PurLayer Intelligence

12

Critical Items

Needs immediate action

28

High Priority

For current quarter

5

Medium Priority

For next quarter

0

This Week

Total updates

Priority Feed

Live from Microsoft 365 Roadmap API + UK Regulatory Sources

Loading Purview data...
CNIL!Critical7d ago

EU AI Act enforcement — CNIL designated French enforcement authority

CNIL designated as French AI Act enforcement authority with fines up to 35M EUR or 7% global turnover

AI ActEnforcementPenalties
AP!Critical8d ago

AP algorithm and AI enforcement — top priority for 2025

Dutch DPA designates algorithm and AI enforcement as top priority, designated AI Act market supervisor

AI EnforcementAlgorithm SupervisionAI Act
AP!!High10d ago

Dutch AP releases data minimization best practices

Autoriteit Persoonsgegevens publishes guidance on implementing data minimization in cloud environments

Compliance deadline: 1 Sept 2026
Data MinimizationRetention PoliciesGDPR+1
CNIL!Critical10d ago

CNIL 2025-2028 AI strategic plan — GDPR applies to AI model training

CNIL strategic plan confirms GDPR applies to AI model training with data subject rights in AI systems

AI Strategic PlanGDPRData Subject Rights
CNIL!Critical12d ago

CNIL issues AI transparency guidelines for data processing

French data protection authority CNIL releases comprehensive guidance on AI system transparency requirements under GDPR

Compliance deadline: 1 Jun 2026
AI GovernanceGDPRTransparency+1
igj!Critical12d ago

NEN 7510 — mandatory healthcare information security standard

Dutch mandatory information security standard for healthcare organisations mapping to ISO 27001 with health-specific controls

NEN 7510ISO 27001Healthcare Security
cssf!Critical14d ago

CSSF Circular 24/847 — ICT incident reporting for financial sector

CSSF mandates ICT incident reporting procedures for Luxembourg financial sector entities

ICT Incident ReportingDORAFinancial Regulation
CNPD!Critical15d ago

Luxembourg CNPD updates processor audit requirements

Commission Nationale pour la Protection des Données clarifies audit obligations for cloud processors

Compliance deadline: 15 May 2026
Audit RequirementsProcessor ComplianceFinancial Services+1
ans!Critical16d ago

HDS certification — mandatory for hosting French health data

HDS (Hebergeur de Donnees de Sante) certification required for any platform hosting French health data

HDSHealth DataCertification
APD/GBA!!High17d ago

Belgian DPA clarifies processor agreement requirements

APD/GBA issues guidance on data processing agreements for cloud service providers

GDPR Article 28Processor AgreementsCloud Services+1
cssf!!High17d ago

CSSF AI governance expectations for supervised entities

CSSF sets human oversight and explainability requirements for AI in supervised financial entities

AI GovernanceHuman OversightExplainability
igj!!High17d ago

IGJ designated AI systems supervisor for healthcare

Health and Youth Care Inspectorate designated as AI systems supervisor for Dutch healthcare

AI SupervisionHealthcare AIHigh-Risk AI
APD/GBA!!High19d ago

APD special category health data processing rules

Belgian DPA issues specific guidance on processing special category health data under GDPR

Health DataSpecial CategoryGDPR
ccb!!High21d ago

CyFun CyberFundamentals Framework — mandatory NIS2 cybersecurity baseline

CCB national cybersecurity standard requiring self-assessment at Basic, Important or Essential level for all organisations

CyFunNIS2Cybersecurity Baseline
AP!!High21d ago

AP customer profiling and data trading enforcement priority

Dutch DPA prioritises enforcement on customer profiling and data trading practices

Customer ProfilingData TradingEnforcement
ICO!Critical23d ago

ICO publishes AI and Data Protection Guidance

Comprehensive guidance on deploying AI systems in compliance with UK GDPR, including specific requirements for automated decision-making and profiling.

Compliance deadline: 30 Jun 2026
AIGDPRAutomated Decision-Making
CNPD!!High23d ago

CNPD co-designated as AI Act supervisory authority alongside CSSF

Luxembourg designates CNPD and CSSF as joint AI Act supervisory authorities

AI ActSupervisionHigh-Risk AI
FCA!Critical25d ago

FCA Consumer Duty: Data & Communications Update

New requirements for how financial services firms communicate with customers and handle their data under Consumer Duty obligations.

Compliance deadline: 1 Apr 2026
Consumer DutyFinancial ServicesCommunications
ANSSI!!High25d ago

ANSSI updates cloud security certification requirements

French cybersecurity agency ANSSI announces enhanced SecNumCloud certification criteria for cloud services

Compliance deadline: 30 Apr 2026
Cloud SecuritySecNumCloudData Sovereignty+1
ans!!High25d ago

ANS digital health standards for interoperability

Agence du Numerique en Sante publishes updated digital health interoperability standards

Digital HealthInteroperabilityStandards
afm!!High25d ago

AFM — financial markets conduct authority and DORA co-supervisor

Autoriteit Financiele Markten designated as DORA co-supervisor for financial markets conduct

DORAFinancial MarketsICT Risk
NCSCMedium28d ago

NCSC Cloud Security Principles Update

Updated guidance for securing cloud services with specific recommendations for Microsoft 365 and Azure configurations.

Cloud SecurityMicrosoft 365Public Sector
APD/GBAMedium28d ago

APD student data and EdTech guidance

Belgian DPA publishes guidance on student data protection and EdTech platform requirements

Student DataEdTechGDPR
dnb!!High28d ago

DNB operational resilience and DORA supervision from January 2025

De Nederlandsche Bank DORA supervision active from January 2025 for financial institutions

DORAOperational ResilienceBanking Supervision
cssf!!High31d ago

MiFID II, UCITS, AIFMD — fund data retention and access control requirements

Luxembourg fund sector data retention and access control requirements under EU financial directives

MiFID IIUCITSAIFMD+1
NHS!!High33d ago

NHS Data Security and Protection Toolkit 2026

Annual update to DSPT requirements with new assertions for AI systems and enhanced third-party assurance requirements.

Compliance deadline: 30 Jun 2026
DSPTHealthcareData Security
NCSC-NL!Critical33d ago

NCSC-NL issues Microsoft 365 security baseline

Dutch National Cyber Security Centre publishes security configuration baseline for Microsoft 365

Security BaselineMicrosoft 365Identity Protection+1
ccb!!High33d ago

Safeonweb@Work — mandatory NIS2 registration platform

CCB-managed mandatory registration platform for NIS2 compliance in Belgium

NIS2Incident ReportingRegistration
acpr!!High33d ago

ACPR banking and insurance prudential supervision updates

ACPR issues updated prudential supervision requirements for banking and insurance ICT risk management

DORAPrudential SupervisionICT Risk
acmMedium33d ago

ACM — digital markets and consumer data protection

Autoriteit Consument en Markt enforces digital markets and consumer data requirements

Digital MarketsConsumer DataCompetition
nbb!!High35d ago

NBB DORA supervision for credit and payment institutions

National Bank of Belgium designated as DORA supervisory authority for credit institutions and payment institutions

DORAICT RiskThird-Party Risk
fsma!!High35d ago

FSMA DORA supervision for investment firms and insurers

FSMA designated as DORA supervisory authority for investment firms, fund managers and insurers

DORAOperational ResilienceICT Risk
ANSSI!!High35d ago

ANSSI OT/ICS security requirements for industrial systems

ANSSI publishes security requirements for operational technology and industrial control systems

OT SecurityICSIndustrial Systems
ccb!!High38d ago

Belgian cybersecurity framework update affects cloud deployments

CCB publishes updated national cybersecurity framework with cloud-specific requirements

Compliance deadline: 1 Jul 2026
Cybersecurity FrameworkCloud SecurityMFA+1
circl!!High38d ago

CIRCL — national CSIRT incident reporting requirements

Luxembourg national CSIRT establishes incident reporting procedures for all sectors

Incident ResponseCSIRTReporting
ANSSI!Critical38d ago

LPM — critical infrastructure operators (OIV) cybersecurity obligations

Loi de Programmation Militaire mandates cybersecurity obligations for critical infrastructure operators

LPMOIVCritical Infrastructure
NCSC-NL!!High38d ago

BIO — mandatory Dutch government information security baseline

Baseline Informatiebeveiliging Overheid mandates information security baseline for all Dutch government

BIOGovernment SecurityBaseline
fod-spf!!High41d ago

FOD/SPF Federal Public Services data governance requirements

Belgian federal government data governance framework for public service organisations

Data GovernanceClassificationRetention
cadaMedium41d ago

CADA — government document access and transparency requirements

Commission d'acces aux documents administratifs establishes Freedom of Information equivalent for government

Freedom of InformationTransparencyDocument Access
govcert-lu!!High43d ago

GOVCERT.LU — government cybersecurity requirements

Luxembourg government cybersecurity centre mandates security controls for government entities

Government CybersecuritySecurity Controls
menjs!!High43d ago

MENJS Ministry of Education data protection requirements

French Ministry of Education mandates data protection requirements for educational institutions

Education DataStudent PrivacyConsent
NCSC-NL!!High43d ago

CBw NIS2 Control Framework — published by NCSC for NIS2 preparation

Dutch NCSC publishes CBw NIS2 Control Framework for organisations preparing for NIS2 compliance

NIS2Control FrameworkCybersecurity
CNPDMedium45d ago

CNPD RE.M.I. initiative — AI regulatory dialogue framework

CNPD launches RE.M.I. initiative for regulatory dialogue on AI and data protection

AI RegulationRE.M.I.Regulatory Dialogue
CNIL!!High45d ago

CNIL AI guidance for schools — published 2025

CNIL publishes specific AI guidance for educational institutions on responsible AI use

AI in EducationStudent ProfilingConsent
AP!!High45d ago

AP enforcement on algorithmic decision-making in schools

Dutch DPA enforces restrictions on algorithmic decision-making in educational institutions

Algorithmic Decision-MakingEducationStudent Rights