Cross-Regulation Collision Map — eight seams in EU digital law
Each act on its own can be worked through. What gets expensive is the seams between them — where two rulebooks describe the same feature, the same dataset or the same screen, and neither of them yields.
Curated for orientation, produced with the Regingada deliverables pipeline. Not legal advice, not a legal assessment of your case.
The acts are manageable one by one
Read on its own, every act in EU digital law is a finite body of text with an addressee, a trigger and a list of duties. Teams get through that. The cost sits somewhere else: at the seams, where two or three regimes reach for the same object and each one brings its own vocabulary, its own addressee and its own clock.
This map lists the eight seams that most often cost coordination in practice. Three of them are pure numbering traps, where identical article numbers carry entirely unrelated duties. The other five are genuine overlaps, where one artefact — a dataset, a feature, an interface — has to satisfy two rulebooks at once.
Index of the eight seams
| No. | Seam | Regimes |
|---|---|---|
| 01 | Article 22 is a false friend | AI Act × GDPR |
| 02 | Three unrelated Article 22s | DSA × GDPR × AI Act |
| 03 | Three Article 27s on top of that | AI Act × GDPR × DSA |
| 04 | FRIA and DPIA live off the same facts | AI Act × GDPR |
| 05 | Recommender systems sit on the seam | DSA × GDPR |
| 06 | Data Act access meets the GDPR legal basis | Data Act × GDPR |
| 07 | One control set, mapped twice | NIS2 × AI Act |
| 08 | Transparency, threefold | AI Act × DSA × GDPR |
Where the regimes rub against each other
-
Article 22 is a false friend
- AI Act
- GDPR
Art. 22 GDPR governs automated individual decision-making; Art. 22 AI Act governs the authorised representative. Same number, no substantive kinship whatsoever. Anyone who does not keep the two workstreams cleanly apart produces documents that cite the wrong article each time.
-
Three unrelated Article 22s
- DSA
- GDPR
- AI Act
The DSA has an Art. 22 as well — trusted flaggers. Three regimes, three entirely different Art. 22 duties. Internal cross-references that do not name their regime are therefore an error type of their own.
-
Three Article 27s on top of that
- AI Act
- GDPR
- DSA
The FRIA (Art. 27 AI Act, deployer), the representative (Art. 27 GDPR, non-EU) and recommender-system transparency (Art. 27 DSA) likewise share nothing but the number. The twin's collision map resolves such number twins systematically.
-
FRIA and DPIA live off the same facts
- AI Act
- GDPR
The fundamental-rights impact assessment (Art. 27 AI Act) and the data protection impact assessment (Art. 35 GDPR) have different addressees and different tests, but they feed on the same factual basis. Two separately maintained sets of facts are paid for twice — and the divergence between them a third time.
-
Recommender systems sit on the seam
- DSA
- GDPR
Art. 27 DSA calls for transparency about the main parameters; the GDPR governs the profiling behind them. One feature, two rulebooks, two clocks — changes to the ranking touch both.
-
Data Act access meets the GDPR legal basis
- Data Act
- GDPR
The access rights in Art. 4 and Art. 5 Data Act apply even where product data is personal data — but then only within a GDPR legal basis. That boundary has to be drawn BEFORE the first request arrives.
-
One control set, mapped twice
- NIS2
- AI Act
NIS2 risk management (Art. 21) and cybersecurity for high-risk AI (Art. 15 AI Act) overlap on the same systems. A single control set carrying two mappings beats two separately maintained catalogues.
-
Transparency, threefold
- AI Act
- DSA
- GDPR
AI labelling (Art. 50 AI Act), advertising transparency (Art. 26 and Art. 39 DSA) and information duties (Art. 13 and Art. 14 GDPR) meet in the same interface. Three catalogues, one screen — work through them one at a time and you rebuild the interface three times.
Seams are shown because a corpus of this shape produces them, not because a lawyer has found that they bite in your company. Which of them actually matter in a concrete fact pattern is an assessment — and that is a mandate.
A stack, not a collision
The designation duties under the GDPR, the DSA, the AI Act, NIS2 and the Data Act are NOT a collision but a stack — they do not replace one another. Each act names its own addressees and its own trigger; a designation made under one act discharges nothing under another.
That is why the stack does not belong on this map. It is counted, not resolved: which acts reach the company, in what order the designations fall due, and which single point of contact can carry several of them at once.
A separate playbook works through the stack: the representative compass.
Where the software stops
Everything above is orientation: a map of where the regimes touch, drawn from a public corpus and readable back to its sources. It is structured self-assessment and decision support — not an evaluation of a specific company, and not legal advice. The assessment is the second step and belongs to the law firm Theo Funk under a separate mandate.
Orientation, not legal advice
This playbook and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.
regingada.com/playbooks/kollisionskarte