&gt;A crucial takeaway is that not only AI developers will be affected but also any private person or company deploying AI systems. The AI Act refers to these entities as "deployers." The deployed AI may often be third-party systems.&lt;/p&gt;

&lt;p&gt;The AI Act defines a deployer broadly as follows:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For instance, a company using a third-party AI system for customer service, fraud prevention, internal procedures chatbot etc. would be classified as a deployer.&lt;/p&gt;

&lt;h2&gt;
  
  
  General Duties
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Risk Classification&lt;/strong&gt;: The Act categorizes AI systems into four risk levels: unacceptable, high, limited, and minimal risk. Unacceptable-risk AI systems are prohibited outright, while high-risk systems face stringent requirements.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Compliance Requirements&lt;/strong&gt;: Providers and deployers of high-risk AI applications must conduct conformity assessments, ensure transparency, and maintain robust governance frameworks. They are also required to ensure that their staff possess adequate AI literacy.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Governance Structure&lt;/strong&gt;: The Act mandates the establishment of a governance framework at both European and national levels, which includes the creation of an AI Office responsible for monitoring and supervising compliance.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Penalties for Noncompliance&lt;/strong&gt;: Penalties for violations can be severe, ranging from €7.5 million or 1.5% of global annual turnover to €35 million or 7%, depending on the nature of the infringement.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Obligations for End User Businesses (Deployers)
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Monitoring and Compliance&lt;/strong&gt;: Deployers must monitor the operation of high-risk AI systems based on the provider's instructions for use. This includes ensuring that the systems operate safely and effectively within their intended context.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Reporting Risks&lt;/strong&gt;: If deployers suspect that using an AI system according to the provider's instructions may lead to risks as defined by the Act, they are required to inform the provider and cease using the system until the issue is resolved.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Transparency Requirements&lt;/strong&gt;: For AI systems that generate or manipulate content (e.g., deepfakes), deployers must clearly disclose that such content has been AI-generated or manipulated. This is part of broader transparency obligations aimed at ensuring users can interpret and understand AI outputs appropriately.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Record Keeping&lt;/strong&gt;: Deployers need to maintain logs of the AI system's operation to ensure traceability and accountability, which can be crucial for compliance checks and audits.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Impact Assessments&lt;/strong&gt;: Certain deployers, particularly public bodies and private operators providing public services, may be required to conduct fundamental rights impact assessments before deploying high-risk AI systems. This involves evaluating the potential impact of these systems in their specific contexts.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Timeline for Compliance
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;February 2, 2025&lt;/strong&gt;: Initial compliance measures for certain provisions begin.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;August 2, 2025&lt;/strong&gt;: Additional obligations for users of general-purpose AI models and commencement of penalties.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;August 2, 2026&lt;/strong&gt;: Full application of most provisions related to high-risk AI systems.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This staggered implementation allows deployers time to adjust their practices in AI deployment.&lt;/p&gt;

&lt;p&gt;You can see more detail timeline here: &lt;a href="https://www.eurlexa.com/act/en/32024R1689/present/timeline" rel="noopener noreferrer"&gt;https://www.eurlexa.com/act/en/32024R1689/present/timeline&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>news</category>
      <category>development</category>
    </item>
    <item>
      <title>🚀 We Have Released Eurlexa - EU Regulation at Your Fingertips 🇪🇺🎉</title>
      <dc:creator>eurlexa</dc:creator>
      <pubDate>Wed, 15 Jan 2025 07:54:08 +0000</pubDate>
      <link>https://dev.to/eurlexa/eurlexa-release-eu-regulation-at-your-fingertips-3gkc</link>
      <guid>https://dev.to/eurlexa/eurlexa-release-eu-regulation-at-your-fingertips-3gkc</guid>
      <description>&lt;p&gt;After more than 2-year-long journey developing Eurlexa we are happy to announce that &lt;a href="https://www.eurlexa.com" rel="noopener noreferrer"&gt;Eurlexa&lt;/a&gt; web app is on at &lt;a href="https://www.eurlexa.com" rel="noopener noreferrer"&gt;https://www.eurlexa.com&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;You are more than welcome to visit.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fccjiohi3o75hvyg30g1a.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fccjiohi3o75hvyg30g1a.png" alt="Eurlexa homepage" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Eurlexa brings EU legislation to your fingertips. Access and search EU regulations and directives with ease on Eurlexa. Eurlexa is a mobile-optimized, user-friendly alternative to EUR-Lex for quick legal references.&lt;/p&gt;

&lt;p&gt;Eurlexa uses mainly these amazing modern, as well as some quite old, technologies:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;SvelteKit&lt;/li&gt;
&lt;li&gt;Supabase and PostgreSQL&lt;/li&gt;
&lt;li&gt;GitHub Actions&lt;/li&gt;
&lt;li&gt;PWA&lt;/li&gt;
&lt;li&gt;Vercel&lt;/li&gt;
&lt;li&gt;SOAP&lt;/li&gt;
&lt;li&gt;SPARQL&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F02ouxxqhex5os9vnaz3l.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F02ouxxqhex5os9vnaz3l.png" alt="Eurlexa GDPR display" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The features include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Mobile optimizations&lt;/li&gt;
&lt;li&gt;Autosuggest search&lt;/li&gt;
&lt;li&gt;Localization for all EU languages&lt;/li&gt;
&lt;li&gt;Table of contents with hashtag links to relevant sections&lt;/li&gt;
&lt;li&gt;The most recent version of regulations or directives, as well as all prior versions&lt;/li&gt;
&lt;li&gt;A track changes view highlighting differences from previous versions&lt;/li&gt;
&lt;li&gt;Timeline of all amendments and corrections and important dates&lt;/li&gt;
&lt;li&gt;Highlighter&lt;/li&gt;
&lt;li&gt;Details on all implementing regulations, judicial precedents, or proposed changes&lt;/li&gt;
&lt;li&gt;Progressive Web App (PWA)&lt;/li&gt;
&lt;li&gt;And much more&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Feel free to explore all features &lt;a href="https://www.eurlexa.com" rel="noopener noreferrer"&gt;Eurlexa&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>EU Drops the Hammer: MiCA Crypto Regulations Now in Full Force in 2025</title>
      <dc:creator>eurlexa</dc:creator>
      <pubDate>Tue, 14 Jan 2025 18:03:59 +0000</pubDate>
      <link>https://dev.to/eurlexa/eu-drops-the-hammer-mica-crypto-regulations-now-in-full-force-in-2025-2blg</link>
      <guid>https://dev.to/eurlexa/eu-drops-the-hammer-mica-crypto-regulations-now-in-full-force-in-2025-2blg</guid>
      <description>&lt;p&gt;(This is a repost under the new Eurlexa Team profile, where we aim to centralize all posts related to Eurlexa.)&lt;/p&gt;

&lt;p&gt;Do you have or use crypto? Are you providing crypto services? If so, in 2025, you need to be very careful, especially if you or your clients or investors are from the European Union.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;As of January 2025, all crypto-asset service providers will need to begin applying for licenses to operate under MiCA in EU.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  MiCA Latest Version
&lt;/h2&gt;

&lt;p&gt;On December 30, 2024, the EU Crypto Regulation known as MiCA came into full effect. The full text of the latest version of MiCA can be found here:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32023R1114/present/text" rel="noopener noreferrer"&gt;https://www.eurlexa.com/act/en/32023R1114/present/text&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Recent Changes
&lt;/h2&gt;

&lt;p&gt;Interestingly, this is already the second version of MiCA. The initial text can be found &lt;a href="https://www.eurlexa.com/act/en/32023R1114/32023R1114/text" rel="noopener noreferrer"&gt;here&lt;/a&gt;. &lt;/p&gt;

&lt;p&gt;The main changes are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The EU Commission has been given the power to supplement MiCA by adopting regulatory technical standards in certain areas.&lt;/li&gt;
&lt;li&gt;Issuers, offerors, or persons seeking admission to trading are required to submit inside information to the European Single Access Point (expected to operate from 2030).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can view the specific updates in detail with track changes mode &lt;a href="https://www.eurlexa.com/act/en/32023R1114/02023R1114-20240109/text/diff/32023R1114" rel="noopener noreferrer"&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Objectives of MiCA
&lt;/h2&gt;

&lt;p&gt;MiCA is a comprehensive framework designed to regulate crypto assets across the EU.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Unified Regulatory Framework&lt;/strong&gt;: MiCA establishes a single set of rules applicable to all 27 EU member states, replacing the fragmented regulatory landscape that previously existed. 
So far, so good — you won’t need to study crypto rules for each individual EU member state.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Consumer Protection&lt;/strong&gt;: MiCA introduces consumer protection measures, including transparency requirements for issuers of crypto-assets, and obligations for crypto-asset service providers (CASPs) to clearly communicate the risks associated with crypto investments. Given the many unfortunate stories from crypto customers, these protective measures are a much-needed step.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Market Integrity&lt;/strong&gt;: MiCA aims to strengthen confidence in crypto markets by prohibiting market manipulation and insider trading. This is a fair addition, similar to regulations in traditional capital markets.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Key Provisions
&lt;/h2&gt;

&lt;p&gt;Now comes the tricky part for crypto in the EU.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Licensing Requirements&lt;/strong&gt;: All CASPs must obtain authorization from national competent authorities to operate within the EU. This includes having at least one director based in the EU and maintaining a registered office there. Competent authorities are typically financial market regulators, not IT experts, making it difficult to predict how stringent the rulings will be. It’s also possible that we may see "licence shopping" — CASPs choosing the most favorable EU regulator. More details on application to provide crypto-asset services are here &lt;a href="https://www.eurlexa.com/act/en/32023R1114/present/text#Article-62-Application-for-authorisation-as-a-crypto-asset-service-provider" rel="noopener noreferrer"&gt;https://www.eurlexa.com/act/en/32023R1114/present/text#Article-62-Application-for-authorisation-as-a-crypto-asset-service-provider&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Regulatory Oversight&lt;/strong&gt;: The European Securities and Markets Authority (ESMA) will oversee significant CASPs — those with more than 15 million active users.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Issuers' Obligations&lt;/strong&gt;: Issuers of asset-referenced tokens (ARTs) and electronic money tokens (EMTs) must prepare detailed whitepapers outlining their offerings, including risks and terms of investment. More details describing content and form of the crypto-asset white paper are here &lt;a href="https://www.eurlexa.com/act/en/32023R1114/present/text#Article-6-Content-and-form-of-the-crypto-asset-white-paper" rel="noopener noreferrer"&gt;https://www.eurlexa.com/act/en/32023R1114/present/text#Article-6-Content-and-form-of-the-crypto-asset-white-paper&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Anti-Money Laundering (AML)&lt;/strong&gt;: All CASPs are required to implement strong AML policies to ensure compliance with EU financial service standards. This was, of course, expected, especially in light of sanctions imposed on Russia.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Licensing and Transitional Period
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;As of January 1, 2025, all CASPs will need to begin applying for licenses to operate under MiCA in EU.&lt;/strong&gt; Here are the key details regarding the transitional provisions and licensing process:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Transitional Period&lt;/strong&gt;: Existing virtual asset service providers (VASPs) — the more commonly used term outside the EU for crypto providers — can continue to operate under their current national licenses until December 31, 2025. In some countries, this transitional period may be extended until July 1, 2026. This allows VASPs time to apply for a MiCA CASP license while still providing services legally.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;License Application Submission&lt;/strong&gt;: From January 1, 2025, companies must submit their applications for a MiCA CASP license. However, they could have begun preparing and submitting applications as early as April 22, 2024, for pre-examination by local authorities, although formal authorization cannot be granted until MiCA comes into effect on December 30, 2024.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Application Process&lt;/strong&gt;: Submitting a license application is necessary but not sufficient on its own. The application must be complete and meet all regulatory requirements. The review process typically takes around 40 working days, but it can take longer if additional information is requested or if the application is complex.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Continued Operation During Application&lt;/strong&gt;: While existing VASPs can operate under their current licenses during the transition period, they must ensure that they submit their CASP license applications before the end of this period to avoid interruptions in service.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In summary, existing providers have until the end of 2025 to transition to a MiCA CASP license while continuing their operations, provided they apply for the new license in a timely manner.&lt;/p&gt;

&lt;h2&gt;
  
  
  Implementing Regulations
&lt;/h2&gt;

&lt;p&gt;Welcome to the EU bureaucracy! Below is a comprehensive list of all EU regulations that supplement or implement MiCA:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R1503/present/text" rel="noopener noreferrer"&gt;Commission Delegated Regulation (EU) 2024/1503 of 22 February 2024 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council by specifying the fees charged by the European Banking Authority to issuers of significant asset-referenced tokens and issuers of significant e-money tokens&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R1504/present/text" rel="noopener noreferrer"&gt;Commission Delegated Regulation (EU) 2024/1504 of 22 February 2024 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council by specifying the procedural rules for the exercise of the power to impose fines or periodic penalty payments by the European Banking Authority on issuers of significant asset-referenced tokens and issuers of significant e-money tokens&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.eurlexa.com/act/en/32024R1506/present/text" rel="noopener noreferrer"&gt;Commission Delegated Regulation (EU) 2024/1506 of 22 February 2024 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council by specifying certain criteria for classifying asset-referenced tokens and e-money tokens as significant&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R1507/present/text" rel="noopener noreferrer"&gt;Commission Delegated Regulation (EU) 2024/1507 of 22 February 2024 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council by specifying the criteria and factors to be taken into account by the European Securities Markets Authority, the European Banking Authority and competent authorities in relation to their intervention powers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R2494/present/text" rel="noopener noreferrer"&gt;Commission Implementing Regulation (EU) 2024/2494 of 24 September 2024 laying down implementing technical standards for the application of Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to standard forms, templates and procedures for the cooperation and exchange of information between competent authorities and EBA and ESMA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R2545/present/text" rel="noopener noreferrer"&gt;Commission Implementing Regulation (EU) 2024/2545 of 24 September 2024 laying down implementing technical standards for the application of Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to standard forms, templates and procedures for the cooperation and exchange of information between competent authorities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R2861/present/text" rel="noopener noreferrer"&gt;Commission Implementing Regulation (EU) 2024/2861 of 12 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to the technical means for the appropriate public disclosure of inside information and for delaying the public disclosure of that information&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R2902/present/text" rel="noopener noreferrer"&gt;Commission Implementing Regulation (EU) 2024/2902 of 20 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to reporting related to asset-referenced tokens and to e-money tokens denominated in a currency that is not an official currency of a Member State&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eurlexa.com/act/en/32024R2984/present/text" rel="noopener noreferrer"&gt;Commission Implementing Regulation (EU) 2024/2984 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to forms, formats and templates for the crypto-asset white papers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;In summary, MiCA aims to create one transparent environment for crypto assets within the EU. As the regulation comes into full effect in 2025, it will significantly shape how crypto-asset service providers operate in Europe, hopefully fostering innovation while ensuring accountability within the market.&lt;/p&gt;

&lt;p&gt;Disclosure: I am a member of &lt;a href="https://www.eurlexa.com/" rel="noopener noreferrer"&gt;eurlexa&lt;/a&gt; team. On Eurlexa you can access and search EU regulations and directives with ease. Eurlexa is a mobile-optimized, user-friendly alternative to EU offical and rather cumbersome EUR-Lex.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>🇪🇺 8 EU Regulations Every Developer Must Know ⚖️💻</title>
      <dc:creator>eurlexa</dc:creator>
      <pubDate>Tue, 14 Jan 2025 18:03:45 +0000</pubDate>
      <link>https://dev.to/eurlexa/8-eu-regulations-every-developer-must-know-194m</link>
      <guid>https://dev.to/eurlexa/8-eu-regulations-every-developer-must-know-194m</guid>
      <description>&lt;p&gt;(This is a repost under the new Eurlexa Team profile, where we aim to centralize all posts related to Eurlexa.)&lt;/p&gt;

&lt;p&gt;Recently, I was involved in coverage of specific rules and regulations that web pages or applications in the EU must adhere to. I thought it might be interesting for others as well to know the most important EU legal rules for IT and web developers.&lt;/p&gt;

&lt;p&gt;Sometimes these Directives and Regulations sets only the basic framework and have many implementing technical regulations as you can learn bellow.&lt;/p&gt;

&lt;p&gt;The most important EU regulations and directives that may affect development are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Directive on Privacy and Electronic Communications &lt;/li&gt;
&lt;li&gt;General Data Protection Regulation&lt;/li&gt;
&lt;li&gt;Artificial Intelligence Act&lt;/li&gt;
&lt;li&gt;Digital Services Act&lt;/li&gt;
&lt;li&gt;Digital Markets Act&lt;/li&gt;
&lt;li&gt;Cyber Resilience Act&lt;/li&gt;
&lt;li&gt;Directive on Measures for a High Common Level of Cybersecurity&lt;/li&gt;
&lt;li&gt;Regulation on Digital Operational Resilience&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Directive on Privacy and Electronic Communications
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32002L0058/present/text" rel="noopener noreferrer"&gt;Cookie Directive&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32002L0058/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32002L0058/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32002L0058/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;Cookie Directive&lt;/em&gt;, &lt;em&gt;ePrivacy Directive&lt;/em&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Any service that uses cookies (other than strictly necessary cookies) or similar tracking technologies, and companies providing electronic communications services&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cookies other than strictly necessary ones stored on a user’s device require the user's consent&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  General Data Protection Regulation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32016R0679/present/text" rel="noopener noreferrer"&gt;GDPR&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32016R0679/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32016R0679/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32016R0679/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;GDPR&lt;/em&gt;, &lt;em&gt;Data Protection Regulation&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Anyone who collects or processes personal data, regardless of their form, size, or sector&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cases when you send personal data outside the EU (this may include the full user IP address to Google, Vercel, etc.)&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Artificial Intelligence Act
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32024R1689/present/text" rel="noopener noreferrer"&gt;AI Act&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32024R1689/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32024R1689/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32024R1689/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;AI Act&lt;/em&gt;, &lt;em&gt;Artificial Intelligence Act&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Developers or providers of AI systems, especially those classified as high-risk or unacceptable risk&lt;/li&gt;
&lt;li&gt;Companies across various sectors that utilize AI technologies for decision-making, customer interaction, or operational efficiency &lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Severe penalties for non-compliance, including fines up to €35 million or 7% of global annual turnover&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Digital Services Act
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32022R2065/present/text" rel="noopener noreferrer"&gt;DSA&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32022R2065/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32022R2065/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32022R2065/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act)&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;DSA&lt;/em&gt;, &lt;em&gt;DSA Regulation&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Online platforms and very large online platforms (VLOPs)&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;FAANG (Facebook, Amazon, Apple, Netflix, Google) or MAMAA (Meta, Apple, Microsoft, Amazon, Alphabet)&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Digital Markets Act
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32022R1925/present/text" rel="noopener noreferrer"&gt;DMA&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32022R1925/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32022R1925/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32022R1925/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act)&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;DMA&lt;/em&gt;, &lt;em&gt;DMA Regulation&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Gatekeeper platforms&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Alphabet (Google), Amazon, Apple, ByteDance (TikTok), Meta (Facebook) and Microsoft&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Cyber Resilience Act
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32024R2847/present/text" rel="noopener noreferrer"&gt;CRA&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32024R2847/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32024R2847/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32024R2847/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;CRA&lt;/em&gt;, &lt;em&gt;CRA Directive&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;manufacturers, importers and distributors of products with digital elements having data connection to a device or network&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt; Organizations involved in developing open-source software intended for commercial use must implement cybersecurity policies and procedures as well&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Directive on Measures for a High Common Level of Cybersecurity
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32022L2555/present/text" rel="noopener noreferrer"&gt;NIS 2&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32022L2555/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32022L2555/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32022L2555/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;NIS 2&lt;/em&gt;, &lt;em&gt;NIS 2 Directive&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Companies in essential sectors such as energy, transport, healthcare, cloud computing services, internet service providers (ISPs), financial services, food production and distribution, chemicals production&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Organizations must report significant incidents not only to national authorities but also to affected service recipients without undue delay&lt;/li&gt;
&lt;li&gt;entities are required to assess the cybersecurity posture of their suppliers&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Regulation on Digital Operational Resilience
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Current consolidated version: &lt;a href="https://www.eurlexa.com/act/en/32022R2554/present/text" rel="noopener noreferrer"&gt;DORA&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Implementing regulations: &lt;a href="https://www.eurlexa.com/act/en/32022R2554/present/info#all-based-on" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Judicial precedents: &lt;a href="https://www.eurlexa.com/act/en/32022R2554/present/info#affected-by-case" rel="noopener noreferrer"&gt;link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Amendments and corrections: &lt;a href="https://www.eurlexa.com/act/en/32022R2554/present/timeline" rel="noopener noreferrer"&gt;link&lt;/a&gt; &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Full title: &lt;em&gt;Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Also known as: &lt;em&gt;DORA&lt;/em&gt;, &lt;em&gt;DORA Regulation&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Who should be concerned?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Financial Institutions and their IT services providers&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Financial institutions must establish rigorous oversight mechanisms and ensure that their vendors comply with DORA&lt;/li&gt;
&lt;li&gt;Financial institutions have to report their key IT vendros to regulators&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;p&gt;So, if you are asked to deliver IT services to a financial institution in the EU, and the project includes AI models for customers' payment terminals data, including an accompanying web app and phone app, as well as servers and database hosted outside of the EU, God bless you.&lt;/p&gt;

&lt;p&gt;Disclosure: I am a member of &lt;a href="https://www.eurlexa.com/" rel="noopener noreferrer"&gt;eurlexa&lt;/a&gt; team. On Eurlexa you can access and search EU regulations and directives with ease. Eurlexa is a mobile-optimized, user-friendly alternative to EU offical and rather cumbersome EUR-Lex.&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
