EU Digital Compliance in 2026: The Rules That Now Reach Into Your Codebase
For about seven years, GDPR was the one European regulation that every product team knew by name. If you ran a website that touched European users, you learned about lawful bases, you built a cookie banner, you signed data processing agreements, and you moved on.
That era is over. Between 2024 and 2028, the European Union has been shipping a stack of digital regulations that are, individually, as demanding as GDPR was, and collectively far more invasive. The difference is that these new rules do not stop at the privacy policy. They reach into your checkout flow, your component library, your incident response process, your software bill of materials, and your product data model.
We build and maintain software for companies operating in Europe, and we spend a lot of our week translating these obligations into tickets. This is our working map of what applies now, what lands next, and what any of it actually means for the people writing code.
Why This Wave Feels Different
GDPR was mostly horizontal. One regulation, one set of principles, applied to everyone processing personal data. The 2024 to 2028 wave is vertical and overlapping. A single mid-sized e-commerce company selling connected home devices across Germany and France can now sit inside the scope of at least eight separate instruments at once, each with its own regulator, its own deadline, and its own definition of who counts as responsible.
Three practical consequences follow from that.
First, compliance is no longer something you can bolt on before launch. Several of these rules require design decisions, and a design decision made badly in month two costs a rebuild in month twenty.
Second, the technical artefacts matter more than the paperwork. Regulators increasingly ask for machine-readable evidence: a software bill of materials, a conformity assessment, an accessibility statement, a consent record, an incident timeline. Nobody is impressed by a policy document that describes a control which does not exist in the system.
Third, deadlines are staggered and some of them have moved. Following the Digital Omnibus package proposed in November 2025, parts of the AI Act were pushed back while other parts stayed exactly where they were. Teams that read one headline and stopped are now planning against the wrong dates.
What Applies Right Now
GDPR, still the foundation
Nothing in the new wave replaces the General Data Protection Regulation. It remains the base layer, and it is still where the largest fines come from. If your data model, your retention jobs, and your subject access request process are weak, everything built on top inherits that weakness. We wrote a separate engineering-focused walkthrough in our practical GDPR guide for websites.
The European Accessibility Act
Directive 2019/882 became applicable on 28 June 2025, and enforcement started ramping through 2026. It covers consumer-facing e-commerce, banking, transport ticketing, telecoms, e-books and more. The technical benchmark is EN 301 549, which currently maps to WCAG 2.1 Level AA, with a revision expected to bring in WCAG 2.2.
This one surprises people because it is not a documentation exercise. It requires real changes to markup, focus management, colour contrast, form error handling and keyboard navigation. A French court has already ordered Carrefour to reach compliance under a daily penalty. Details are in our European Accessibility Act guide.
The Data Act
Regulation 2023/2854 became applicable on 12 September 2025. It gives users a right to the data their connected products generate, and it forces cloud providers to make switching realistic rather than theoretical. From 12 September 2026, connected products and related services newly placed on the market have to be designed so that data is accessible by default, which is an architecture requirement rather than a legal one. See our Data Act walkthrough.
NIS2
Member States have been transposing NIS2 at very different speeds. Germany opened its registration portal on 6 January 2026, the Netherlands brought its law into force on 15 August 2026, and other countries are still catching up. If you are in scope, you owe incident notifications on a 24 hour clock, and you owe your customers evidence that you manage supply chain risk. Our NIS2 field guide covers the practical side.
Verification of Payee
Since 9 October 2025, payment service providers in the euro area have had to offer a free check that the payee name matches the IBAN before a transfer is confirmed. For anyone building payment or payout flows, that added a new pre-confirmation step and a new set of near-match states to handle in the UI. We covered it in instant payments and Verification of Payee.
What Lands In The Next Twelve Months
2 August 2026: AI Act transparency
Article 50 obligations are now live. If your product talks to users through a chatbot, you have to tell them they are talking to a machine. If it generates synthetic audio, images, video or text, the output has to be marked in a machine-readable way. A further tranche, including watermarking detail and a ban on nudification tools, follows on 2 December 2026.
The heavier high-risk obligations moved. Stand-alone Annex III systems now have until 2 December 2027, and AI embedded in regulated products until 2 August 2028. That is a real reprieve, but only for the high-risk tier. Full breakdown in our AI Act transparency article.
11 September 2026: Cyber Resilience Act reporting
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through a single EU reporting platform. Early warning within 24 hours, full notification within 72 hours, final report within 14 days. You cannot meet a 24 hour clock without knowing what is inside your product, which is why teams are building SBOM pipelines a year ahead of the formal SBOM mandate. See the CRA guide.
12 September 2026: Data Act design obligations
The design-for-access requirement bites for newly placed products.
27 September 2026: Empowering Consumers Directive
Generic environmental claims lose their legal cover, sustainability labels need verification, and a harmonised notice and label for commercial guarantees has to appear in the buying flow. This is a content and template change across product pages, category pages and checkout. Covered in green claims and product data compliance.
24 December 2026: European Digital Identity Wallet
Every Member State has to make at least one wallet available. Obliged relying parties, including banks, transport, energy, health and telecoms, must accept it from December 2027. If you want to be an early acceptor, you need to register as a relying party and support the wallet's credential formats. Our EUDI Wallet integration guide explains what that involves.
What Is Still Moving
Two files are worth watching without over-planning around them.
The Digital Omnibus would fold cookie consent rules into GDPR itself, through a proposed Article 88a and Article 88b. The headline changes are a single-click accept or reject, a rule against re-prompting users who declined for six months, and legally binding machine-readable consent signals. Trilogue negotiations ran through mid-2026. Nothing is final, and we would not rebuild a consent platform on the assumption that it passes unchanged, but the direction is clear enough to influence how you architect one. Read our take in cookie consent after the Digital Omnibus.
The Digital Fairness Act is still at proposal stage, expected late in 2026, and aimed squarely at dark patterns, personalised pricing and addictive design. Realistically it applies somewhere between 2028 and 2030. It matters now only because it tells you which interface patterns are living on borrowed time.
The Payments Layer Nobody Planned For
There is one more shift that is not a regulation at all, but which behaves like one because of how quickly it is spreading through European checkout pages.
Wero, the wallet built by the European Payments Initiative, moved from person to person transfers into e-commerce during 2025 and 2026. It settles over SEPA Instant Credit Transfer in roughly ten seconds and bypasses the card schemes entirely. Lidl announced support on lidl.de in July 2026, with in-store acceptance and the Belgian and French shops following later in the year. Decathlon, Rossmann, Hornbach, Eventim and others are already live.
Nobody is legally required to accept Wero. But when a discounter with Lidl's footprint adds a payment method, the rest of a market tends to follow, and the integration is not free work: it lands in your checkout, your order state machine, your refund logic and your reconciliation. We wrote it up in the Wero integration guide.
How To Sequence This Without Losing A Quarter
The instinct is to open a compliance workstream and try to close everything. That usually produces a spreadsheet and very little shipped code. What works better, in our experience:
Start with scope, honestly. Most of these rules have thresholds, exemptions and definitions that materially change what you owe. A micro-enterprise providing services is outside much of the Accessibility Act. A company that does not manufacture products with digital elements is outside the CRA. Half an hour with the actual scoping articles saves months.
Find the overlaps and build once. Accessibility work under the EAA also improves the clarity requirements in the AI Act's transparency rules. Consent infrastructure built for GDPR carries most of the load for the Digital Omnibus changes. An SBOM pipeline built for the CRA answers a large chunk of NIS2 supply chain questions. Treat these as shared platform work, not as twelve separate projects.
Fix the things that need design decisions first. Data access by default, credential acceptance, accessibility semantics and consent architecture are expensive to retrofit. Reporting workflows and documentation are not. Sequence accordingly.
Write down what you decided and why. Most of these regimes expect you to be able to explain your reasoning, not just show a green tick. A short architecture decision record beats a long policy PDF.
Where We Fit
We are a software company, not a law firm, and we say that plainly to every client. We do not issue legal opinions. What we do is take the interpretation your legal team has landed on and turn it into working systems: consent platforms, accessible component libraries, data access APIs, SBOM pipelines, wallet integrations, payment flows and the boring infrastructure underneath all of it.
Our teams work from Ljubljana and Novi Sad, inside the regulatory environment we are describing, which means we deal with these deadlines on our own products too.
If you are trying to work out which of these actually apply to you, or you have a date on the calendar and no plan behind it, get in touch at office@c9group.dev. You can also read more about how we support companies entering or scaling in Europe on our European market entry page.