Australia
Selling technology from Australia into Europe
Being on the other side of the world from Brussels does not keep European regulation at arm's length. Once you serve customers, users or devices in the EU, some rules apply to you directly and others arrive through your customers' own obligations. This tells you which is which.
Before you invest in consultants, audits or a full GRC platform, start with a simple, evidence-based readiness check.
About 3 minutes. No account. Free result.
The dataset
Built from official EU legal texts
Product scope
- 7
- EU regulation families screened
- 3
- distinct applicability categories
- 30
- evidence artifacts mapped
Statutory maximum penalties
- Up to €20M or 4%
- GDPR
- Up to €35M or 7%
- EU AI Act
- Up to €15M or 2.5%
- Cyber Resilience Act
- €10M / 2%+
- NIS2
For certain infringements, where GDPR applies.
GDPR Article 83(5).
For non-compliance with the prohibited AI practices in Article 5.
AI Act Article 99(3).
For SMEs, including start-ups, the lower maximum applies (Article 99(6)).
For certain infringements of the essential cybersecurity requirements and specified obligations.
CRA Article 64(2).
For certain infringements by essential entities, Member States must set a maximum of at least €10 million or 2% of worldwide turnover, whichever is higher. National implementation and enforcement vary.
NIS2 Article 34(4).
Maximum statutory penalties. Actual exposure depends on applicability, role, infringement and enforcement circumstances.
What changes when Europe becomes a market
Most Australian technology companies meet EU regulation commercially before they meet it legally: a European prospect sends a security questionnaire, a data processing agreement and a list of clauses their legal team requires, and the deal stalls while you work out what any of it means.
Two things are happening at once. Some EU instruments have extraterritorial reach and bind you regardless of where you are incorporated. Others bind your customer, who is contractually obliged to pass obligations down to suppliers, including you.
Treating both as one undifferentiated pile of “EU compliance” is what makes the work feel unbounded. Separated, it is usually a short list.
Direct obligation vs customer-driven requirement
A direct obligation exists whether or not a customer ever asks. If you offer a product to individuals in the EU or monitor their behaviour, data protection rules reach you from Australia and are enforced by EU supervisory authorities.
A customer-driven requirement exists because your buyer is regulated. An EU bank contracting an Australian SaaS vendor must include specific terms in its ICT contracts; a covered operator must manage supply-chain security. You will be asked to sign up to those terms as a condition of the contract.
- Direct: reaches you by law, enforced against you, does not disappear if the deal does
- Customer-driven: reaches you by contract, negotiated commercially, blocks revenue when unmet
- Possible: depends on a fact you have not yet established, worth resolving before a buyer asks
The rules that reach Australian vendors
The dataset covers seven EU instruments. These are the ones that surface in European deals for companies based in Australia.
- GDPR
- Reaches you directly where you target or monitor people in the EU, and contractually whenever you process personal data for a European customer.
- DORA
- Australia's fintech and payments sector increasingly touches EU-regulated financial groups. Supplying an EU financial entity means accepting prescribed contractual terms, and more of them if your service supports a critical or important function.
- NIS2
- Often arrives as supply-chain security due diligence from European customers in energy, health, digital infrastructure and public sector: familiar territory for vendors who already work with Australia's SOCI-regulated sectors.
- EU AI Act
- Applies where AI output is used in the EU. Your obligations differ sharply depending on whether you build the model or embed someone else's.
- CRA
- Relevant to hardware and software products placed on the EU market, including vulnerability handling over the product's supported lifetime.
- Data Act
- Relevant to connected products, related services, and cloud providers facing customer switching and data access requests.
- ePrivacy Directive
- Applies to cookies, SDKs and analytics in anything you ship to EU users, separately from data protection law.
A free 3-minute assessment
Six short steps: your company, what you sell, how you touch Europe, who buys from you, a few follow-up questions chosen from your answers, and what evidence you already hold.
The result separates direct obligations from customer-driven requirements, shows your evidence readiness, and names the documents you are missing. It is free, and there is no email gate.
How it works
01
Answer 6 short steps
Your company, EU activity, customers and current evidence.
02
See what applies, and why
Separate direct EU obligations from requirements flowing down from European customers.
03
Get your action plan
See your evidence gaps and the exact steps required to become EU-market ready.
04
Build the evidence
Documents, controls and a sequenced remediation roadmap, in the order to tackle them.
The $149 readiness plan
If you want the fix rather than the diagnosis, the RegRoute EU Readiness Pack is a one-time USD 149 purchase: the full sequenced remediation plan with owner and effort per step, article-level legal sources, practical evidence templates and a shareable PDF report.
One payment, no subscription, and no account to create.
$149 USD
Australia-specific context
There is no current EU adequacy decision covering Australia. That does not stop European data reaching your systems, but it does mean the transfer mechanism has to be assessed rather than assumed. Because of this, European buyers may request transfer paperwork from Australian vendors that is not required from vendors in adequate countries.
The Privacy Act 1988 and the Australian Privacy Principles, together with the Notifiable Data Breaches scheme, are a genuine starting advantage: you will already have a data inventory, a named privacy contact and breach procedures. They are not a substitute. The GDPR's scope, the rights it grants individuals, and what a European buyer expects documented all go further, and Australia's ongoing privacy-law reform narrows the gap without closing it.
APRA's CPS 230 has given Australian suppliers to the financial sector real fluency in operational-risk concepts that overlap with DORA, such as critical operations, third-party dependency and continuity planning, which is a head start, though the two frameworks remain legally distinct. Distance and time zone also surface routinely in European deals with Australian vendors: expect questions about support-hours coverage and disaster-recovery locations alongside the legal transfer question.
Guides for Australian companies
Longer, sourced explanations of questions like these.
- GDPR for Australian companies
How the GDPR reaches an Australian company with no EU presence, why the Privacy Act and the APPs are not a substitute, and what a European buyer will actually put in front of you.
- DORA for SaaS vendors based in Australia
DORA is written for EU banks and insurers, not Australian software vendors. Here is how it still lands on your desk through a contract, and why CPS 230 fluency does not close the gap.
- Selling SaaS from Australia to Europe
What actually happens between demo and signature on a European enterprise SaaS deal, and the documents an Australian vendor needs ready at each stage.
Guides
Each guide answers one question directly, separates direct legal obligations from customer-driven requirements, and links to the official EU source.
- Which EU Regulations Apply to Non-EU SaaS Companies?
- DORA for SaaS vendors serving EU financial firms
- GDPR compliance checklist for technology companies outside Europe
- Does the Cyber Resilience Act Apply to SaaS?
- Does NIS2 Apply to Non-EU Companies?
- EU AI Act for Non-EU Companies: Provider, Deployer or Neither?
What you receive
A management report, not a dashboard
Your result and, once unlocked, your complete plan are built to be read by a customer's security team or your own leadership, not just clicked through.
Illustrative example
EU market readiness
Direct, customer-driven and possible requirements, plus evidence readiness.
Your roadmap
Actions sequenced into do now, next and later.
Evidence
Have, partial, missing and unknown, artifact by artifact.
Find out what applies to your company.
About 3 minutes. No account.
Australia
General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.