Hello,
the Digital Policy Alert added new events. Please find a brief overview below.
Best regards,
the DPA Team
May 22, 2026
| Treaty Adoption | Authorisation, Registration And Licensing
On 22 May 2026, the European Union and Mexico signed the Modernised Global Agreement (MGA) and the interim Trade Agreement (iTA) including requirements for authorisation and licensing. Under Chapter 16 of the MGA, if a party requires a supplier of public telecommunications networks or services to have a licence, the party must publish the types of telecommunications services requiring licences, all licensing criteria and procedures, the period of time it normally requires to reach a decision concerning an application, and the terms and conditions generally applicable to a licence. Licensing criteria, applicable procedures, and any obligations or conditions imposed must be related to the telecommunications services provided, objective, proportionate, transparent and non-discriminatory. Each party must decide upon the granting of the licence within a reasonable period of time so as to allow the supplier to start providing its telecommunications networks or services without undue delay. An applicant or licensee must receive, as a procedural requirement or upon request, written reasons for any denial of a licence, imposition of supplier-specific conditions or obligations, revocation of the licence, or refusal to renew a licence. Administrative fees imposed on suppliers must be objective, transparent, non-discriminatory and proportionate to the administrative costs reasonably incurred. Equivalent procedural standards apply horizontally to other services authorisation regimes under the MGA's domestic regulation provisions. The iTA covers this component of the MGA and will enter into force following consent of the European Parliament and the adoption of a Council decision on conclusion. The iTA will expire once the MGA enters into force.
May 26, 2026
| Order Drafting | Data Governance
On 26 May 2026, the Network and Information Security (NIS) Cooperation Group, comprising EU Member States, the European Commission, and the EU Agency for Cybersecurity (ENISA), adopted common templates for incident reporting under Directive 2022/2555 (NIS2). The common templates provide a uniform format for reporting cyber incidents across the EU. The adoption is intended to reduce the administrative burden on companies fulfilling incident reporting obligations under the NIS2 Directive. The common templates align with broader EU efforts, including the proposed single-entry point for incident reporting under the Digital Omnibus. As a next step, the European Commission plans to adopt the common templates through an implementing act, which would make them mandatory for all Member States.