EU Digital Fitness Check consultation – implications for multinational businesses
April 16, 2026
EU Digital Fitness Check consultation – implications for multinational businessesApril 16, 2026 Why should I read this?The European Commission (EC) is reviewing how EU digital rules interact across data, cybersecurity and AI frameworks. This matters if your business develops or uses AI, relies on data access or sharing, or faces EU cybersecurity obligations. It also matters if you place connected products or digital services on the EU market. The same systems and processes can fall under several frameworks, including the NIS2 Directive, GDPR, the Data Act and the AI Act. These regimes may apply to the same products, services, teams and compliance workflows. This can create overlapping obligations, duplicated reporting and uncertainty in cross-border scenarios. Following the Digital Omnibus simplification package, the EC launched the Digital Fitness Check consultation. The aim is to identify where frictions arise and how rules interact in practice. The direction of travel is not deregulation, but clearer and more workable implementation. What should I do?Although no immediate compliance action is required, this review can help identify existing friction and operational strain. In particular, businesses should consider:
The objective is not to redesign compliance frameworks but to identify existing duplication, uncertainty or operational tension. What else do I need to know?Key challenges under the current EU digital frameworkIn our response to the consultation, we focused on several practical challenges for multinational businesses under EU digital rules:
Regulatory direction and upcoming developmentsRecent EU initiatives confirm a shift towards implementation, clarification and simplification of existing digital rules. This includes the Commission’s March 2026 draft Cyber Resilience Act guidance, ongoing NIS2 implementation work, and the January 2026 cybersecurity package. These initiatives align with the broader direction of the Digital Omnibus and the Digital Fitness Check consultation. The focus is on how existing rules interact in practice and where cumulative burdens arise. The draft Cyber Resilience Act guidance provides direction on scope, product classification and vulnerability handling. It also clarifies interaction with other EU frameworks. Reporting obligations are expected from September 2026, with core requirements applicable from December 2027. The January 2026 cybersecurity package responds to these issues. It combines a proposed Cybersecurity Act revision with targeted NIS2 amendments and more streamlined incident reporting. It is also intended to complement the upcoming Cloud and AI Development Act and the Digital Omnibus simplification effort. For businesses, compliance expectations will continue to evolve as implementation becomes more structured and coordinated across Member States. Further reading:
- Five months of the EU Data Act: Key lessons for your organisation - EU Digital Omnibus: At a glance - NIS2 Hub: Navigating cybersecurity compliance - Insights: NIS2 Implementation Tracker - Updata: Your quarterly privacy & cybersecurity update - EU: Regulatory developments concerning the AI Act Latest Insights
Latest News
Latest Events
legal updates June 02, 2026 UK Retail Finance Horizon Scanner - May 2026 legal updates June 02, 2026 Employer contributions to the Teachers' Pension Scheme (TPS) set to ease fo... legal updates June 01, 2026 UK: Reform of the Consumer Credit Act 1974 takes shape legal updates May 29, 2026 Consumer Lens - Session 1 | The Rise of European Class Actions client news June 02, 2026 Next stop, public ownership: Eversheds Sutherland advises DfT on GTR transi... firm news June 01, 2026 Eversheds Sutherland strengthens restructuring offering with senior partner... firm news June 01, 2026 Eversheds Sutherland strengthens Commercial Advisory practice with technolo... client news May 28, 2026 Eversheds Sutherland advises Schroders Greencoat on acquisition of Dutch bi... virtual Spanish employment law training June 02, 2026 2pm - 5pm (BST) Virtual virtual Education Webinar - Legal refresher for education institutions – governance... June 04, 2026 11:00AM - 12:00PM virtual UK employment law training June 09, 2026 1pm - 4pm (BST) Virtual virtual Education Webinar - Occupational Stress : Preventing Suffering, Enhancing W... June 10, 2026 11:00AM - 12:00PM |