Skip to content

Australia

Selling technology from Australia into Europe

Being on the other side of the world from Brussels does not keep European regulation at arm's length. Once you serve customers, users or devices in the EU, some rules apply to you directly and others arrive through your customers' own obligations. This tells you which is which.

Before you invest in consultants, audits or a full GRC platform, start with a simple, evidence-based readiness check.

Check my EU readiness

About 3 minutes. No account. Free result.

The dataset

Built from official EU legal texts

Product scope

7
EU regulation families screened
3
distinct applicability categories
30
evidence artifacts mapped

Statutory maximum penalties

Up to €20M or 4%
GDPR

For certain infringements, where GDPR applies.

GDPR Article 83(5).

Up to €35M or 7%
EU AI Act

For non-compliance with the prohibited AI practices in Article 5.

AI Act Article 99(3).

For SMEs, including start-ups, the lower maximum applies (Article 99(6)).

Up to €15M or 2.5%
Cyber Resilience Act

For certain infringements of the essential cybersecurity requirements and specified obligations.

CRA Article 64(2).

€10M / 2%+
NIS2

For certain infringements by essential entities, Member States must set a maximum of at least €10 million or 2% of worldwide turnover, whichever is higher. National implementation and enforcement vary.

NIS2 Article 34(4).

Maximum statutory penalties. Actual exposure depends on applicability, role, infringement and enforcement circumstances.

What changes when Europe becomes a market

Most Australian technology companies meet EU regulation commercially before they meet it legally: a European prospect sends a security questionnaire, a data processing agreement and a list of clauses their legal team requires, and the deal stalls while you work out what any of it means.

Two things are happening at once. Some EU instruments have extraterritorial reach and bind you regardless of where you are incorporated. Others bind your customer, who is contractually obliged to pass obligations down to suppliers, including you.

Treating both as one undifferentiated pile of “EU compliance” is what makes the work feel unbounded. Separated, it is usually a short list.

Direct obligation vs customer-driven requirement

A direct obligation exists whether or not a customer ever asks. If you offer a product to individuals in the EU or monitor their behaviour, data protection rules reach you from Australia and are enforced by EU supervisory authorities.

A customer-driven requirement exists because your buyer is regulated. An EU bank contracting an Australian SaaS vendor must include specific terms in its ICT contracts; a covered operator must manage supply-chain security. You will be asked to sign up to those terms as a condition of the contract.

  • Direct: reaches you by law, enforced against you, does not disappear if the deal does
  • Customer-driven: reaches you by contract, negotiated commercially, blocks revenue when unmet
  • Possible: depends on a fact you have not yet established, worth resolving before a buyer asks

The rules that reach Australian vendors

The dataset covers seven EU instruments. These are the ones that surface in European deals for companies based in Australia.

GDPR
Reaches you directly where you target or monitor people in the EU, and contractually whenever you process personal data for a European customer.
DORA
Australia's fintech and payments sector increasingly touches EU-regulated financial groups. Supplying an EU financial entity means accepting prescribed contractual terms, and more of them if your service supports a critical or important function.
NIS2
Often arrives as supply-chain security due diligence from European customers in energy, health, digital infrastructure and public sector: familiar territory for vendors who already work with Australia's SOCI-regulated sectors.
EU AI Act
Applies where AI output is used in the EU. Your obligations differ sharply depending on whether you build the model or embed someone else's.
CRA
Relevant to hardware and software products placed on the EU market, including vulnerability handling over the product's supported lifetime.
Data Act
Relevant to connected products, related services, and cloud providers facing customer switching and data access requests.
ePrivacy Directive
Applies to cookies, SDKs and analytics in anything you ship to EU users, separately from data protection law.

EU regulations we cover

A free 3-minute assessment

Six short steps: your company, what you sell, how you touch Europe, who buys from you, a few follow-up questions chosen from your answers, and what evidence you already hold.

The result separates direct obligations from customer-driven requirements, shows your evidence readiness, and names the documents you are missing. It is free, and there is no email gate.

How it works

  1. 01

    Answer 6 short steps

    Your company, EU activity, customers and current evidence.

  2. 02

    See what applies, and why

    Separate direct EU obligations from requirements flowing down from European customers.

  3. 03

    Get your action plan

    See your evidence gaps and the exact steps required to become EU-market ready.

  4. 04

    Build the evidence

    Documents, controls and a sequenced remediation roadmap, in the order to tackle them.

The $149 readiness plan

If you want the fix rather than the diagnosis, the RegRoute EU Readiness Pack is a one-time USD 149 purchase: the full sequenced remediation plan with owner and effort per step, article-level legal sources, practical evidence templates and a shareable PDF report.

One payment, no subscription, and no account to create.

$149 USD

Australia-specific context

There is no current EU adequacy decision covering Australia. That does not stop European data reaching your systems, but it does mean the transfer mechanism has to be assessed rather than assumed. Because of this, European buyers may request transfer paperwork from Australian vendors that is not required from vendors in adequate countries.

The Privacy Act 1988 and the Australian Privacy Principles, together with the Notifiable Data Breaches scheme, are a genuine starting advantage: you will already have a data inventory, a named privacy contact and breach procedures. They are not a substitute. The GDPR's scope, the rights it grants individuals, and what a European buyer expects documented all go further, and Australia's ongoing privacy-law reform narrows the gap without closing it.

APRA's CPS 230 has given Australian suppliers to the financial sector real fluency in operational-risk concepts that overlap with DORA, such as critical operations, third-party dependency and continuity planning, which is a head start, though the two frameworks remain legally distinct. Distance and time zone also surface routinely in European deals with Australian vendors: expect questions about support-hours coverage and disaster-recovery locations alongside the legal transfer question.

Guides for Australian companies

Longer, sourced explanations of questions like these.

  • GDPR for Australian companies

    How the GDPR reaches an Australian company with no EU presence, why the Privacy Act and the APPs are not a substitute, and what a European buyer will actually put in front of you.

  • DORA for SaaS vendors based in Australia

    DORA is written for EU banks and insurers, not Australian software vendors. Here is how it still lands on your desk through a contract, and why CPS 230 fluency does not close the gap.

  • Selling SaaS from Australia to Europe

    What actually happens between demo and signature on a European enterprise SaaS deal, and the documents an Australian vendor needs ready at each stage.

Guides

Each guide answers one question directly, separates direct legal obligations from customer-driven requirements, and links to the official EU source.

What you receive

A management report, not a dashboard

Your result and, once unlocked, your complete plan are built to be read by a customer's security team or your own leadership, not just clicked through.

Illustrative example

EU market readiness

Direct, customer-driven and possible requirements, plus evidence readiness.

Your roadmap

Actions sequenced into do now, next and later.

Evidence

Have, partial, missing and unknown, artifact by artifact.

Find out what applies to your company.

Check my EU readiness

About 3 minutes. No account.

Australia

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.