Skip to content
atlas

EU regulation

A type of EU law that applies directly and identically in every member state, with no national law needed to bring it in.

Draft - this entry has not been reviewed yet.

Formal

A legal act of the European Union that is binding in full and applies directly in all member states from the date it takes effect - for example GDPR, DORA and the Cyber Resilience Act - although countries may add rules on authorities and fines where it allows.

In plain English

Like a single book of rules for a chess tournament played in many countries - every table follows the same page, and no host country may print its own version.

In practice

A web shop selling to both Denmark and Germany follows one GDPR text for handling customer data, and only checks national rules for details the regulation leaves open.

Why it matters

Knowing whether a rule is a regulation or a directive tells you where to read your duties - in the EU text itself or in your own country's law.

Technical deep dive

Under Article 288 TFEU a regulation has general application, is binding in its entirety and is directly applicable in all member states. Direct applicability means it becomes part of national law on its own, without any transposing act; in fact the Court of Justice held in Variola (34/73) that member states must not adopt national measures that reproduce or disguise the text of a regulation, because that would obscure its EU origin and the Court's jurisdiction to interpret it. Unlike directives, regulations can create rights and obligations between private parties (horizontal effect), and under the primacy principle a conflicting national rule must be set aside by the national court (Simmenthal, 106/77).

Two dates must be kept apart: entry into force and date of application. GDPR entered into force on 24 May 2016 but applied from 25 May 2018; DORA entered into force on 16 January 2023 and applied from 17 January 2025; the Cyber Resilience Act entered into force on 10 December 2024 but applies in stages, with reporting duties from 11 September 2026 and most obligations from 11 December 2027. The gap exists to let organisations and authorities prepare, and compliance programmes are planned against the application dates.

Direct applicability does not mean national law is irrelevant. Many regulations contain opening clauses that require or allow national rules. GDPR leaves room in, among others, Art. 6(2)-(3) for public-sector processing, Art. 8(1) for the age of consent for information society services (between 13 and 16; Denmark chose 13 in databeskyttelsesloven), Art. 87 for national identification numbers such as the CPR number and Art. 88 for employment. Regulations also typically require member states to designate competent authorities and lay down penalties, as GDPR Art. 84 and DORA Art. 50 do, which is why Danish supplementary acts exist even for directly applicable rules.

Much of the technical content sits in secondary acts adopted by the Commission under a regulation or directive: delegated acts under Art. 290 TFEU, which supplement or amend non-essential elements (for example DORA's regulatory technical standards such as Delegated Regulation (EU) 2024/1774), and implementing acts under Art. 291, which set uniform conditions for implementation. These are themselves regulations and apply directly; notably, an implementing regulation can be adopted under a directive, as with Implementing Regulation (EU) 2024/2690 laying down technical requirements under NIS2 for certain digital-infrastructure and digital-service entities. Reading a regulation in practice therefore means reading the base act, its level-2 acts, guidance from the EDPB or European Supervisory Authorities where relevant, national supplementary rules, and case law of the Court of Justice.

What to learn first

Everything this builds on, foundations first.

  1. Compliance
  2. →EU regulation

Relationships

Requires
Compliance
Don't confuse with
EU directive

Sources & further reading

Standards & official texts

  • Treaty on the Functioning of the European Union, Article 288

Course material

  • Cyber Security Fast Track - Kursuskompendium, Ordliste (GDPR)

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.