The rulebook keeps growing. Your team didn’t.
01Why it matters in privacy
The GDPR was the start, not the settlement. The AI Act, the DSA, the DMA, the Data Act, NIS2 — each with its own timeline, its own supervisory authority, its own guidance arriving on no particular schedule. And in most organisations one person covers all of it, usually alongside another job.
The failure mode isn’t dramatic. It’s finding out in November that an obligation started in June, from someone outside your team.
02How it works in your field
You set your areas — data protection, AI and media, whatever else you carry — and the jurisdictions your organisation operates in.
Then: EU legislation, both as adopted and as currently in force; the Commission’s digital policy publications; judgments from the Court of Justice and the General Court interpreting the GDPR and the wider digital rulebook; national court decisions in Portugal and Germany; guidance and opinions from European and national data protection authorities as they publish them; and the press.
Everything arrives classified and summarised, so you can tell a genuine obligation from commentary about one without opening either.
03What changes in your week
Phase-in dates stop creeping up on you, because the instrument that sets them is in front of you when it’s adopted rather than when it bites.
When the Court decides something on transfers, or legitimate interest, or automated decisions, it’s in tomorrow’s briefing rather than in a conference slide six months on.
Your notes build a record. When someone asks why you took a position in March, the reasoning is attached to the thing you read.
And “what’s changed on AI transparency since the spring” is a question, not a project.
