---
title: "Digital and Technology Regulation"
id: "2052"
type: "expertise"
slug: "digital-and-technology-regulation"
published_at: "2026-01-26T10:34:21+00:00"
modified_at: "2026-07-29T10:10:39+00:00"
url: "https://www.august-debouzy.com/en/expertise/digital-and-technology-regulation/"
markdown_url: "https://www.august-debouzy.com/en/expertise/digital-and-technology-regulation.md"
excerpt: "Turning digital regulation into a strategic and operational advantage European digital regulation is reshaping the rules across every industry: manufacturing, healthcare, finance, energy, mobility, retail, media, and public services. The frameworks governing online services (DSA, DMA), data (Data Act), artificial..."
taxonomy_language:
  - "English"
taxonomy_post_translations:
  - "pll_6977432d77143"
taxonomy_tax_expertise:
  - "Digital and Technology Regulation"
taxonomy_tax_famille_expertise:
  - "Regulatory"
---

## Turning digital regulation *into a strategic and operational advantage*

European digital regulation is reshaping the rules across every industry: manufacturing, healthcare, finance, energy, mobility, retail, media, and public services. The frameworks governing online services (DSA, DMA), data (Data Act), artificial intelligence (AI Act), and cybersecurity (NIS2, Cyber Resilience Act) establish obligations that determine access to the European market, the viability of business models, and the success of growth operations.

We translate these requirements into actionable strategies. Each project draws on our combined expertise in business law, intellectual property, data protection, cybersecurity, and litigation: activity qualification, compliance management, transaction security, regulator relations, and dispute resolution.

Scale-ups, fast-growing SMEs, investment funds, large corporations, financial institutions, platforms, media groups, and public bodies work with us to turn new regulatory frameworks into sustainable competitive advantages.

## *our* Capabilities

### (01) Compliance for Digital Services: DSA, DMA, and Sectoral Frameworks

The Digital Services Act and the Digital Markets Act impose differentiated obligations on platforms, marketplaces, search engines, and intermediaries. The legal status of each player determines its scope of compliance. We assess and qualify activities, design compliance programs (content moderation, algorithmic transparency, interoperability, reporting), and oversee implementation. Sector-specific requirements are built in from the start. In fundraising or acquisition transactions, our regulatory audits preserve valuation and support the negotiation of warranties.

### (02) Data Governance and Circulation: Data Act, GDPR, and Data Sovereignty

The Data Act introduces new rules on data sharing and portability between public and private entities. We analyze data flows to identify obligations and potential conflicts over ownership or use. We negotiate access terms, draft contractual clauses, and advise on data valorization strategies. International transfers (standard contractual clauses, BCRs, Data Privacy Framework) and the tensions between the GDPR and extraterritorial laws inform our recommendations. Each decision balances compliance, sovereignty, and performance, preventing operational bottlenecks through foresight.

### (03) Artificial Intelligence and High-Risk Systems

The AI Act, which will gradually apply between 2025 and 2027, classifies AI systems according to their risk level. The classification determines the technical, documentary, and certification requirements for compliance. Generative AI raises specific challenges, including intellectual property, transparency of synthetic content, and liability. In regulated sectors such as healthcare, finance, and defense, AI compliance intersects with additional legal frameworks. In transactions, we assess AI-related risks and negotiate warranties that protect investments. Innovation remains possible within a secure and controlled framework.

### (04) Cybersecurity, Resilience, and Crisis Management

NIS2, DORA, and the Cyber Resilience Act (phased implementation through 2027) strengthen obligations for infrastructure operators, software providers, and manufacturers of connected products. Entity classification (essential or important) dictates the level of compliance required. We conduct risk assessments, design compliance roadmaps, and formalize incident response procedures. We prepare authority notifications and coordinate actions during crises. Contractual clauses are adapted to secure supply chains. This reduces exposure to sanctions and strengthens operational resilience.

### (05) Liability, Litigation, and Protection of Digital Actors

The legal status of each actor—hosting provider, publisher, or platform—determines its liability regime for hosted content. We design moderation policies, formalize notice-and-takedown procedures, and defend companies facing complaints, abusive removals, or disclosure requests. Our approach balances vigilance obligations with freedom of expression. In regulatory investigations (CNIL, Arcom, ARCEP, Competition Authority), we manage communications, respond to enforcement notices, and prepare appeals, safeguarding both reputation and business continuity.

### (06) Cross-Border Operations and Regulatory Conflicts

Multinational groups, international funds, and non-EU companies operating in Europe often face conflicts between legal frameworks such as the GDPR, CLOUD Act, and data laws in China or Brazil. We structure multijurisdictional compliance strategies, negotiate international transfer mechanisms (SCCs, BCRs), and anticipate incompatibility risks. For non-European expansions, we analyze local requirements and align EU compliance with extraterritorial regulations. This ensures secure, predictable international growth.

### (07) Regulators, Transactions, and Strategic Influence

Constructive dialogue with regulators (CNIL, Arcom, ARCEP, European Commission, Competition Authority) validates strategies early and prevents obstacles. In M&A and fundraising operations, we conduct compliance audits, assess risks, and negotiate representations, warranties, and exit clauses in case of regulatory changes. We also monitor public consultations, analyze draft legislation, and prepare advocacy positions to influence EU policy developments.

Collective excellence

at the service of the

*highest standards.*

Team

[Mahasti Razavi ( Managing Partner )](https://www.august-debouzy.com/en/collaborateur/mahasti-razavi/)

[Basile Ader ( Partner )](https://www.august-debouzy.com/en/collaborateur/basile-ader/)

[Alexandra Berg-Moussa ( Partner )](https://www.august-debouzy.com/en/collaborateur/alexandra-berg-moussa/)

[Florence Chafiol ( Partner )](https://www.august-debouzy.com/en/collaborateur/florence-chafiol/)

[Benjamin van Gaver ( Partner )](https://www.august-debouzy.com/en/collaborateur/benjamin-van-gaver/)

[Marc Mossé ( Senior Counsel )](https://www.august-debouzy.com/en/collaborateur/marc-mosse/)

[Thibaut Amourette ( Counsel )](https://www.august-debouzy.com/en/collaborateur/thibaut-amourette/)

[Roxane Blanc-Dubois ( Counsel )](https://www.august-debouzy.com/en/collaborateur/roxane-blanc-dubois/)

[Eden Gall ( Counsel )](https://www.august-debouzy.com/en/collaborateur/eden-gall/)

[Inès Bouzayen ( Senior Associate )](https://www.august-debouzy.com/en/collaborateur/ines-bouzayen/)

[Charlotte Chen ( Senior Associate )](https://www.august-debouzy.com/en/collaborateur/charlotte-chen/)

[Léa Margono ( Senior Associate )](https://www.august-debouzy.com/en/collaborateur/lea-margono/)

[Robin Nini ( Senior Associate )](https://www.august-debouzy.com/en/collaborateur/robin-nini/)

[Alexandra Antalis ( Associate )](https://www.august-debouzy.com/en/collaborateur/alexandra-antalis/)

[Benjamin Fontani ( Associate )](https://www.august-debouzy.com/en/collaborateur/benjamin-fontani/)

[Chloé Niedergang ( Associate )](https://www.august-debouzy.com/en/collaborateur/chloe-niedergang/)

Précédent     Suivant

## Contact Us

## *Latest* News

[19/12/25 Legal Article 15 min Digital Omnibus Regulation on AI Will the European principle of Smart Regulation eventually benefit artificial intelligence? One can only hope so. As Regulation (EU) 2024/1689 of 13 June 2](https://www.august-debouzy.com/en/legal-article/digital-omnibus-regulation-on-ai/)

[12/09/25 Legal Article 3 min 12 September 2025: Implementation of Certain Provisions of the Data Act Regulation (EU) 2023/2854 of 13 December 2023, establishing common rules on fair access to and use of data (the “Data Act”), governs the access, sharing, a](https://www.august-debouzy.com/en/legal-article/12-september-2025-implementation-of-certain-provisions-of-the-data-act/)

[31/07/25 Legal Article 4 min August 2, 2025: A New Milestone in the Implementation of the AI Act AI Act: next phase of implementation on August 2, 2025](https://www.august-debouzy.com/en/legal-article/august-2-2025-a-new-milestone-in-the-implementation-of-the-ai-act/)

[11/07/25 Legal Article 4 min Entry into force of Directive (EU) 2019/882: accessibility by design. The European Directive on the accessibility of products and services (commonly known as the EEA Act) requires businesses to incorporate accessibility into the design of their digital and physical offerings. This is a legal imperative that anchors an essential ethical requirement. It came into force on 28 June 2025.](https://www.august-debouzy.com/en/legal-article/entry-into-force-of-directive-eu-2019882-accessibility-by-design/)

[24/06/25 Legal Article 3 min Code of practice for general-purpose AI models: final text remains outstanding! Pursuant to Article 56 of Regulation (EU) 2024/1689 on Artificial Intelligence (“AI Act”), a non-binding code of practice, developed by a multi-stakeholder expert group supported by the AI Office, was to be published no later than May 2, 2025. The code of practice is intended to guide providers of general-purpose artificial intelligence models in implementing the new obligations imposed by the AI Act and to serve as a reference framework…](https://www.august-debouzy.com/en/legal-article/code-of-practice-for-general-purpose-ai-models-final-text-remains-outstanding/)

01

05

Précédent     Suivant

[Find our latest news](https://www.august-debouzy.com/en/hub/)
News

## *FAQ*

### (01) How can you anticipate and manage obligations under the Digital Services Act (DSA) and the Digital Markets Act (DMA)?

The DSA (Regulation (EU) 2022/2065) and DMA (Regulation (EU) 2022/1925) form the core of European digital regulation and impose structural obligations on online platforms. The DSA has been fully applicable since 17 February 2024, requiring platforms to moderate illegal content, ensure advertising transparency and manage systemic risks. The DMA, applicable since 7 March 2024, imposes interoperability and non-discrimination obligations on gatekeepers, with fines of up to 10% of worldwide turnover. We advise platforms, publishers and business users on assessing their status, achieving operational compliance and representation before the Commission and courts.

### (02) How can you comply with the AI Act and legally govern the deployment of artificial intelligence systems?

Regulation (EU) 2024/1689 (AI Act), in force since 1 August 2024, classifies AI systems by risk level and imposes graduated obligations on providers and deployers. Prohibited AI practices have been applicable since 2 February 2025, exposing violators to fines of up to EUR 35 million or 7% of worldwide turnover. Obligations relating to high-risk systems are phasing in progressively through 2027. We advise technology companies, AI users and investors on classifying their systems, designing compliance frameworks, drafting deployment contracts and engaging with supervisory authorities.

### (03) How can you prepare your organization for cybersecurity obligations (NIS2, DORA) and operational resilience?

The NIS2 Directive (2022/2555), transposed into French law by ordinance of 15 January 2025, subjects between 10,000 and 15,000 French entities to enhanced cyber risk management and incident notification obligations. DORA (Regulation 2022/2554), applicable since 17 January 2025, requires financial entities and their critical ICT service providers to implement a digital operational resilience framework including penetration testing and specific contractual requirements. We support companies in identifying their regulatory status, implementing compliance programs and managing incidents.

### (04) How can you govern data use under the Data Act and the Data Governance Act?

The Data Act (Regulation 2023/2854), applicable since 12 September 2025, establishes new rights of access to and sharing of data generated by connected objects and associated services, imposing obligations on manufacturers and service providers. The Data Governance Act (2022/868), applicable since 24 September 2023, governs the reuse of public sector data and creates a framework for data intermediaries. We advise companies on data access contracts, structuring data flows and sharing obligations, anticipating interactions with the GDPR and sector-specific regulations.

### (05) Why choose August Debouzy as your law firm for digital and technology regulation?

Digital platforms, technology companies, publishers, AI providers, financial entities and industrial groups entrust us with their compliance with European digital and technology regulations. Our cross-cutting approach covers the DSA, DMA, AI Act, NIS2, DORA, Data Act, Data Governance Act, GDPR and sector-specific regulations. We combine continuous regulatory monitoring, design of operational compliance frameworks and representation before supervisory authorities (European Commission, ARCOM, ANSSI, ACPR, AMF).
