Fragmentation of EU Digital Regulations Puts Pressure on Corporate Compliance
A recent report by the International Association of Privacy Professionals (IAPP) indicates that nearly a quarter of corporate professionals lack confidence in their organization's ability to comply with EU digital regulations, with over half having only some confidence. As multiple digital laws take effect, companies face complex compliance challenges.

Brief Overview
- According to a report by the nonprofit data privacy organization IAPP, nearly a quarter of corporate professionals lack confidence in their organization's ability to comply with the growing number of EU digital regulations. Slightly more than half of the surveyed professionals expressed only some confidence.
- As digital laws such as the EU AI Act, Data Governance Act, Data Act, Digital Markets Act, NIS2 Directive, and Digital Services Act take effect, IT leaders play a key role in ensuring organizational compliance. The lead researcher for privacy law and policy at IAPP,EU Digital Laws Report 2025author Müge Fazlioglu, told CIO Dive.
- Fazlioglu noted: "The digital legal and policy environment, not only in the EU but globally, is challenging. We live in a world where data collection and processing volumes are constantly increasing, and AI adoption across nearly all industries is accelerating this trend. We see legislators and regulators responding with new laws and policies to manage and guide this ecosystem."
In-Depth Insights
The proliferation of digital laws and regulations coincides with a period when enterprises are rapidly deploying new AI technologies while lacking confidence in fully complying with new regulations.
The 2024 Privacy Governance Report, cited in the IAPP EU Digital Laws Report, shows that only one in five respondents expressed full confidence in their organization's ability to fully comply with this set of regulations.
Fazlioglu stated that tracking the requirements and different implementation phases of new regulations is a critical issue for business leaders.
She said: "Most digital governance professionals do not show high confidence in their organization's ability to track and comply with the new requirements of this emerging set of EU digital laws."
The EU's suite of digital laws aims to protect personal and non-personal data, ensure markets remain competitive, and create new data-sharing infrastructure. For example, the Data Act seeks to increase the availability of high-quality data by mandating data-sharing obligations for certain organizations. Meanwhile, the Digital Markets Act aims to regulate competition among digital platforms.
Therefore, Fazlioglu said, enterprises must not only prioritize how to implement the requirements of each law but also consider the intersections between these laws and with prior regulations such as the EU's General Data Protection Regulation.
Major U.S. tech providers have already faced challenges in complying with EU digital laws. In April 2025, the European Commission ruled that Apple and Meta's service offerings in Europe did not comply with the Digital Markets Act. The Commission is the executive body responsible for enforcing EU law.
The EU is also cracking down on non-U.S. companies, including Chinese-owned retail company Temu. Earlier this year, the Commission preliminarily found that Temu had violations under the Digital Services Act.