Operations | Monitoring | ITSM | DevOps | Cloud

What does the EU Data Act mean for Observability?

The EU Data Act came into effect on January 12th, 2024 and most of its provisions apply from September 12th, 2025. The EU Data Act is designed to give individuals and businesses more control over the data they generate, ensuring fair access, use, and sharing across sectors. For any data generating platform that intends to operate in the European Union, this new legislation matters.

Automating GDPR compliance for web applications with CircleCI

Since 2018, the General Data Protection Regulation (GDPR) compliance has been an important milestone in the evolution of privacy laws for web application users across Europe. GDPR requires companies to obtain explicit user consent for data collection and processing, and only for specified, legitimate purposes. It’s a law based on principles of transparency and purpose limitation. This law applies to global companies dealing with EU citizen data, giving individuals control over personal data.

DORA Compliance Software Options And Use Cases

DORA entered into application on January 17, 2025, and since then, DORA compliance software, such as Spektion, has become an essential part of many DORA-compliant workflows. However, in this article, we go beyond just one software solution and round up the most common DORA compliance software categories that covered entities are currently using. We also examine what they excel at and how they come together in the context of DORA compliance.

The first rule of DORA Metrics...

DORA Metrics are widely regarded as the gold standard for measuring the performance of software development teams. The metrics themselves though are generic, high-level pointers – they are not an instruction manual. Adopting the DORA approach is the first step down the path to continuous improvement. The next steps are deciding how the measures should be defined in the context of your own organisations processes and then figuring out how to retrieve (and present) the relevant data.

EU AI Act: what changes in August 2025 and how to prepare

‍ On August 2, 2025, a key part of the EU AI Act comes into force. It has serious implications for how you manage incidents related to artificial intelligence. ‍ While the full regulation will not apply until 2026, new obligations for providers of general-purpose AI (GPAI) models begin this summer. If you are building or deploying AI-powered services in Europe, the clock is ticking.

The GENIUS Act: A Regulatory Milestone for Stablecoins and the Digital Dollar

The GENIUS Act (Guiding and Establishing National Innovation for US Stablecoins), passed by the US Senate on June 17, 2025, represents a pivotal moment in the regulatory landscape of crypto assets. Many industry leaders, like Paolo Ardoino, the CEO of Tether, have lauded this legislation. They see it as a pathway toward achieving a clear and structured legal framework for stablecoin issuers. Beyond setting forth technical prerequisites, this legislation might serve to recalibrate the dollar's role in the digital economy and fortify the standing of crypto allies.

Is your cloud data truly sovereign? The CLOUD Act & FISA 702 reality check

As UK public sector bodies, financial institutions, and enterprises accelerate cloud adoption, a pivotal question emerges: Who truly controls your data, and under which laws? With data breaches and regulatory scrutiny intensifying, storing data and workloads in a host country alone doesn't guarantee sovereignty. U.S.

The 6th DORA requirement no one told you about

In this day and age, rare is the organization (if there is one at all) that has never been hit by a cyberattack. Few have escaped the nightmare of systems going down, customers losing access to their accounts, or payments getting stuck mid-transfer. Just as common is all the stress on the path to recovery and the absence of a structured, streamlined, and repeatable process for effectively preparing for the worst.

How to Prepare for APRA CPS 230 Regulations

Understand what APRA CPS 230 means for your organization, and how to get compliance-ready by the July 2025 deadline. If you work for an Australian business in the financial services industry, you’ve likely already heard of the Australian Prudential Regulation Authority (APRA). You may also have heard that a new set of APRA regulations, CPS 230, will become mandatory for all APRA-regulated companies to comply with as of 1 July 2025.