European Union
EU-wide instruments set the floor; member states implement, overlay and enforce through their own regulators. The Radar currently maps the EU layer plus nine member states in depth, with capture from EU vantages so the banner you show Berlin is the banner that gets tested.
EU instruments (GDPR, ePrivacy, Omnibus, EAA, AI Act, DSA) → member-state implementation → national regulators (CNIL, DSK, AEPD, Garante, AP, APD, DSB, DPA, DPC).
Sub-jurisdictions, live from the matrix
Law counts shown for the hotel (hospitality) example; every cell opens the full verbatim stack.
The instruments that do the damage
€7.1bn+ in cumulative fines since 2018; ~€1.2bn issued in 2025 alone; enforcement now reaches SMEs, not just Big Tech.
Enforcement live since 28 June 2025 for e-commerce, banking, telecoms and more; EN 301 549 is the technical bar; microenterprise service providers excepted.
Chatbot disclosure, AI-content marking and deepfake labelling duties apply from 2 August 2026.
Review-verification disclosure, fake-review bans and the 30-day prior-price rule for reductions, in force since May 2022.
Enforcement climate, cited
Member states mapped in depth today: France, Germany, Spain, Italy, Netherlands, Belgium, Austria, Denmark, Ireland. National overlays (LCEN, DDG/TDDDG, LSSI, Impressum duties) attach per country.
Serving this market? See your stack.
Pick your sector and sub-sector in the Explorer, or start with the introductory audit from this market's vantage.
Applicability depends on confirmed facts about your business (establishment, targeting, reach) and supported scope. Figures are cited to their sources and periods; items marked for approval are re-verified before publication.