Guide
Guides
Each guide answers one question directly, separates direct legal obligations from customer-driven requirements, and links to the official EU source.
Cross-regulation overview
- Which EU Regulations Apply to Non-EU SaaS Companies?
A non-EU SaaS company may face direct EU obligations under some regulations, customer-driven requirements under others, and no meaningful exposure under others. The answer depends on what the company sells, where its customers and users are located, its role in the supply chain, its size, its customers' sector, and its product architecture. Selling into Europe alone does not answer the question.
Reviewed 2026-08-21
Data protection: GDPR
- GDPR compliance checklist for technology companies outside Europe
The GDPR can reach a company with no EU office when it offers goods or services to people in the EU or monitors their behaviour there. It can also arrive through a contract when a European customer gives the company personal data to process. A useful checklist must keep those direct and customer-driven routes separate rather than treating a country, certification or contract template as the answer.
Reviewed 2026-08-07
Financial-sector resilience: DORA
- DORA for SaaS vendors serving EU financial firms
DORA is addressed to EU financial entities, not most of their technology suppliers. For the normal SaaS vendor, it arrives through mandatory customer contract terms and vendor-risk processes. A small number of ICT providers formally designated as critical are different: that designation creates direct EU oversight and cannot be inferred from customer size or reputation.
Reviewed 2026-08-07
NIS2
- Does NIS2 Apply to Non-EU Companies?
NIS2 does not automatically apply to every non-EU SaaS or technology company selling into Europe. Direct statutory scope depends on the company's own service/entity category, size and other Article 2 conditions, checked against the applicable national implementation. Separately, and independently of that direct-scope question, a non-EU vendor may receive NIS2-driven security and evidence requests from an EU customer that is itself regulated. That request alone does not make the vendor directly subject to NIS2.
Reviewed 2026-08-21
CRA
- Does the Cyber Resilience Act Apply to SaaS?
The Cyber Resilience Act does not exempt or automatically cover SaaS and cloud businesses as a category. Its scope test looks at products with digital elements made available on the EU market, not at business model. Being established outside the EU does not by itself exclude a company from that test, and an EU customer alone does not by itself bring one in. A pure, standalone SaaS or cloud service still needs its own separate analysis rather than an automatic answer either way. Remote or cloud data processing can form part of a covered product where the CRA's own statutory test is met. The processing must be designed and developed by, or under the responsibility of, the manufacturer, and the product must not be able to perform one of its functions without it. Product architecture and EU market-placement facts decide the answer, not company location or a business-model label alone.
Reviewed 2026-08-21
Artificial intelligence: AI Act
- EU AI Act for Non-EU Companies: Provider, Deployer or Neither?
Being established outside the EU does not automatically exclude a company from the AI Act. The first question is role: provider, deployer, importer, distributor, or provider of a general-purpose AI model. The Act defines each differently, and a role is not chosen by label or contract. The second question is territorial scope under Article 2: whether the company places an AI system on the EU market, puts one into service there, or, for providers and deployers outside the EU, whether the system's output is used in the Union. The third question is the risk/system category, which decides which specific duties, if any, follow. Different roles carry different obligations, and none of these questions can be skipped by the fact of using AI alone.
Reviewed 2026-08-21
General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.