· Alexander Lewisch

Europe's Third Way: The EU Architecture for a Secure and Fair Digital Society

The EU's regulatory framework for its digitalisation strategy

A hand holding a compass behind a protective shield in front of a digital skyline above the map of Europe
AI-generated image

Introduction

The internet, once celebrated as a borderless space of freedom and unlimited possibility, has changed its face over the past two decades. From the utopia of an unrestrictedly global network, it has become an arena of hard geopolitical interests, economic monopolies and new security risks. The era of digital “laissez-faire,” in which technology developed faster than democracy could react, is coming to an end. Nowhere in the world is this paradigm shift being carried out as consistently as in the European Union.

What critics often dismiss as bureaucratic “regulatory frenzy” or an economic “brake,” is, on closer inspection, the historically necessary attempt to reclaim state and civic sovereignty in the digital space. The EU has recognised that data is fertile ground on which societal influence, economic dominance and national security thrive. That is why Brussels is creating a reference standard of regulations and directives that ranges from the General Data Protection Regulation (GDPR) to the AI Act, in order to achieve its goals in global competition with the USA and China.

The Third Way: digital humanism between Silicon Valley and state capitalism

To understand the current flood of legal acts, one has to look at the global poles. On one side stands the US model, shaped by the “Silicon Valley” ethos: maximum freedom for markets, “move fast and break things,” and a dominance of private platforms that effectively dictate the rules of public communication. On the other side stands the model of digital “state capitalism” of the Communist Party of China, in which technology serves primarily social control and state security interests.

Europe has decided to follow neither of these models. The European Commission’s strategy aims at a “third way,” that of digital humanism. Its core thesis is that technology must serve people, and not the other way around. In its agenda for a Europe fit for the digital age, the Commission defines regulation not as a brake on innovation, but as a trust-building measure. Only when citizens and businesses can trust that their data is safe, that algorithms do not discriminate and that infrastructures do not fail, will they truly embrace these technologies.¹

The architecture of EU digital regulation: the "compliance house" with the AI Act as the roof, the pillars of the data economy (Data Act, DGA) and platforms & market (DSA, DMA), and the foundation of GDPR, NIS-2, CRA and DORA

Figure 1: Source: image generated by Gemini (Google AI)

For a long time, the General Data Protection Regulation (GDPR) was considered the lone lighthouse of EU digital policy. It was a protective shield, conceived to defend the privacy of the individual against the data hunger of marketing departments and the advertising industry. But the reality of the 2020s called for a rethink. A protective shield alone is not enough if the infrastructure itself is under attack, or if a few gatekeepers control market access. That is why the EU expanded its strategy. It is no longer only about protection, but also about order (governance) and resilience (security). One can see the new laws as building blocks of a single large architecture designed to correct three fundamental deficits of the digital market.

The security deficit and the protection of fundamental rights

The GDPR formed the historical foundation of this architecture by anchoring the protection of privacy and sovereignty over personal data as an inviolable fundamental right. But this right to informational self-determination remains theoretical if the IT infrastructure is vulnerable. With the increasing networking of infrastructures in need of protection — such as healthcare facilities, energy grids and financial systems — cybersecurity has become a matter of national security. In response to existing threats, the EU relies on a trio of consistent legal security measures. The NIS-2 Directive obliges operators of critical infrastructures to practise professional risk management. The Cyber Resilience Act (CRA) turns the logic around and, for the first time, puts the manufacturers of hardware and software under obligation, anchoring security already in the design. This is complemented by the Digital Operational Resilience Act (DORA), which specifically hardens the financial sector against digital disruptive factors.²

The competition deficit

Because the digital economy tends towards the formation of monopolies, network effects have led to a few US corporations acting de facto as gatekeepers. Whoever is not listed in the app store or does not appear in the search ranking does not exist economically. This is where the Digital Markets Act (DMA) and the Digital Services Act (DSA) come into play. While the DMA is intended to revive competition by breaking up monopoly structures, the DSA obliges platforms to assume societal responsibility, for example in the fight against disinformation and hate speech.³ It is the attempt to enforce the rule of law in the digital space too: “Because what is illegal offline must be illegal online too.”⁴

The innovation deficit

Europe largely lost the first round of digitalisation (consumer internet, social media) to the USA. In the second round — the industrial Internet of Things (IoT) and artificial intelligence — Europe wants to take the lead. That is why the Data Act and the Data Governance Act (DGA) are intended to break open the silos in which machine data is trapped today, in order to create a fair European single market for data. At the same time, the AI Act sets the world’s first legal framework for artificial intelligence, enabling innovation without, however, sacrificing ethical principles.⁵

The “foundation” of European digital regulation

Progressing digitalisation requires a reliable and robust legal basis on which businesses can securely build their innovative business models and data-usage concepts. This “foundation” of the European compliance architecture consists of four central legal frameworks (GDPR, NIS-2, CRA and DORA), which together guarantee the essential baseline protection for data, IT infrastructures and digital products. Only when the protection of individual privacy, the organisational readiness to defend against cyber threats and the technical security of the deployed hardware and software mesh together seamlessly does a resilient and viable basis emerge — on which the more complex regulations of the European digital strategy that build upon it can be successfully mastered.⁶

The GDPR as the cornerstone of data protection

The General Data Protection Regulation (Regulation (EU) 2016/679) forms the legal foundation for the protection of personal data within the European Union. Its main objective is to safeguard the fundamental rights and privacy of natural persons in the processing of data. Central principles such as data minimisation, purpose limitation and transparency are anchored in Article 5. In addition, Article 32 obliges all processing companies to guarantee a high level of security in the processing of this data through appropriate technical and organisational measures. The General Data Protection Regulation formally entered into force as early as 24 May 2016. To give companies, authorities and organisations enough time for the sometimes massive legal and technical adjustments, a two-year transition phase was granted. Since the cut-off date of 25 May 2018, the law has been directly, fully and legally binding throughout the entire European Union.⁷

NIS-2 and the resilience of organisations

With the NIS-2 Directive (Directive (EU) 2022/2555), the EU broadens the focus to the general network and information security of critical and important entities. The regulation obliges organisations, in Article 21, to carry out professional and comprehensive risk management in the field of cybersecurity, for which management, under Article 20, explicitly bears responsibility. These preventive measures are flanked by strict reporting obligations under Article 23, which stipulate that significant security incidents must be reported to the competent national authorities within very tight deadlines. Since NIS-2 is an EU directive, it does not take effect directly but must be cast into national law. It entered into force at EU level on 16 January 2023. The national legislators of the member states subsequently had, under Article 41, a binding transposition deadline of 17 October 2024 to convert the requirements into local law. From that date, the companies concerned must fulfil the new cybersecurity and reporting obligations in practice.⁸

The Cyber Resilience Act (CRA) for secure products

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first to specifically put manufacturers of products with digital elements — that is, hardware and software — under obligation. The focus here is on the principle of built-in security (“security by design”), which means that essential security requirements must be met already during development and production, as detailed in Annex I of the regulation. In addition, the regulation requires, in Articles 10 and 13, that manufacturers remediate vulnerabilities and provide corresponding security updates over the entire life cycle of the product, or over a defined period. The Cyber Resilience Act was finally published in the EU Official Journal at the end of 2024 and officially entered into force on 10 December 2024. Because the regulation requires far-reaching changes for the development and worldwide production of hardware and software, the legislator grants a generous adjustment phase of 36 months. The requirements for secure products therefore only have to be mandatorily met from 11 December 2027, whereby certain reporting obligations for manufacturers regarding vulnerabilities and incidents are brought forward and apply from 11 September 2026 (Article 71).⁹

DORA as a special law for the financial sector

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is conceived as a strict special law that secures exclusively the digital operational resilience of the European financial sector. The regulation establishes, in Articles 5 to 16, a very specific and tightly meshed framework for ICT risk management that banks, insurers and other financial service providers must mandatorily follow. Beyond this, DORA regulates, in Articles 28 to 44, the handling of ICT third-party risks in detail and prescribes, in Articles 24 to 27, regular, far-reaching tests of operational resilience — such as scenario-based tests, compatibility tests, performance tests, end-to-end tests and threat-led penetration tests. The Digital Operational Resilience Act entered into force in parallel with the NIS-2 Directive on 16 January 2023. In contrast to NIS-2, however, DORA is a regulation and therefore applies directly in all member states without the need for national transposition laws. Financial market actors and their ICT service providers were granted a preparation period of exactly 24 months. Since 17 January 2025 (Article 64), the strict regulatory requirements are binding for the industry.¹⁰

INFOBOX “Lex specialis derogat legi generali”

The principle lex specialis derogat legi generali (Latin for “the more specific law overrides the more general law”) is a fundamental legal conflict rule that is applied in almost all modern legal orders to resolve conflicts of norms. This methodical rule takes effect whenever two different legal provisions govern the same matter but overlap or contradict one another in their requirements or legal consequences. In such a situation, the principle ordains that the more specific norm — that is, the one that regulates the matter in more detail, more narrowly, or for a particular group of addressees — necessarily takes precedence over the more generally framed norm.¹¹

The European data economy

On the solid foundation of cybersecurity and data protection, which stabilises IT systems and protects personal rights, European legislation has erected two supporting pillars in its compliance architecture. While the foundation has a primarily defensive and safeguarding character, the first pillar — consisting of the Data Governance Act and the Data Act — places the active, value-creating and fair use of information in the foreground. These provisions concern the European data economy, since they define the legal rules of the game for how data from networked devices can be used economically, shared voluntarily via trustworthy intermediaries, and distributed fairly between businesses as well as consumers — without endangering the security and data-protection requirements anchored in the foundation.¹²

The Data Governance Act (DGA) as a trust anchor

The Data Governance Act (Regulation (EU) 2022/868) creates the legal and structural framework for promoting data exchange and strengthening trust in shared data use within the EU. The focus here is not on creating new, mandatory access rights, but on establishing secure infrastructures for voluntary data exchange. This is done in particular through the strict regulation of neutral data intermediation services (data intermediaries) in Article 10, which are meant to act as trustworthy intermediaries between data holders and data users, as well as through the promotion of so-called “data altruism” for the common good, regulated in Article 16. The goal is to establish a secure European single market in which public and private data is protected but nevertheless shared in an innovation-friendly way.¹³

The Data Act (DA) for the economic use of data

The Data Act (Regulation (EU) 2023/2854) precisely regulates who may access generated data and use it economically, under which conditions, with the emphasis on data from networked devices (Internet of Things, IoT). The regulation grants users, in Articles 3 and 4, the far-reaching right to access the data generated by their devices and, where needed, to pass it on to third parties. In addition, Articles 8 and 9 lay down fair, reasonable and non-discriminatory (FRAND — “Fair, Reasonable, and Non-Discriminatory”) conditions for data exchange between companies (B2B), and Articles 23 to 31 make strict stipulations to ease switching between cloud providers and to prevent economic lock-in effects.¹⁴

Interplay, conflicts and precedence rules

In legal and technical practice, these two regulations mesh together complementarily. While the Data Governance Act provides the trustworthy infrastructure and the rules of the game for intermediaries (the “how” of data exchange), the Data Act defines the concrete economic access and usage rights to the data itself (the “what” and “who”). There is hardly any substantive conflict between the two frameworks, since they deliberately complement one another in their scope. Overlaps and potential conflicts do exist, however, with the GDPR. Here both the Data Act and the Data Governance Act explicitly ordain that, when personal data flows, the GDPR takes precedence as absolute lex specialis. The Data Act, for example, does not authorise the processing of personal data without a legal basis under Art. 6 GDPR, so that data protection remains untouched. The precedence of the GDPR is also explicitly emphasised in the DGA in recital 4 and in the DA in Article 3(2).¹³ ¹⁴

A secure and fair digital space

While the EU’s data strategy promotes the secure exchange of information, the second major pillar of European digital regulation targets the infrastructure of the internet itself, and thus the online platforms. With the Digital Services Act (DSA) and the Digital Markets Act (DMA), the European Union has created a comprehensive set of rules to make the internet safer, more transparent and more competitive. Both laws form, in a sense, the new digital basic law of the EU and work together as a trustworthy point of reference — but they address different problem areas of the platform economy.

The Digital Services Act (DSA): security and fundamental rights online

The DSA (Regulation (EU) 2022/2065) places the focus on societal responsibility and the protection of users. Its central guiding idea is: “What is illegal offline must be illegal online too.” It forces digital services to take more responsibility for the content they disseminate. Platforms must make their recommendation algorithms transparent (Art. 27) and give users the option to adjust or reject them. In addition, the DSA prohibits manipulative designs (Art. 25), so-called “dark patterns,” and targeted advertising that draws on sensitive data or targets minors (Art. 26 and 28). On top of this come clear and fast reporting procedures (notice-and-action in Art. 16), through which users can report illegal content or hate speech. Platforms are obliged to react promptly to user reports. Special obligations apply to very large online platforms (VLOPs) and search engines, which must proactively minimise systemic risks (Art. 33 to Art. 43).¹⁵

The Digital Markets Act (DMA): fair play in digital competition

While the DSA focuses on content, the DMA (Regulation (EU) 2022/1925) has the market power of the tech giants in its sights. It is aimed exclusively at so-called gatekeepers — the few enormous digital corporations that form an unavoidable interface between businesses and consumers. The DMA is meant to prevent these corporations from abusing their market power to stifle competition. Gatekeepers may no longer give preferential treatment to their own services on their platforms (prohibition of self-preferencing in Art. 6(5)). A search engine operator, for example, may therefore not artificially push its own price-comparison service to position 1 of the search results. Users also gain more freedoms. They must be able to delete pre-installed apps (Art. 6(3)) and may not be forced to use the gatekeepers’ payment systems. Furthermore, the DMA stipulates that basic functions of messenger services, such as WhatsApp, must become interoperable, so that in the future messages can also be sent across provider boundaries (Art. 7).¹⁶

Interplay, conflicts and precedence rules

In practice, the DSA and DMA by no means stand isolated next to each other; rather they often mesh together, which leads to legal points of friction. For the large tech corporations that are classified as gatekeepers under the DMA and, at the same time, as very large online platforms under the DSA, the principle of cumulative application applies — i.e. they must fulfil the obligations of both frameworks in parallel. Potential for conflict arises above all where both laws regulate the same matter from different angles, such as user-based advertising. While the DMA ties the combining of data from different platform services to explicit user consent (Art. 5), the DSA draws hard red lines by generally prohibiting personalised advertising based on sensitive data (Art. 26) or advertising to minors (Art. 28). A user’s “yes” to an advertising measure under the DMA is by no means yet legal under the DSA.

With regard to the precedence rules, the DSA and DMA neither cancel out nor hinder each other, since they fundamentally pursue different protection goals (user safety versus fair competition). Compared with other legal norms, however, there are clear hierarchies. Here too the GDPR forms the absolute red line, since its provisions remain untouched and its requirements for the processing of personal data always take precedence (see Art. 2 DSA and Art. 1 DMA). Moreover, the DMA does not replace classic EU competition law (Art. 101 and 102 TFEU), but complements it preventively (ex-ante), as is expressly clarified in Art. 1 DMA.¹⁵ ¹⁶ ¹⁷

The roof of the compliance house: the AI Act

The conclusion and the roof of European digital regulation is formed by the AI Act (for details on the AI Act, see issue 2 of Quality News for the year 2024). While the previous legal texts regulate access to data, its processing and the power of platforms, the AI Act addresses the intelligent and automated decision-making systems that build upon them. Its central trust anchor is a strictly risk-based approach. The legal requirements for an AI system rise in proportion to the potential dangers it poses to the fundamental rights, the health or the safety of citizens. The law essentially divides AI systems into different risk categories, to which concrete compliance obligations are attached.

To protect fundamental European values, the law draws absolute red lines (unacceptable risk — prohibited practices, Art. 5). AI systems that pose an unacceptable threat are simply banned. These include, for example, “social scoring,” the subliminal cognitive manipulation of persons, and the mass, untargeted scraping of facial images from the internet to build databases. The core of compliance (Art. 6 and Art. 8–22) is formed by high-risk systems that are deployed in sensitive areas, such as in critical infrastructure, in human resources, in law enforcement or in creditworthiness assessment. Here the strictest compliance obligations apply before market launch. Providers must establish a seamless risk-management system (Art. 9), guarantee high requirements for the training data (Art. 10) and effective human oversight (“human-in-the-loop”) (Art. 14). For systems with limited risk (Art. 50), transparency is in the foreground. Users must know that they are interacting with a machine. Thus a clear labelling obligation applies, for example, to chatbots, deep fakes or AI-generated texts and images. Special obligations apply to AI models with a general purpose (Art. 51 ff.). With the rapid rise of generative AI, the law was extended with rules for so-called general-purpose AI (GPAI). Providers of these foundation models must produce comprehensive technical documentation, respect copyright when training the models, and carry out additional evaluations for models with systemic risk.¹⁸

Interplay and precedence rules of the AI Act

The AI Act fits seamlessly as a roof into the European digital strategy. The AI Act creates no new legal basis for the processing of personal data. In Art. 2(7), the AI Act explicitly clarifies that the requirements of the GDPR remain untouched and take precedence. If a high-risk AI processes personal data, it must therefore satisfy both frameworks. A practical conflict or contradiction exists between the “right to be forgotten” (= erasure under the GDPR) and the AI’s need for stable, representative training data. The AI Act demands a high degree of robustness and cybersecurity from high-risk AI. In order to avoid bureaucratic double checks, however, the law provides that conformity assessments should, where possible, be integrated into existing testing procedures of the cybersecurity laws, such as the CRA, NIS-2 or DORA.

A strong economic symbiosis also exists between the AI Act and the European data strategy. While the DGA and the Data Act ensure, in a legally secure way, that data silos are broken open and industrial data is made available, the AI Act functions as a quality filter. Article 10 of the AI Act (“data and data governance”) defines extremely strict requirements for the training data of high-risk AI, in order to prevent systematic bias and discrimination.

There are also important intersections on the topic of platform regulation (DSA/DMA). While the DSA forces large platforms to monitor the societal effects of their algorithms, the AI Act regulates in parallel the technical quality and reliability of the underlying AI models. The DMA prohibits gatekeepers from unfairly siphoning off the data of their business users in order to feed their own competing services. In parallel, the AI Act forces precisely these powerful actors, when developing foundation models (GPAI), to meet strict documentation and copyright obligations (Art. 51 ff.).¹⁸

Conclusion

With the step-by-step introduction and interlocking of the ambitious regulations and directives, the European Union has set in motion a historic process. An isolated protective shield like the GDPR is no longer sufficient in today’s era of networked infrastructures and platform monopolies. Instead, there now stands a robust, self-contained compliance architecture.

On a stable foundation of data protection and cybersecurity (GDPR, NIS-2, CRA, DORA) rise the pillars of a fair and value-creating data economy (DGA, Data Act) as well as of a responsible platform economy (DSA, DMA). This construct is completed by the AI Act, which as the roof regulates the rapid developments in artificial intelligence according to strict, risk-based principles.

This European “third way” of “digital humanism” makes clear that regulation and innovation need not be opposites. Rather, trust in secure data, impartial algorithms and fair markets is the fundamental precondition for society and the economy to adopt new technologies at all. What critics often too hastily dismiss as a bureaucratic brake is in truth the necessary attempt to reclaim state and civic sovereignty in the digital space.

Thanks to the economic weight of the EU single market, this architecture also unfolds a global radiance. An often-overlooked aspect of this regulatory density is its foreign-policy effect. The legal scholar Anu Bradford coined the term “Brussels effect” for this.¹⁹ It describes the phenomenon that multinational corporations often adopt European standards worldwide, because it would be economically inefficient to maintain different technical standards for different markets. In this way the EU is trying not only to regulate its own single market, but also to export its democratic values into the rest of the world through market mechanisms. If the requirements of the compliance architecture become the international gold standard, the EU has not only protected itself but has also actively and durably shaped the rules of the game of global digitalisation.

Illustration: a hand holding a compass behind a protective shield from which light rays radiate into a digital skyline above the map of Europe

Figure 2: Source: image generated by Gemini (Google AI)

The central frameworks at a glance

Regulation (Reg.)/ Directive (Dir.)Central articlesCore theme/ objectiveEntry into force/ start of application
GDPR Reg. (EU) 2016/679Art. 5 (principles), Art. 6 (lawfulness), Art. 17 (right to erasure)Protection of personal data and informational self-determinationEntry into force: 24 May 2016 · Application: 25 May 2018
NIS-2 Dir. (EU) 2022/2555Art. 21 (risk management), Art. 23 (reporting obligations)High level of cybersecurity for critical infrastructures and supply chainsEntry into force: 16 Jan 2023 · Transposition by: 17 Oct 2024
CRA (Cyber Resilience Act) Reg. (EU) 2024/2847Art. 13/14 (vulnerability & incident reporting), Annex I (security by design)Horizontal cybersecurity requirements for hardware/software with digital elementsEntry into force: 10 Dec 2024 · Application: 11 Dec 2027 (reporting obligations from 09/2026)
DORA Reg. (EU) 2022/2554Art. 5–16 (ICT risk management), Art. 17–23 (incident reporting)Digital operational resilience in the financial sector and for ICT service providersEntry into force: 16 Jan 2023 · Application: 17 Jan 2025
DGA (Data Governance Act) Reg. (EU) 2022/868Art. 12 (data intermediation), Art. 18 (data altruism)Trustworthy structures and secure intermediaries for data sharing in EuropeEntry into force: 23 Jun 2022 · Application: 24 Sep 2023
Data Act Reg. (EU) 2023/2854Art. 10 (dispute settlement), Art. 13 (unfair contracts)Rights to data access (e.g. IoT) and protection against economic exploitation in B2BEntry into force: 11 Jan 2024 · Application: 12 Sep 2025
DSA (Digital Services Act) Reg. (EU) 2022/2065Art. 16 (notice & action), Art. 25 (dark patterns), Art. 26/28 (advertising bans)Responsibility for content, combating illegal content and protecting fundamental rights onlineEntry into force: 16 Nov 2022 · Application: 17 Feb 2024
DMA (Digital Markets Act) Reg. (EU) 2022/1925Art. 3 (gatekeeper status), Art. 5–7 (obligations & interoperability)A fair competitive environment, breaking the market power of the huge “gatekeeper” corporationsEntry into force: 01 Nov 2022 · Application: 02 May 2023

Sources

  1. European Commission (2020): Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions: Shaping Europe’s digital future. COM(2020) 67 final. In: eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:52020DC0067
  2. European Commission (2020): Joint Communication to the European Parliament and the Council: The EU’s Cybersecurity Strategy for the Digital Decade. JOIN(2020) 18 final. In: https://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:52020JC0018
  3. European Commission (2020): Europe fit for the Digital Age: new rules for digital platforms. Press release (IP/20/2347) of 15 December 2020.
  4. European Commission (2020): Proposal for a Regulation of the European Parliament and of the Council on contestable and fair markets in the digital sector (Digital Markets Act). COM(2020) 842 final. In: https://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:52020PC0842
  5. European Commission (2020): Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions: A European strategy for data. COM(2020) 66 final. In: http://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:52020DC0066

Published in QualityNews H1/2026