# Which Laws Apply to Service Robots? An EU Compliance Map

Canonical URL: https://xpertdpo.com/service-robots-eu-laws-compliance/

Content type: Article

Published: 2026-08-14T10:57:23+01:00

Updated: 2026-08-14T10:57:25+01:00

Author: Philipa Jane Farley, Head of Legal and Operations

Summary: Which laws apply to service robots? This practical map separates EU, Irish and UK rules across AI, privacy, cyber, product, consumer and employment regulation.

## Article

A service robot can be an AI system, a connected product, machinery, a data-processing platform, a consumer interface and a workplace tool at the same time.

 The correct compliance map depends on the functions enabled, the environment, the people affected, the organisation's role and the market in which the system is supplied or used.

 A mobile unit used only to transport linen along a controlled hospital route raises a different legal profile from the same hardware configured to recognise patients, hold conversations, detect distress and recommend which alert should be prioritised.

 This article maps the principal EU and Irish layers and gives a separate UK position for each. It builds on our [function-led governance guide](https://xpertdpo.com/service-robots-embodied-ai-governance/). It is a reference map, not a substitute for classification against the facts of a particular deployment.

### Start with the regulatory object, trigger and role

 The fastest route through the legal overlap is to ask three questions for each function:

1. **What is the regulated object?** This may be the AI system, personal-data processing, connected product, machinery, service, employment practice or consumer interaction.
2. **What triggers the regime?** The trigger may be intended purpose, type of data, sector, product characteristics, legal effect, market, entity size or a person's vulnerability.
3. **Which role does the organisation hold?** Provider and deployer, controller and processor, manufacturer and distributor are separate legal vocabularies.

| Layer | Typical trigger | Roles carrying duties |
| --- | --- | --- |
| AI regulation | An AI system and its intended purpose or use context | Provider, deployer, importer, distributor, authorised representative |
| Data protection | Processing personal data | Controller, joint controller, processor, subprocessor |
| Connected-data rules | Data generated by a connected product or related service | User, data holder, manufacturer, service provider and relevant third parties |
| Cyber regulation | Product with digital elements or an in-scope essential or important entity | Manufacturer and other economic operators; in-scope entity management bodies and operators |
| Product and machinery safety | Product type, physical function, intended use and market placement | Manufacturer, importer, distributor, authorised representative, user/employer |
| Consumer and accessibility law | Consumer-facing supply, claims, contract or listed accessible product/service | Trader, producer, service provider and other defined economic operators |
| Workplace and equality law | Use affecting workers, applicants or protected groups | Employer, service provider and other responsible organisations |
| Sector rules | Intended medical purpose, regulated care, transport or another controlled activity | Regulated provider, professional, manufacturer and sector-specific duty holders |

 The [Robot Function Card](https://xpertdpo.com/service-robots-embodied-ai-governance/) provides the evidence needed to answer these questions. A product-level conformity document will not settle the deployer's GDPR basis, and a DPIA will not replace a machinery risk assessment.

### The EU AI Act: classify the function, not the robot

 The [EU AI Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?locale=en) applies to AI systems rather than to every automated or connected feature. A service robot may contain several AI systems or functions, and they may fall into different categories.

 Potentially relevant layers include:

- **prohibited practices**, including specified manipulative or exploitative practices and, subject to defined exceptions, emotion recognition in workplaces and education institutions
- **high-risk systems under Annex III**, which can include specified biometric, employment, essential-service and other consequential uses
- **high-risk safety components or products under Annex I**, where the AI system is a safety component of a listed regulated product, or is itself such a product, and third-party conformity assessment is required
- **transparency requirements**, including informing people when they interact directly with an AI system unless that is obvious from the circumstances and context
- **general obligations**, such as AI literacy for providers and deployers and the role-specific duties that apply to the system

 A robot that greets customers is not high-risk merely because it speaks. An employment function that allocates tasks or evaluates workers may require a different analysis. A care robot does not automatically fall within the AI Act's essential-service or medical-device categories; the precise purpose and applicable Annex entry matter.

 The timing also requires care. Following [Regulation (EU) 2026/1744](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744), most AI Act provisions apply from 2 August 2026, while the detailed high-risk requirements in Chapter III, Sections 1 to 3 apply to Annex III systems from 2 December 2027 and to Annex I product-related systems from 2 August 2028. The amendment contains further specified transitions, including for new prohibitions and transparency measures. Organisations should use the current [Commission implementation timeline](https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline/) rather than an older project plan.

 The manufacturer of the physical robot may be the AI provider, but a software company may provide a separate model-enabled function. The customer will often be a deployer. Under Article 25, another party can become the provider if it rebrands the system, makes a substantial modification or changes its intended purpose in the circumstances set out there.

 For high-risk systems, deployer duties can include using the system in accordance with instructions, assigning competent human oversight, monitoring operation, keeping relevant logs and carrying out a fundamental-rights impact assessment where Article 27 applies. The [XpertDPO AI Act role-mapping guide](https://xpertdpo.com/ai-act-role-mapping-provider-deployer-importer-and-distributor/) explains these distinctions in more detail.

### Ireland's AI governance position

 Ireland has implemented a distributed national governance model through the [Regulation of Artificial Intelligence Act 2026](https://data.oireachtas.ie/ie/oireachtas/act/2026/31/eng/enacted/a3126.pdf). The AI Office of Ireland acts as the national single point of contact and has central coordination, cooperation and capability functions. Designated authorities retain sectoral and subject-matter remits.

 That means a robot issue may involve the Irish Office and one or more existing regulators. Personal-data questions remain within the data-protection framework. Employment, product safety, consumer protection, health and other regulated uses can involve the relevant competent authority. Our guide to the [AI Office of Ireland and its distributed regulatory structure](https://xpertdpo.com/ai-office-of-ireland-powers-regulators-reporting/) sets out the institutional map.

 Do not write `AI Office` as the universal regulator. Record which provision, function and sector determine the competent route.

### United Kingdom position on AI regulation

 The UK does not currently have an EU-style cross-sector AI Act. AI-enabled robots remain subject to existing data-protection, equality, consumer, competition, product-safety, workplace and sector-specific law, with regulators applying those rules within their remits.

 A business using an AI-enabled consumer interface remains responsible for its conduct under consumer law. The [Competition and Markets Authority's guidance on AI agents](https://www.gov.uk/government/publications/complying-with-consumer-law-when-using-ai-agents) makes that point directly.

 UK product-regulation reform is developing under the Product Regulation and Metrology Act 2025 and related policy work. Detailed future requirements should not be treated as operational until the relevant secondary legislation applies. Organisations deploying in both the EU and UK should maintain one evidence base where possible but record the legal conclusion separately for each market.

### EU and Irish data protection: GDPR remains central

 Where a robot processes personal data, the [GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016R0679) applies to the processing within its territorial scope. Relevant duties can include:

- purpose limitation, data minimisation, fairness and transparency
- an Article 6 lawful basis and an Article 9 condition for special-category processing
- controller, joint-controller and processor allocation based on actual influence over purposes and essential means
- privacy by design and default
- appropriate security, processor terms and international-transfer safeguards
- a DPIA where the processing is likely to result in high risk
- effective individual rights and, where applicable, Article 22 safeguards for solely automated decisions with legal or similarly significant effects

 The [GDPR article in this series](https://xpertdpo.com/service-robots-gdpr-lawful-basis-consent/) explains why lawful basis and Article 22 must be analysed function by function.

 The domestic or household exemption is narrow. A natural person's purely personal household use may fall outside the GDPR, depending on the facts. A manufacturer, cloud provider, care organisation or commercial home-service operator does not inherit that exemption for its own processing merely because the robot operates inside someone's home.

 Ireland's Data Protection Act 2018 and sector-specific national provisions sit alongside the GDPR. The Data Protection Commission's [DPIA guidance](https://www.dataprotection.ie/en/organisations/know-your-obligations/data-protection-impact-assessments) is particularly relevant where innovative technology, systematic monitoring, vulnerable people or special-category data combine.

 The ePrivacy framework can also apply to storing information in or accessing information from terminal equipment, as implemented in national law. Its application to a robot function is fact-specific and sits alongside the GDPR; it should not be reduced to a website-cookie analysis.

### United Kingdom data-protection position

 In the UK, the UK GDPR and Data Protection Act 2018 provide the principal data-protection framework. The Data (Use and Access) Act 2025 amended parts of that framework, including automated-decision provisions and organisational complaint handling. The commencement position of the specific amendment should be checked when assessing a live function.

 The new organisational data-protection complaints duty has been in force since 19 June 2026. The [ICO's guidance](https://ico.org.uk/for-organisations/how-to-deal-with-data-protection-complaints/) requires a clear route, acknowledgement within 30 days, investigation and response without undue delay. A robot complaint may begin as a service or safety concern, so intake processes need to recognise the data-protection element.

 The Privacy and Electronic Communications Regulations 2003 can also apply to relevant communications and terminal-equipment activity. As in the EU, the test depends on the actual technology and operation.

### EU connected-product data: the Data Act

 The [EU Data Act](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=LEGISSUM%3A4723374) has applied since 12 September 2025. It regulates access to and use of data generated by connected products and related services, including rights and duties involving users, data holders and third parties.

 A connected service robot is a strong candidate for scope, but the exact position depends on the product and data. The organisation should determine:

- which product and related-service data is generated
- who is the user for the relevant provisions
- which party is the data holder
- how access, sharing and contractual restrictions work
- whether trade secrets or security interests are engaged
- which data is personal and therefore also subject to the GDPR

 The Data Act is not a privacy-law replacement or permission to disclose personal data. Where the data relates to identifiable people, the GDPR analysis still applies. A vendor may therefore need to make connected-product data accessible while the parties also establish a valid data-protection route for the requested use.

### United Kingdom connected-data position

 The UK has no direct equivalent of the EU Data Act's general connected-product data regime. The Data (Use and Access) Act 2025 includes powers and structures for smart-data schemes in specified contexts, but organisations should not assume that the same user-access and data-holder duties apply to every UK service robot.

 Contracts remain particularly important for access to operational, diagnostic and fleet data. A UK customer should still establish who can retrieve the data needed for safety, rights, complaints, incident investigation and exit, even where no equivalent horizontal connected-product right applies.

### EU cybersecurity: Cyber Resilience Act and NIS2

 The [Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/2024-11-20/eng) regulates products with digital elements made available on the EU market. A connected service robot and relevant separately marketed software can fall within scope, subject to exclusions and interactions with sectoral product law.

 Manufacturer duties include cybersecurity risk assessment, secure design and development, vulnerability handling, documentation, support and security updates. Importers and distributors have their own checks and duties. The reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026; the main regime applies from 11 December 2027. Support periods will normally need to reflect the expected use, subject to the Regulation's rules, and cannot be treated as an unspecified commercial courtesy.

 A deploying customer is not automatically the manufacturer. Its practical task is to obtain evidence that the product and supplier chain can meet the applicable requirements and that the organisation can operate the product securely.

 The [NIS2 Directive](https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32022L2555) regulates in-scope essential and important entities, not robots as objects. Scope depends on sector, size, designation and national implementation. Health, transport, digital infrastructure and specified manufacturing or service activities may be relevant. An in-scope organisation must include robot systems in its risk-management, supply-chain, incident and business-continuity controls where they support its network and information systems.

 In Ireland, the national law implementing NIS2 and the competent authority for the entity and sector should be checked. Do not infer NIS2 scope simply because a robot is connected or used in a hospital.

### United Kingdom cybersecurity position

 The UK's [consumer connectable-product security regime](https://www.gov.uk/guidance/regulations-consumer-connectable-product-security) has applied since 29 April 2024. It places baseline security requirements on manufacturers and other relevant businesses for defined consumer connectable products, including requirements concerning passwords, vulnerability reporting and information about security-update periods. Exclusions and product definitions matter; it is not a universal law for every commercial, industrial or medical robot.

 The Network and Information Systems Regulations 2018 continue to regulate relevant operators of essential services and digital service providers, with reforms developing. As with NIS2, organisational scope and service dependency are the key questions.

 For a cross-border product, the EU Cyber Resilience Act and UK regime should be mapped separately. A common secure-development and vulnerability-evidence pack can support both, but the legal roles, scope and reporting routes are not identical.

### EU machinery and general product safety

 Physical movement brings product and workplace safety into the assessment.

 The [EU Machinery Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32023R1230) applies from 20 January 2027. It expressly addresses autonomous mobile machinery and safety components with fully or partially self-evolving behaviour using machine-learning approaches. Until its general application, the existing Machinery Directive framework and national implementing law remain relevant.

 Whether a service robot is machinery, partly completed machinery or another regulated product depends on its design and intended function. The manufacturer must address the applicable essential health and safety requirements, conformity assessment, technical documentation and instructions. Importers and distributors have defined obligations. Employers and service operators also retain duties for safe use, training, maintenance and workplace risk assessment.

 The [General Product Safety Regulation](https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32023R0988) applies to consumer products where relevant risks are not fully covered by specific EU harmonisation law. It includes safety, traceability, accident-reporting and corrective-action structures. It should be treated as a gap-filling horizontal regime, not as a replacement for machinery, medical-device or other specific product rules.

### United Kingdom machinery and product-safety position

 For Great Britain, the [Supply of Machinery (Safety) Regulations 2008](https://www.gov.uk/government/publications/supply-of-machinery-safety-regulations-2008/supply-of-machinery-safety-regulations-2008-great-britain) remain central for in-scope machinery. UKCA and continuing recognition arrangements for CE marking depend on the product sector and current government rules, so the [sector-specific marking position](https://www.gov.uk/government/publications/product-regulations-by-sector-and-current-approaches-to-product-marking-ukca-and-ce-regimes) should be checked before placement on the market.

 The General Product Safety Regulations 2005 continue to provide the principal horizontal consumer-product safety framework in Great Britain while reforms develop. Northern Ireland can follow different EU-linked product rules under the applicable arrangements, so a single `UK` product conclusion may be insufficient for market access.

 The Product Regulation and Metrology Act 2025 provides powers for further regulation, including the treatment of emerging technology. It does not by itself mean that every proposed detailed AI-product duty is already in force.

### Medical devices, care services and regulated uses in the EU and Ireland

 The [Medical Devices Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32017R0745) can apply where the manufacturer gives the product or software a specific intended medical purpose. A robot used to diagnose, prevent, monitor, predict, prognose, treat or alleviate disease or injury may fall within the definition, depending on its intended purpose and claims.

 Use in a hospital or care home is not enough by itself. A general delivery or cleaning robot does not become a medical device because of its location. Conversely, a mobility, rehabilitation or clinical-monitoring function should not be treated as general-purpose merely because it shares hardware with non-medical functions.

 Medical-device status can also affect AI Act classification where an AI system is the medical device or safety component and the relevant third-party conformity-assessment condition is met.

 Irish health, social-care and professional rules may separately govern the service provider, quality of care, records, safeguarding and clinical accountability. Those duties attach to the regulated service and responsible professionals even where the robot is supplied by an external manufacturer. The technology does not displace the provider's existing standard of care or duty to maintain a safe service.

### United Kingdom medical-device and care position

 In Great Britain, medical devices are principally regulated under the Medical Devices Regulations 2002, as amended, within the powers established by the Medicines and Medical Devices Act 2021. The MHRA framework, registration, marking and transitional arrangements should be checked for the product and date.

 As in the EU, intended medical purpose is central. Care-sector regulation and professional duties continue to apply to the organisation using the robot. A supplier's medical-device compliance does not decide whether the service operator has staffed, explained or monitored the function appropriately.

### EU consumer law, accessibility and child-facing products

 Consumer law applies to how robot products and services are marketed, sold and operated.

 Under the [Unfair Commercial Practices Directive](https://eur-lex.europa.eu/eli/dir/2005/29/oj/eng), claims and omissions about capability, autonomy, safety, availability, updates, privacy or emotional understanding must not mislead the average consumer. Where a practice is directed at a clearly identifiable vulnerable group, including vulnerability arising from age or disability, the assessment can be made from the perspective of the average member of that group.

 The [Sale of Goods Directive](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L0771) and [Digital Content and Digital Services Directive](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L0770) can affect conformity, updates and remedies for consumer products and digital services. A business cannot avoid consumer responsibility by saying that an external AI provider generated the response or action.

 The [European Accessibility Act](https://eur-lex.europa.eu/eli/dir/2019/882/oj/eng) applies to listed products and services. It is not a general accessibility statute for every service robot, although other equality and national accessibility duties may apply. Classification against the listed scope is required.

 Child-facing companion or educational robots may also fall within toy-safety law where they meet the toy definition. The new [Toy Safety Regulation](https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32025R2509) generally applies from 1 August 2030, with specified earlier provisions. Until then, the current Toy Safety Directive framework remains relevant. Connected toys can also engage data protection, AI transparency and cybersecurity rules.

### United Kingdom consumer, accessibility and child-facing position

 The Consumer Protection from Unfair Trading Regulations 2008, Consumer Rights Act 2015 and Digital Markets, Competition and Consumers Act 2024 framework are relevant to claims, unfair practices, contract performance and enforcement in the UK. The CMA's AI-agent guidance confirms that businesses remain responsible for consumer-law compliance when automated agents act on their behalf.

 The Equality Act 2010 can require reasonable adjustments and prohibit discrimination in services and employment. Product-specific accessibility duties and sector requirements may also apply, but the EU European Accessibility Act should not be presented as directly governing Great Britain.

 UK toy-safety rules and product-security requirements should be assessed separately for child-facing products. Marketing a robot as educational, therapeutic or emotionally aware can also influence consumer expectations and the assessment of misleading claims.

### EU workplace, equality and occupational-safety rules

 Robots used around workers engage more than physical safety.

 The [Framework Occupational Safety and Health Directive](https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1494331771492&uri=CELEX%3A31989L0391) requires employers to assess risks, take preventive measures and provide information and training. For robots, that includes collision, trapping and ergonomic risks as well as workload, alert fatigue, loss of control, psychosocial effects and behaviour during faults or emergency stops.

 The AI Act can classify specified employment AI as high-risk, including systems used for recruitment, decisions affecting work relationships, task allocation based on personal characteristics or behaviour, and performance monitoring or evaluation. Emotion recognition in workplaces is prohibited subject to the AI Act's limited medical or safety exception.

 EU equality directives and national law apply where design or use discriminates on protected grounds. GDPR transparency, fairness and automated-decision safeguards may apply in parallel.

 The [Platform Work Directive](https://eur-lex.europa.eu/eli/dir/2024/2831/oj?uri=CELEX%3A32024L2831) adds specific algorithmic-management protections in platform work. It is a useful example of rules concerning automated monitoring, information, human oversight and review, but it should not be generalised to every employer or robot deployment.

 In Ireland, employment, equality, health-and-safety, consultation and data-protection requirements should be mapped to the actual workforce use. Introducing a robot for logistics does not authorise later use of its telemetry to rank staff.

### United Kingdom workplace and equality position

 The Health and Safety at Work etc. Act 1974 and associated workplace equipment and risk-management regulations require employers to manage physical and operational risk. The Equality Act 2010 prohibits relevant discrimination and requires reasonable adjustments in defined circumstances. UK data-protection law applies to monitoring, inference and automated decisions concerning workers.

 The UK does not mirror the AI Act's high-risk employment category or its specific prohibition on workplace emotion recognition. That absence should not be read as permission. A function can still be unlawful or indefensible under data protection, equality, employment, health-and-safety or contractual duties.

 Worker consultation, clear purpose limits, alternative processes and evidence of meaningful human review remain central governance controls.

### Product liability, service liability and contractual responsibility

 Compliance does not end with the question of which regulator can investigate.

 The revised [EU Product Liability Directive](https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng) expressly accommodates software and related digital services integrated with or interconnected to a product. Member States must transpose it by 9 December 2026, and the revised rules apply through national law to products placed on the market or put into service after that date.

 Before and alongside that transition, national product-liability, negligence, contract and sector rules continue to matter. An unsafe movement, defective update, misleading instruction or service decision may involve several parties and several routes. Contractual allocation does not necessarily remove statutory responsibility to an injured person.

 For deploying organisations, the practical point is to preserve configuration, update, maintenance, incident and human-decision evidence. Without it, the parties may be unable to establish which system behaviour, service choice or change contributed to harm.

### United Kingdom product-liability position

 The UK Consumer Protection Act 1987 product-liability regime remains in place and is under [Law Commission review](https://lawcom.gov.uk/project/product-liability/). The EU revised Directive does not apply in Great Britain. Future reform should be described as developing until enacted and commenced.

### Use one evidence base, but do not merge the legal conclusions

 Many controls support several regimes: a precise intended-purpose statement, role map, data-flow diagram, risk assessment, technical file, human-oversight plan, update history, incident route and complaints record.

 Reusing the evidence is sensible. Treating the legal tests as interchangeable is not.

 A DPIA can contribute to an AI Act fundamental-rights assessment but may not satisfy it automatically. Cybersecurity testing can support product safety and GDPR security, but each asks its own question. A CE-marked product can still be used unfairly by a deployer. A supplier's processor terms do not settle whether it is a separate controller for model improvement.

> One evidence pack can support several regimes. It cannot turn several legal tests into one approval.

 The organisation should maintain a matrix showing the function, regime, trigger, role, evidence, owner, conclusion and review date. The [vendor due-diligence article in this series](https://xpertdpo.com/robot-vendor-due-diligence-security/) explains what to request before procurement and throughout operation.

### The XpertDPO view

 Service-robot regulation looks overwhelming when it is organised as a list of laws. It becomes manageable when organised around regulated objects and functions.

 Start with what the robot is enabled to do. Separate the AI, processing, product, connected service and operating model. Identify each legal role. Then record the EU, Irish and UK conclusion against the relevant trigger and date.

 That approach prevents two opposite errors: assuming that a sophisticated robot is automatically high-risk under every regime, or assuming that product conformity and a vendor contract have dealt with the deployment.

 Our [AI Governance and DPIA Lifecycle Support](https://xpertdpo.com/ai-governance-dpia-lifecycle-support/) helps organisations connect these regimes without losing the distinct legal tests. Our [DPO Support](https://xpertdpo.com/dpo-support/) provides independent privacy advice and monitoring within that wider governance structure.

 Next in the series, [Robot Vendor Due Diligence: Security, Updates and Operational Control](https://xpertdpo.com/robot-vendor-due-diligence-security/) turns this map into evidence requests, contract controls and operational checks.

### Sources and further reading

- [EU AI Act, Regulation (EU) 2024/1689](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?locale=en)
- [Regulation (EU) 2026/1744 amending the AI Act](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744)
- [GDPR, Regulation (EU) 2016/679](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016R0679)
- [EU Data Act overview](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=LEGISSUM%3A4723374)
- [Cyber Resilience Act, Regulation (EU) 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/2024-11-20/eng)
- [NIS2 Directive, Directive (EU) 2022/2555](https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32022L2555)
- [Machinery Regulation, Regulation (EU) 2023/1230](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32023R1230)
- [General Product Safety Regulation, Regulation (EU) 2023/988](https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32023R0988)
- [Medical Devices Regulation, Regulation (EU) 2017/745](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32017R0745)
- [Revised Product Liability Directive, Directive (EU) 2024/2853](https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng)
- [Regulation of Artificial Intelligence Act 2026](https://data.oireachtas.ie/ie/oireachtas/act/2026/31/eng/enacted/a3126.pdf)
- [UK consumer connectable-product security regulations](https://www.gov.uk/guidance/regulations-consumer-connectable-product-security)
- [UK Data (Use and Access) Act 2025](https://www.legislation.gov.uk/ukpga/2025/18/pdfs/ukpga_20250018_en.pdf)

## General Information Only

This article is provided for general information and does not constitute legal, regulatory, or professional advice. Data protection obligations depend on the specific facts, context, and jurisdiction involved. You should not rely on this content as a substitute for advice tailored to your organisation.

If you would like support with a specific issue, please contact us: https://xpertdpo.com/contact/
