There is broad consensus that the Digital Single Market remains unfinished. This summer series asks whether the continued expansion of the EU’s digital rulebook brings it closer to completion or makes it a more distant prospect.
Every field has its stock complaint, the one you can serve at any conference without fear of contradiction. In EU digital law it is this. The rulebook lacks a coherent conceptual vocabulary. The same person is a data subject in one instrument and an end user in the next, the same platform changes costume from article to article.
This summer I decided to check it, and to open the series with the result, because definitions are position zero for what this newsletter studies. Everything a regulation requires runs through its defined terms, so a gap or an incompatibility in the vocabulary reappears in every provision built on the affected terms, and nothing downstream repairs it. Firms inherit the residue as legal uncertainty. They spend on advice rather than on products, and where the words are widest they over-comply. The burden of establishing what the law asks shifts, in practice, onto the regulated, and a market that works this way taxes its own competitiveness.
I. The complaint, and what I tested
The standard version goes like this. Brussels legislated in a hurry, so the instruments do not speak the same language. The same actor is a business user here and a trader there. Nobody harmonized anything.
Against this background, I analyzed the definitions provisions of the 34 binding EU digital instruments adopted between 2000 and 2025 and recorded every expressly defined term with its verbatim wording. I then asked what each definition actually triggers. The census covers roughly 1,400 definitional records.
The result reads like a plot twist. The complaint is wrong in the form some make it, because the rulebook turns out to be more coherent than its reputation. And yet it is harder to navigate than any coherent body of law should be.
Here is the underlining logic: the usual critique counts labels, but label counting is the tourist’s version of the exercise. A pair of definitions can use different words and cover exactly the same ground. Another pair can share a word while covering different ground, which may or may not matter depending on what the word triggers. So I ran a different test. For every candidate divergence, I compared what each classification actually triggers, article by article, then asked whether the difference is explained by what each instrument is for.
II. Four things that get called one problem
Some divergences all but dissolve on reading. The clearest example concerns the definition of an online search engine, which is widely said to differ across the Digital Markets Act, the Platform-to-Business Regulation and the Digital Services Act. Two of the three are the same definition. The DMA does not define the term at all; it points at the P2B and adopts its wording by reference. The DSA copies that wording word for word and changes one element, the genus, so that ‘a digital service’ becomes ‘an intermediary service’. The change is not cosmetic, since intermediary service is itself a defined term confined to mere conduit, caching and hosting, which nests the DSA’s search engine inside a narrower category; a service could in principle qualify under the DMA and P2B while falling outside the DSA. So the celebrated three-way divergence reduces to a boundary question at the edge of one instrument.
Some divergences are real and justified. The Data Act and the Data Governance Act define data holder differently in four separate respects, which looks damning until you check what the term does in each instrument. In one it carries a duty; in the other, none at all. The difference tracks each regulation’s purpose, and what survives of the criticism concerns legibility.
Some divergences leave a genuine question, and the sharpest example in the whole census sits here. The AI Act and the GDPR both define biometric data, and the AI Act’s version is the GDPR’s version with one clause removed. The removed clause is the one that does the limiting. Strip it out and the concept covers processing that characterises a person without identifying them, a substantially larger category of technology than most providers seem to have assumed falls inside the AI Act’s biometric provisions. Nothing pulls the clause back in, because the definition is freestanding, and the only bridge to the GDPR is a recital. The reportable-incident divergence between NIS2 and DORA belongs to the same family. One definition reaches harm to other people on its face; the other reaches it only through classification criteria that sit outside the definition. The financial sector treats DORA as displacing NIS2 cleanly, a position resting on an operative DORA provision and Commission guidance, but the displacement provision makes displacement conditional on an equivalence test, and the guidance asserts that the condition is met rather than demonstrating it. Who bears the risk if a court reads the condition literally is the question left over.
And some definitions move on their own. This is the category I see discussed least. It will be instantly familiar to a software engineer. PSD2 defines its telecoms vocabulary by pointing at another instrument; in coding terms, it declared a dependency without pinning the version. The package updated in 2020, materially wider than before, and the reference was never revisited. A payments legislator even reopened PSD2 in 2024, for instant credit transfers, and left the definitions untouched, so one of the Directive’s exclusions had quietly grown. The same structure appears between the General Product Safety Regulation and the Product Liability Directive, where a scope change is scheduled for December 2026 and nobody has to legislate for it to happen. The usual complaint is that the vocabulary is too loose, each instrument defining for itself. The issue here is the opposite one. References of this kind keep vocabulary current, and mostly that is what you want. It turns sour when what sits at the end of the pointer is a perimeter. In both of these cases the moving text decides who the law covers, and it was moved by a legislator working on another subject. The instrument the regulated firm actually reads carries no trace of the change.
III. What the definitions articles do not contain
The most useful thing the census produced has nothing to do with any pair of terms. It is a structural observation. The categories that decide who is regulated are frequently not definitions at all.
NIS2 has no definitional clause for essential entity, for important entity, or for significant incident. Those categories are assembled from a scope article carrying a size threshold imported from a Commission recommendation, an article operating through an annex, a residual clause, and a separate provision buried in the reporting chapter. The Cyber Resilience Act does the same thing for its two product tiers. An audit that reads only the definitions articles misses all of it.
There is a related pattern, and it comes in degrees. In the Open Data Directive, the statement that the public procurement directives’ definitions apply sits in a recital, though the operative article carries a self-standing definition, so in practice nothing turns on it. In the AI Act, a recital is the only bridge between the biometric vocabulary and the GDPR, and there the exposure is real. Recitals are interpretive context, not operative provisions. They are the comments in the code, and a compliance officer who executes the comments is running something a court is free to ignore.
IV. Where the rulebook actually performs
Any honest account has to include the findings that run against the incoherence thesis, and there are two.
The data-protection cluster achieves coherence by importing rather than redrafting. Roughly half of the named terms across that group are incorporated from elsewhere; one instrument takes forty-four of its terms from eight external acts; and no instrument in the cluster redefines personal data. Every one of them takes it from GDPR Article 4(1), the single place the term is defined. Where Brussels wanted a single meaning it obtained one. The product safety and product liability pair tell a similar story, sharing their economic-operator vocabulary almost entirely, with the borrowing recorded on the face of the recitals. Two instruments drafted years apart, aligned deliberately.
Both facts matter because they remove the excuse. Alignment was available, and where the drafters chose it they achieved it, so the navigation cost everywhere else cannot be written off as the inevitable price of layered regulation. It was a choice, made instrument by instrument, and it could have been made differently.
V. The balance, and what comes next
The good news is that the founding complaint is mostly wrong. The vocabulary is more aligned than its reputation, and the worst of the alleged divergences dissolve on reading. Where the drafters wanted one meaning they got one, which proves the machinery can do it. The bad news sits where nobody was looking. The categories that decide who is regulated are assembled outside the definitions articles, and some references move scope with no legislator signing for it. A firm that wants certainty has to trace every term across instruments before relying on it, and none of that effort shows up in the usual scorecards, though all of it shows up in compliance budgets.
The next entries in this summer series take the same method to the obligations the instruments impose and to the regulators that share them, because if the words already require this much tracing, wait until they start colliding.
Everything above is what I found. Below is what it rests on, with the pinpoints. Nine exhibits, both sides of every divergence quoted in full, verified against the consolidated texts. Enough to check any claim I have made without opening a single instrument, and enough to lift a pinpoint straight into a memo or a submission. If one of these divergences touches a file on your desk, the citation is ready to use. If none of them does, you have a map of where the rulebook will be tested next.



