EULAW

European Regulation published on http://eur-lex.europa.eu/

Issues
Issuetype Summary Source
Regulation REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance)
Regulation REGULATION (EU) 2024/1624 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (Text with EEA relevance)
Regulation REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (Text with EEA relevance)
Regulation REGULATION (EU) 2023/2854 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) (Text with EEA relevance)
Regulation REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)
Regulation DIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (Text with EEA relevance)
Regulation REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) (Text with EEA relevance)
Regulation REGULATION (EU) 2019/2088 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 November 2019 on sustainability‐related disclosures in the financial services sector (Text with EEA relevance)
Regulation DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (Text with EEA relevance)
Regulation COMMISSION IMPLEMENTING REGULATION (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat (Text with EEA relevance)
Regulation COMMISSION IMPLEMENTING REGULATION (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information (Text with EEA relevance)
Regulation COMMISSION DELEGATED REGULATION (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition (Text with EEA relevance)
Regulation COMMISSION DELEGATED REGULATION (EU) 2025/532 of 24 March 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions (Text with EEA relevance)
Regulation COMMISSION DELEGATED REGULATION (EU) 2025/420 of 16 December 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards to specify the criteria for determining the composition of the joint examination team ensuring a balanced participation of staff members from the ESAs and from the relevant competent authorities, their designation, tasks and working arrangements (Text with EEA relevance)
Regulation COMMISSION DELEGATED REGULATION (EU) 2025/295 of 24 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards on harmonisation of conditions enabling the conduct of the oversight activities (Text with EEA relevance)
Regulation COMMISSION DELEGATED REGULATION (EU) 2024/1502 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by specifying the criteria for the designation of ICT third-party service providers as critical for financial entities (Text with EEA relevance)
Regulation COMMISSION DELEGATED REGULATION (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents (Text with EEA relevance)

REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance)

Issues
Summary Source
+ REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance)
---+ Preamble: 1
---+ CHAPTER I GENERAL PROVISIONS
------+ Article 1 Subject matter`
------+ Article 2 Scope
------+ Article 3 Definitions
------+ Article 4 AI literacy
---+ CHAPTER II PROHIBITED AI PRACTICES
------+ Article 5 Prohibited AI practices
---+ CHAPTER III HIGH-RISK AI SYSTEMS
------+ SECTION 1 Classification of AI systems as high-risk
---------+ Article 6 Classification rules for high-risk AI systems
---------+ Article 7 Amendments to Annex III
------+ SECTION 2 Requirements for high-risk AI systems
---------+ Article 8 Compliance with the requirements
---------+ Article 9 Risk management system
---------+ Article 10 Data and data governance
---------+ Article 11 Technical documentation
---------+ Article 12 Record-keeping
---------+ Article 13 Transparency and provision of information to deployers
---------+ Article 14 Human oversight
---------+ Article 15 Accuracy, robustness and cybersecurity
------+ SECTION 3 Obligations of providers and deployers of high-risk AI systems and other parties
---------+ Article 16 Obligations of providers of high-risk AI systems
---------+ Article 17 Quality management system
---------+ Article 18 Documentation keeping
---------+ Article 19 Automatically generated logs
---------+ Article 20 Corrective actions and duty of information
---------+ Article 21 Cooperation with competent authorities
---------+ Article 22 Authorised representatives of providers of high-risk AI systems
---------+ Article 23 Obligations of importers
---------+ Article 24 Obligations of distributors
---------+ Article 25 Responsibilities along the AI value chain
---------+ Article 26 Obligations of deployers of high-risk AI systems
---------+ Article 27 Fundamental rights impact assessment for high-risk AI systems
------+ SECTION 4 Notifying authorities and notified bodies
---------+ Article 28 Notifying authorities
---------+ Article 29 Application of a conformity assessment body for notification
---------+ Article 30 Notification procedure
---------+ Article 31 Requirements relating to notified bodies
---------+ Article 32 Presumption of conformity with requirements relating to notified bodies
---------+ Article 33 Subsidiaries of notified bodies and subcontracting
---------+ Article 34 Operational obligations of notified bodies
---------+ Article 35 Identification numbers and lists of notified bodies
---------+ Article 36 Changes to notifications
---------+ Article 37 Challenge to the competence of notified bodies
---------+ Article 38 Coordination of notified bodies
---------+ Article 39 Conformity assessment bodies of third countries
------+ SECTION 5 Standards, conformity assessment, certificates, registration
---------+ Article 40 Harmonised standards and standardisation deliverables
---------+ Article 41 Common specifications
---------+ Article 42 Presumption of conformity with certain requirements
---------+ Article 43 Conformity assessment
---------+ Article 44 Certificates
---------+ Article 45 Information obligations of notified bodies
---------+ Article 46 Derogation from conformity assessment procedure
---------+ Article 47 EU declaration of conformity
---------+ Article 48 CE marking
---------+ Article 49 Registration
---+ CHAPTER IV TRANSPARENCY OBLIGATIONS FOR PROVIDERS AND DEPLOYERS OF CERTAIN AI SYSTEMS
------+ Article 50 Transparency obligations for providers and deployers of certain AI systems
---+ CHAPTER V GENERAL-PURPOSE AI MODELS
------+ SECTION 1 Classification rules
---------+ Article 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk
---------+ Article 52 Procedure
------+ SECTION 2 Obligations for providers of general-purpose AI models
---------+ Article 53 Obligations for providers of general-purpose AI models
---------+ Article 54 Authorised representatives of providers of general-purpose AI models
------+ SECTION 3 Obligations of providers of general-purpose AI models with systemic risk
---------+ Article 55 Obligations of providers of general-purpose AI models with systemic risk
------+ SECTION 4 Codes of practice
---------+ Article 56 Codes of practice
---+ CHAPTER VI MEASURES IN SUPPORT OF INNOVATION
------+ Article 57 AI regulatory sandboxes
------+ Article 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes
------+ Article 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
------+ Article 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes
------+ Article 61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes
------+ Article 62 Measures for providers and deployers, in particular SMEs, including start-ups
------+ Article 63 Derogations for specific operators
---+ CHAPTER VII GOVERNANCE
------+ SECTION 1 Governance at Union level
---------+ Article 64 AI Office
---------+ Article 65 Establishment and structure of the European Artificial Intelligence Board
---------+ Article 66 Tasks of the Board
---------+ Article 67 Advisory forum
---------+ Article 68 Scientific panel of independent experts
---------+ Article 69 Access to the pool of experts by the Member States
------+ SECTION 2 National competent authorities
---------+ Article 70 Designation of national competent authorities and single points of contact
---+ CHAPTER VIII EU DATABASE FOR HIGH-RISK AI SYSTEMS
------+ Article 71 EU database for high-risk AI systems listed in Annex III
---+ CHAPTER IX POST-MARKET MONITORING, INFORMATION SHARING AND MARKET SURVEILLANCE
------+ SECTION 1 Post-market monitoring
---------+ Article 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
------+ SECTION 2 Sharing of information on serious incidents
---------+ Article 73 Reporting of serious incidents
------+ SECTION 3 Enforcement
---------+ Article 74 Market surveillance and control of AI systems in the Union market
---------+ Article 75 Mutual assistance, market surveillance and control of general-purpose AI systems
---------+ Article 76 Supervision of testing in real world conditions by market surveillance authorities
---------+ Article 77 Powers of authorities protecting fundamental rights
---------+ Article 78 Confidentiality
---------+ Article 79 Procedure at national level for dealing with AI systems presenting a risk
---------+ Article 80 Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III
---------+ Article 81 Union safeguard procedure
---------+ Article 82 Compliant AI systems which present a risk
---------+ Article 83 Formal non-compliance
---------+ Article 84 Union AI testing support structures
------+ SECTION 4 Remedies
---------+ Article 85 Right to lodge a complaint with a market surveillance authority
---------+ Article 86 Right to explanation of individual decision-making
---------+ Article 87 Reporting of infringements and protection of reporting persons
------+ SECTION 5 Supervision, investigation, enforcement and monitoring in respect of providers of general-purpose AI models
---------+ Article 88 Enforcement of the obligations of providers of general-purpose AI models
---------+ Article 89 Monitoring actions
---------+ Article 90 Alerts of systemic risks by the scientific panel
---------+ Article 91 Power to request documentation and information
---------+ Article 92 Power to conduct evaluations
---------+ Article 93 Power to request measures
---------+ Article 94 Procedural rights of economic operators of the general-purpose AI model
---+ CHAPTER X CODES OF CONDUCT AND GUIDELINES
------+ Article 95 Codes of conduct for voluntary application of specific requirements
------+ Article 96 Guidelines from the Commission on the implementation of this Regulation
---+ CHAPTER XI DELEGATION OF POWER AND COMMITTEE PROCEDURE
------+ Article 97 Exercise of the delegation
------+ Article 98 Committee procedure
---+ CHAPTER XII PENALTIES
------+ Article 99 Penalties
------+ Article 100 Administrative fines on Union institutions, bodies, offices and agencies
------+ Article 101 Fines for providers of general-purpose AI models
---+ CHAPTER XIII FINAL PROVISIONS
------+ Article 102 Amendment to Regulation (EC) No 300/2008
------+ Article 103 Amendment to Regulation (EU) No 167/2013
------+ Article 104 Amendment to Regulation (EU) No 168/2013
------+ Article 105 Amendment to Directive 2014/90/EU
------+ Article 106 Amendment to Directive (EU) 2016/797
------+ Article 107 Amendment to Regulation (EU) 2018/858
------+ Article 108 Amendments to Regulation (EU) 2018/1139
------+ Article 109 Amendment to Regulation (EU) 2019/2144
------+ Article 110 Amendment to Directive (EU) 2020/1828
------+ Article 111 AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked
------+ Article 112 Evaluation and review
------+ Article 113 Entry into force and application

REGULATION (EU) 2024/1624 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (Text with EEA relevance)

Issues
Summary Source
+ REGULATION (EU) 2024/1624 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (Text with EEA relevance)
---+ Preamble: 1
---+ CHAPTER I GENERAL PROVISIONS
------+ SECTION 1 Subject matter and definitions
---------+ Article 1 Subject matter
---------+ Article 2 Definitions
------+ SECTION 2 Scope
---------+ Article 3 Obliged entities
---------+ Article 4 Exemptions for certain providers of gambling services
---------+ Article 5 Exemptions for certain professional football clubs
---------+ Article 6 Exemptions for certain financial activities
---------+ Article 7 Prior notification of exemptions
------+ SECTION 3 Cross-border operations
---------+ Article 8 Notification of cross-border operations and application of national law
---+ CHAPTER II INTERNAL POLICIES, PROCEDURES AND CONTROLS OF OBLIGED ENTITIES
------+ SECTION 1 Internal policies, procedures and controls, risk assessment and staff
---------+ Article 9 Scope of internal policies, procedures and controls
---------+ Article 10 Business-wide risk assessment
---------+ Article 11 Compliance functions
---------+ Article 12 Awareness of requirements
---------+ Article 13 Integrity of employees
---------+ Article 14 Reporting of breaches and protection of reporting persons
---------+ Article 15 Situation of specific employees
------+ SECTION 2 Provisions applying to groups
---------+ Article 16 Group-wide requirements
---------+ Article 17 Branches and subsidiaries in third countries
------+ SECTION 3 Outsourcing
---------+ Article 18 Outsourcing
---+ CHAPTER III CUSTOMER DUE DILIGENCE
------+ SECTION 1 General provisions
---------+ Article 19 Application of customer due diligence measures
---------+ Article 20 Customer due diligence measures
---------+ Article 21 Inability to comply with the requirement to apply customer due diligence measures
---------+ Article 22 Identification and verification of the identity of customers and beneficial owners
---------+ Article 23 Timing of the verification of the customer and beneficial owner identity
---------+ Article 24 Reporting of discrepancies with information contained in beneficial ownership registers
---------+ Article 25 Identification of the purpose and intended nature of a business relationship or occasional transaction
---------+ Article 26 Ongoing monitoring of the business relationship and monitoring of transactions performed by customers
---------+ Article 27 Temporary measures for customers subject to UN financial sanctions
---------+ Article 28 Regulatory technical standards on the information necessary for the performance of customer due diligence
------+ SECTION 2 Third-country policy and money laundering and terrorist financing threats from outside the Union
---------+ Article 29 Identification of third countries with significant strategic deficiencies in their national AML/CFT regimes
---------+ Article 30 Identification of third countries with compliance weaknesses in their national AML/CFT regimes
---------+ Article 31 Identification of third countries posing a specific and serious threat to the Union’s financial system
---------+ Article 32 Guidelines on money laundering and terrorist financing risks, trends and methods
------+ SECTION 3 Simplified due diligence
---------+ Article 33 Simplified due diligence measures
------+ SECTION 4 Enhanced due diligence
---------+ Article 34 Scope of application of enhanced due diligence measures
---------+ Article 35 Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union
---------+ Article 36 Specific enhanced due diligence measures for cross-border correspondent relationships
---------+ Article 37 Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers
---------+ Article 38 Specific measures for individual third-country respondent institutions
---------+ Article 39 Prohibition of correspondent relationships with shell institutions
---------+ Article 40 Measures to mitigate risks in relation to transactions with a self-hosted address
---------+ Article 41 Specific provisions regarding applicants for residence by investment schemes
---------+ Article 42 Specific provisions regarding politically exposed persons
---------+ Article 43 List of prominent public functions
---------+ Article 44 Politically exposed persons who are beneficiaries of insurance policies
---------+ Article 45 Measures for persons who cease to be politically exposed persons
---------+ Article 46 Family members and persons known to be close associates of politically exposed persons
------+ SECTION 5 Specific customer due diligence provisions
---------+ Article 47 Specifications for the life and other investment-related insurance sector
------+ SECTION 6 Reliance on customer due diligence performed by other obliged entities
---------+ Article 48 General provisions relating to reliance on other obliged entities
---------+ Article 49 Process of reliance on another obliged entity
---------+ Article 50 Guidelines on reliance on other obliged entities
---+ CHAPTER IV BENEFICIAL OWNERSHIP TRANSPARENCY
------+ Article 51 Identification of beneficial owners for legal entities
------+ Article 52 Beneficial ownership through ownership interest
------+ Article 53 Beneficial ownership through control
------+ Article 54 Coexistence of ownership interest and control in the ownership structure
------+ Article 55 Ownership structures involving legal arrangements or similar legal entities
------+ Article 56 Notifications
------+ Article 57 Identification of beneficial owners for legal entities similar to express trust
------+ Article 58 Identification of beneficial owners for express trusts and similar legal arrangements
------+ Article 59 Identification of a class of beneficiaries
------+ Article 60 Identification of objects of a power and default takers in discretionary trusts
------+ Article 61 Identification of beneficial owners of collective investment undertakings
------+ Article 62 Beneficial ownership information
------+ Article 63 Obligations of legal entities
------+ Article 64 Trustee obligations
------+ Article 65 Exceptions to obligations of legal entities and legal arrangements
------+ Article 66 Nominee obligations
------+ Article 67 Foreign legal entities and foreign legal arrangements
------+ Article 68 Penalties
---+ CHAPTER V REPORTING OBLIGATIONS
------+ Article 69 Reporting of suspicions
------+ Article 70 Specific provisions for reporting of suspicions by certain categories of obliged entities
------+ Article 71 Refraining from carrying out transactions
------+ Article 72 Disclosure to FIU
------+ Article 73 Prohibition of disclosure
------+ Article 74 Threshold-based reports of transactions in certain high-value goods
---+ CHAPTER VI INFORMATION SHARING
------+ Article 75 Exchange of information in the framework of partnerships for information sharing
---+ CHAPTER VII DATA PROTECTION AND RECORD RETENTION
------+ Article 76 Processing of personal data
------+ Article 77 Record retention
------+ Article 78 Provision of records to competent authorities
---+ CHAPTER VIII MEASURES TO MITIGATE RISKS DERIVING FROM ANONYMOUS INSTRUMENTS
------+ Article 79 Anonymous accounts and bearer shares and bearer share warrants
------+ Article 80 Limits to large cash payments in exchange for goods or services
---+ CHAPTER IX FINAL PROVISIONS
------+ SECTION 1 Cooperation between FIUs and the EPPO
---------+ Article 81 Cooperation between FIUs and the EPPO
---------+ Article 82 Requests for information to the EPPO
------+ SECTION 2 Cooperation between FIUs and OLAF
---------+ Article 83 Cooperation between FIUs and OLAF
---------+ Article 84 Requests for information to OLAF
------+ SECTION 3 Other provisions
---------+ Article 85 Exercise of the delegation
---------+ Article 86 Committee procedure
---------+ Article 87 Review
---------+ Article 88 Reports
---------+ Article 89 Relation to Directive (EU) 2015/849
---------+ Article 90 Entry into force and application

REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (Text with EEA relevance)

Issues
Summary Source
+ REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (Text with EEA relevance)
---+ Preamble: 1
---+ CHAPTER I GENERAL PROVISIONS
------+ Article 1 Subject matter
------+ Article 2 Scope
------+ Article 3 Definitions
------+ Article 4 Free movement
------+ Article 5 Procurement or use of products with digital elements
------+ Article 6 Requirements for products with digital elements
------+ Article 7 Important products with digital elements
------+ Article 8 Critical products with digital elements
------+ Article 9 Stakeholder consultation
------+ Article 10 Enhancing skills in a cyber resilient digital environment
------+ Article 11 General product safety
------+ Article 12 High-risk AI systems
---+ CHAPTER II OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
------+ Article 13 Obligations of manufacturers
------+ Article 14 Reporting obligations of manufacturers
------+ Article 15 Voluntary reporting
------+ Article 16 Establishment of a single reporting platform
------+ Article 17 Other provisions related to reporting
------+ Article 18 Authorised representatives
------+ Article 19 Obligations of importers
------+ Article 20 Obligations of distributors
------+ Article 21 Cases in which obligations of manufacturers apply to importers and distributors
------+ Article 22 Other cases in which obligations of manufacturers apply
------+ Article 23 Identification of economic operators
------+ Article 24 Obligations of open-source software stewards
------+ Article 25 Security attestation of free and open-source software
------+ Article 26 Guidance
---+ CHAPTER III CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
------+ Article 27 Presumption of conformity
------+ Article 28 EU declaration of conformity
------+ Article 29 General principles of the CE marking
------+ Article 30 Rules and conditions for affixing the CE marking
------+ Article 31 Technical documentation
------+ Article 32 Conformity assessment procedures for products with digital elements
------+ Article 33 Support measures for microenterprises and small and medium-sized enterprises, including start-ups
------+ Article 34 Mutual recognition agreements
---+ CHAPTER IV NOTIFICATION OF CONFORMITY ASSESSMENT BODIES
------+ Article 35 Notification
------+ Article 36 Notifying authorities
------+ Article 37 Requirements relating to notifying authorities
------+ Article 38 Information obligation on notifying authorities
------+ Article 39 Requirements relating to notified bodies
------+ Article 40 Presumption of conformity of notified bodies
------+ Article 41 Subsidiaries of and subcontracting by notified bodies
------+ Article 42 Application for notification
------+ Article 43 Notification procedure
------+ Article 44 Identification numbers and lists of notified bodies
------+ Article 45 Changes to notifications
------+ Article 46 Challenge of the competence of notified bodies
------+ Article 47 Operational obligations of notified bodies
------+ Article 48 Appeal against decisions of notified bodies
------+ Article 49 Information obligation on notified bodies
------+ Article 50 Exchange of experience
------+ Article 51 Coordination of notified bodies
---+ CHAPTER V MARKET SURVEILLANCE AND ENFORCEMENT
------+ Article 52 Market surveillance and control of products with digital elements in the Union market
------+ Article 53 Access to data and documentation
------+ Article 54 Procedure at national level concerning products with digital elements presenting a significant cybersecurity risk
------+ Article 55 Union safeguard procedure
------+ Article 56 Procedure at Union level concerning products with digital elements presenting a significant cybersecurity risk
------+ Article 57 Compliant products with digital elements which present a significant cybersecurity risk
------+ Article 58 Formal non-compliance
------+ Article 59 Joint activities of market surveillance authorities
------+ Article 60 Sweeps
---+ CHAPTER VI DELEGATED POWERS AND COMMITTEE PROCEDURE
------+ Article 61 Exercise of the delegation
------+ Article 62 Committee procedure
---+ CHAPTER VII CONFIDENTIALITY AND PENALTIES
------+ Article 63 Confidentiality
------+ Article 64 Penalties
------+ Article 65 Representative actions
---+ CHAPTER VIII TRANSITIONAL AND FINAL PROVISIONS
------+ Article 66 Amendment to Regulation (EU) 2019/1020
------+ Article 67 Amendment to Directive (EU) 2020/1828
------+ Article 68 Amendment to Regulation (EU) No 168/2013
------+ Article 69 Transitional provisions
------+ Article 70 Evaluation and review
------+ Article 71 Entry into force and application

REGULATION (EU) 2023/2854 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) (Text with EEA relevance)

Issues
Summary Source
+ REGULATION (EU) 2023/2854 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) (Text with EEA relevance)
---+ Preamble: 1
---+ CHAPTER I GENERAL PROVISIONS
------+ Article 1 Subject matter and scope
------+ Article 2 Definitions
---+ CHAPTER II BUSINESS TO CONSUMER AND BUSINESS TO BUSINESS DATA SHARING
------+ Article 3 Obligation to make product data and related service data accessible to the user
------+ Article 4 The rights and obligations of users and data holders with regard to access, use and making available product data and related service data
------+ Article 5 Right of the user to share data with third parties
------+ Article 6 Obligations of third parties receiving data at the request of the user
------+ Article 7 Scope of business-to-consumer and business-to-business data sharing obligations
---+ CHAPTER III OBLIGATIONS FOR DATA HOLDERS OBLIGED TO MAKE DATA AVAILABLE PURSUANT TO UNION LAW
------+ Article 8 Conditions under which data holders make data available to data recipients
------+ Article 9 Compensation for making data available
------+ Article 10 Dispute settlement
------+ Article 11 Technical protection measures on the unauthorised use or disclosure of data
------+ Article 12 Scope of obligations for data holders obliged pursuant to Union law to make data available
---+ CHAPTER IV UNFAIR CONTRACTUAL TERMS RELATED TO DATA ACCESS AND USE BETWEEN ENTERPRISES
------+ Article 13 Unfair contractual terms unilaterally imposed on another enterprise
---+ CHAPTER V MAKING DATA AVAILABLE TO PUBLIC SECTOR BODIES, THE COMMISSION, THE EUROPEAN CENTRAL BANK AND UNION BODIES ON THE BASIS OF AN EXCEPTIONAL NEED
------+ Article 14 Obligation to make data available on the basis of an exceptional need
------+ Article 15 Exceptional need to use data
------+ Article 16 Relationship with other obligations to make data available to public sector bodies, the Commission, the European Central Bank and Union bodies
------+ Article 17 Requests for data to be made available
------+ Article 18 Compliance with requests for data
------+ Article 19 Obligations of public sector bodies, the Commission, the European Central Bank and Union bodies
------+ Article 20 Compensation in cases of an exceptional need
------+ Article 21 Sharing of data obtained in the context of an exceptional need with research organisations or statistical bodies
------+ Article 22 Mutual assistance and cross-border cooperation
---+ CHAPTER VI SWITCHING BETWEEN DATA PROCESSING SERVICES
------+ Article 23 Removing obstacles to effective switching
------+ Article 24 Scope of the technical obligations
------+ Article 25 Contractual terms concerning switching
------+ Article 26 Information obligation of providers of data processing services
------+ Article 27 Obligation of good faith
------+ Article 28 Contractual transparency obligations on international access and transfer
------+ Article 29 Gradual withdrawal of switching charges
------+ Article 30 Technical aspects of switching
------+ Article 31 Specific regime for certain data processing services
---+ CHAPTER VII UNLAWFUL INTERNATIONAL GOVERNMENTAL ACCESS AND TRANSFER OF NON-PERSONAL DATA
------+ Article 32 International governmental access and transfer
---+ CHAPTER VIII INTEROPERABILITY
------+ Article 33 Essential requirements regarding interoperability of data, of data sharing mechanisms and services, as well as of common European data spaces
------+ Article 34 Interoperability for the purposes of in-parallel use of data processing services
------+ Article 35 Interoperability of data processing services
------+ Article 36 Essential requirements regarding smart contracts for executing data sharing agreements
---+ CHAPTER IX IMPLEMENTATION AND ENFORCEMENT
------+ Article 37 Competent authorities and data coordinators
------+ Article 38 Right to lodge a complaint
------+ Article 39 Right to an effective judicial remedy
------+ Article 40 Penalties
------+ Article 41 Model contractual terms and standard contractual clauses
------+ Article 42 Role of the EDIB
---+ CHAPTER X SUI GENERIS RIGHT UNDER DIRECTIVE 96/9/EC
------+ Article 43 Databases containing certain data
---+ CHAPTER XI FINAL PROVISIONS
------+ Article 44 Other Union legal acts governing rights and obligations on data access and use
------+ Article 45 Exercise of the delegation
------+ Article 46 Committee procedure
------+ Article 47 Amendment to Regulation (EU) 2017/2394
------+ Article 48 Amendment to Directive (EU) 2020/1828
------+ Article 49 Evaluation and review
------+ Article 50 Entry into force and application

REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)

Issues
Summary Source
+ REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)
---+ CHAPTER I General provisions
------+ Article 1 Subject-matter and objectives
------+ Article 2 Material scope
------+ Article 3 Territorial scope
------+ Article 4 Definitions
---+ CHAPTER II Principles
------+ Article 5 Principles relating to processing of personal data
------+ Article 6 Lawfulness of processing
------+ Article 7 Conditions for consent
------+ Article 8 Conditions applicable to child's consent in relation to information society services
------+ Article 9 Processing of special categories of personal data
------+ Article 10 Processing of personal data relating to criminal convictions and offences
------+ Article 11 Processing which does not require identification
---+ CHAPTER III Rights of the data subject
------+ Section 1 Transparency and modalities
---------+ Article 12 Transparent information, communication and modalities for the exercise of the rights of the data subject
------+ Section 2 Information and access to personal data
---------+ Article 13 Information to be provided where personal data are collected from the data subject
---------+ Article 14 Information to be provided where personal data have not been obtained from the data subject
---------+ Article 15 Right of access by the data subject
------+ Section 3 Rectification and erasure
---------+ Article 16 Right to rectification
---------+ Article 17 Right to erasure (‘right to be forgotten’)
---------+ Article 18 Right to restriction of processing
---------+ Article 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing
---------+ Article 20 Right to data portability
------+ Section 4 Right to object and automated individual decision-making
---------+ Article 21 Right to object
---------+ Article 22 Automated individual decision-making, including profiling
------+ Section 5 Restrictions
---------+ Article 23 Restrictions
---+ CHAPTER IV Controller and processor
------+ Section 1 General obligations
---------+ Article 24 Responsibility of the controller
---------+ Article 25 Data protection by design and by default
---------+ Article 26 Joint controllers
---------+ Article 27 Representatives of controllers or processors not established in the Union
---------+ Article 28 Processor
---------+ Article 29 Processing under the authority of the controller or processor
---------+ Article 30 Records of processing activities
---------+ Article 31 Cooperation with the supervisory authority
------+ Section 2 Security of personal data
---------+ Article 32 Security of processing
---------+ Article 33 Notification of a personal data breach to the supervisory authority
---------+ Article 34 Communication of a personal data breach to the data subject
------+ Section 3 Data protection impact assessment and prior consultation
---------+ Article 35 Data protection impact assessment
---------+ Article 36 Prior consultation
------+ Section 4 Data protection officer
---------+ Article 37 Designation of the data protection officer
---------+ Article 38 Position of the data protection officer
---------+ Article 39 Tasks of the data protection officer
------+ Section 5 Codes of conduct and certification
---------+ Article 40 Codes of conduct
---------+ Article 41 Monitoring of approved codes of conduct
---------+ Article 42 Certification
---------+ Article 43 Certification bodies
---+ CHAPTER V Transfers of personal data to third countries or international organisations
------+ Article 44 General principle for transfers
------+ Article 45 Transfers on the basis of an adequacy decision
------+ Article 46 Transfers subject to appropriate safeguards
------+ Article 47 Binding corporate rules
------+ Article 48 Transfers or disclosures not authorised by Union law
------+ Article 49 Derogations for specific situations
------+ Article 50 International cooperation for the protection of personal data
---+ CHAPTER VI Independent supervisory authorities
------+ Section 1 Independent status
---------+ Article 51 Supervisory authority
---------+ Article 52 Independence
---------+ Article 53 General conditions for the members of the supervisory authority
---------+ Article 54 Rules on the establishment of the supervisory authority
------+ Section 2 Competence, tasks and powers
---------+ Article 55 Competence
---------+ Article 56 Competence of the lead supervisory authority
---------+ Article 57 Tasks
---------+ Article 58 Powers
---------+ Article 59 Activity reports
---+ CHAPTER VII Cooperation and consistency
------+ Section 1 Cooperation
---------+ Article 60 Cooperation between the lead supervisory authority and the other supervisory authorities concerned
---------+ Article 61 Mutual assistance
---------+ Article 62 Joint operations of supervisory authorities
------+ Section 2 Consistency
---------+ Article 63 Consistency mechanism
---------+ Article 64 Opinion of the Board
---------+ Article 65 Dispute resolution by the Board
---------+ Article 66 Urgency procedure
---------+ Article 67 Exchange of information
------+ Section 3 European data protection board
---------+ Article 68 European Data Protection Board
---------+ Article 69 Independence
---------+ Article 70 Tasks of the Board
---------+ Article 71 Reports
---------+ Article 72 Procedure
---------+ Article 73 Chair
---------+ Article 74 Tasks of the Chair
---------+ Article 75 Secretariat
---------+ Article 76 Confidentiality
---+ CHAPTER VIII Remedies, liability and penalties
------+ Article 77 Right to lodge a complaint with a supervisory authority
------+ Article 78 Right to an effective judicial remedy against a supervisory authority
------+ Article 79 Right to an effective judicial remedy against a controller or processor
------+ Article 80 Representation of data subjects
------+ Article 81 Suspension of proceedings
------+ Article 82 Right to compensation and liability
------+ Article 83 General conditions for imposing administrative fines
------+ Article 84 Penalties
---+ CHAPTER IX Provisions relating to specific processing situations
------+ Article 85 Processing and freedom of expression and information
------+ Article 86 Processing and public access to official documents
------+ Article 87 Processing of the national identification number
------+ Article 88 Processing in the context of employment
------+ Article 89 Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
------+ Article 90 Obligations of secrecy
------+ Article 91 Existing data protection rules of churches and religious associations
---+ CHAPTER X Delegated acts and implementing acts
------+ Article 92 Exercise of the delegation
------+ Article 93 Committee procedure
---+ CHAPTER XI Final provisions
------+ Article 94 Repeal of Directive 95/46/EC
------+ Article 95 Relationship with Directive 2002/58/EC
------+ Article 96 Relationship with previously concluded Agreements
------+ Article 97 Commission reports
------+ Article 98 Review of other Union legal acts on data protection
------+ Article 99 Entry into force and application

DIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (Text with EEA relevance)

Issues
Summary Source
+ DIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (Text with EEA relevance)
---+ CHAPTER I GENERAL PROVISIONS
------+ Article 1 Subject matter
------+ Article 2 Scope
------+ Article 3 Essential and important entities
------+ Article 4 Sector-specific Union legal acts
------+ Article 5 Minimum harmonisation
------+ Article 6 Definitions
---+ CHAPTER II COORDINATED CYBERSECURITY FRAMEWORKS
------+ Article 7 National cybersecurity strategy
------+ Article 8 Competent authorities and single points of contact
------+ Article 9 National cyber crisis management frameworks
------+ Article 10 Computer security incident response teams (CSIRTs)
------+ Article 11 Requirements, technical capabilities and tasks of CSIRTs
------+ Article 12 Coordinated vulnerability disclosure and a European vulnerability database
------+ Article 13 Cooperation at national level
---+ CHAPTER III COOPERATION AT UNION AND INTERNATIONAL LEVEL
------+ Article 14 Cooperation Group
------+ Article 15 CSIRTs network
------+ Article 16 European cyber crisis liaison organisation network (EU-CyCLONe)
------+ Article 17 International cooperation
------+ Article 18 Report on the state of cybersecurity in the Union
------+ Article 19 Peer reviews
---+ CHAPTER IV CYBERSECURITY RISK-MANAGEMENT MEASURES AND REPORTING OBLIGATIONS
------+ Article 20 Governance
------+ Article 21 Cybersecurity risk-management measures
------+ Article 22 Union level coordinated security risk assessments of critical supply chains
------+ Article 23 Reporting obligations
------+ Article 24 Use of European cybersecurity certification schemes
------+ Article 25 Standardisation
---+ CHAPTER V JURISDICTION AND REGISTRATION
------+ Article 26 Jurisdiction and territoriality
------+ Article 27 Registry of entities
------+ Article 28 Database of domain name registration data
---+ CHAPTER VI INFORMATION SHARING
------+ Article 29 Cybersecurity information-sharing arrangements
------+ Article 30 Voluntary notification of relevant information
---+ CHAPTER VII SUPERVISION AND ENFORCEMENT
------+ Article 31 General aspects concerning supervision and enforcement
------+ Article 32 Supervisory and enforcement measures in relation to essential entities
------+ Article 33 Supervisory and enforcement measures in relation to important entities
------+ Article 34 General conditions for imposing administrative fines on essential and important entities
------+ Article 35 Infringements entailing a personal data breach
------+ Article 36 Penalties
------+ Article 37 Mutual assistance
---+ CHAPTER VIII DELEGATED AND IMPLEMENTING ACTS
------+ Article 38 Exercise of the delegation
------+ Article 39 Committee procedure
---+ CHAPTER IX FINAL PROVISIONS
------+ Article 40 Review
------+ Article 41 Transposition
------+ Article 42 Amendment of Regulation (EU) No 910/2014
------+ Article 43 Amendment of Directive (EU) 2018/1972
------+ Article 44 Repeal
------+ Article 45 Entry into force
------+ Article 46 Addressees
---+ ANNEX I SECTORS OF HIGH CRITICALITY
---+ ANNEX II OTHER CRITICAL SECTORS
---+ ANNEX III CORRELATION TABLE

REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) (Text with EEA relevance)

Issues
Summary Source
+ REGULATION (EU) 2022/1925 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act) (Text with EEA relevance)
---+ CHAPTER I SUBJECT MATTER, SCOPE AND DEFINITIONS
------+ Article 1 Subject matter and scope
------+ Article 2 Definitions
---+ CHAPTER II GATEKEEPERS
------+ Article 3 Designation of gatekeepers
------+ Article 4 Review of the status of gatekeeper
---+ CHAPTER III PRACTICES OF GATEKEEPERS THAT LIMIT CONTESTABILITY OR ARE UNFAIR
------+ Article 5 Obligations for gatekeepers
------+ Article 6 Obligations for gatekeepers susceptible of being further specified under Article 8
------+ Article 7 Obligation for gatekeepers on interoperability of number-independent interpersonal communications services
------+ Article 8 Compliance with obligations for gatekeepers
------+ Article 9 Suspension
------+ Article 10 Exemption for grounds of public health and public security
------+ Article 11 Reporting
------+ Article 12 Updating obligations for gatekeepers
------+ Article 13 Anti-circumvention
------+ Article 14 Obligation to inform about concentrations
------+ Article 15 Obligation of an audit
---+ CHAPTER IV MARKET INVESTIGATION
------+ Article 16 Opening of a market investigation
------+ Article 17 Market investigation for designating gatekeepers
------+ Article 18 Market investigation into systematic non-compliance
------+ Article 19 Market investigation into new services and new practices
---+ CHAPTER V INVESTIGATIVE, ENFORCEMENT AND MONITORING POWERS
------+ Article 20 Opening of proceedings
------+ Article 21 Requests for information
------+ Article 22 Power to carry out interviews and take statements
------+ Article 23 Powers to conduct inspections
------+ Article 24 Interim measures
------+ Article 25 Commitments
------+ Article 26 Monitoring of obligations and measures
------+ Article 27 Information by third parties
------+ Article 28 Compliance function
------+ Article 29 Non-compliance
------+ Article 30 Fines
------+ Article 31 Periodic penalty payments
------+ Article 32 Limitation periods for the imposition of penalties
------+ Article 33 Limitation periods for the enforcement of penalties
------+ Article 34 Right to be heard and access to the file
------+ Article 35 Annual reporting
------+ Article 36 Professional secrecy
------+ Article 37 Cooperation with national authorities
------+ Article 38 Cooperation and coordination with national competent authorities enforcing competition rules
------+ Article 39 Cooperation with national courts
------+ Article 40 The high-level group
------+ Article 41 Request for a market investigation
------+ Article 42 Representative actions
------+ Article 43 Reporting of breaches and protection of reporting persons
---+ CHAPTER VI FINAL PROVISIONS
------+ Article 44 Publication of decisions
------+ Article 45 Review by the Court of Justice
------+ Article 46 Implementing provisions
------+ Article 47 Guidelines
------+ Article 48 Standardisation
------+ Article 49 Exercise of the delegation
------+ Article 50 Committee procedure
------+ Article 51 Amendment to Directive (EU) 2019/1937
------+ Article 52 Amendment to Directive (EU) 2020/1828
------+ Article 53 Review
------+ Article 54 Entry into force and application
---+ ANNEX

REGULATION (EU) 2019/2088 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 November 2019 on sustainability‐related disclosures in the financial services sector (Text with EEA relevance)

Issues
Summary Source
+ REGULATION (EU) 2019/2088 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 November 2019 on sustainability‐related disclosures in the financial services sector (Text with EEA relevance)
---+ Article 1 Subject matter
---+ Article 2 Definitions
---+ Article 2a Principle of do no significant harm
---+ Article 3 Transparency of sustainability risk policies
---+ Article 4 Transparency of adverse sustainability impacts at entity level
---+ Article 5 Transparency of remuneration policies in relation to the integration of sustainability risks
---+ Article 6 Transparency of the integration of sustainability risks
---+ Article 7 Transparency of adverse sustainability impacts at financial product level
---+ Article 8 Transparency of the promotion of environmental or social characteristics in pre‐contractual disclosures
---+ Article 9 Transparency of sustainable investments in pre‐contractual disclosures
---+ Article 10 Transparency of the promotion of environmental or social characteristics and of sustainable investments on websites
---+ Article 11 Transparency of the promotion of environmental or social characteristics and of sustainable investments in periodic reports
---+ Article 12 Review of disclosures
---+ Article 13 Marketing communications
---+ Article 14 Competent authorities
---+ Article 15 Transparency by IORPs and insurance intermediaries
---+ Article 16 Pension products covered by Regulations (EC) No 883/2004 and (EC) No 987/2009
---+ Article 17 Exemptions
---+ Article 18 Report
---+ Article 18a Accessibility of information on the European single access point
---+ Article 19 Evaluation
---+ Article 20 Entry into force and application

DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (Text with EEA relevance)

Issues
Summary Source
+ DIRECTIVE (EU) 2015/2366 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (Text with EEA relevance)
---+ TITLE I SUBJECT MATTER, SCOPE AND DEFINITIONS
------+ Article 1 Subject matter
------+ Article 2 Scope
------+ Article 3 Exclusions
------+ Article 4 Definitions
---+ TITLE II PAYMENT SERVICE PROVIDERS
------+ CHAPTER 1 Payment institutions
---------+ Section 1 General rules
------------+ Article 5 Applications for authorisation
------------+ Article 6 Control of the shareholding
------------+ Article 7 Initial capital
------------+ Article 8 Own funds
------------+ Article 9 Calculation of own funds
------------+ Article 10 Safeguarding requirements
------------+ Article 11 Granting of authorisation
------------+ Article 12 Communication of the decision
------------+ Article 13 Withdrawal of authorisation
------------+ Article 14 Registration in the home Member State
------------+ Article 15 EBA register
------------+ Article 16 Maintenance of authorisation
------------+ Article 17 Accounting and statutory audit
------------+ Article 18 Activities
---------+ Section 2 Other requirements
------------+ Article 19 Use of agents, branches or entities to which activities are outsourced
------------+ Article 20 Liability
------------+ Article 21 Record-keeping
---------+ Section 3 Competent authorities and supervision
------------+ Article 22 Designation of competent authorities
------------+ Article 23 Supervision
------------+ Article 24 Professional secrecy
------------+ Article 25 Right to apply to the courts
------------+ Article 26 Exchange of information
------------+ Article 27 Settlement of disagreements between competent authorities of different Member States
------------+ Article 28 Application to exercise the right of establishment and freedom to provide services
------------+ Article 29 Supervision of payment institutions exercising the right of establishment and freedom to provide services
------------+ Article 30 Measures in case of non-compliance, including precautionary measures
------------+ Article 31 Reasons and communication
---------+ Section 4 Exemption
------------+ Article 32 Conditions
------------+ Article 33 Account information service providers
------------+ Article 34 Notification and information
------+ CHAPTER 2 Common provisions
---------+ Article 35 Access to payment systems
---------+ Article 35a Conditions for requesting participation in designated payment systems
---------+ Article 36 Access to accounts maintained with a credit institution
---------+ Article 37 Prohibition of persons other than payment service providers from providing payment services and duty of notification
---+ TITLE III TRANSPARENCY OF CONDITIONS AND INFORMATION REQUIREMENTS FOR PAYMENT SERVICES
------+ CHAPTER 1 General rules
---------+ Article 38 Scope
---------+ Article 39 Other provisions in Union law
---------+ Article 40 Charges for information
---------+ Article 41 Burden of proof on information requirements
---------+ Article 42 Derogation from information requirements for low-value payment instruments and electronic money
------+ CHAPTER 2 Single payment transactions
---------+ Article 43 Scope
---------+ Article 44 Prior general information
---------+ Article 45 Information and conditions
---------+ Article 46 Information for the payer and payee after the initiation of a payment order
---------+ Article 47 Information for payer’s account servicing payment service provider in the event of a payment initiation service
---------+ Article 48 Information for the payer after receipt of the payment order
---------+ Article 49 Information for the payee after execution
------+ CHAPTER 3 Framework contracts
---------+ Article 50 Scope
---------+ Article 51 Prior general information
---------+ Article 52 Information and conditions
---------+ Article 53 Accessibility of information and conditions of the framework contract
---------+ Article 54 Changes in conditions of the framework contract
---------+ Article 55 Termination
---------+ Article 56 Information before execution of individual payment transactions
---------+ Article 57 Information for the payer on individual payment transactions
---------+ Article 58 Information for the payee on individual payment transactions
------+ CHAPTER 4 Common provisions
---------+ Article 59 Currency and currency conversion
---------+ Article 60 Information on additional charges or reductions
---+ TITLE IV RIGHTS AND OBLIGATIONS IN RELATION TO THE PROVISION AND USE OF PAYMENT SERVICES
------+ CHAPTER 1 Common provisions
---------+ Article 61 Scope
---------+ Article 62 Charges applicable
---------+ Article 63 Derogation for low value payment instruments and electronic money
------+ CHAPTER 2 Authorisation of payment transactions
---------+ Article 64 Consent and withdrawal of consent
---------+ Article 65 Confirmation on the availability of funds
---------+ Article 66 Rules on access to payment account in the case of payment initiation services
---------+ Article 67 Rules on access to and use of payment account information in the case of account information services
---------+ Article 68 Limits of the use of the payment instrument and of the access to payment accounts by payment service providers
---------+ Article 69 Obligations of the payment service user in relation to payment instruments and personalised security credentials
---------+ Article 70 Obligations of the payment service provider in relation to payment instruments
---------+ Article 71 Notification and rectification of unauthorised or incorrectly executed payment transactions
---------+ Article 72 Evidence on authentication and execution of payment transactions
---------+ Article 73 Payment service provider’s liability for unauthorised payment transactions
---------+ Article 74 Payer’s liability for unauthorised payment transactions
---------+ Article 75 Payment transactions where the transaction amount is not known in advance
---------+ Article 76 Refunds for payment transactions initiated by or through a payee
---------+ Article 77 Requests for refunds for payment transactions initiated by or through a payee
------+ CHAPTER 3 Execution of payment transactions
---------+ Section 1 Payment orders and amounts transferred
------------+ Article 78 Receipt of payment orders
------------+ Article 79 Refusal of payment orders
------------+ Article 80 Irrevocability of a payment order
------------+ Article 81 Amounts transferred and amounts received
---------+ Section 2 Execution time and value date
------------+ Article 82 Scope
------------+ Article 83 Payment transactions to a payment account
------------+ Article 84 Absence of payee’s payment account with the payment service provider
------------+ Article 85 Cash placed on a payment account
------------+ Article 86 National payment transactions
------------+ Article 87 Value date and availability of funds
---------+ Section 3 Liability
------------+ Article 88 Incorrect unique identifiers
------------+ Article 89 Payment service providers’ liability for non-execution, defective or late execution of payment transactions
------------+ Article 90 Liability in the case of payment initiation services for non-execution, defective or late execution of payment transactions
------------+ Article 91 Additional financial compensation
------------+ Article 92 Right of recourse
------------+ Article 93 Abnormal and unforeseeable circumstances
------+ CHAPTER 4 Data protection
---------+ Article 94 Data protection
------+ CHAPTER 5 Operational and security risks and authentication
---------+ Article 95 Management of operational and security risks
---------+ Article 96 Incident reporting
---------+ Article 97 Authentication
---------+ Article 98 Regulatory technical standards on authentication and communication
------+ CHAPTER 6 ADR procedures for the settlement of disputes
---------+ Section 1 Complaint procedures
------------+ Article 99 Complaints
------------+ Article 100 Competent authorities
---------+ Section 2 ADR procedures and penalties
------------+ Article 101 Dispute resolution
------------+ Article 102 ADR procedures
------------+ Article 103 Penalties
---+ TITLE V DELEGATED ACTS AND REGULATORY TECHNICAL STANDARDS
------+ Article 104 Delegated acts
------+ Article 105 Exercise of the delegation
------+ Article 106 Obligation to inform consumers of their rights
---+ TITLE VI FINAL PROVISIONS
------+ Article 107 Full harmonisation
------+ Article 108 Review clause
------+ Article 109 Transitional provision
------+ Article 110 Amendments to Directive 2002/65/EC
------+ Article 111 Amendments to Directive 2009/110/EC
------+ Article 112 Amendments to Regulation (EU) No 1093/2010
------+ Article 113 Amendment to Directive 2013/36/EU
------+ Article 114 Repeal
------+ Article 115 Transposition
------+ Article 116 Entry into force
------+ Article 117 Addresses
---+ ANNEX I
---+ ANNEX II

COMMISSION IMPLEMENTING REGULATION (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION IMPLEMENTING REGULATION (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat (Text with EEA relevance)
---+ Preamble: 1
---+ Article 1 Template for reporting ICT-related major incidents
---+ Article 2 Joint submission of initial notification, intermediate and final reports
---+ Article 3 Recurring ICT-related incidents
---+ Article 4 Use of secure electronic channels
---+ Article 5 Reclassification of major ICT-related incidents
---+ Article 6 Notification of outsourcing of the reporting obligations
---+ Article 7 Aggregated reporting
---+ Article 8 Notification of significant cyber threats
---+ Article 9 Entry into force

COMMISSION IMPLEMENTING REGULATION (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION IMPLEMENTING REGULATION (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information (Text with EEA relevance)
---+ Preamble: 1
---+ Article 1 Definitions
---+ Article 2 Ranking of ICT third-party providers in the supply chain
---+ Article 3 General requirements for the templates of the register of information
---+ Article 4 Data format requirement
---+ Article 5 Content of the register of information
---+ Article 6 Scope of the register of information at sub-consolidated and consolidated level
---+ Article 7 Entry into force

COMMISSION DELEGATED REGULATION (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION DELEGATED REGULATION (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition (Text with EEA relevance)
---+ Preamble: 1
---+ Article 1 Definitions
---+ Article 2 Identification of financial entities required to perform TLPT
---+ Article 3 TCT and TLPT Test Managers
---+ Article 4 Organisational arrangements for financial entities
---+ Article 5 Risk management for TLPT
---+ Article 6 Risk management for pooled or joint TLPTs
---+ Article 7 Selection of TLPT providers
---+ Article 8 Specificities for pooled or joint TLPTs
---+ Article 9 Preparation phase
---+ Article 10 Testing phase: threat intelligence
---+ Article 11 Testing phase: red team test
---+ Article 12 Closure phase
---+ Article 13 Remediation plan
---+ Article 14 Attestation
---+ Article 15 Use of internal testers
---+ Article 16 Cooperation and mutual recognition
---+ Article 17 Entry into force

COMMISSION DELEGATED REGULATION (EU) 2025/532 of 24 March 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION DELEGATED REGULATION (EU) 2025/532 of 24 March 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions (Text with EEA relevance)
---+ Preamble: 1
---+ Article 1 Overall risk profile and complexity
---+ Article 2 Group application
---+ Article 3 Due diligence and risk assessment regarding the use of subcontractors that support critical or important functions
---+ Article 4 Conditions under which ICT services that support critical or important functions or a material part thereof may be subcontracted
---+ Article 5 Material changes to subcontracting arrangements of ICT services that support critical or important functions or material parts thereof
---+ Article 6 Termination of the contract between the financial entity and the ICT third-party service provider
---+ Article 7 Entry into force

COMMISSION DELEGATED REGULATION (EU) 2025/420 of 16 December 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards to specify the criteria for determining the composition of the joint examination team ensuring a balanced participation of staff members from the ESAs and from the relevant competent authorities, their designation, tasks and working arrangements (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION DELEGATED REGULATION (EU) 2025/420 of 16 December 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards to specify the criteria for determining the composition of the joint examination team ensuring a balanced participation of staff members from the ESAs and from the relevant competent authorities, their designation, tasks and working arrangements (Text with EEA relevance)
---+ Preamble: 1
---+ Article 1 Tasks of the members of the joint examination team
---+ Article 2 Establishment of the joint examination team
---+ Article 3 Members of the joint examination team
---+ Article 4 Change of the membership in the joint examination team
---+ Article 5 Working arrangements of the members of the joint examination team
---+ Article 6 Entry into force

COMMISSION DELEGATED REGULATION (EU) 2025/295 of 24 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards on harmonisation of conditions enabling the conduct of the oversight activities (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION DELEGATED REGULATION (EU) 2025/295 of 24 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards on harmonisation of conditions enabling the conduct of the oversight activities (Text with EEA relevance)
---+ Preamble: 1
---+ Article 1 Information to be provided by ICT third-party service provider in the application to be designated as critical
---+ Article 2 Content, structure and format of the information to be submitted, disclosed or reported by critical ICT third-party service providers
---+ Article 3 Information from critical ICT third-party service providers after the issuance of recommendations
---+ Article 4 Structure and format of information provided by critical ICT third-party service providers
---+ Article 5 Template for providing information on subcontracting arrangements
---+ Article 6 Competent authorities’ assessment of the risks addressed in the recommendations of the Lead Overseer
---+ Article 7 Entry into force

COMMISSION DELEGATED REGULATION (EU) 2024/1502 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by specifying the criteria for the designation of ICT third-party service providers as critical for financial entities (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION DELEGATED REGULATION (EU) 2024/1502 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by specifying the criteria for the designation of ICT third-party service providers as critical for financial entities (Text with EEA relevance)
---+ Preamble: 1
---+ Article 1 Assessment approach
---+ Article 2 Systemic impact of ICT third-party service providers on the stability, continuity or quality of the provision of financial services
---+ Article 3 Systemic character and importance of the ICT services provided to financial entities
---+ Article 4 Criticality or importance of the functions
---+ Article 5 Degree of substitutability
---+ Article 6 Information sources to enable criticality assessment
---+ Article 7 Entry into force and application

COMMISSION DELEGATED REGULATION (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents (Text with EEA relevance)

Issues
Summary Source
+ COMMISSION DELEGATED REGULATION (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents (Text with EEA relevance)
---+ Preamble: 1
---+ CHAPTER I CLASSIFICATION CRITERIA
------+ Article 1 Clients, financial counterparts and transactions
------+ Article 2 Reputational impact
------+ Article 3 Duration and service downtime
------+ Article 4 Geographical spread
------+ Article 5 Data losses
------+ Article 6 Criticality of services affected
------+ Article 7 Economic impact
---+ CHAPTER II MAJOR INCIDENTS AND MATERIALITY THRESHOLDS
------+ Article 8 Major incidents
------+ Article 9 Materiality thresholds for determining major incidents
---+ CHAPTER III SIGNIFICANT CYBER THREATS
------+ Article 10 High materiality thresholds for determining significant cyber threats
---+ CHAPTER IV RELEVANCE OF MAJOR INCIDENTS TO COMPETENT AUTHORITIES IN OTHER MEMBER STATES AND DETAILS OF REPORTS TO BE SHARED WITH OTHER COMPETENT AUTHORITIES
------+ Article 11 Relevance of major incidents to competent authorities in other Member States
------+ Article 12 Details of major incidents to be shared with other competent authorities
---+ CHAPTER V FINAL PROVISIONS
------+ Article 13 Entry into force

Impressum German English