GDPR was never the whole picture
GDPR gets all the attention, but it sits inside a much bigger family of EU rules covering data, technology and digital security. Most small businesses will never touch most of them — but a few apply more widely than people expect, and two of the four below changed materially in 2026.
Here is a plain-English tour of the four that come up most often, and an honest answer on whether each one is your problem.
ePrivacy — the “cookies and marketing” law
If GDPR is about personal data generally, the ePrivacy Directive (Directive 2002/58/EC, as amended by Directive 2009/136/EC) is specifically about electronic communications: cookies, website tracking, and unsolicited marketing by email, SMS or phone. It is the reason your website needs a cookie banner, and the reason unsolicited marketing email needs consent rather than a legitimate interest argument.
In Cyprus it is transposed by the Regulation of Electronic Communications and Postal Services Law 112(I)/2004, as amended. That is the law your cookie banner actually answers to — cookies and online tracking sit under it, not under GDPR directly, even though the standard of consent it borrows comes from GDPR.
One terminology point is worth clearing up, because it causes real confusion. For years there was a proposed “ePrivacy Regulation” meant to replace the Directive. The Commission announced it was dropping that proposal in its 2025 work programme on 11 February 2025, and the withdrawal was formally published in the Official Journal on 6 October 2025. The Directive — and Law 112(I)/2004 with it — remain the applicable rules. Anyone still waiting for the Regulation to arrive is waiting for something that was cancelled.
There is a second round of change in progress, but it has not landed. See the last section.
Applies to you if: you run any website with cookies or analytics, or send marketing emails, SMS or calls.
EU AI Act — rules for artificial intelligence
The AI Act (Regulation (EU) 2024/1689) regulates how AI systems can be built and used across the EU, with obligations scaling to how risky the use is.
Two dates matter right now, and they have come apart from each other:
- 2 August 2026 — already in effect. The Article 50 transparency obligations apply. In practice: if you run a customer-facing chatbot, people have to be told they are dealing with a machine, and certain AI-generated content has to be labelled.
- 2 December 2027 — deferred. The obligations for standalone high-risk AI systems listed in Annex III were originally due on 2 August 2026. Regulation (EU) 2026/1744 — the “Digital Omnibus on AI”, adopted 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — moved them to 2 December 2027.
The deferral is the part that gets misreported. It moved the high-risk deadline. It did not move the transparency one. If you have a chatbot on your website or publish AI-generated content, that obligation is live now, not next year.
Applies to you if: you use AI tools that make or influence decisions about people — hiring software, credit scoring, chatbots, recommendation engines.
NIS2 — cybersecurity for essential and important services
NIS2 (Directive (EU) 2022/2555) is an EU cybersecurity directive aimed at organisations in sectors considered essential or important to society and the economy — energy, transport, health, water, digital infrastructure, public administration, postal services and, depending on size, a good many others. It requires cybersecurity risk-management measures, incident reporting to a national authority, and — the part that surprises people — direct management accountability for getting it right.
Cyprus has transposed it. The Security of Networks and Information Systems (Amendment) Law 60(I)/2025 amended the 2020 Law (Law 89(I)/2020) and has been in force since 25 April 2025. The Digital Security Authority is the designated competent authority, and the current phase of work is identifying essential and important entities, then supervision and enforcement.
The practical shift is scope. The predecessor regime covered a small set of critical operators; NIS2 reaches roughly ten times as many organisations, largely through a size-cap rule that pulls in medium and large companies across the listed sectors. Plenty of businesses that had never heard of the old rules are inside the new ones.
Applies to you if: you’re a medium or large business in an essential or important sector — or a supplier to one, because their obligations will reach you through your contract.
DORA — operational resilience for financial services
DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) is narrower and more specific: it applies to the EU financial sector — banks, investment firms, insurers, payment institutions, crypto-asset service providers — and to the critical ICT providers that serve them. It has applied since 17 January 2025.
It sets requirements for managing ICT risk, reporting major ICT-related incidents, testing digital resilience, and managing third-party ICT dependencies. If you provide IT or cloud services to a regulated financial entity, expect DORA terms to arrive in your contracts even though the Regulation does not name you directly.
Applies to you if: you’re a financial services business, or you supply IT or cloud services to one.
A quick self-check
- Website with cookies, or you send marketing email → ePrivacy (in Cyprus, Law 112(I)/2004)
- You use AI in decisions about people, or run a chatbot → AI Act (Regulation (EU) 2024/1689)
- Medium or large business in an essential or important sector → NIS2 (in Cyprus, Law 60(I)/2025)
- Financial services, or a critical ICT supplier to one → DORA (Regulation (EU) 2022/2554)
- You process any personal data at all → GDPR, always — starting with a lawful basis
Most small Cyprus businesses will find GDPR and ePrivacy are the two that bite directly, with the AI Act becoming relevant faster than expected as ordinary tools embed AI features by default.
Worth noting: these regimes overlap on incidents. A single cyber attack can trigger a 72-hour breach notification under GDPR, an incident report under NIS2, and a major-incident report under DORA — to different authorities, on different clocks. Knowing in advance which of them apply to you is the whole point of the exercise.
One more thing: some of this is being rewritten
The EU is actively working to simplify how these rules interact, under what is being called the Digital Omnibus. It is two separate files, and conflating them is the most common mistake being made about it right now:
- The AI Omnibus is done. That is Regulation (EU) 2026/1744, described above — already in force.
- The Data Omnibus is not. The proposal covering GDPR, ePrivacy, NIS2 and DORA — including ideas like single-click consent, browser-level preference signals, and a single portal for incident reporting across all four regimes — remains under negotiation between the Parliament and the Council as of September 2026.
That second point matters practically. Nothing about your cookie banner or your accountability obligations has changed yet, whatever the headlines suggest. If you are being sold a product on the basis that consent rules have already been relaxed, that sale is ahead of the law. We’ll cover the Data Omnibus properly once it is actually adopted.
Not sure which of these four apply to your business, or what that means in practice? Let’s Talk GDPR.
Related reading
- What is Consent Under GDPR?
- What is a Lawful Basis Under GDPR?
- Privacy by Design and by Default: Building GDPR In From the Start
- How Long Can You Legally Keep Customer Data?
- GDPR Glossary
References
- Directive 2002/58/EC (ePrivacy Directive), as amended by Directive 2009/136/EC — privacy and electronic communications.
- Regulation of Electronic Communications and Postal Services Law 112(I)/2004, as amended, Cyprus — national transposition of the ePrivacy Directive, including the consent requirement for cookies.
- European Commission work programme 2025 (11 February 2025) — announced intention to withdraw the proposed ePrivacy Regulation; the withdrawal was published in the Official Journal on 6 October 2025.
- Regulation (EU) 2024/1689 (AI Act) — harmonised rules on artificial intelligence, including the Article 50 transparency obligations applicable from 2 August 2026.
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230; published in the Official Journal 24 July 2026, in force 27 July 2026; defers the Annex III high-risk obligations to 2 December 2027.
- Directive (EU) 2022/2555 (NIS2) — measures for a high common level of cybersecurity across the Union.
- Security of Networks and Information Systems (Amendment) Law 60(I)/2025, Cyprus — amending Law 89(I)/2020; in force 25 April 2025; the Digital Security Authority is the designated competent authority.
- Regulation (EU) 2022/2554 (DORA) — digital operational resilience for the financial sector; applicable from 17 January 2025.
- Regulation (EU) 2016/679 (GDPR) Article 33 — notification of a personal data breach to the supervisory authority.