Skip to content

All Topics

The primary way in. Every topic gathers the exact provisions, paragraphs, findings and sections tagged with it — across all content types.

⌕
Personal Data 33923

Information relating to identified or identifiable natural persons

135981120874701172
Controllers 16938

Entities that determine purposes and means of processing

722052583784579
Processing 16729

Any operation performed on personal data

617154284404523
Supervisory Authorities 12728

National data protection authorities and their powers

578641761992498
Supervision 10878

Oversight and enforcement by supervisory authorities

538025311853809
Consent 7100

Freely given, specific, informed indication of data subject wishes

304620321644169
Public Authority 6108

Government bodies and their data processing activities

36701106814253
Monitoring 5335

Systematic observation and tracking of individuals

239012791067277
Processors 4971

Entities that process data on behalf of controllers

27891058804260
Law Enforcement 4476

Processing for law enforcement purposes

2287943872170
Security 3977

Technical and organizational measures to protect personal data

19521214530139
Types of Special Categories of Personal Data 3878

A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, political opinions, religious beliefs, genetic data, biometric data, health data, and criminal convictions.

18061276522152
Identification 3831

Methods and processes for identifying individuals

15431229797178
International Transfer 3724

Transfer of personal data outside the EU/EEA

2774404260184
Right of Access 3601

Data subject right to access their personal data

1915111547351
Transparency 3593

Openness about data processing activities

1657846825108
Healthcare 3321

Processing of health data and medical information

148098067999
Social Media 2679

Social networking platforms and privacy considerations

1205865348216
Legitimate Interest 2640

Processing necessary for legitimate interests pursued by controller or third party

116868765364
Marketing 2604

Use of personal data for marketing and advertising purposes

97473468688
Accountability 2529

Principle of demonstrating GDPR compliance

127168241067
Telecommunications 2518

Processing by telecom providers and eprivacy

94980360557
Minors 2512

Special protections for children under GDPR

143162929274
Codes of Conduct 2298

Industry codes of conduct for data protection

18782159179
Data Breaches 2272

Security incidents involving unauthorized access to personal data

97173943159
Certification 2235

Data protection certification mechanisms

187213511880
Retention Period 2094

The duration for which personal data may be stored

85067749540
Cookies 2036

Online tracking technologies and consent requirements

90957540287
Profiling 1841

Automated processing to evaluate personal aspects

79656830379
Access Controls 1773

Access management and authentication

70449947860
Processing Agreement 1744

Contract between controller and processor defining processing terms

122228117340
Automated Decision-Making 1716

Processing involving automated decisions without human involvement

66458731082
Health Data 1690

Processing of health and medical data

62049446740
Human Resources 1624

Processing of employee and HR data

865332220163
DPIA 1607

Data Protection Impact Assessment - systematic evaluation of processing risks

104124917749
Liability 1587

Legal responsibility for GDPR violations and damages

1351885933
Representatives 1574

Representatives of controllers not established in the EU

670477230143
IP Address 1520

Internet protocol addresses as personal data

710531133120
Integrity and Confidentiality Principle 1468

While security and beveiliging topics exist, there is no dedicated topic for the integrity and confidentiality principle specifically as articulated in GDPR Article 5(1)(f), which is a distinct foundational principle requiring separate coverage.

57253628934
Direct Marketing 1437

Processing for marketing and advertising purposes

63943426845
Insurance 1374

Processing by insurance companies

68145118131
Video Surveillance 1280

Use of cameras for monitoring and recording individuals

71630421224
Recipient 1270

A person or body to which personal data are disclosed (Art 4(9) GDPR).

53337226785
Biometric Data 1269

Processing of biometric data for identification

753217104102
Pseudonymization 1137

Processing data in a pseudonymized manner

45544914733
Storage Limitation 1123

Principle that data should not be kept longer than necessary

41233633417
Anonymization 1108

Irreversible removal of identifying information from data

51632717736
Scientific Research 1069

Processing for scientific research purposes

54428811372
Privacy by Design & Default 1066

This topic is essential as it specifically addresses Article 25 GDPR requirements for implementing data protection principles through design and default settings, covering both technical and organizational measures that must be embedded into processing systems from inception.

5194454236
Privacy Shield 1061

Former EU-US data transfer framework (invalidated)

7681287166
Fines 1034

Administrative fines imposed for GDPR violations

38134323441
Notification Obligation 1034

Duty to report data breaches to authorities and affected individuals

38538519628
Right to be Forgotten 981

Right to have personal data erased under certain conditions

41433317423
Privacy by Design 898

Embedding data protection into system design from the outset

5851729027
Accuracy 894

Principle that personal data must be accurate and up to date

5482198328
Artificial Intelligence 880

AI systems and their implications for data protection

5851148175
Encryption 784

Encryption and cryptographic measures

40220710536
Fairness & Transparency 753

Fairness and transparency are co-principles with lawfulness in Article 5(1)(a) GDPR and are inseparable from the concept of lawful processing, deserving dedicated coverage.

27424016448
Right to Object 711

Data subject right to object to processing

24924319112
Professional Secrecy 697

Confidentiality obligations for data protection personnel

4231397941
Privacy by Default 696

Ensuring highest privacy settings apply by default

4501198624
Information Provision Modalities and Communication Methods 695

The content focuses on how information should be communicated to data subjects (transparent, clear, accessible modalities), which is distinct from the content of information itself and deserves its own topic covering communication methods and accessibility requirements.

29718317329
Criminal Data 693

Processing of criminal convictions and offences

527924619
Genetic Data 659

Processing of genetic and hereditary data

4061854013
Employees 652

Employee data protection and workplace privacy

29517113129
Authority Powers for Fundamental Rights Protection 620

This new topic is needed because the content specifically addresses the powers and authorities granted to competent authorities to protect fundamental rights in AI systems, including inspection, intervention, and corrective action powers that are not adequately covered by existing topics.

23418014748
Joint Controllers 574

Multiple controllers jointly determining purposes and means

393117526
Statistics 567

Statistical purposes and statistical processing

2491877141
Territorial scope (GDPR) 547

When the GDPR applies geographically: establishment in the Union, targeting (offering goods or services), and behavioural monitoring by non-EU controllers (Article 3 GDPR).

397545136
AI Value Chain Actors and Roles 485

The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their roles, and how they interact would be valuable for comprehensive AI Act compliance.

400363115
Education 453

Processing in educational institutions

279784432
Material scope (GDPR) 425

What processing the GDPR applies to — and the exclusions: purely personal or household activity, law enforcement, EU institutions (Article 2 GDPR).

2351423411
Data Portability 417

Right to receive and transfer personal data in structured, machine-readable format

1871484115
Meaningful Human Review and Decision-Making 392

The content on human oversight emphasizes the need for meaningful human review and decision-making authority, which deserves its own dedicated topic to distinguish it from general oversight mechanisms.

3403655
Data Subject Rights Exercise Modalities and Procedures 366

This content specifically addresses the transparent communication and practical modalities for how data subjects can exercise their GDPR rights, which is not adequately covered by existing topics focused on individual rights in isolation.

13111110815
High-Risk AI Classification 357

The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedicated topic beyond the general 'AI Risk Assessment' category.

3543
Right to Restriction 352

Right to restrict processing of personal data

172986113
Notified Body Independence 304

Notified bodies must maintain strict independence and impartiality standards, which are critical operational obligations that warrant a dedicated topic for detailed coverage.

15666628
Archiving 294

Archiving in the public interest

182721715
Scientific Panel Independence 278

A specific topic is needed to address the independence and impartiality requirements that are critical for scientific panels to maintain credibility and objectivity in their advisory role.

15662428
Annex III Amendments 268

This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated tracking and analysis separate from general AI Act compliance.

2332663
Prior Consultation 257

Consultation with supervisory authority before processing

126683117
Authority Cooperation 254

This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authorities that are distinct from general compliance obligations and warrant dedicated coverage.

225254
Conformity Assessment for AI Systems 253

Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Act that warrants dedicated coverage.

2521
Lawful Basis 251

This topic is essential as Article 6 GDPR provides the specific legal bases that determine whether processing is lawful, which is the core requirement of the 'Lawfulness of processing' content.

69655947
Provider Obligations for AI Systems 245

The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that deserves its own dedicated topic for better organization and searchability.

226991
Child Consent 238

This new topic is needed because the content specifically addresses the unique conditions and requirements for obtaining valid consent from children in the context of information society services, which is distinct from general consent requirements and requires specialized treatment of age verification, parental involvement, and child-specific safeguards.

102862413
AI Risk Assessment 229

The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, which is distinct from general DPIA and needs dedicated coverage.

19319133
Cloud Computing 228

Use of cloud services and associated data protection requirements

158212018
Notified Body Reporting and Notification Obligations 217

The content addresses specific reporting and notification obligations of notified bodies to authorities and other stakeholders, which is a distinct operational requirement deserving separate coverage.

108682613
Notified Bodies for AI Systems 204

This topic is needed to comprehensively cover the role, responsibilities, and obligations of notified bodies in the AI Act conformity assessment framework, including their designation, accreditation, and operational requirements.

2013
Competent Authorities Designation and Powers under DSA 192

The content is titled 'Competences' from the DSA and discusses the allocation and scope of authority powers under the Digital Services Act. This requires a dedicated topic covering DSA-specific competent authority designation, powers, and responsibilities.

192
Article 19 GDPR - Notification of Rectification, Erasure or Restriction 178

This specific GDPR provision addresses the controller's obligation to notify data subjects and third parties about rectification, erasure, or restriction of processing. It is a distinct procedural requirement that deserves its own dedicated topic for comprehensive coverage of notification obligations under Article 19.

8270195
DSA Scope and Digital Services Coverage 177

The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and to properly categorize DSA-specific regulatory coverage.

1761
Conformity Body Notification 170

This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Act, which is a distinct regulatory mechanism not adequately covered by existing topics.

170
NIS2 Addressees and Responsible Entities 169

The 'Addressees' section of NIS2 specifically identifies and defines the entities and authorities to whom the directive applies and who bear responsibility for compliance. This requires a dedicated topic covering the identification, classification, and designation procedures for all addressees under NIS2.

169
GPAI Systemic Risk 168

This new topic is needed because the content specifically addresses the classification and identification of general-purpose AI models that present systemic risk, which is a distinct regulatory category under the AI Act that requires dedicated coverage separate from general high-risk AI classification.

1662
Political Opinions 151

Processing of political views and affiliations

57423016
AI Office Establishment and Role 149

The AI Office is a new institutional body created by the AI Act with specific establishment procedures, roles, responsibilities, and governance structures that warrant dedicated coverage distinct from general procedural frameworks.

1481
AI Act Procedures 148

The 'Procedure' section of the AI Act establishes the overarching procedural framework and mechanisms for implementing and enforcing the regulation. This topic is needed to capture the procedural architecture that underpins all compliance, assessment, and enforcement activities under the AI Act.

1471
Inspection Access Rights and Cooperation Obligations 143

A dedicated topic is needed to address the specific rights of inspectors to access facilities, systems, and documents, and the corresponding obligations of AI providers and deployers to cooperate with inspections.

5544365
Market Surveillance and Control of AI Systems 126

This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems under the AI Act, which is a distinct regulatory domain not fully captured by existing topics.

11295
AI Standards 123

This new topic is needed to specifically address the role of harmonised standards and standardisation deliverables in the AI Act framework, including their development, adoption, and use in demonstrating compliance with AI system requirements.

91111110
GDPR Subject-Matter and Objectives 122

This content is specifically about the introductory provisions establishing the subject-matter and objectives of the GDPR, which is a distinct topic from general scope/definitions that deserves its own classification for regulatory framework documentation.

50491310
Religious Beliefs 116

Processing of religious or philosophical beliefs

5627256
Digital Services Coordinator 113

While 'digital-services-coordinators-dsa' exists, a more specific topic on the establishment, institutional framework, and foundational role of DSCs would better capture the comprehensive nature of this content about competent authorities and their designation.

113
AI Act Territorial Scope 112

The scope section of the AI Act includes specific provisions on territorial applicability and which providers are subject to the regulation regardless of their location, warranting a dedicated topic.

112
Audit Logs 111

Logging and auditing of processing activities

34322420
Digital Services Coordinators under DSA 109

This new topic is needed because Digital Services Coordinators are a distinct institutional role under DSA with specific designation procedures, responsibilities, and powers that warrant dedicated coverage separate from general competent authorities.

109
Post-Market Monitoring for AI Systems 108

Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and critical component that warrants its own topic.

9774
AI Act Requirements 107

The content specifically addresses 'Compliance with the requirements' from the AI Act, which warrants a dedicated topic for AI Act-specific requirements that goes beyond general compliance and risk assessment topics.

1052
VLOP/VLSE Framework 103

The content title specifically focuses on 'Very large online platforms and very large online search engines' as a distinct regulatory category under the DSA. A dedicated topic covering the comprehensive regulatory framework, definitions, and comparative analysis of these two service categories would provide better organization and clarity than distributing this information across multiple existing topics.

103
Delegation of Powers 100

The content specifically addresses 'Exercise of the delegation' which is a distinct procedural topic covering how delegated powers are exercised, implemented, and managed within the AI Act framework. This topic is not adequately covered by existing topics and deserves its own dedicated classification.

973
Committee Procedure under AI Act 99

The content specifically addresses 'Committee procedure' as a distinct procedural mechanism under the AI Act. This topic is not adequately covered by existing topics and requires its own dedicated entry to capture the specific procedural rules, voting mechanisms, composition requirements, and decision-making processes of regulatory committees established under the AI Act framework.

9621
GDPR Article 5 Principles of Processing 96

This content specifically addresses the foundational principles of personal data processing under GDPR Article 5, which encompasses multiple related but distinct principles that warrant a dedicated topic for comprehensive coverage of this critical regulatory framework.

4329174
AI Incident Notification 90

The AI Act establishes specific procedures for notifying authorities about serious incidents and anomalies in high-risk AI systems, which requires dedicated coverage distinct from general information duties and incident reporting.

8451
Market Surveillance Corrective Actions and Enforcement 84

This topic addresses the specific enforcement and corrective actions available to authorities during market surveillance, including withdrawal, suspension, and remedial measures, which are distinct from general corrective action procedures.

542252
Right to Rectification 84

Right to have inaccurate personal data corrected

4320129
Technical Documentation for AI Systems 83

The AI Act imposes specific technical documentation requirements for AI systems, particularly high-risk AI systems. This dedicated topic would cover the mandatory documentation of system design, functionality, performance, testing, and operational parameters required for AI Act compliance.

7463
Unacceptable Risk AI Systems 82

The content specifically addresses unacceptable-risk AI systems as a distinct category of prohibited practices, warranting a dedicated topic for this specific classification and its requirements.

64772
DSA Terms and Conditions Requirements 79

This new topic is needed to specifically address the requirements for terms and conditions documents under the DSA, including transparency, accessibility, and mandatory content requirements for digital service providers.

79
Risk Management System 76

This new topic is needed because risk management systems are a distinct and mandatory requirement under the AI Act, encompassing systematic processes for identifying, assessing, mitigating, and monitoring risks throughout an AI system's lifecycle, which is not adequately covered by existing topics.

51975
AI Record-Keeping 74

The AI Act imposes specific record-keeping obligations for AI systems that are distinct from general GDPR record-keeping. A dedicated topic would capture AI-specific documentation, logging, and record retention requirements that differ from traditional data protection record-keeping.

6563
Implementation Guidelines 74

This content is specifically about Commission guidelines for implementing the AI Act. A dedicated topic would capture guidance documents, interpretive materials, and practical implementation support materials from the European Commission.

482321
Notified Body Responsibilities and Operational Obligations 73

This new topic is needed to capture the specific operational obligations, responsibilities, and procedural requirements that notified bodies must fulfill when conducting conformity assessments and maintaining their designation.

421565
Data Governance for AI 72

The AI Act's section on 'Data and data governance' requires specific provisions for managing training data, validation data, and test data in AI systems. This concept is distinct from general data protection and deserves its own topic to capture AI-specific data governance requirements including data quality, documentation, and management practices.

2621214
Interim Measures under AI Act 71

This new topic is needed to specifically address interim measures provisions in the AI Act, which allow authorities to take temporary protective actions against high-risk AI systems that pose immediate risks to fundamental rights, safety, or public security, pending full compliance assessment or corrective actions.

6254
Documentation Keeping for AI Systems 70

While 'record-keeping-ai' exists, a more specific topic focused on documentation keeping as a distinct concept would better capture the AI Act's specific requirements around maintaining, organizing, and preserving documentation throughout an AI system's lifecycle, including technical, compliance, and operational documentation.

6172
Training Data Requirements 69

The AI Act specifically addresses requirements for training, validation, and test data used in high-risk AI systems. This warrants a dedicated topic covering data sourcing, quality standards, documentation requirements, and characteristics that must be maintained for AI model development.

3714114
Authority Access Rights to AI Systems and Documentation 68

This new topic would specifically address the rights and procedures for competent authorities to access AI systems, facilities, documentation, and data during oversight activities, which is a critical component of the cooperation framework but not fully captured by existing topics.

6161
Human Oversight 68

This new topic is needed because human oversight is a specific and distinct requirement under the AI Act that deserves dedicated coverage, encompassing mechanisms for human control, intervention, and review of AI system operations and decisions.

362082
Notified Body Information Obligations 66

This specific topic is needed to comprehensively cover the distinct information obligations that notified bodies must fulfill under the AI Act, including their duties to disclose assessment findings, report non-compliance, notify authorities of incidents, and provide transparent information to stakeholders.

56432
AI Act Material Scope 64

The material scope defines which types of AI systems and activities fall within the regulation's coverage, including specific exclusions and definitional boundaries that merit dedicated coverage.

64
Data Portability 62

Right to receive and transfer personal data

26151110
Notified Body Assessment Procedures 61

The content extensively covers the operational procedures and methodologies that notified bodies must follow when conducting conformity assessments, which deserves its own dedicated topic.

341953
Right to Explanation 60

This topic is essential as it specifically addresses the fundamental right of individuals to receive meaningful explanations about how automated decisions affecting them are made, which is a critical transparency and accountability mechanism in both GDPR and AI Act frameworks.

2115106
Monitoring Actions under AI Act 58

The content specifically addresses 'Monitoring actions' as a distinct topic under the AI Act, which encompasses systematic oversight procedures, compliance verification, and market surveillance activities that are not fully captured by existing more general monitoring topics.

48631
Delegated Acts 55

This content specifically addresses the procedural framework for adopting delegated acts under the AI Act, including how they apply to safety components and sectoral regulations. This is a distinct procedural topic not adequately covered by existing topics.

541
Annex III Classification Changes and Updates 54

The content specifically addresses amendments to Annex III, which represents a distinct regulatory mechanism for updating high-risk AI system classifications. This topic would capture the procedural and substantive aspects of how Annex III is modified over time.

54
Hosting Services under DSA 54

While intermediary liability and DSA scope topics exist, there is no dedicated topic specifically for hosting services, their liability conditions, exemptions, and specific obligations under DSA Article 6, which represents a distinct regulatory category requiring focused coverage.

54
AI Corrective Powers 52

This new topic is needed to specifically address the corrective and intervention powers that authorities possess to protect fundamental rights, including emergency measures, system suspensions, and market restrictions that go beyond standard inspection and monitoring activities.

43621
Notified Body Competence Challenges and Dispute Resolution 49

This new topic is needed because the content specifically addresses challenges to the competence of notified bodies, which is a distinct regulatory mechanism not adequately covered by existing topics. It encompasses dispute resolution procedures, grounds for challenges, and remedial actions related to notified body competence.

291242
AI Risk Mitigation 46

Risk management systems include specific measures to mitigate identified risks. This concept deserves dedicated coverage as it encompasses the practical implementation of risk reduction strategies beyond general risk assessment.

221262
AI Conformity Declaration 44

The EU declaration of conformity is a specific, mandatory compliance document under the AI Act that deserves its own dedicated topic to cover its requirements, content, format, maintenance, and availability obligations for AI system providers.

3743
AI Act Formal Non-Compliance 41

This topic is needed to specifically address formal non-compliance under the AI Act, covering the determination, notification, and enforcement procedures specific to AI regulation compliance failures.

32441
Intermediary Liability Framework under DSA 41

This topic is needed to comprehensively cover the broader intermediary liability framework under the DSA, of which mere conduit is one component, including the conditions, standards, and exemptions that apply to different types of digital services.

401
Standards Publication 41

The content discusses how harmonised standards are published and enter into force, which is a distinct procedural topic that deserves dedicated coverage separate from general standards adoption.

2885
AI Provider Transparency 40

This specific topic is needed to comprehensively cover the transparency obligations framework that applies to both providers and deployers of AI systems, which is a distinct and important compliance area under the AI Act that warrants its own dedicated topic for better organization and retrieval.

28543
Conformity Assessment Procedures and Methodologies 38

This new topic is needed to specifically address the procedural and methodological aspects of conformity assessment for AI systems, including step-by-step procedures, assessment phases, documentation requirements, and reporting mechanisms that are distinct from the general conformity assessment concept.

371
Out-of-Court Dispute Settlement under DSA 38

This is a distinct DSA topic that warrants its own entry, as it covers specific procedures, requirements, and mechanisms for resolving disputes outside of court, including mediator qualifications, settlement procedures, and accessibility requirements that are not adequately covered by existing topics.

38
Online Interface Design and Organization 34

This topic is needed to specifically address DSA requirements regarding how online service providers must design and organize their interfaces to ensure transparency, accessibility, and compliance with content moderation and user information obligations. It bridges interface design principles with regulatory compliance requirements.

322
Corrective Actions and Duty of Information Framework 33

This topic combines two interconnected AI Act obligations: the requirement for providers to take corrective actions when systems fail to comply, and the corresponding duty to inform authorities and stakeholders about these actions and any identified issues. This integrated framework is essential for understanding post-market compliance mechanisms.

25421
AI Corrective Actions 32

This new topic is needed because corrective actions are a specific and distinct obligation under the AI Act that encompasses systematic procedures for addressing identified risks, defects, and incidents in AI systems, requiring dedicated coverage separate from general risk management.

25322
Entry Into Force 31

This new topic is needed to specifically address the temporal aspects of when the AI Act and its various provisions enter into force and become applicable to different actors and systems.

121133
Prohibited AI Practices 31

The content specifically addresses prohibited AI practices under the AI Act, which is a distinct regulatory concept not adequately covered by existing topics. This requires its own topic to capture the specific restrictions, enforcement mechanisms, and compliance requirements.

13844
Advertising Practices and Requirements under DSA 27

This new topic is needed to specifically address advertising practices on online platforms under DSA, including transparency requirements, content moderation of ads, disclosure of sponsored content, and protection against misleading or deceptive advertising practices.

207
Administrative Fines on Union Institutions, Bodies, Offices and Agencies 23

This specific provision addresses a distinct category of administrative fines applicable exclusively to Union institutions, bodies, offices and agencies, which differs from fines applicable to private actors and requires separate treatment to capture the unique institutional context and procedures.

13522
Confidentiality Obligations and Requirements 23

This topic is needed to comprehensively address confidentiality as a distinct data protection principle in the AI Act and GDPR, covering obligations, requirements, and implementation measures specific to maintaining confidentiality of personal and sensitive data.

11651
Data Access and Scrutiny Mechanisms under DSA 22

This new topic is needed because the content specifically addresses data access and scrutiny as a distinct DSA requirement, which encompasses mechanisms for authorities, researchers, and civil society to access and examine platform data for compliance verification and systemic risk assessment.

22
AI Governance Framework 21

Compliance with AI Act requirements involves establishing a comprehensive governance framework covering organizational structures, policies, and procedures, which is distinct from individual compliance obligations.

16221
Caching Services under DSA 18

Caching is a specific intermediary service category under DSA Article 5 with distinct liability conditions and technical requirements that warrant dedicated topic coverage separate from general intermediary liability frameworks.

18
AI Information Duties 17

This new topic is needed because the AI Act imposes specific duties on providers to inform relevant parties (users, authorities, affected persons) about corrective actions, incidents, and system modifications, which represents a distinct compliance obligation that warrants separate topical coverage.

8431
Notifying Authorities 17

This topic is needed to specifically address the procedures, requirements, timelines, and mechanisms for notifying authorities about AI systems, incidents, and compliance matters under the AI Act, which is a distinct regulatory obligation not fully captured by existing topics.

17
AI Impact Assessment 16

This new topic is needed because fundamental rights impact assessments are a specific and distinct requirement under the AI Act (Article 27) for high-risk AI systems, requiring dedicated coverage of assessment methodologies, rights considerations, and documentation requirements that are not adequately covered by existing topics.

754
Quality Management 16

This new topic is needed to specifically address the detailed requirements, implementation procedures, and operational aspects of quality management systems for AI systems as mandated by Article 17 of the AI Act, which is distinct from general quality management concepts.

142
Annex III High-Risk AI Categories 14

The classification rules reference specific categories of high-risk AI systems listed in Annex III, which warrant a dedicated topic to address the enumerated use cases and application domains that trigger high-risk classification.

14
Notice and Action Mechanisms under DSA 14

This new topic is needed to specifically address the notice and action procedures that are central to DSA compliance, including how service providers must notify users of content moderation decisions, how authorities issue orders, and the procedural requirements for these mechanisms.

14
AI Transitional Provisions 13

The content specifically addresses AI systems already placed on the market, which raises questions about transitional arrangements, compliance deadlines, and how existing deployments are regulated differently from new systems entering the market.

652
European Cybersecurity Certification Schemes 13

This new topic is needed to specifically address European cybersecurity certification schemes (EUCS) as referenced in NIS2, which establish a framework for certifying cloud services and other ICT products/services against defined security criteria.

1111
Infringement Reporting 13

This specific topic is needed to comprehensively cover Article 84 of the AI Act, which establishes a dedicated framework for reporting infringements and protecting those who report them, including confidentiality protections and safeguards against retaliation.

7411
Application Scope: Temporal and Territorial Dimensions 12

This topic is needed to capture the specific provisions regarding when (temporal) and where (territorial) the AI Act applies, which are distinct from general scope and definitions.

6321
Mutual Assistance Between Member States for AI Oversight 12

This topic is essential as the provision specifically addresses mutual assistance mechanisms between member states and the AI Office for coordinating market surveillance and control activities for AI systems.

741
Transparency Reporting Obligations Overview 12

While individual aspects of transparency reporting are covered by existing topics, there is no comprehensive overview topic that addresses transparency reporting obligations as a unified framework under DSA Article 24, including the general principles, scope, and procedural requirements.

6221
Compliance Function Establishment and Role 11

The DSA content specifically addresses compliance functions as organizational entities with defined roles, responsibilities, and governance structures. This topic is needed to comprehensively cover the establishment, structure, and operational framework of compliance functions under DSA requirements.

911
DSA Transparency 11

This new topic is needed because the content specifically addresses transparency reporting obligations for intermediary service providers under the DSA, which is a distinct and important compliance requirement that deserves dedicated coverage separate from general transparency obligations or AI-focused transparency requirements.

11
Points of Contact for Commission and Board under DSA 11

While general points of contact topics exist, this content specifically addresses the establishment and coordination of contact points between Member States' authorities, the Commission, and the Board as a unified DSA governance mechanism, which warrants a dedicated topic.

101
AI Registration 10

The AI Act includes specific registration requirements for high-risk AI systems and their providers. This topic is not adequately covered by existing topics and requires dedicated coverage of registration procedures, databases, timelines, and obligations specific to AI systems under the AI Act.

10
Presumption of Conformity for AI Systems 10

This new topic is needed because the content specifically addresses the legal mechanism of 'presumption of conformity with requirements relating to notified bodies,' which is a distinct procedural concept in the AI Act that deserves its own dedicated topic for proper classification and retrieval of related regulatory content.

10
AI Act Compliance Overview 9

A dedicated topic for the comprehensive overview of AI Act compliance requirements would help organize content that discusses the full scope of obligations across different actor types and system categories.

9
AI Enforcement Actions 8

The Penalties section includes procedural aspects of how penalties are imposed, appealed, and enforced, which warrants a dedicated topic covering the administrative and procedural dimensions of penalty enforcement.

521
Single Point of Contact for AI Regulation 7

The establishment of single points of contact represents a distinct procedural and coordination mechanism within the AI Act that warrants separate coverage from general competent authority designation, as it focuses specifically on communication and liaison functions.

421
AI Act General Procedural Framework 6

The source document is specifically titled 'Procedure' from the AI Act, suggesting a comprehensive procedural section that warrants a dedicated topic covering the general procedural framework, mechanisms, and requirements applicable across the regulation.

6
AI Act Violations 6

The content specifically addresses 'Non-compliance' as a distinct legal concept under the DSA/AI Act framework. This requires a dedicated topic to comprehensively cover violation types, determination procedures, consequences, and remediation mechanisms that are not fully captured by existing penalty or enforcement topics.

42
Cross-Regulation Integration: AI Act and Sectoral Requirements 6

The content emphasizes how delegated acts under the AI Act must take into account requirements from sectoral regulations (specifically Regulation 2024/1689 for safety components). This cross-regulatory integration is a distinct topic requiring dedicated coverage.

321
Points of Contact for DSA Service Recipients 6

This new topic is needed to specifically address the DSA requirement for service providers to maintain accessible points of contact for recipients of services, including procedures for designation, accessibility requirements, and communication obligations.

51
AI Investigative Powers 5

This new topic is needed to specifically address the investigative and information-gathering powers of competent authorities under the AI Act, which is distinct from general cooperation obligations and encompasses the procedural mechanisms for requesting and obtaining documentation.

221
AI Transparency 5

This new topic is needed to specifically capture the transparency obligations framework for AI systems providers and deployers, which is a distinct and comprehensive requirement under the AI Act that encompasses disclosure of system characteristics, performance metrics, limitations, and intended use to end-users and relevant stakeholders.

32
Codes of Practice Development and Adoption Procedures 5

The content specifically addresses 'Codes of practice' as a regulatory mechanism, requiring detailed coverage of how these codes are developed, adopted, and implemented within the AI Act framework.

221
Compensation Mechanisms and Remedies under DSA 5

The DSA content section on 'Compensation' requires a dedicated topic to address compensation mechanisms, procedures, and remedies available under the Digital Services Act, which is distinct from general liability frameworks.

5
Infringement Reporting Procedures and Mechanisms 5

This new topic is needed because the content specifically addresses the procedures, mechanisms, and requirements for reporting infringements of AI Act requirements, which is a distinct procedural framework not adequately covered by existing topics.

5
National-Level Risk Procedures for AI Systems 5

This specific topic addresses the national-level procedural framework for identifying, assessing, and responding to AI systems presenting risks, which is distinct from general market surveillance and authority powers, and represents a key procedural mechanism in the AI Act.

41
AI Act Notification 4

While 'notifying-authorities-procedures-ai' exists, a dedicated topic for the specific 'Notification Procedure' from the AI Act would provide more granular coverage of this particular procedural mechanism, including its specific requirements, timelines, and implementation within the AI Act framework.

4
AI Act Definitions and Terminology 3

While 'AI Act Scope and Definitions' exists, a more granular topic specifically focused on the definitional content and terminology would better capture the nuanced nature of how the AI Act defines key concepts like 'AI system,' 'high-risk,' 'provider,' 'deployer,' and other foundational terms that are essential for understanding and implementing the regulation.

3
AI Act Scope 3

The 'Subject matter' section is foundational to understanding what the AI Act covers, defines key terms, and establishes the scope of application. This concept deserves its own dedicated topic as it is distinct from general compliance requirements.

3
AI System Manipulation and Exploitation Practices 3

The prohibited AI practices content likely addresses specific manipulation and exploitation techniques that are banned, which represents a distinct regulatory concern beyond general prohibition.

21
Compliance Independence 3

DSA compliance functions require independence and impartiality to effectively monitor and enforce compliance. This topic is needed to address the specific requirements for maintaining compliance function independence from operational pressures and conflicts of interest.

21
Deployer Obligations for AI Systems 3

The content specifically addresses obligations of deployers (users/operators) of high-risk AI systems under the AI Act, which is distinct from provider obligations and requires its own dedicated topic for comprehensive coverage of deployer-specific requirements.

3
High-Risk AI Obligations 3

This specific topic is needed to comprehensively cover the distinct set of obligations imposed specifically on providers of high-risk AI systems under Articles 16-17 of the AI Act, which is the core subject of this content and goes beyond general provider obligations.

21
NIS2 Jurisdiction and Territoriality 3

This new topic is needed because NIS2 has specific provisions on jurisdiction and territoriality that determine how the regulation applies across member states and to third-country entities, which is not adequately covered by existing topics.

21
NIS2 Repeal Provisions 3

The content is titled 'Repeal' from NIS2 source material, indicating it contains provisions that repeal or supersede previous legislation. This is a distinct regulatory concept requiring its own topic for proper classification of legislative replacement and transition provisions.

21
Whistleblower Protection 3

This new topic is essential because the content explicitly addresses the protection of reporting persons, including safeguards against retaliation, confidentiality measures, and legal protections, which constitute a critical and distinct regulatory framework within the AI Act.

111
Activity Reports under DSA 2

Activity reports are a specific and distinct DSA transparency mechanism that deserves dedicated coverage. While related to general transparency reporting, activity reports have unique requirements regarding content, frequency, metrics, and publication that warrant a dedicated topic.

2
AI Accuracy Requirements 2

Accuracy is a critical AI Act requirement deserving dedicated topic coverage for measurement, validation, monitoring, and maintenance of AI system performance standards.

11
AI Board Tasks and Responsibilities 2

The content addresses the specific tasks, functions, and responsibilities assigned to the European AI Board, which represents a distinct aspect of its establishment and role.

2
Algorithm Transparency 2

DSA Article 24 transparency reporting includes specific requirements for algorithmic transparency and recommendation system disclosure. This warrants a dedicated topic separate from general transparency obligations to address the unique technical and substantive requirements for algorithmic system reporting.

2
Compensation Mechanisms and Remedies 2

The content specifically addresses 'Compensation' as a standalone topic from the DSA, which requires dedicated coverage for compensation procedures, eligibility criteria, calculation methods, and enforcement mechanisms for both individual and collective remedies.

2
Union Safeguard Procedure for AI Systems 2

This new topic is needed because the Union safeguard procedure is a distinct and critical procedural mechanism in the AI Act that coordinates emergency interventions across member states and EU institutions, requiring its own dedicated topic for comprehensive coverage of safeguard activation criteria, procedures, timelines, and coordination mechanisms.

2
Commitments Framework under DSA 1

The content specifically addresses 'Commitments' as a distinct DSA mechanism that warrants its own dedicated topic, separate from general codes of conduct, as it represents a specific framework for voluntary undertakings by service providers with particular procedural and compliance characteristics.

1
Commitments Framework under DSA 1

The content is specifically about 'Commitments' under DSA, which represents a distinct regulatory mechanism separate from but related to codes of conduct. Commitments are formal undertakings by service providers to comply with specific standards and should have their own dedicated topic for proper classification and retrieval.

1
Topics awaiting content (3)

Codes of Practice Compliance and Monitoring

Codes of practice require specific mechanisms for monitoring compliance and enforcement, which is distinct from general AI Act compliance and deserves dedicated topic coverage.

GPAI Enforcement

This new topic is needed because the content specifically addresses the enforcement of GPAI provider obligations, which requires dedicated procedures and mechanisms distinct from general AI system enforcement.

Points of Contact

The DSA provision on points of contact emphasizes accessibility and effective communication with service recipients. This specific topic would capture the detailed requirements for making contact points accessible, responsive, and user-friendly, which is distinct from general contact point designation procedures.

Complete List

A

Accountability 2529 Access Controls 1773 Automated Decision-Making 1716 Anonymization 1108 Accuracy 894 Artificial Intelligence 880 Authority Powers for Fundamental Rights Protection 620 AI Value Chain Actors and Roles 485 Archiving 294 Annex III Amendments 268 Authority Cooperation 254 AI Risk Assessment 229 Article 19 GDPR - Notification of Rectification, Erasure or Restriction 178 AI Office Establishment and Role 149 AI Act Procedures 148 AI Standards 123 AI Act Territorial Scope 112 Audit Logs 111 AI Act Requirements 107 AI Incident Notification 90 AI Record-Keeping 74 Authority Access Rights to AI Systems and Documentation 68 AI Act Material Scope 64 Annex III Classification Changes and Updates 54 AI Corrective Powers 52 AI Risk Mitigation 46 AI Conformity Declaration 44 AI Act Formal Non-Compliance 41 AI Provider Transparency 40 AI Corrective Actions 32 Advertising Practices and Requirements under DSA 27 Administrative Fines on Union Institutions, Bodies, Offices and Agencies 23 AI Governance Framework 21 AI Information Duties 17 AI Impact Assessment 16 Annex III High-Risk AI Categories 14 AI Transitional Provisions 13 Application Scope: Temporal and Territorial Dimensions 12 AI Registration 10 AI Act Compliance Overview 9 AI Enforcement Actions 8 AI Act General Procedural Framework 6 AI Act Violations 6 AI Investigative Powers 5 AI Transparency 5 AI Act Notification 4 AI Act Definitions and Terminology 3 AI Act Scope 3 AI System Manipulation and Exploitation Practices 3 Activity Reports under DSA 2 AI Accuracy Requirements 2 AI Board Tasks and Responsibilities 2 Algorithm Transparency 2