SOURCE 0 - CSDDD VOCABULARY
Fifteen questions professionals ask about proving CSDDD compliance — due diligence, remediation, civil liability, transition plans — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA ACT VOCABULARY
Fifteen questions professionals ask about proving Data Act compliance — trade-secret refusal, compensation, contract dates, cloud switching — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - MDAI VOCABULARY (MEDICAL DEVICE AI: MDR × AI ACT)
Fourteen questions professionals ask about proving Medical Device AI (MDR × AI Act) compliance, mapped to the SOURCE 0 doctrinal vocabulary.
SOURCE 0 - CYBER RESILIENCE ACT VOCABULARY
Fourteen questions professionals ask about proving Cyber Resilience Act compliance — the 24-hour clock, SBOMs, support periods, substantial modifications — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA GOVERNANCE ACT VOCABULARY
Fourteen questions professionals ask about proving Data Governance Act compliance — intermediation conduct, altruism registration, consent timing, third-country transfers — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - GDPR VOCABULARY
Fifty questions professionals ask about proving GDPR compliance — consent, breach notification, DPIAs, international transfers — each mapped to the SOURCE 0 term that answers it, and to the article of Regulation (EU) 2016/679 it rests on.
SOURCE 0 - CSSF CIRCULARS DO NOT FIX THE DETECTION TIME
Two CSSF circulars restructure Luxembourg's DORA incident-reporting transition. Neither requires independent verification of the detection, classification, or resolution timestamps entities self-report.
SOURCE 0 - ONE TIMELINE, TWO REGULATORS
Under DORA, a cross-border group does not file one report of a major ICT incident — it files several, one per entity, each to its own competent authority. Each is drafted independently. Nothing reconciles them.
SOURCE 0 - PROVING A FIX WAS IN PLACE BEFORE A DATE
Commits, tickets, and scans prove what your own systems recorded about a fix. None of them, on their own, fixes when it actually took effect — before an independent third party, and before the dispute began.
SOURCE 0 - THE AUDIT THAT CLEARED ITSELF
Anthropic's own review of a Claude access incident is credible — and, on its own, unfalsifiable by anyone outside Anthropic. This is the Endogenous Audit Paradox in its most literal form.
SOURCE 0 - THE DEFAULT NO ONE ELSE SAW
TikTok says its teen accounts have had 50+ preset safety features "from the moment they set up an account." The Commission tested today's configuration and found it wanting. Neither account fixes what a specific default actually was at an earlier date.
SOURCE 0 - WHEN THE VICTIM LIST STAYS SEALED
OpenAI says four accounts were breached. Only two are named, and neither naming came from OpenAI. The count itself is a disclosure, not a finding.
SOURCE 0 - THE STANDARD THAT ARRIVED BEFORE THE PRESUMPTION
EN 18286 has been approved — the first European standard built for the AI Act. But approval isn't citation, and citation is what triggers the Article 40 presumption of conformity. SOURCE 0 seals what your QMS was, and since when, in the interval between the two.
SOURCE 0 - EU CUSTOMS REFORM VOCABULARY
Trust & Check, EU Customs Data Hub, presumed importer, Union Handling Fee: 15 questions on EU customs reform vocabulary. SOURCE 0 seals the data before its transmission to customs authorities.
SOURCE 0 - VOCABULAIRE DE LA RÉFORME DOUANIÈRE DE L’EU
Trust & Check, EU Customs Data Hub, importateur présumé, Union Handling Fee : 15 questions sur le vocabulaire de la réforme douanière de l'UE. SOURCE 0 scelle la donnée avant sa transmission aux autorités.
SOURCE 0 - TRUST AND CHECK AND THE EU CUSTOMS DATA HUB
Since 2026, the EU customs union has been undergoing its most radical transformation since 1968. Between the already effective abolition of the €150 exemption, the upcoming rollout of the EU Customs Data Hub, and the rise of the elite "Trust & Check" status, executives must audit their Sincérité today. Stop managing forms — master your data to protect your liability.
SOURCE 0 - THE PLAN ONLY ITS AUTHOR CAN DATE
Since December 2023, French courts have substantively reviewed companies' vigilance plans — not rubber-stamped them. But every review examines whatever document the company presents today. Nothing independently fixes what the plan said before the claim was filed.
SOURCE 0 - THE STATUS GRANTED BEFORE THE PROOF
The EU's Trust and Check trader status is verified once, before the Customs Data Hub is fully operational. In the interval between the two, only the trader's own records attest to its compliance.
SOURCE 0 - LE STATUT ACCORDÉ AVANT LA PREUVE
Le statut d'opérateur Trust and Check de l'UE est vérifié une fois, avant que le Customs Data Hub ne soit pleinement opérationnel. Dans l'intervalle entre les deux, seuls les registres de l'opérateur attestent de sa conformité.
SOURCE 0 - THE DAY THE INFRINGEMENT STOPPED
A continuing AI Act infringement's five-year limitation clock starts on the day it ceased. That date is usually set by the same organisation whose diligence is in question.

