Europe
EU / EEA, with separate UK requirements
GDPR: privacy by design
For in-scope processing, establish a lawful basis, clear notices, data minimisation, retention limits, user-rights workflows, and processor agreements. Assess safeguards for transfers outside the EEA.
European Commission · GDPRCookies & tracking
Obtain prior consent for cookies and similar tracking where required. Keep exempt, necessary technologies separate and make withdrawal easy.
Your Europe · CookiesEuropean Accessibility Act
Check whether your product or service is covered, including consumer e-commerce. Requirements apply from 28 June 2025, with exemptions and transition rules; build accessible navigation, forms, and checkout.
Your Europe · AccessibilityAI Act
Classify AI features and your provider or deployer role. Check prohibited uses, literacy duties, and applicable transparency requirements; high-risk obligations have separate timelines.
European Commission · AI ActUK projects
Assess UK GDPR and PECR separately. Review notices, lawful processing, and consent or exemptions for cookies, pixels, and similar technologies.
ICO · UK tracking rules