Activity Tracker

The DPA Activity Tracker provides our latest information on developments in legislatures, judiciaries and the executive branches of G20, EU member states and Switzerland.

6 events advancing 4 policy or regulatory changes:

Most active jurisdictions Number of policy changes

Graph

Table

Most active policy areas Number of policy changes
Targeted economic activity Number of policy changes
Reset filters
6 events advancing 4 policy or regulatory changes:
adopted

Cyber Trust Mark requirements in critical information infrastructure and cybersecurity industries

Latest event Date: 2026-12-31 order implementation

Obligation for auditors of critical information infrastructure to obtain Cyber Trust Mark Level 5 certification enters into force

On 31 December 2026, the window for compliance with the Cyber Security Agency (CSA) obligation directing Critical Information Infrastructure Auditors to have obtained the Cyber Trust Mark (CTM) Level 5 certification ends. This mandate, announced dur…

Implementer
Singapore
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, ML and AI development, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
in consultation

Bill amending Cybersecurity Act including provisions on mandatory cyber incident reporting obligations for critical information infrastructure agencies

Latest event Date: 2026-07-15 law consultation closed

National Cyber ​​Security Commission closes consultation on Bill amending Cybersecurity Act including provisions on mandatory cyber incident reporting obligations for critical information infrastructure agencies

On 15 July 2026, the National Cyber Security Commission closes the consultation on the Bill amending the Cybersecurity Act. The proposed amendments are intended to address developments in the cybersecurity landscape since the enactment of the Cybers…

Implementer
Thailand
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
in force

Extension of EU economic sanctions against Russia under Decision 2014/512/CFSP (Council Decision (CFSP) 2026/1437)

Latest event Date: 2026-06-26 order implementation

Council decision expending economic sanctions against Russia for 12 months enters into force

On 26 June 2026, the Council decision extending EU economic sanctions against Russia entered into force. The decision renews the restrictive measures under Decision 2014/512/CFSP, adopted in response to Russia’s actions destabilising the situation i…

Implementer
European Union
Policy area International trade
Policy or regulatory element Export ban
Economic activity digital payment provider (incl. cryptocurrencies), semiconductors, software provider: other software, platform intermediary: other, infrastructure provider: other
adopted

Guidance on quantum technology pertaining to sensing

Latest event Date: 2026-06-24 outline adoption

Cyber Security Centre published guidance on quantum technology pertaining to sensing

On 24 June 2026, the Cyber Security Centre published guidance on quantum technology pertaining to sensing. The guidance outlines the risks and implications of integrating quantum sensing technologies into digital environments. The guidance focuses o…

Implementer
Australia
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, software provider: other software, infrastructure provider: other
Page
1