Regulators
National authorities responsible for enforcement of EU AI Act, GDPR, MiCA, and DORA. Profiles by country with sourced facts.
No matches. Try a different filter or search term.
EU EU-wide
Who is the EBA: the EU's banking authority — and supervisor of the biggest stablecoins
The European Banking Authority writes the EU's banking rulebook and, under MiCA, is the body that directly supervises the largest 'significant' stablecoins — the one part of crypto licensing that is centralised at EU level, not national. What it does, how it differs from ESMA, who runs it after the 2026 leadership change, and its role under DORA — every fact sourced.
Who is EIOPA: the EU's insurance and pensions authority — and the third DORA ESA
The European Insurance and Occupational Pensions Authority is the EU's supervisor for insurance and occupational pensions. It has no crypto or MiCA role at all — it matters to this site for one reason: it is the third of the three ESAs that jointly run DORA. What it does, how it differs from EBA and ESMA, and who runs it — every fact sourced.
Who is the EDPB: the EU's data protection coordinator
The European Data Protection Board is the EU-wide body that coordinates national data-protection regulators (DPAs) and resolves cross-border GDPR disputes. What it does, how the one-stop-shop mechanism works, who leads it, and what binding decisions look like.
Who is the European AI Office: the EU's enforcer for GPT-class AI models
The European AI Office is the body that polices general-purpose AI — the GPT/Claude/Gemini-class models — directly from Brussels. What it does, the structural detail most coverage skips (it is not an independent agency — it is a department inside the European Commission), who runs it, and where it stops and national authorities take over — every fact sourced.
Who is ESMA: the EU's securities-markets and crypto rule-maker
The European Securities and Markets Authority is the EU body that writes the technical rulebook for MiCA crypto and is one of the three authorities overseeing DORA. What it does, what it deliberately does NOT do (it does not licence or fine crypto firms — national regulators do), who runs it, and where it sits next to EBA — every fact sourced.
Who is the EDPS: the EU institutions' own data protection supervisor
The European Data Protection Supervisor (EDPS) is the independent authority that watches how the EU's own institutions — the Commission, Parliament, Council, Europol and the rest — handle personal data. What it does, how it differs from the EDPB it is constantly confused with, and who runs it. Every fact sourced.
FR France
Who is the CNIL: France's data protection authority, created decades before the GDPR
The CNIL is France's GDPR supervisory authority — born from the 1974 SAFARI scandal and created by the 1978 Loi Informatique et Libertés, decades before the GDPR. This guide covers what it does, its 18-member college and sanctions chamber, the landmark fines from Google's first €50M to a record €325M, who runs it, and its 2024 figures — every fact sourced.
Who is the ACPR: France's prudential supervisor and stablecoin authority under MiCA
The ACPR is France's banking and insurance prudential supervisor, backed by the Banque de France — and, under MiCA, the authority that licenses stablecoin issuers. This guide covers what it does, its three decision-making bodies, the banks it has fined for money-laundering failures (including a €50 million penalty on La Banque Postale), who runs it, and its role under DORA — every fact sourced.
Who is the AMF: France's financial markets regulator and crypto gatekeeper under MiCA
The AMF is France's financial markets regulator — and, under MiCA, the authority that authorises crypto-asset service providers to operate in France. This guide covers what it does, its two-body structure, how it splits crypto supervision with the ACPR, who chairs it, the fines its Enforcement Committee hands down, and its role under MiCA and DORA — every fact sourced.
DE Germany
Who is the BfDI: Germany's federal data protection commissioner
The BfDI is Germany's federal data-protection regulator — but it supervises only federal bodies and the telecom and postal sector. The rest is handled by 16 state authorities. What the BfDI does, how Germany's two-tier system works, and who runs it. Every fact sourced.
Who is the BNetzA: Germany's AI Act market-surveillance authority
Germany chose its Federal Network Agency (Bundesnetzagentur, BNetzA) — the regulator that runs the power grid and telecoms — as its lead AI Act authority, not its data-protection commissioner. What the BNetzA is, the AI role set out in the draft KI-MIG law, and who runs it. Every fact sourced.
Who is BaFin: Germany's financial regulator under MiCA and DORA
BaFin is Germany's integrated financial supervisor — banks, insurers, securities — and the national authority that licenses crypto firms under MiCA and supervises financial-sector IT resilience under DORA. Germany leads the EU in authorised crypto providers. What BaFin does and who runs it, every fact sourced.
IE Ireland
Who is the DPC: Ireland's data regulator that polices most of Big Tech
The Data Protection Commission is Ireland's GDPR supervisory authority — and, because Meta, Google, Apple, TikTok, X and LinkedIn run their EU operations from Ireland, the lead regulator for most of Big Tech across the whole EU under the one-stop-shop. What it does, why one national authority carries EU-wide weight, and who runs it after the move from one Commissioner to a three-person Commission — every fact sourced.
Who is the Central Bank of Ireland: the country's financial regulator and MiCA authority
The Central Bank of Ireland is both the country's central bank and its financial regulator in one — and, under MiCA, Ireland's single national competent authority for crypto. What it does, how the 2010 reform merged central banking and supervision, who governs it, and its role under MiCA and DORA. Every fact sourced.
LU Luxembourg
Who is the CNPD: Luxembourg's data regulator behind the €746M Amazon fine
The CNPD is Luxembourg's GDPR supervisory authority — a small national regulator that issued the second-largest GDPR fine in history, €746 million against Amazon, because so many global companies base their EU operations in the Grand Duchy. What it is, how its collège is composed after the 2025 change, and why a tiny country's regulator carries outsized weight. Every fact sourced.
Who is the CSSF: Luxembourg's financial regulator and single MiCA authority
The CSSF supervises the professionals and products of Luxembourg's vast financial sector — and, under MiCA, it is the country's single competent authority for crypto, unlike France's split. What it does, its role under MiCA and DORA, and who sits on its Executive Board through a 2026 change. Every fact sourced.
ES Spain
Who is AESIA: Spain's AI supervisory authority
AESIA is the EU's first dedicated national AI agency — Spain's authority for supervising and, where needed, sanctioning AI systems under the AI Act. What it does, the key detail that it is not an independent authority (unlike a data-protection DPA), who runs it, and where it sits — every fact sourced.
Who is the AEPD: Spain's data protection authority — the EU's busiest fining regulator
The Agencia Española de Protección de Datos is Spain's GDPR supervisory authority — and, by number of fines, the most prolific data-protection enforcer in the EU. What it does, why it is not the same body as Spain's AI authority AESIA, the 2025 leadership change under a new selection model, and who runs it — every fact sourced.