2025 regulatory landscape: 40+ digital & ESG laws to have on the radar

In short

  • The adoption of new regulations is accelerating, with 41 key pieces of regulations identified as part of the IoT Analytics’ Digital and ESG Regulation Outlook 2025–2030.
  • 4 EU regulations are set to have a very high impact on organizations in the coming years: The EU Cyber Resilience Act (CRA), EU Data Act, EU AI Act, and EU CSRD received a very high impact score.

Why it matters

Regulations often come with severe financial and operational penalties if not complied with. Enterprises should be aware of the regulations that impact their operations and work with their legal teams to ensure business compliance and readiness to adapt as new regulations come into effect.


In this article

Introduction: The emerging regulations radar

40+ new or amended regulations will impact how organizations operate worldwide. The adoption of new or updated regulations is accelerating, according to IoT Analytics’ Digital and ESG Regulation Outlook 2025–2030 (published August 2025). This is being driven by outdated laws, rapid technological innovations, and growing demands for corporate accountability in how companies handle data, the use of AI, and environmental, social, and governance (ESG) impacts, with the EU leading the charge. To assess the impact these regulations will have on organizations worldwide, the IoT Analytics analyst team identified 41 upcoming or recently updated regulations that will impact enterprises to some degree, with a focus on regulations in the EU, US, China, and the UK.

The impact radar shows 4 upcoming regulations with very high impact. 4 of the upcoming regulations, all from the EU, are classified as having very high overall impact scores and require urgent attention from enterprises doing business in the EU. They are:

  1. Cyber Resilience Act (CRA) – This act impacts all entities that manufacture, import, or distribute products with digital elements (PDE) placed on the EU market. It places strict cybersecurity obligations on manufacturers and mandates tight incident reporting deadlines. Both the cost of implementation and the severity of non-compliance penalties are very high.
  2. Data Act – This act impacts all manufacturers of connected products placed on the EU market, users of and data recipients from these products, data holders and processors, and public sector organizations. It gives users the right to access their product data, regulates business-to-business data sharing, eliminates switching fees for cloud providers, and removes trade secrets as an exemption for data access. Both the cost of implementation and the severity of non-compliance penalties are very high.
  3. AI Act – The act impacts developers, deployers, and users (except for personal/non-professional use) of AI, as well as importers, resellers, and distributors of AI systems. It categorizes AI systems into 4 risk levels, ranging from unacceptable risk to minimal risk. High-risk systems must undergo assessment and be registered in the EU, while generative AI (GenAI) content is subject to specific use and labeling requirements. Both the cost of implementation and the severity of noncompliance penalties are very high.
  4. Corporate Sustainability Reporting Directive (CSRD) – This act impacts companies that fulfil any of the following criteria: are considered large based on revenue criteria, are listed on an EU-regulated market, are banks or insurance companies, or are EU subsidiaries of non-EU companies. In all, it impacts approximately 60,000 companies. It places ESG and sustainability strategy reporting requirements on companies and requires these reports to be reviewed by independent auditors. Implementation costs are very high, and the severity of noncompliance penalties is fairly high.

The full report delves into each regulation, with the assessed organizational impact score and regulation specifics where relevant. Below are the 41 identified regulations, including their purpose, impacted entities, and the penalties for non-compliance.

Digital and ESG Regulations Outlook 2025-2030 - Cover

Digital and ESG Regulations Outlook 2025-2030

A 152-page report detailing the impact of key existing and upcoming regulations on enterprises operating in the EU, U.S., China, and the U.K.

Already a subscriber? View your reports and trackers here →

Data regulations

EU is a gold standard for privacy laws. Without question, the EU leads with the strictest, most mature data laws. Its General Data Protection Regulation (GDPR) remains the global benchmark for personal data protection, with robust user rights, breach reporting requirements, and substantial penalties. Even US states like California have adopted privacy acts that align closely with GDPR. Meanwhile, China’s strict data acts largely have a national security focus while also providing users the ability to consent to cross-border data transfers.

RegulationRegionDescriptionWho it applies toNon-compliance penalties
California Privacy Rights Act (CPRA)USRegulates how personal data of California residents is used, limits data sharing for targeted ads, and protects correction/deletion rightsFor-profit businesses engaged in the collection, processing, or sharing of California residents’ data. To be in scope, a business must fulfill at least one of the following criteria:
– Have an annual revenue of at least $25 million
– Handle data of 100,000 or more consumers or households
– Earn 50% or more of its revenue from selling or sharing personal information
Fines up to $7,500 for each intentional violation, alongside possible operational restrictions or public disclosure orders
Data ActEUGrants access to non-personal data, regulates non-personal data sharing across firms and governments, and addresses personal data in specific contextsAll manufacturers of connected products placed on the EU market, EU users of connected products, EU data recipients receiving data from data holders, data holders, providers of data processing services for EU customers, and public sector and EU bodies requesting dataFines set by EU Member States, with GDPR penalties applying for personal data breaches
Data Governance Act (DGA)EUSets rules for the re-use of public sector data, regulates data intermediation services, and establishes the EU Data Innovation Board, all aiming to foster a trustworthy environment for data sharing within the European UnionPublic sector entities holding data subject to re-use, data intermediation service providers, data altruism organizations, natural and legal persons, and the EU Data Innovation BoardFines and operational penalties are set by EU Member States
Data Protection Act (DPA)UKRegulates how personal data is used by organizations, businesses, and the government; provides individuals with rights over their personal information; and aligns with the EU GDPR (as the UK was part of the EU when the GDPR was adopted)Any company or entity operating within the UK that processes personal data, including data controllers—entities that determine the purposes and means of processing personal data—and data processors—entities processing personal data on behalf of controllersFines up to £17.5 million or 4% of a company’s annual revenue (whichever is higher), alongside possible operational restrictions or public disclosure orders
Data Security Law (DSL)ChinaRegulates all data handling activities in China, primarily setting strict controls for important and core data to ensure security and national interestsAll entities that collect, process, store, and transfer data in general (not just personal data), specifically important data handlers, core national data handles, critical information infrastructure operators, and government bodies handling dataFines up to ¥10 million (approximately $1.5 million USD), alongside possible operational restrictions, public disclosure orders, or even criminal prosecution
Digital Markets Act (DMA)EURegulates obligations and restrictions on designated gatekeepers—large online platforms with significant market influenceAll entities identified as gatekeepers, defined by meeting criteria such as an annual turnover exceeding €7.5 billion, operations in at least 3 EU Member States, and a user base of over 45 million monthly active end-users and 10,000 annual business usersFines up to 20% of the company’s annual revenue, alongside possible operational restrictions or public disclosure orders
Digital Services Act (DSA)EUEnforces obligations for digital service providers, platforms, and intermediaries; manages illegal content; ensures transparency; and mitigates risksIntermediary service providers, hosting service providers, online platforms, and online search enginesFines up to 6% of a company’s annual revenue, alongside possible operational restrictions or public disclosure orders
General Data Protection Regulation (GDPR)EURegulates how entities can collect, process, and protect the personal data of individuals within the EUAny company or entity operating within the European Union that processes personal data.Absolute fines up to €20 million or percentage-based fines up to 4% of revenue (whichever is higher), public disclosure orders, product recalls or bans, suspension of operations, and rectification or erasure of data
Health Insurance Portability and Accountability Act (HIPAA)USRegulates the privacy, security, and confidentiality of individuals’ health data, and allows appropriate data access for healthcare operationsHealth plans, including insurers and healthcare maintenance organizations (HMOs); healthcare clearinghouses; healthcare providers; and businesses handling protected health information (PHI) on behalf of the above-mentioned entities, like billing companies, data processors, or cloud service providers (CSPs)Fines up to $250,000, alongside possible operational restrictions, public disclosure orders, or even imprisonment up to 10 years
Personal Information Protection Law (PIPL)ChinaRegulates the collection, use, storage, transfer, and disclosure of personal information on individuals located in ChinaData handlers that collect, process, store, and transfer personal data of individuals located in China; critical information infrastructure operators that handle large-scale or sensitive data; and platform operators with complex business models and a large number of users that process personal dataFines up to ¥50 million (approximately $7 million USD) or 5% of annual revenue (whichever is higher), alongside possible operational restrictions, public disclosure orders, and even a ban from managerial roles

Cybersecurity regulations

The scope of cybersecurity acts is expanding globally. The EU, US, UK, and China are either tightening existing cybersecurity laws or introducing new ones, with non-compliance bringing hefty fines and negative operational actions. Beyond avoiding fines, meeting cybersecurity requirements is increasingly essential for doing business. For digital and connected products, failure to comply can mean exclusion from entire markets.

RegulationRegionDescriptionWho it applies toNon-compliance penalties
Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)USRequires critical infrastructure entities to report significant cyber incidents and ransomware payments to the US Cybersecurity and Infrastructure Security Agency (CISA)All private and public entities in critical infrastructure sectors as defined by Presidential Policy Directive 21 (PPD-21), which include entities operating in the energy, healthcare, financial services, transportation, and communications sectorsFines established through civil actions, alongside possible public disclosure orders
Cyber Resilience Act (CRA)EUSets security standards and mandatory requirements for designing digital products, requiring manufacturers to manage vulnerabilities throughout the product lifecycleManufacturers that design, develop, or market PDEs under their name; importers that place non-EU PDEs on the EU market; and distributors that supply PDEs without modifying themAt least €15 million or a minimum of 2.5% of the total annual worldwide turnover (whichever is higher), alongside possible public disclosure orders, product recalls or bans, suspension of operations, and loss of license
Cybersecurity and Infrastructure Security Agency (CISA) ActUSEstablishes CISA in the Department of Homeland Security and strengthens federal protection of critical infrastructure from cyber threatsFederal agencies, state, local, tribal, and territorial governments, and all critical infrastructure operatorsPenalties for non-compliance do not exist unless mandated by other legislative acts
Cybersecurity LawChinaRegulates network security, personal data protection, and critical information infrastructureAll network and critical information infrastructure operators, network product providers and 3rd-party contractors, entities that deal with personal and cross-border data (if data is collected in China), and entities operating in ChinaA fine of ¥1 million, alongside possible product recalls or bans, suspension of operations, and loss of licenses
Digital Operations Resilience Act (DORA)EUMandates ICT risk management frameworks for the financial sector and requires oversight of critical third-party ICT service providersMost financial entities, such as banks, investment firms, payment institutions, asset and fund managers, insurers, and crypto platforms, and 3rd-party ICT service providers offering services to financial entities, such as cloud and data service providers, software vendors, and ICT outsourcing firmsFines are set by EU Member States, while operational penalties include public disclosure orders, product recalls or bans, suspension of operations, and loss of licenses
Executive Order (EO) 14028 on Improving the Nation’s CybersecurityUSRequires federal agencies to implement security measures and software bills of materials (SBOMs) to ensure the integrity of the software supply chainAll federal agencies, critical infrastructure operators, ICT and OT service providers, cloud service providers, software (classified as critical), and hardware vendors, if under contract with federal agencies and critical infrastructure operators (CIO)No fines, but organizations could face operational penalties such as public disclosure orders, suspension of operations, and disqualification from federal contracts
EU Cybersecurity ActEURegulates the European Union Agency for Cybersecurity (ENISA) and establishes a European cybersecurity certification framework for ICT products, services, and processesENISA and providers of ICT products, services, and processes only if they choose to certify their products or are mandated to do so by EU or national regulationsFines are set by EU Member States, while operational penalties include product recalls or bans and suspension of operations
IoT Cybersecurity Improvement ActUSMandates the development of minimum-security standards for IoT devices purchased or used by federal agenciesAll federal agencies that procure or manage IoT devices, IoT device manufacturers or vendors that supply IoT devices to US federal agencies, and IoT service providers for US federal agenciesNo fines, but organizations could face operational penalties such as product recall or bans, suspension of operations, loss of licenses, and disqualification from federal contracts
National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0USGuides organizations in managing cybersecurity risks through 6 core functions: govern, identify, protect, detect, respond, and recoverAll US federal agencies, when mandated by other EOs and regulations, and critical infrastructure service providers, when mandated by EOs and legislationPenalties for non-compliance do not exist unless mandated by other legislative acts
National Security Investment (NSI) ActUKRegulates acquisitions and investments that can have national security risks and allows the government to condition acquisitions in 17 sensitive sectorsUK-based companies acquiring another UK or foreign company with UK operations or foreign companies acquiring control over UK business, assets, or intellectual propertyAt least £10 million or 5% of revenue (whichever is higher), alongside possible transaction voiding
Network and Information Systems RegulationsUKEstablishes measures to improve the cybersecurity and resilience of critical services and implements reporting obligationsAll operators of essential services, such as energy, health, and digital infrastructure companies, as well as online marketplaces, online search engines, and cloud service providersA fine of £17 million, alongside possible public disclosure orders, product recalls or bans, suspension of operations, and loss of licenses
Network Data Security Management RegulationChinaSecures network data in China and establishes risk assessments and strict controls on data sharing and cross-border transfersAll entities involved in network data processing within China, including data collection, storage, use, transfer, and deletion, specifically network data processors, critical information infrastructure operators, large platforms, and 3rd-party service providersA fine of ¥10 million, alongside possible product recalls or bans, suspension of operations, and loss of licenses
Network Information Systems Directive 2 (NIS2)EUA legislative act aimed at establishing security risk management measures, regulating management compliance, and setting incident reporting procedures while repealing and replacing the original 2016 NIS Directive, addressing prior shortcomings in cybersecurity legislationPublic and private sector entities of all sizes (small, medium, and large) with domestic or foreign headquarters operating within the EU jurisdictionFines of at least €10 million or a minimum of 2% of the total annual worldwide turnover (whichever is higher), alongside operational restrictions and public disclosure orders
Product Security and Telecommunications Infrastructure Act (PSTIA)UKImposes cybersecurity requirements on manufacturers, importers, and distributors of UK consumer smart productsAny manufacturer of a UK consumer smart product, entity that markets a product manufactured by another entity under that entity’s name or trademark, importer of UK consumer smart products, and distributor of UK consumer smart productsA fine of at least £10 million or 4% of revenue (whichever is higher), alongside possible public disclosure orders, product recalls or bans, suspension of operations, and loss of licenses
Regulation 2023/2841: Regulation on Cybersecurity Measures for EU InstitutionsEUEstablishes common cybersecurity measures across EU institutionsEU institutions, offices, and agenciesNo fines, but institutions could face suspension of operations, warnings, and recommendations
Regulation 2024/482: Commission Implementing Regulation on European Common Criteria-based Cybersecurity Certification SchemeEUEstablishes rules and obligations for manufacturers and certification entities involved in the EU Common Criteria (introduced in the EU Cybersecurity Act)Manufacturers, importers, and distributors of ICT products subject to or pursuing EUCC certification, whether required by EU law or chosen voluntarilyFines are set by EU Member States, while operational penalties include public disclosure orders, product recalls or bans, and suspension of operations
Telecommunications (Security) Act (TSA)UKEnforces legal obligations on telecom providers in the UK to safeguard their networksPublic electronic communication network providers, public electronic communications service providers, suppliers of telecommunication equipment, and managed service providers for telecommunication networksA fine of at least £10 million or 10% of revenue (whichever is higher), alongside possible public disclosure orders, product recalls or bans, suspension of operations, loss of licenses, and enforcement notices

AI regulations

AI technology outpaces regulatory development worldwide. AI is a prime example of a technology that is evolving faster than legislative acts can keep pace, leaving many jurisdictions either unregulated or without clear compliance requirements. Governments are still in the early stages of AI governance, relying on guidelines rather than regulations. Meanwhile, much of the world is looking to the EU, the US, and China for regulatory direction. Many governments are delaying their own AI regulation efforts to observe how these leading economies structure governance. In general, the EU is moving ahead with strict, rule-based AI oversight while the US favors a more innovation-oriented approach. China, by contrast, is prioritizing control through state-led security and enforcement frameworks.

RegulationRegionDescriptionWho it applies toNon-compliance penalties
AI ActEURegulates the development, marketing, and use of AI systems, bans certain AI practices, imposes obligations on high-risk AI, and ensures human oversightAll AI providers (developers and deployers), including providers of foundational models, GenAI, and pre-trained AI models integrated in AI systems, as well as AI component suppliers; all AI deployers (users), except for personal or non-professional activities; and importers, resellers, and distributors of AI systemsA fine of €35 million or 7% of revenue (whichever is higher), alongside possible content access restrictions
EO 14141 on Advancing US Leadership in AI InfrastructureUSSets rules on the development of AI data centers, requires clean energy usage, and requires compliance with NIST standardsCompanies engaged in the development, operation, or supply of AI infrastructure, specifically in AI infrastructure development (AI data centers, computing clusters, clean energy infrastructure) and AI model development and operationsDoes not specify explicit penalties but empowers federal agencies (the Departments of Defense, Energy, and Commerce) to establish regulations that enforce penalties
Interim Measures for the Management of GenAI ServicesChinaEnforces rules for AI service providers on content control, data security, algorithm transparency, user rights, and compliance with state ideologyGenAI service providers that develop, deploy, or offer GenAI services (such as LLMs, image generators, and automated content creation tools) and AI infrastructure and platform operators, such as cloud computing platforms, data centers, and algorithm marketplaces that provide infrastructure for generative AI servicesFinancial penalties from other legal acts, such as the Personal Information Protection Law and the Cybersecurity Law, apply

Sustainability regulations

Regulatory pressure sustains green tech demand. As IoT Analytics recently noted, CEO discussions around sustainability and related topics have steadily declined in corporate earnings calls since their peak in Q1 2021. This does not mean companies are abandoning or losing interest in sustainability initiatives, though it could indicate such initiatives are afterthoughts for CEOs amid new digitalization and AI initiatives. Nonetheless, regulations remain in place that compel transparent reporting and set targets for energy consumption reduction. These regulatory pressures are helping propel the sustainability platform market toward an estimated $3.7 billion by 2029.

RegulationRegionDescriptionWho it applies toNon-compliance penalties
Corporate Sustainability and Due Diligence Directive (CSDDD)EURequires due diligence reporting and regulates how companies identify, prevent, and address human rights and environmental impacts in their value chainsAll companies with over 1,000 employees and a global revenue of at least €450m in the last financial yearFines are set by EU Member States (percentage-based fines are at least 5% of revenue), as are operational restrictions
Corporate Sustainability Reporting Directive (CSRD)EURequires companies to disclose ESG impacts, imposes standardized reporting, and requires independent auditsAll companies that fulfil any of the following criteria:
• Are large EU companies (meeting the revenue criteria)
• Are listed on an EU-regulated market
• Are EU banks or insurance companies
• Are non-EU companies (meeting the revenue criteria)
Fines and operational penalties are set by EU Member States
Ecodesign for Sustainable Products Regulation (ESPR)EUSets sustainability requirements for a wide range of physical products placed on the EU market and establishes the digital product passportAll manufacturers of physical goods placed on the EU market, including components and intermediate products (with exceptions for food and feed, medical products, living organisms, vehicles, and certain products in the construction sector), importers and distributors of physical goods, and online marketplaces and online search enginesFines and operational penalties are set by EU Member States
(New) Energy Efficiency Directive (EED)EUEnforces measures to improve energy efficiency in the EU and sets binding requirements and targets for energy consumption reduction in various sectorsAll enterprises with high energy consumption (i.e., enterprises consuming >10 TJ annually and those consuming > 85 TJ over the past 3 years), all data centers with an IT power demand of over 500 kW, and public sector contractorsFines and operational penalties are set by EU Member States
Machinery RegulationEUEstablishes safety and compliance rules for machinery and related products and addresses new AI and connectivity-related risksMachinery manufacturers, importers, and distributorsFines and operational penalties are set by EU Member States
Net Zero Industry Act (NZIA)EUSets rules for scaling up EU manufacturing capacity, streamlining permitting procedures, and sets supply chain resilience rules for 19 net-zero technologiesAll companies that manufacture, develop, or operate net-zero technologiesFines and operational penalties are set by EU Member States
New Batteries RegulationEURegulates the production, recycling, and disposal of batteries and sets rules for extended producer responsibility, material recovery, and supply chain due diligenceBattery manufacturers, importers and distributors of batteries, waste management and recycling operators, and independent operators involved in battery repair, maintenance, or repurposingFines and operational penalties are set by EU Member States
Renewable Energy Directive (RED) IIIEUSets targets to increase renewable energy levels by 2030 and requires Member States to optimize permitting procedures and grid integration for clean energy transitionTransmission system operators, distribution system operators, fuel suppliers, renewable energy producers, battery manufacturers, and EV manufacturersFines and operational penalties are set by EU Member States
Sustainable Finance Disclosure Regulation (SFDR)EURegulates the transparency of sustainability risks in the decision-making processes of financial market participants and financial advisersFinancial market participants, such as investment and insurance firms, institutions for occupational retirement provision, manufacturers of pension products, alternative investment fund managers (AIFMs), entrepreneurship and venture capital funds, management companies of undertakings for collective investment in transferable securities (UCITS), and credit institutions, as well as financial advisors, such as insurance intermediaries, investment firms, AIFMs, and UCITSFines and operational penalties are set by EU Member States
Taxonomy RegulationEUSets criteria to assess if an economic activity is sustainable and establishes the extent to which an investment is environmentally sustainableFinancial market participants, such as asset managers, institutional investors, insurance companies, and pension funds; financial advisors; and large public interest companies, subject to non-financial reporting under Directive 2013/34/EUFines and operational penalties are set by EU Member States

Below, the team shares a few key pages from the Digital and ESG Regulation Outlook 2025–2030 report showing the impact score for all 41 regulations shared above.

Scoring the impact of regulations on enterprises (Insights+)

Access key market data for $99/month per user

The Insights+ Subscription unlocks exclusive facts & figures. You will gain access to:

  • Additional analyses derived directly from our reports, databases, and trackers
  • An extended version of each research article, not available to the public

Full report access not included. For enterprise offerings, please contact sales: sales@iot-analytics.com

Disclosure

Companies mentioned in this article—along with their products—are used as examples to showcase market developments. No company paid or received preferential treatment in this article, and it is at the discretion of the analyst to select which examples are used. IoT Analytics makes efforts to vary the companies and products mentioned to help shine attention to the numerous IoT and related technology market players.

It is worth noting that IoT Analytics may have commercial relationships with some companies mentioned in its articles, as some companies license IoT Analytics market research. However, for confidentiality, IoT Analytics cannot disclose individual relationships. Please contact compliance@iot-analytics.com for any questions or concerns on this front.

More information and further reading

Related publications

You may also be interested in the following reports:

Related articles

You may also be interested in the following articles:

Sign up for our research newsletter and follow us on LinkedIn to stay up-to-date on the latest trends shaping the IoT markets. For complete enterprise IoT coverage with access to all of IoT Analytics’ paid content & reports, including dedicated analyst time, check out the Enterprise subscription.

Share this with others:

<a href="https://iot-analytics.com/author/justina-alexandra-sava/" target="_self">Justina-Alexandra Sava</a>

Justina-Alexandra Sava

Justina is a market research analyst in our Hamburg, Germany office. Her work focuses on software and professional services related topics, specifically: Marketplaces, IoT professional services, technology regulation.

Research Newsletter

Sign up for our exclusive email updates today, and receive the latest market insights before others.

IoT Analytics, founded and operating out of Germany, is a leading provider of strategic IoT market insights and a trusted advisor for 1000+ corporate partners worldwide.

Learn more about how we can help you achieve your goals faster with the right data-driven insights and intelligence.