Activity Tracker

The DPA Activity Tracker provides our latest information on developments in legislatures, judiciaries and the executive branches of G20, EU member states and Switzerland.

5 events advancing 5 policy or regulatory changes:

Most active jurisdictions Number of policy changes

Graph

Table

Most active policy areas Number of policy changes
Targeted economic activity Number of policy changes
Reset filters
5 events advancing 5 policy or regulatory changes:
adopted

Cyber Trust Mark requirements in critical information infrastructure and cybersecurity industries

Latest event Date: 2026-12-31 order implementation

Obligation for auditors of critical information infrastructure to obtain Cyber Trust Mark Level 5 certification enters into force

On 31 December 2026, the window for compliance with the Cyber Security Agency (CSA) obligation directing Critical Information Infrastructure Auditors to have obtained the Cyber Trust Mark (CTM) Level 5 certification ends. This mandate, announced dur…

Implementer
Singapore
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, ML and AI development, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
adopted

Cybersecurity Act (No. 36764) implementing Directive on measures for a high common level of cybersecurity across the Union (NIS/2 Directive No. 2022/2555)

Latest event Date: 2026-08-15 law implementation

Cybersecurity Act (No. 36764) implementing Directive on measures for a high common level of cybersecurity across the Union (NIS 2 Directive No. 2022/2555) enters into force

On 15 August 2026, the Cybersecurity Act (No. 36764) implementing Directive on measures for a high common level of cybersecurity across the Union (Directive No. 2022/2555) enters into force. The Act lays down rules on managing risks to the security …

Implementer
Netherlands
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
adopted

Critical Entities Resilience Act (No. 36765) implementing Directive on resilience of critical entities (Directive No. 2022/2557)

Latest event Date: 2026-08-15 law implementation

Critical Entities Resilience Act (No. 36765) implementing Directive on resilience of critical entities (Directive No. 2022/2557) enters into force

On 15 August 2026, the Critical Entities Resilience Act (No. 36765) implementing Directive on resilience of critical entities (Directive No. 2022/2557) enters into force. Under the Act, relevant ministers designate critical entities based on criteri…

Implementer
Netherlands
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
in consultation

Annual reporting format on implementation in Internet of Things sector covering provider categories and technical compliance to support supervision and ecosystem mapping

Latest event Date: 2026-07-26 order consultation closed

Ministry of Communication and Digital Affairs closes consultation on annual reporting format on implementation in Internet of Things sector covering provider categories and technical compliance to support supervision and ecosystem mapping

On 26 July 2026, the Ministry of Communication and Digital Affairs closes the consultation on the annual reporting format for the implementation of the Internet of Things (IoT) sector. The consultation covered proposed reporting obligations for sens…

Implementer
Indonesia
Policy area Other operating conditions
Policy or regulatory element Organisational requirement
Economic activity infrastructure provider: internet and telecom services, technological consumer goods, software provider: other software, infrastructure provider: network hardware and equipment
processing consultation

Bill amending Cybersecurity Act including provisions on mandatory cyber incident reporting obligations for critical information infrastructure agencies

Latest event Date: 2026-07-15 law consultation closed

National Cyber ​​Security Commission closes consultation on Bill amending Cybersecurity Act including provisions on mandatory cyber incident reporting obligations for critical information infrastructure agencies

On 15 July 2026, the National Cyber Security Commission closes the consultation on the Bill amending the Cybersecurity Act. The proposed amendments are intended to address developments in the cybersecurity landscape since the enactment of the Cybers…

Implementer
Thailand
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
Page
1