digital economy regulation

Get an independent, global perspective on regulation affecting the development of the digital economy with Cullen International. Our intelligence is trusted by global tech companies, regulators and governments to provide them with expert insight on topics relevant to the development of new technologies such as Artificial Intelligence (AI) and Internet of Things (IoT).
Whatever your information needs, you can rely on us for a single, impartial view of national and international regulation in the digital age.

general topics covered

    Get concise, easy-to-understand updates on the EU's digital policy, as well as the main policy and regulatory developments in the Americas. A single source of alerts and reports on data protection and privacy rules in the EU and the Americas, and initiatives on international transfers of personal data. Policy and regulatory initiatives shaping the data economy in Europe.
    Track regulators’ responses to cyber risks with updates on the implementation of the EU cybersecurity rules as well as specific cybersecurity strategies in the Americas. Coverage of regulatory developments impacting technologies such as cloud, AI and IoT. Follow initiatives specifically targeting digital platforms.
    Follow the latest developments in consumer protection around digital content, products and services. Get an overview of regulation that seeks to foster the development of e-Commerce in Europe and the Americas.

geographical coverage

Americas (Data sheet)
Europe (Data sheet)
Global Trends (Data sheet)

Find out more about the countries, organisations and topics covered by our Digital Economy service in our region-specific datasheets.

latest intelligence

EU Digital & Media Weekly Report
27 September 26 Visiola Pula

This edition features stories about the European Parliament rapporteur’s proposed changes to the framework for high-risk suppliers under the Cybersecurity Act 2 (CSA2) and the proposal amending the directive on measures for a high common level of cybersecurity across the EU (NIS2); an event discussing how the Digital Markets Act and existing competition rules can address generative AI and AI assistants; a consultation on guidelines from the European Data Protection Board (EDPB) on data protection authorities' powers to impose fines under the GDPR; EDPB guidelines on the interplay between the Digital Services Act and the GDPR; and the first stakeholder meeting of the Media Board. It also lists events taking place this week.

European Parliament rapporteur seeks further harmonisation of NIS2 security requirements and supervision
27 September 26 Visiola Pula

The rapporteur would require that national measures going beyond new EU rules covering the same risk-management requirements cease to apply one year after the EU rules take effect. The European Commission would have to deliver guidance on the consistent application of key aspects of the directive on measures for a high common level of cybersecurity across the EU (NIS2), including when security audits may be required.

Artificial intelligence regulation and policy are in early stages in the Caribbean
25 September 26 Pedro Miranda

Artificial intelligence (AI) policy in the Caribbean remains at an early and uneven stage. Some countries are developing strategies, institutions and readiness assessments, while others have no specific AI policy. Only Cuba and the Dominican Republic have adopted national AI strategies, although neither policy document allocates a specific amount of public investment to AI.

How suitable is the EU Digital Markets Act for addressing AI?
24 September 26 Miljana Todorovic

While the Digital Markets Act was not specifically designed for AI, it can address AI-related competition concerns that arise from the types of digital platform bottlenecks and gatekeeper practices already targeted by the regulation. These include, for example, barriers to the distribution of alternative products and services. For other concerns, such as the use of publishers’ content for AI services, the enforcement of general antitrust rules plays an important role.

CSA2: European Parliament rapporteur proposes case-by-case designation of high-risk suppliers
23 September 26 Javier Huerta Bravo

Markéta Gregorová (Greens, Czechia) suggested that the European Commission’s identification of high-risk suppliers (HRS) under the proposed Cybersecurity Act 2 be based on “specific and substantiated evidence”, without requiring a previous, separate designation of a high-risk country. The rapporteur proposed a two-year deadline for phasing out HRS equipment from all telecom networks, following the HRS identification. The Commission proposal would set a three-year deadline for mobile networks, while the deadlines for fixed and satellite would be determined by the Commission at a later stage. Ms Gregorová would open the door to compensating telecoms operators and other entities subject to phase-out requirements if they cause a disproportionate burden. This is not foreseen under the Commission proposal.

Adviser to EU top court says consent to use of personal data for direct marketing does not extend to subsequent use by unidentified “partners”
22 September 26 Alessandra Vaes

The Advocate General of the Court of Justice of the EU considered that consent to direct marketing by a company's “partners” is valid only if individuals are informed of the partners’ identities when giving consent. If this is not the case, such partners must obtain fresh consent to lawfully process the individuals’ personal data for direct marketing purposes.

Get access to the full reports and find out what our service could do for you with a free trial.