Global Compliance & Risk Management

Field notes on the operational layer of platform governance.

Visual guides to the regulation. Reports on the implementation. Writing from inside seven years of trust & safety, online safety, and compliance work.

Browse the library What's new Subscribe
§ Most recent

Just added.

§ Dispatches · 4 pieces

Reports, field notes, and live trackers.

Longer-form analyses and ongoing monitoring of where the laws below are being applied, contested, or quietly worked around. Filed from inside the operational layer.

Report · May 2026

The AI Reckoning

Safety, security, adoption, and the real cost of moving fast. Data, timelines, case studies, and research from inside the industry on what the wave of frontier-AI deployment has actually produced so far.

Read the report
Field note · May 2026

The Camera Roll Cloud

Meta's opt-in camera roll suggestions launched in the EU and UK on 16 April 2026. The two-toggle anatomy, the AI Terms underneath, regional carve-outs (Illinois & Texas excluded), peer comparison against Apple, Google and Snapchat, and the 30,000-photo insider breach disclosed nine days before launch.

Read the field note
Live tracker · Quarterly

What Ofcom is saying about the OSA

Each quarter, Ofcom publishes an industry bulletin signalling which Parts of the Online Safety Act it's animating through codes, guidance, supervision, or enforcement. 5 editions tracked, plotted against the Act coming alive.

Open the tracker
Compliance report · Mar 2026

OnlyFans · OSA Compliance Report

Applicability, Part 5 vs Part 3 duties, age assurance, CSEA reporting, Category 1 obligations. The practical walk-through of one of the UK Online Safety Act's hardest test cases.

Read the report
§ The Library · 13 frameworks

Visual guides to the laws, bills and regulations reshaping platforms.

Each guide breaks the statute down to its operational implications. Color-coded by jurisdiction.

AI · EU

EU AI Act

Risk pyramid, prohibited practices, Annex III high-risk domains, GPAI, timeline, penalties, decision tree.

Read →
AI · EU · How-to

EU AI Act · In Practice

Sector-by-sector implementation guide. Fourteen sectors with concrete steps, common mistakes, artefact templates, and the self-test.

Read →
EU

Digital Services Act

The four-tier hierarchy, due diligence duties, VLOP obligations, transparency reporting, systemic risk.

Read →
EU

DMA · Procedural Framework

Gatekeeper designation, the Article 5/6/7 obligations, market investigations, enforcement procedure.

Read →
EU

GDPR

Principles, lawful bases, data subject rights, transfers, breach notification, DPIAs, fines.

Read →
EU · UK

PECR

Privacy and Electronic Communications Regulations: cookies, marketing consent, traffic data.

Read →
UK

Online Safety Act

Three pillars of duty: illegal content, child safety, and fraudulent advertising & transparency. Layered by service category, enforced by Ofcom.

Read →
US · California

CCPA

California consumer privacy: rights, business obligations, sale opt-outs, sensitive personal information.

Read →
US

COPPA

Children's Online Privacy Protection Act: verifiable parental consent, data minimisation, FTC enforcement.

Read →
US

TCPA

Telephone Consumer Protection Act: prior express consent, autodialer rules, DNC, statutory damages.

Read →
US

CAN-SPAM Act

Commercial email rules: header accuracy, opt-out, sender identification, FTC penalties.

Read →
APAC · Singapore

Singapore PDPA

Personal Data Protection Act: consent obligations, DNC registry, data breach notifications, mandatory DPO.

Read →
APAC · Australia

Australian Privacy Act

Australian Privacy Principles, NDB scheme, OAIC enforcement, the ongoing Stage 2 reforms.

Read →
§ Cross-jurisdictional · Key dates

When the rules change.

The dates that matter across the laws this site covers. Past, present, and what's queued next. Filter by jurisdiction or scroll the lot.

Filter
Aug 2027
EU AI Act · Article 6
High-risk AI systems obligations apply in full
Aug 2026
EU AI Act
Full application of the AI Act outside high-risk Annex III
Aug 2025
EU AI Act · Chapter V
GPAI obligations apply: transparency, copyright, systemic risk
Jul 2025
UK Online Safety Act · ss.11-12
Children's safety duties commence; mandatory age assurance for adult content
Mar 2025
UK Online Safety Act · ss.9-10
Illegal content duties commence; Ofcom Codes of Practice take effect
Feb 2025
EU AI Act · Article 5
Prohibited AI practices ban applies; AI literacy obligations start
Aug 2024
EU AI Act
Regulation (EU) 2024/1689 enters into force
Mar 2024
EU Digital Markets Act
DMA full application for designated gatekeepers
Feb 2024
EU Digital Services Act
DSA full application for all in-scope intermediaries
Oct 2023
UK Online Safety Act
Royal Assent; phased commencement begins under Ofcom
§ Coverage · 5 jurisdictions · 12 frameworks

The structure.

Platform governance at the centre, jurisdictions radiating out, frameworks at the edges. Click any node to open its guide.

§ Live research · Open

The Trust Gap.

A short, anonymous survey on public perceptions of data collection by social media and tech companies. About 10 minutes.

Take the survey
§ About

I'm Lubos.

Seven years working on online safety, trust & safety, and compliance. TikTok, Lockwood Publishing, now Klaviyo. The work that shapes the experience of being online sits below the regulation that frames it, in the policy decisions, the risk thresholds, the escalation chains, and the moderation queues. This site is where I write some of it down.

Read the full bio
Lubos Dusek