INSIGHT EUROPEAN UNION 1 MIN READ

EU | ICT Regulations & Cybersecurity

Published

The EU prioritizes digital security with landmark regulations such as DORA and GDPR, in addition to the AI Act.

  • In 2018, the EU introduced the General Data Protection Regulation (GDPR) to establish guidelines for gathering and processing personal information. It mandates data collection notifications, explicit consent, timely breach notifications, etc. || Source: Investopedia
    + In 2023, the EU launched the Digital Operational Resilience Act (DORA) to enhance IT security for financial entities. It ensures European financial resilience during disruptions, harmonizing rules for 20 financial entities and ICT third-party service providers. || Source: EIOPA
  • In 2021, the European Commission proposed the first EU framework for AI, classifying systems based on risk levels. In December 2023, the Parliament and Council reached a provisional agreement on the AI Act, awaiting formal adoption to become EU law. || Source: European Parliament
  • In 2022, 37.3% of EU enterprises had ICT security measures. Large enterprises (79.6%) were almost 2.5 times more likely to have ICT security documents than small enterprises. || Source: Eurostat
    + In the ITU G5 benchmark, Europe outperforms other regions, with 28 countries at G4 level and ten at G5. Europe’s lead has narrowed, with the gap to global averages reducing from 45% in 2007 to 21% in 2018. || Source: ITU