What regulation-ai.eu collects, why, who processes it and how to have it deleted. Audience measurement only if you accept it; no advertising trackers.
The short version
This site carries no advertising trackers and nothing that follows you to other sites. It does use Google Analytics to count visits — and only if you say yes: nothing is requested from Google, and no cookie is set, until you accept in the banner. Decline and the site works exactly the same.
We hold personal data only where you have handed it to us: a newsletter subscription, a purchase, an exam attempt, a certificate, or an email you sent us. If you have only read pages, and you declined measurement, we hold nothing about you.
Cookies and audience measurement
| Cookie | Set by | Purpose | Kept |
|---|---|---|---|
rai-consent (local storage) |
This site | Remembers whether you accepted or declined, so you are not asked on every page | 6 months, then you are asked again |
_ga, _ga_G-3FS986W00M |
Google Analytics, only after you accept | Tells repeat visits apart so the visit count is not simply the page count | Up to 2 years, or until you decline |
rai-consent is the record of your own choice and is stored in your browser only — it is never sent anywhere, and it is what the ePrivacy rules exempt as strictly necessary.
Google Analytics is loaded by injecting Google's tag after the click, not before: if you decline, or ignore the banner, or browse with JavaScript off, your visit produces no request to Google whatsoever. There is no "cookieless ping". Advertising signals (ad_storage, ad_user_data, ad_personalization) are set to denied permanently — we run no advertising.
To change your mind at any time, use the Cookies link in the footer of any page. Declining there also deletes the _ga cookies already set.
What Google receives when you have accepted: the pages you view, approximate location derived from a truncated IP, browser and device type, and how you arrived. Google Ireland Limited acts as our processor; Google may transfer data to the United States under the EU–US Data Privacy Framework and its standard contractual clauses.
What we collect, and why
| What | When | Why | Kept |
|---|---|---|---|
| Email address | You subscribe to the newsletter | To send the newsletter | Until you unsubscribe |
| Email address, IP address | You submit the subscription form | The IP is recorded with the submission as an anti-abuse measure | Until you unsubscribe |
| Email address, purchase reference | You buy a toolkit or a course | To deliver the files, to re-issue your download links, and to honour refunds | As long as needed for accounting obligations |
| Email address, answers, score | You sit a certification exam | To grade the paper server-side and to let you review the attempt | Until you ask us to delete it |
| Email address, the name you chose, course and score | You are issued a certificate | So the certificate can be publicly verified by its id | Until you ask us to delete it |
| Message content, sender address | You write to info@regulation-ai.eu | To answer you | Until you ask us to delete it |
The public certificate check deliberately returns the holder name, course, score and issue date — and never the email address. That is the whole design: a certificate has to be verifiable by a third party without exposing the holder's address.
Who else processes it
We use four providers, each with its own terms:
- Convex — the application backend and database, running in the eu-west-1 region.
- Stripe — payment processing. Card details never reach this site; they go to Stripe directly.
- AgentMail, sending through Amazon SES — outbound and inbound email for
info@regulation-ai.eu. - Google Ireland Limited — audience measurement through Google Analytics 4, only for visitors who accepted it. This is the only provider that receives anything about people who merely read pages, and only after they said yes.
We do not sell personal data, and we do not share it for advertising.
Your rights
Consent to measurement can be withdrawn at any time through the Cookies link in the footer, with no consequence for using the site.
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, or restrict what we do with it, and you can object to processing. Write to info@regulation-ai.eu from the address concerned and say what you want done. We do not charge for this and we do not require a form.
If you subscribed to the newsletter, every message carries a one-click unsubscribe link; you do not need to email anyone.
You also have the right to complain to your national data protection authority.
Changes
This notice was last updated on 16 August 2026: Google Analytics 4 was added to the site behind a consent banner, and the sections on cookies and processors were rewritten accordingly. Before that date the site loaded no analytics at all.
It was first published on 9 August 2026. Substantive changes are dated here rather than made silently.
Contact
info@regulation-ai.eu
Official AI Act Compliance Deadline Calendar
Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.
| Obligation | Applies to | Original date | New date | Status | Countdown | Legal basis |
|---|---|---|---|---|---|---|
| Prohibited Practices (Art. 5) | All providers and deployers | active | — | AI Act Art. 5 | ||
| GPAI Rules (Chapter 5) | GPAI model providers | active | — | AI Act Art. 51-56 | ||
| Commission Enforcement Powers over GPAI | GPAI model providers | active | — | AI Act Art. 88-94, 101 | ||
| Transparency Obligations (Art. 50) | Providers and deployers of chatbots, generative, emotion recognition systems | active | — | AI Act Art. 50 | ||
| New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) | Providers and deployers of generative AI systems | active | — | AI Omnibus 2026 Art. 5 | ||
| AI-Generated Content Marking (pre-existing systems) | Providers of generative AI systems on the market before 2 Aug 2026 | active | — | AI Act Art. 50(2) — transitional | ||
| Regulatory Sandboxes | National competent authorities | deferred | — | AI Omnibus 2026 Art. 57 | ||
| High-risk AI — Annex III (standalone) | Providers of standalone Annex III systems | deferred | — | AI Omnibus 2026 Art. 6(2) | ||
| High-risk AI — Annex I (embedded) | AI embedded in Annex I regulated products | deferred | — | AI Omnibus 2026 Art. 6(1) |
⬇ Download JSON · CC BY 4.0
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Only audience measurement, and only if you accept it. Google Analytics is the single third-party script on the site: it is not loaded at all until you click Accept in the banner, so refusing means no request to Google, no cookie and no measurement. There are no advertising or session-recording scripts, and nothing tracks you across other sites.
Only what you have given us: your email address if you subscribed or bought something, your name and score if you sat an exam and were issued a certificate, and the content of any message you sent to info@regulation-ai.eu. If you have done none of those things, we hold nothing about you.
Email info@regulation-ai.eu from the address concerned and ask. We delete on request. Note that a certificate you asked us to make publicly verifiable will stop being verifiable once its record is deleted.
In the European Union. The application backend runs on Convex in the eu-west-1 region. Payments are handled by Stripe and email by AgentMail, which sends through Amazon SES; both are separate controllers or processors with their own privacy terms.
Stay ahead of AI Act changes
Get compliance alerts when deadlines or obligations change.
No spam. One-click unsubscribe.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.