{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-11",
    "fingerprint": "ewai:se:cf479a",
    "proof": "sha256:0ad1cccd70f61bc729ddc4210e5730294d05357b1fe10932ad884f97e44cdb75",
    "jurisdiction": "se",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "object_type": "action_kit",
  "object_id": "action_kit:eu:dora",
  "schema_version": "1",
  "schema": "https://legal.exploreworldai.com/api/public/v1/schemas/action_kit",
  "url": "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora",
  "source": "NovaCopilot",
  "item": {
    "coverage": {
      "complete": 5,
      "total": 5,
      "label": "5 of 5 answers ready"
    },
    "subject": "eu:dora",
    "act": "dora",
    "article": null,
    "actions": [
      {
        "obligation": "obligation:eu:dora-art-5-financial-entity",
        "verification": "governance",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-6-financial-entity",
        "verification": "governance",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-11-financial-entity",
        "verification": "governance",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-17-financial-entity",
        "verification": "internal_review",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-19-financial-entity",
        "verification": "authority_filing",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-24-financial-entity",
        "verification": "testing",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-26-financial-entity",
        "verification": "testing",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-28-financial-entity",
        "verification": "register",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      },
      {
        "obligation": "obligation:eu:dora-art-30-financial-entity",
        "verification": "contract",
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ]
      }
    ],
    "answers": [
      {
        "key": "what_to_do",
        "status": "ready",
        "sha256": "63fbd26a80cffa8a3f2d3d8e3c8e86969f53811ecbb59d53687ea2bf76fa0c5c"
      },
      {
        "key": "who",
        "status": "ready",
        "sha256": "91fe92fe9602c063ded03393c6d3d9f2d58208934d19215e24e494f66d53105c"
      },
      {
        "key": "verification",
        "status": "ready",
        "sha256": "4939a72777b8fac0d5a53bea5ef0cf0de951a911deba5823a8d4e15194d13ce6"
      },
      {
        "key": "documents",
        "status": "ready",
        "sha256": "c2ffa6ab26ef3f2c45300bd6ed80d730ab2163291ef667fede8bf6d4d87f544b"
      },
      {
        "key": "if_not_met",
        "status": "ready",
        "sha256": "1880a9bd9f3667b3a27494a003ad775ee37a542c13c931cbe0babc10df4ad7f6"
      }
    ],
    "answers_full": [
      {
        "key": "what_to_do",
        "status": "ready",
        "answer": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it. Maintain a sound, comprehensive and documented ICT risk management framework. Put in place an ICT business continuity policy with response and recovery plans. (+6 more)",
        "ids": [
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity",
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity"
        ],
        "question": "What must I do?",
        "sha256": "63fbd26a80cffa8a3f2d3d8e3c8e86969f53811ecbb59d53687ea2bf76fa0c5c"
      },
      {
        "key": "who",
        "status": "ready",
        "answer": "Responsible roles: financial-entity.",
        "ids": [
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity",
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity"
        ],
        "question": "Who is responsible?",
        "sha256": "91fe92fe9602c063ded03393c6d3d9f2d58208934d19215e24e494f66d53105c"
      },
      {
        "key": "verification",
        "status": "ready",
        "answer": "Verified by: governance, internal_review, authority_filing, testing, register, contract. Board-approved document with named owner and review date.",
        "ids": [
          "verification:governance",
          "verification:internal_review",
          "verification:authority_filing",
          "verification:testing",
          "verification:register",
          "verification:contract"
        ],
        "question": "How is this verified?",
        "sha256": "4939a72777b8fac0d5a53bea5ef0cf0de951a911deba5823a8d4e15194d13ce6"
      },
      {
        "key": "documents",
        "status": "ready",
        "answer": "Keep: Approved policy or plan, Board minutes with approval, Named owner, Dated internal compliance note, Filed report or declaration, Submission receipt or publication URL with date, Test plan, Test report with findings, Remediation log, Register extract, Retention schedule, Signed contract with clauses, Clause checklist.",
        "ids": [
          "documentation_requirement:eu:dora"
        ],
        "question": "Which documents are required?",
        "sha256": "c2ffa6ab26ef3f2c45300bd6ed80d730ab2163291ef667fede8bf6d4d87f544b"
      },
      {
        "key": "if_not_met",
        "status": "ready",
        "answer": "2 sanctions, up to 1 % of turnover.",
        "ids": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "question": "What happens if the requirement is not met?",
        "sha256": "1880a9bd9f3667b3a27494a003ad775ee37a542c13c931cbe0babc10df4ad7f6"
      }
    ],
    "action_list": [
      {
        "obligation": "obligation:eu:dora-art-5-financial-entity",
        "provision": "dora art. 5",
        "role": "financial-entity",
        "action": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.",
        "deadline": null,
        "recipient": null,
        "verification": "governance",
        "verification_method": "Board-approved document with named owner and review date.",
        "evidence": [
          "Approved policy or plan",
          "Board minutes with approval",
          "Named owner"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:nis2-art-20-management-body",
          "obligation:eu:amlr-art-9-obliged-entity",
          "obligation:eu:amlr-art-11-obliged-entity",
          "obligation:eu:csddd-art-11-company",
          "obligation:eu:csddd-art-14-company"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-6-financial-entity",
        "provision": "dora art. 6",
        "role": "financial-entity",
        "action": "Maintain a sound, comprehensive and documented ICT risk management framework.",
        "deadline": null,
        "recipient": null,
        "verification": "governance",
        "verification_method": "Board-approved document with named owner and review date.",
        "evidence": [
          "Approved policy or plan",
          "Board minutes with approval",
          "Named owner"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:nis2-art-20-management-body",
          "obligation:eu:amlr-art-9-obliged-entity",
          "obligation:eu:amlr-art-11-obliged-entity",
          "obligation:eu:csddd-art-11-company",
          "obligation:eu:csddd-art-14-company"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-11-financial-entity",
        "provision": "dora art. 11",
        "role": "financial-entity",
        "action": "Put in place an ICT business continuity policy with response and recovery plans.",
        "deadline": null,
        "recipient": null,
        "verification": "governance",
        "verification_method": "Board-approved document with named owner and review date.",
        "evidence": [
          "Approved policy or plan",
          "Board minutes with approval",
          "Named owner"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:nis2-art-20-management-body",
          "obligation:eu:amlr-art-9-obliged-entity",
          "obligation:eu:amlr-art-11-obliged-entity",
          "obligation:eu:csddd-art-11-company",
          "obligation:eu:csddd-art-14-company"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-17-financial-entity",
        "provision": "dora art. 17",
        "role": "financial-entity",
        "action": "Define and implement an ICT-related incident management process.",
        "deadline": null,
        "recipient": null,
        "verification": "internal_review",
        "verification_method": "Internal review against the duty text.",
        "evidence": [
          "Dated internal compliance note"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:ai-act-art-16-provider",
          "obligation:eu:ai-act-art-9-provider",
          "obligation:eu:ai-act-art-17-provider",
          "obligation:eu:ai-act-art-72-provider",
          "obligation:eu:ai-act-art-26-deployer"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-19-financial-entity",
        "provision": "dora art. 19",
        "role": "financial-entity",
        "action": "Report major ICT-related incidents to the competent authority.",
        "deadline": "24 hours",
        "recipient": "Competent authority",
        "verification": "authority_filing",
        "verification_method": "Filing or publication can be shown with date and recipient.",
        "evidence": [
          "Filed report or declaration",
          "Submission receipt or publication URL with date"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:ai-act-art-73-provider",
          "obligation:eu:gdpr-art-33-controller",
          "obligation:eu:gdpr-art-33-processor",
          "obligation:eu:nis2-art-23-essential-entity",
          "obligation:eu:amlr-art-69-obliged-entity"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-24-financial-entity",
        "provision": "dora art. 24",
        "role": "financial-entity",
        "action": "Establish a digital operational resilience testing programme.",
        "deadline": null,
        "recipient": null,
        "verification": "testing",
        "verification_method": "Tests executed on a schedule with findings and remediation tracked.",
        "evidence": [
          "Test plan",
          "Test report with findings",
          "Remediation log"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:ai-act-art-10-provider",
          "obligation:eu:gdpr-art-18-controller",
          "obligation:eu:gdpr-art-22-controller"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-26-financial-entity",
        "provision": "dora art. 26",
        "role": "financial-entity",
        "action": "Carry out threat-led penetration testing where identified by the competent authority.",
        "deadline": null,
        "recipient": null,
        "verification": "testing",
        "verification_method": "Tests executed on a schedule with findings and remediation tracked.",
        "evidence": [
          "Test plan",
          "Test report with findings",
          "Remediation log"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:ai-act-art-10-provider",
          "obligation:eu:gdpr-art-18-controller",
          "obligation:eu:gdpr-art-22-controller"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-28-financial-entity",
        "provision": "dora art. 28",
        "role": "financial-entity",
        "action": "Manage ICT third-party risk and keep a register of information on all ICT service contracts.",
        "deadline": null,
        "recipient": null,
        "verification": "register",
        "verification_method": "A complete, current register or archive can be produced on request.",
        "evidence": [
          "Register extract",
          "Retention schedule"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:ai-act-art-11-provider",
          "obligation:eu:ai-act-art-12-provider",
          "obligation:eu:ai-act-art-53-gpai-provider",
          "obligation:eu:gdpr-art-30-controller",
          "obligation:eu:amlr-art-10-obliged-entity"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "obligation": "obligation:eu:dora-art-30-financial-entity",
        "provision": "dora art. 30",
        "role": "financial-entity",
        "action": "Include the key contractual provisions in contracts with ICT third-party service providers.",
        "deadline": null,
        "recipient": null,
        "verification": "contract",
        "verification_method": "Required clauses are present in signed agreements or published terms.",
        "evidence": [
          "Signed contract with clauses",
          "Clause checklist"
        ],
        "exceptions": [
          "exception:eu:dora-microenterprise"
        ],
        "sanctions": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "related_rules": [
          "obligation:eu:gdpr-art-28-processor",
          "obligation:eu:accessibility-art-13-service-provider",
          "obligation:eu:gdpr-art-20-controller",
          "obligation:eu:gdpr-art-44-controller"
        ],
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      }
    ],
    "checklist": [
      {
        "step": 1,
        "role": "financial-entity",
        "do": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.",
        "verify": "Board-approved document with named owner and review date.",
        "keep": [
          "Approved policy or plan",
          "Board minutes with approval",
          "Named owner"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 2,
        "role": "financial-entity",
        "do": "Maintain a sound, comprehensive and documented ICT risk management framework.",
        "verify": "Board-approved document with named owner and review date.",
        "keep": [
          "Approved policy or plan",
          "Board minutes with approval",
          "Named owner"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 3,
        "role": "financial-entity",
        "do": "Put in place an ICT business continuity policy with response and recovery plans.",
        "verify": "Board-approved document with named owner and review date.",
        "keep": [
          "Approved policy or plan",
          "Board minutes with approval",
          "Named owner"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 4,
        "role": "financial-entity",
        "do": "Define and implement an ICT-related incident management process.",
        "verify": "Internal review against the duty text.",
        "keep": [
          "Dated internal compliance note"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 5,
        "role": "financial-entity",
        "do": "Report major ICT-related incidents to the competent authority.",
        "verify": "Filing or publication can be shown with date and recipient.",
        "keep": [
          "Filed report or declaration",
          "Submission receipt or publication URL with date"
        ],
        "deadline": "24 hours",
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 6,
        "role": "financial-entity",
        "do": "Establish a digital operational resilience testing programme.",
        "verify": "Tests executed on a schedule with findings and remediation tracked.",
        "keep": [
          "Test plan",
          "Test report with findings",
          "Remediation log"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 7,
        "role": "financial-entity",
        "do": "Carry out threat-led penetration testing where identified by the competent authority.",
        "verify": "Tests executed on a schedule with findings and remediation tracked.",
        "keep": [
          "Test plan",
          "Test report with findings",
          "Remediation log"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 8,
        "role": "financial-entity",
        "do": "Manage ICT third-party risk and keep a register of information on all ICT service contracts.",
        "verify": "A complete, current register or archive can be produced on request.",
        "keep": [
          "Register extract",
          "Retention schedule"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      },
      {
        "step": 9,
        "role": "financial-entity",
        "do": "Include the key contractual provisions in contracts with ICT third-party service providers.",
        "verify": "Required clauses are present in signed agreements or published terms.",
        "keep": [
          "Signed contract with clauses",
          "Clause checklist"
        ],
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "done": false
      }
    ],
    "links": {
      "sme_kit": "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora",
      "act_kit": null,
      "articles": [
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-5",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-6",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-11",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-17",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-19",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-24",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-26",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-28",
        "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora--art-30"
      ],
      "risk": [
        "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/eu:dora--financial-entity"
      ],
      "timeline": [
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-5-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-6-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-11-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-17-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-19-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-24-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-26-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-28-financial-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/timeline/eu:dora-art-30-financial-entity"
      ],
      "list": "https://legal.exploreworldai.com/api/public/v1/action-kits"
    },
    "method": "Rule to action: five fixed agent questions from deterministic registers. Verification and evidence come from fixed keyword rules on the duty text. No model writes anything.",
    "attribution": "Source: NovaCopilot",
    "hash": "b71c827afbb99fa2163cf07a08aa843a416c03a689e1ab67a89ea1ffce9ce72f"
  },
  "links": {
    "provisions": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/eu:dora",
    "case_law": {
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/eu:dora",
      "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/eu:dora"
    },
    "evidence": {
      "provenance": null,
      "chain_verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify",
      "object_changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes"
    },
    "compact": "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora?view=compact",
    "representations": {},
    "machine_languages": [
      "en",
      "sv"
    ],
    "ref": "eu:dora"
  },
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "whats_new": "https://legal.exploreworldai.com/api/public/v1/whats-new?jurisdiction=eu",
    "conditional": "Send If-None-Match with the ETag; unchanged objects return 304 without body.",
    "recheck_after_seconds": 86400
  },
  "hash": "sha256:0ad1cccd70f61bc729ddc4210e5730294d05357b1fe10932ad884f97e44cdb75",
  "version": "legal-2026-10-11",
  "expires": "2026-10-12T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-11+legal-2026-10-11+2026-10-11T14:14:29",
    "content_hash": "sha256:0ad1cccd70f61bc729ddc4210e5730294d05357b1fe10932ad884f97e44cdb75",
    "revalidate_after": "2026-10-11T15:27:18.764Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/eu:dora",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}