Orientation
The EU Data & Privacy Legal Ecosystem — Map
A layered map of the instruments in this area and how they stack.
The EU data & privacy legal ecosystem
Work in progress. This area of the knowledge base is a structured stub: the instrument list and key dates below are drawn from primary sources, but the deep dives are still being written. Anything marked ⚠️ VERIFY has not been independently confirmed.
EU data law splits into two families: protecting personal data (fundamental rights) and unlocking data for the economy (the data strategy):
| Layer | Question it answers | Main instruments |
|---|---|---|
| 1. Personal data protection | How may personal data be processed? | GDPR, Law Enforcement Directive ⚠️ VERIFY, ePrivacy Directive |
| 2. Data access & sharing | Who can access and reuse (industrial) data? | Data Act, Data Governance Act |
| 3. Sectoral data spaces | How is data shared inside a sector? | European Health Data Space ⚠️ VERIFY, sectoral data-space initiatives |
| 4. Adjacent | Identity, platforms, AI, security of processing | eIDAS 2, DSA (see Digital area), AI Act (see AI area), NIS2 (see Cyber area) |
Where to start
- GDPR — the anchor of the whole system; everything else defers to it.
- Data Act — access and use rights for connected-product data, switching rights for cloud, and unfair-terms controls.
- Data Governance Act — data intermediaries, data altruism, and reuse of protected public-sector data.