Regingada
Playbook · Cross-regulation

Cross-Regulation Collision Map — eight seams in EU digital law

Deliverable · Source: Funk corpus (CELEX/ELI-anchored) · Status: 2026-08

Each act on its own can be worked through. What gets expensive is the seams between them — where two rulebooks describe the same feature, the same dataset or the same screen, and neither of them yields.

Curated for orientation, produced with the Regingada deliverables pipeline. Not legal advice, not a legal assessment of your case.

1 · Why a map

The acts are manageable one by one

Read on its own, every act in EU digital law is a finite body of text with an addressee, a trigger and a list of duties. Teams get through that. The cost sits somewhere else: at the seams, where two or three regimes reach for the same object and each one brings its own vocabulary, its own addressee and its own clock.

This map lists the eight seams that most often cost coordination in practice. Three of them are pure numbering traps, where identical article numbers carry entirely unrelated duties. The other five are genuine overlaps, where one artefact — a dataset, a feature, an interface — has to satisfy two rulebooks at once.

Index of the eight seams

No. Seam Regimes
01Article 22 is a false friendAI Act × GDPR
02Three unrelated Article 22sDSA × GDPR × AI Act
03Three Article 27s on top of thatAI Act × GDPR × DSA
04FRIA and DPIA live off the same factsAI Act × GDPR
05Recommender systems sit on the seamDSA × GDPR
06Data Act access meets the GDPR legal basisData Act × GDPR
07One control set, mapped twiceNIS2 × AI Act
08Transparency, threefoldAI Act × DSA × GDPR
2 · The eight seams

Where the regimes rub against each other

  • Article 22 is a false friend

    • AI Act
    • GDPR

    Art. 22 GDPR governs automated individual decision-making; Art. 22 AI Act governs the authorised representative. Same number, no substantive kinship whatsoever. Anyone who does not keep the two workstreams cleanly apart produces documents that cite the wrong article each time.

  • Three unrelated Article 22s

    • DSA
    • GDPR
    • AI Act

    The DSA has an Art. 22 as well — trusted flaggers. Three regimes, three entirely different Art. 22 duties. Internal cross-references that do not name their regime are therefore an error type of their own.

  • Three Article 27s on top of that

    • AI Act
    • GDPR
    • DSA

    The FRIA (Art. 27 AI Act, deployer), the representative (Art. 27 GDPR, non-EU) and recommender-system transparency (Art. 27 DSA) likewise share nothing but the number. The twin's collision map resolves such number twins systematically.

  • FRIA and DPIA live off the same facts

    • AI Act
    • GDPR

    The fundamental-rights impact assessment (Art. 27 AI Act) and the data protection impact assessment (Art. 35 GDPR) have different addressees and different tests, but they feed on the same factual basis. Two separately maintained sets of facts are paid for twice — and the divergence between them a third time.

  • Recommender systems sit on the seam

    • DSA
    • GDPR

    Art. 27 DSA calls for transparency about the main parameters; the GDPR governs the profiling behind them. One feature, two rulebooks, two clocks — changes to the ranking touch both.

  • Data Act access meets the GDPR legal basis

    • Data Act
    • GDPR

    The access rights in Art. 4 and Art. 5 Data Act apply even where product data is personal data — but then only within a GDPR legal basis. That boundary has to be drawn BEFORE the first request arrives.

  • One control set, mapped twice

    • NIS2
    • AI Act

    NIS2 risk management (Art. 21) and cybersecurity for high-risk AI (Art. 15 AI Act) overlap on the same systems. A single control set carrying two mappings beats two separately maintained catalogues.

  • Transparency, threefold

    • AI Act
    • DSA
    • GDPR

    AI labelling (Art. 50 AI Act), advertising transparency (Art. 26 and Art. 39 DSA) and information duties (Art. 13 and Art. 14 GDPR) meet in the same interface. Three catalogues, one screen — work through them one at a time and you rebuild the interface three times.

Seams are shown because a corpus of this shape produces them, not because a lawyer has found that they bite in your company. Which of them actually matter in a concrete fact pattern is an assessment — and that is a mandate.

3 · The representative special case

A stack, not a collision

The designation duties under the GDPR, the DSA, the AI Act, NIS2 and the Data Act are NOT a collision but a stack — they do not replace one another. Each act names its own addressees and its own trigger; a designation made under one act discharges nothing under another.

That is why the stack does not belong on this map. It is counted, not resolved: which acts reach the company, in what order the designations fall due, and which single point of contact can carry several of them at once.

A separate playbook works through the stack: the representative compass.

4 · Step 2

Where the software stops

Everything above is orientation: a map of where the regimes touch, drawn from a public corpus and readable back to its sources. It is structured self-assessment and decision support — not an evaluation of a specific company, and not legal advice. The assessment is the second step and belongs to the law firm Theo Funk under a separate mandate.

Get this playbook by e-mail

We send this playbook once to the address below — as a document, no list, no follow-up. Fastest path stays Save as PDF above.

One-off use: we use your address to answer this request and for nothing else — no list, no marketing. Transmission details and your rights: privacy policy.

Disclaimer

Orientation, not legal advice

This playbook and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.