
We have published a Policy & Regulatory Landscape page covering nineteen frameworks across the European Union, the United Kingdom and the United States. Building it changed what we thought we knew about one of them.
Ask almost anyone working on European health data when the European Health Data Space starts to matter, and you will be told 2029, when the secondary-use rules begin to apply for most categories, or 2031, when the remaining categories including genomic data follow. Both dates are correct. Both are also, for most practical purposes, the wrong thing to be planning around.
The Regulation applies in general from 26 March 2027. That date carries the deadline for the Commission’s key implementing acts. It also brings into application several Chapter IV provisions that determine how secondary use will actually work: the templates for data access applications and permits, the dataset description and data quality and utility label rules, and the requirements for secure processing environments themselves.
Those specifications will be built to by twenty-seven national health data access bodies. Whatever they say about what an environment records, and what accompanies an approved output when it leaves one, will be expensive to revisit afterwards. 2029 is when secondary use arrives. 2027 is when the decisions that shape it are made, and that work is happening now.
We knew the 2029 and 2031 dates. We had repeated them ourselves. It was only in going through the Regulation properly, entry by entry, that the 2027 position became obvious. That is a reasonable argument for maintaining a tracker rather than relying on the dates that circulate.
Nineteen frameworks, grouped by jurisdiction. For each one: what it is, what its current status is, and a short section on where it intersects with provenance and evidence governance. It covers the EHDS, the AI Act, the Data Act, the Data Governance Act, the Data Union Strategy, the Digital Omnibus, the proposed Biotech Act, the Cloud and AI Development Act, the GDPR and EOSC; the UK GDPR and the Data (Use and Access) Act, NHS Secure Data Environments, MHRA GxP data integrity guidance and the regulation of AI in healthcare; and in the United States, 21 CFR Part 11, FDA data integrity and clinical-systems guidance, HIPAA and the NIST AI Risk Management Framework.
It is deliberately not a comprehensive catalogue of legislation in any jurisdiction. Frameworks are included because they materially affect how organisations create, process, govern or demonstrate digital evidence. Plenty of important law is left out on that basis.
Every entry has its own review date. A single “last updated” line at the foot of a page covering nineteen frameworks tells a reader nothing useful. They cannot tell whether the entry they care about was checked yesterday or nine months ago, so they end up checking everything themselves, and the page has failed at the only job it had.
Every entry links to the primary source. The instrument, the guidance document, the official page. Thirty links in total. Our entries are summaries, and we say plainly on the page that where the summary and the source differ, the source governs. A tracker that asks to be trusted instead of checked is not worth having.
There is a status vocabulary, and we defined it. “In force” is technically true of the AI Act and tells you almost nothing, because its obligations apply in tranches running to 2028. The page distinguishes in force, in application, staged application, proposed, guidance and under revision, and says what each means.
There is a “What we are watching” section. Eight items expected to change within twelve months, each naming the specific thing to watch for rather than simply flagging that a file is open. This is the part that makes the page worth returning to rather than reading once.
The European Data Union Strategy commits the Commission to launching a standardisation request for a European data quality standard covering completeness, consistency, semantic clarity, governance — and provenance. A related initiative addresses annotation and labelling practices, with the stated aim of ensuring trust in data’s origin and conditions of use.
That is, as far as we can tell, the most direct commitment to provenance standardisation currently on the European agenda, and it appears in a document more often discussed for its competitiveness framing. It is now the clearest venue we know of for the questions we work on, and we have said so on the page.
The page is reviewed in full every quarter and updated between reviews whenever a tracked framework changes materially. The next scheduled full review is December 2026. Recent changes are logged at the top of the page.
We would rather be corrected than agreed with. If an entry is wrong, out of date, misleadingly summarised or missing something that belongs there, please tell us. We will fix it and credit you if you would like us to.
Explore the Policy Landscape page
Related: our proposed Minimum Evidence Record, and the two papers in our Evidence Governance Series — From Data Governance to Evidence Governance and Europe Knows Where Its Servers Are.
If your organisation generates, manages, analyses or governs biological evidence and would be interested in participating in a UK or European provenance demonstrator, The BioChain would welcome the conversation.
Get in touch
Regulatory developments, technical notes and platform news — sent occasionally, straight to your inbox.