The rules do not wait for your quarterly review
A periodic review captures the rules at one point in time. Regulators and standards bodies can publish amendments, guidance, enforcement decisions, templates, and deadlines between reviews.
By the next review, the rule or guidance behind a control may have changed. A regulatory-change process must monitor the relevant sources and route material updates to an owner.
The sources publish on different schedules
Do not rely on memory and inbox scanning across several regimes. GDPR, NIS2, DORA, the EU AI Act, CSRD, the EU Data Act, and the Cyber Resilience Act each have their own legal texts, guidance, deadlines, and enforcement activity.
DLA Piper's January 2026 survey provides one measure of that activity: European supervisory authorities received an average of 443 personal-data breach notifications per day between 28 January 2025 and 27 January 2026, up 22% from 363 the year before. The figure measures breach notifications, not rule changes, but it shows that regulatory work continues every day. Define which official sources matter to your organization and monitor them on a schedule.
How companies actually find out the law changed
How you learn that a rule changed matters. A monitored source should flag the change, someone should assess its impact, and the team should adjust before enforcement. That requires consistent monitoring across your regulatory perimeter.
Without it, an auditor may cite a standard you have never seen, a customer's security questionnaire may ask about a control you do not have, or a regulator's letter may reference an obligation that took effect months ago. By then the change is expensive to address. No monitored workflow routed it to the right owner when it was published.
Build a regulatory perimeter you can defend
Watching the law means defining the perimeter first. List the official sources, jurisdictions, regulators, product lines, entities, and topics that matter. Then classify each change: new obligation, changed definition, changed date, guidance, enforcement signal, or low-relevance noise.
That is more defensible than claiming to watch everything. You can show which sources are monitored, when they were checked, what changed, why it mattered, who received it, and what action followed. A law tracker is valuable when the monitoring record is as auditable as the alert.
Finding out late has a price, and it is set by someone else
Late detection leaves less time to respond. Under the GDPR, DLA Piper reported EUR 7.1 billion in aggregate fines from 25 May 2018 to 10 January 2026. The largest action in the survey was the Irish Data Protection Commission's EUR 1.2 billion decision against Meta Platforms Ireland in 2023. For specified infringements, Article 83 allows a fine up to the higher of EUR 20 million or 4% of total worldwide annual turnover.
A late change can also trigger rushed remediation, legal work, and failed customer reviews. Finding a relevant update early gives the owner more time to assess it and change the affected policy or control.
Monitor important sources between reviews
If the rules move continuously, checking once a quarter is too slow. Humans should make judgment calls, but they should not be the only sensor watching the perimeter.
Continuous automated monitoring can surface a relevant change when it is published rather than when it is enforced. The goal is reliable coverage of what applies to you, delivered in time to act. A program that finds changes after the damage is already reacting too late.
Automate monitoring and route changes to an owner
Sorena Law Tracker watches the sources that matter on a schedule you can prove. It filters the flow down to changes that touch your obligations and reports what moved.
The system flags each change, ties it to the obligations it affects, and puts it in front of the owner while there is still time to respond. The team can handle regulatory change as a tracked event instead of learning about it from an auditor or enforcement letter.
Keep a record of what changed and who acted
Define the official sources in your regulatory perimeter, monitor them between periodic reviews, and record each relevant change. Route the change to an owner with the affected obligations, controls, and response deadline attached.
Frequently asked questions
How much regulatory change is there really?+
More than a team should track by inbox and memory. You are not following one regulation but many at once ([GDPR](/artifacts/eu/general-data-protection-regulation), [NIS2](/artifacts/eu/nis2-directive), [DORA](/artifacts/eu/digital-operational-resilience-act), the [EU AI Act](/artifacts/eu/artificial-intelligence-act), [CSRD](/artifacts/eu/corporate-sustainability-reporting-directive), the [EU Data Act](/artifacts/eu/data-act), the [Cyber Resilience Act](/artifacts/eu/cyber-resilience-act), plus national and sector rules), each amended on its own schedule. As one measure of the pace, DLA Piper reported European supervisory authorities received an average of 443 personal-data breach notifications per day between 28 January 2025 and 27 January 2026.
Isn't an annual compliance review enough?+
No. An annual review tests against a point-in-time view of the rulebook. By the time the next review comes, the rule, guidance, deadline, or standard you planned against may have changed. Point-in-time checks cannot cover a target that keeps moving; continuous monitoring is how you catch the movement between reviews.
What does it actually cost to find out about a change too late?+
The cost depends on the obligation and the response. DLA Piper reported EUR 7.1 billion in aggregate [GDPR](/artifacts/eu/general-data-protection-regulation) fines through 10 January 2026, with the largest action at EUR 1.2 billion. For specified infringements, Article 83 allows a fine up to the higher of EUR 20 million or 4% of worldwide annual turnover.
Sources
- DLA Piper GDPR Fines and Data Breach Survey, January 2026https://www.dlapiper.com/en-us/insights/publications/2026/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2026?ref=sorena.io
- EUR-Lex, Regulation (EU) 2016/679 General Data Protection Regulationhttps://eur-lex.europa.eu/eli/reg/2016/679/oj?ref=sorena.io


