digital economy regulation

Get an independent, global perspective on regulation affecting the development of the digital economy with Cullen International. Our intelligence is trusted by global tech companies, regulators and governments to provide them with expert insight on topics relevant to the development of new technologies such as Artificial Intelligence (AI) and Internet of Things (IoT).
Whatever your information needs, you can rely on us for a single, impartial view of national and international regulation in the digital age.

general topics covered

    Get concise, easy-to-understand updates on the EU's digital policy, as well as the main policy and regulatory developments in the Americas. A single source of alerts and reports on data protection and privacy rules in the EU and the Americas, and initiatives on international transfers of personal data. Policy and regulatory initiatives shaping the data economy in Europe.
    Track regulators’ responses to cyber risks with updates on the implementation of the EU cybersecurity rules as well as specific cybersecurity strategies in the Americas. Coverage of regulatory developments impacting technologies such as cloud, AI and IoT. Follow initiatives specifically targeting digital platforms.
    Follow the latest developments in consumer protection around digital content, products and services. Get an overview of regulation that seeks to foster the development of e-Commerce in Europe and the Americas.

geographical coverage

Americas (Data sheet)
Europe (Data sheet)
Global Trends (Data sheet)

Find out more about the countries, organisations and topics covered by our Digital Economy service in our region-specific datasheets.

latest intelligence

Dutch data protection authority imposes €825m fine on Uber for violating GDPR requirements on automated decision-making
13 September 26 Alessandra Vaes

The Dutch DPA’s fine against Uber is the second largest GDPR fine to date. The Dutch DPA found that, by suspending drivers’ accounts without human intervention, Uber subjected the drivers to decisions based solely on automated processing. Under the GDPR, such automated decision-making (ADM) is generally prohibited where it produces legal or similarly significantly affects the individuals concerned, subject to certain exceptions. Where an exception applies, the data controller must inform the relevant individuals that decisions concerning them are based on ADM.

EU Digital & Media Weekly Report
13 September 26 Alessandra Vaes

This edition features a story on the application of the Cyber Resilience Act’s reporting requirements; a new edition of the EU Timeline, highlighting key EU policy and regulatory developments foreseen until the end of 2026; and an update of the Digital Economy Trackers.

EU Timeline
10 September 26 Marianna Mattera

This edition of Cullen International’s EU Timeline highlights key policy and regulatory developments foreseen at EU level until the end of 2026.

EU Digital & Media Weekly Report
06 September 26 Marianna Mattera

This edition covers EU-level policy and regulatory developments tracked by Cullen International’s Digital Economy and Media services over the past week, as well as key reports published during the summer. These include an analysis of EU countries’ positions on the framework restricting high-risk suppliers under the proposed Cybersecurity Act 2 (CSA2); reports on the European Commission guidance on the Cyber Resilience Act (CRA); an analysis of core amendments to the EU AI Act, following the entry into force of the AI Omnibus; a story about the reinstatement of temporary rules on voluntary detection of child sexual abuse by messaging apps; a story about France’s Constitutional court ruling against a blanket social media ban for under-15s, with a potential impact on the Commission’s upcoming social media delay proposal; and developments in cases under the Digital Markets Act (DMA) and the Digital Service Act (DSA). It also lists events taking place this week.

CSA2: analysis of EU countries’ positions on proposed framework restricting high-risk suppliers
01 September 26 Visiola Pula

According to a document prepared by the Council’s general secretariat and seen by Cullen International, several member states raised concerns over the proposed mechanism to designate high-risk suppliers (HRS) under the Cybersecurity Act 2 (CSA2). They called for an assessment in which suppliers’ links to countries posing cybersecurity concerns are treated as a risk indicator rather than a determining factor. Regarding telecoms networks, several member states questioned the proposed EU-wide three-year timeline for phasing out HRS components from 5G networks, favouring greater flexibility to account for national circumstances and the equipment lifecycles.

European Commission publishes guidance on how new cybersecurity rules for products with digital elements apply to free and open-source software
11 August 26 Alessandra Vaes

This Flash highlights the main aspects addressed in the guidance on the Cyber Resilience Act (CRA) related to free and open-source software (FOSS). It provides examples where FOSS is considered to be supplied during a commercial activity and hence placed on the market, triggering the obligations for manufacturers. The guidance also clarifies the concept of stewards and when they would be subject to the CRA reporting obligations. A steward sustains and supports FOSS intended for commercial use but does not place the software on the market.

Get access to the full reports and find out what our service could do for you with a free trial.

get in touch

For more information about our Digital Economy service, please contact: