EU compliance for businesses 2026/2027 – guide to new EU regulations

By Mallbutiken · Fact checked October 7, 2026 · Pillar guide for EU regulations & compliance

Short answer: In 2026/2027, companies are facing several parallel EU regulations concerning products, data, supply chains, marketing, cybersecurity, and sustainability. These should not be managed as isolated islands of documentation. An effective compliance architecture starts by identifying which regulations apply to which products and processes, and then linking responsibilities, data, documentation, deadlines, and supplier requirements into a unified control system.

This page is the hub for Mallbutiken's EU regulatory guides.

EU compliance 2026/2027 – which regulations should companies monitor?

There is no single “EU compliance law”. Which rules apply to a company depends on factors such as product, market, import role, digital service, company size, industry, and how data is used.

Area Regulation Typical main question Guide
Packaging PPWR Role, technical documentation, substances, EPR, future labeling PPWR 2026
Product data ESPR / DPP What data and identifiers are required when the product act enters into force? Digital product passport
Batteries EU 2023/1542 Battery passport, CE, data, due diligence Battery passport 2027
Imports CBAM Scope, 50-tonne threshold, emissions data, declarant status CBAM 2026
Supply chain EUDR Geolocation, risk assessment, DDS, and traceability EUDR 2026/2027
Marketing UCPD + EU 2024/825 Environmental claims, climate claims, and evidence Greenwashing 2026
Data Data Act Data access, contractual terms, and cloud switching EU Data Act 2026
Digital accessibility EAA / Swedish Accessibility Act Which e-commerce services and digital interfaces are covered? Accessibility Act for e-commerce
Cybersecurity NIS2 / Swedish Cybersecurity Act Scope, security measures, incident reporting Which companies are covered by NIS2?

New in-depth guides – updated October 7, 2026

Product and packaging regulations: build the same master data once

PPWR, ESPR/DPP, the Battery Regulation, GPSR, and the Cyber Resilience Act may require different documents but often reuse the same core discipline: product identity, actor role, technical documentation, risk analysis, supplier evidence, change control, and traceability.

Companies therefore benefit from a common product compliance register where each product is linked to applicable regulations, document owners, evidence, versions, markets, and deadlines. This reduces the risk of collecting the same product information multiple times in separate spreadsheets.

Digital product passports are a data issue – not just a QR code

ESPR clearly shows how product compliance is moving closer to data governance. Read our guide on digital product passports and ESPR and the sector-specific guide on battery passports from February 18, 2027.

Supply chain, imports, and supplier data

CBAM and EUDR are two clear examples of regulations where the quality of compliance in practice depends on information outside the company itself. The importer needs to be able to obtain the correct data from producers and suppliers, check its quality, and link it to the correct shipment, product, or production site.

This makes supplier agreements and onboarding important compliance tools. Requirements for data formats, verification, change notifications, audit rights, response times, and liability for incorrect data should be assessed at the procurement stage.

Data, digital services, and cybersecurity

The EU Data Act, GDPR, NIS2, AI Act, and CRA affect different parts of the organization's data and technology environment. A common model should therefore map systems, data flows, suppliers, access, incidents, contractual requirements, and responsibilities.

For GDPR questions regarding transfers outside the EU/EEA, there is our guide on TIA and SCC for international data transfers. If two organizations determine processing together, there is also the guide on joint controllership under Article 26 GDPR.

Environmental claims: compliance meets marketing

The risk of greenwashing shows why compliance cannot stay solely within the legal function. Product and environmental data may be correct, but marketing can still be misleading if the overall impression is broader than the evidence. Therefore, an internal "claim gate" is needed that links marketing text to verified data and approvals.

Read Environmental claims and greenwashing 2026 – what are companies allowed to say?.

How to build a common EU compliance process

  1. Create a regulatory matrix. List regulations per product, service, market, and entity.
  2. Assign responsibilities. Each regulation and control needs a clear owner.
  3. Build common master data. Product, supplier, country, material, data flow, and evidence should be reused.
  4. Create a requirements register. Separate live requirements, future requirements, and readiness actions.
  5. Link evidence. Each control should point to actual underlying documentation – not just a "complete" status.
  6. Implement change control. A new supplier, new product version, or new legislation should trigger a reassessment.
  7. Integrate agreements. Data and compliance requirements need to be included in procurement, SaaS, supplier, and collaboration agreements.
  8. Track deadlines centrally. Avoid separate calendars for each regulation.

Common mistakes

One Excel per law

Data duplication and conflicting versions arise quickly.

Compliance after launch

Documentation is only created when the product is already on the market.

No supplier linkage

The organization sets requirements without ensuring the supplier can provide evidence.

Old deadlines

Project plans are based on articles that have not been updated following EU amendments.

Templates and working documents for EU compliance

Mallbutiken's collection gathers document packages for several of the regulations above. The purpose is to provide an editable work structure – not to replace a product-specific legal or technical assessment.

Need Relevant document package
CBAM, imports, and emissions data CBAM Compliance 2026/2027
Packaging and PPWR PPWR Packaging Compliance
DPP and ESPR readiness ESPR & Digital Product Passport Readiness
Battery passports and battery rules EU Battery Regulation & Battery Passport
EUDR and geolocation EUDR Due Diligence
Environmental claims Greenwashing Compliance

Find the right template for the EU regulation

See all document templates and compliance packages within product rules, data, imports, sustainability, and cybersecurity.

EU Compliance & Product Rules – Templates

Frequently asked questions about EU compliance

Does a small company need to follow the same EU rules as a large one?

It depends on the regulation. Some rules have size thresholds, later deadlines, or simplifications for micro and small enterprises, while others depend primarily on the product or role.

Is CE marking the same as EU compliance?

No. CE marking is relevant for certain harmonized product rules, but many rules in this guide have other mechanisms and documentation requirements.

Which regulation should we start with?

Start with the rules that are already in force or have the nearest deadline and where the business risk is greatest. Then prioritize data gaps and processes that can be reused across multiple regulations.

Sources and further reading

Important: This is an overview guide. Each regulation has its own definitions, transitional rules, and exceptions. Use the in-depth guides and current primary sources before making decisions.
Back to blog