These are the instruments in the current dataset. Each entry is recorded against its official text, and the assessment decides which of them actually reach your company.
GDPR
Regulation (EU) 2016/679 — General Data Protection Regulation
Europe's data protection regulation. It can apply to a company with no EU establishment where it offers goods or services to people in the EU, or monitors their behaviour, and it applies to processors handling EU personal data on a customer's instructions.
Anyone handling personal data of people in Europe.
Guides: GDPR compliance checklist for technology companies outside Europe
Official source (CELEX 32016R0679)·Verified 2026-08-17
DORA
Regulation (EU) 2022/2554 — Digital Operational Resilience Act
Digital operational resilience rules for the EU financial sector. Financial entities must manage ICT third-party risk, which reaches their non-EU technology suppliers through mandatory contractual terms.
ICT providers to EU banks, insurers, funds and payment firms.
Guides: DORA for SaaS vendors serving EU financial firms
Official source (CELEX 32022R2554)·Verified 2026-08-17
NIS2
Directive (EU) 2022/2555 — NIS2 Directive
Cybersecurity directive covering essential and important entities. Some digital service providers are in scope in their own right; many suppliers meet it as a supply-chain security requirement passed down by covered customers.
Digital infrastructure providers and suppliers to covered sectors.
Guides: Does NIS2 Apply to Non-EU Companies?
Official source (CELEX 32022L2555)·Verified 2026-08-17
EU AI Act
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Risk-based rules for AI systems and general-purpose AI models. Obligations differ sharply between providers and deployers, and reach non-EU companies whose AI output is used in the Union.
AI providers, integrators and deployers serving EU users.
Guides: EU AI Act for Non-EU Companies: Provider, Deployer or Neither?
Official source (CELEX 32024R1689)·Verified 2026-08-17
AI Digital Omnibus amendment
Regulation (EU) 2026/1744 — amending Regulation (EU) 2024/1689
Amending regulation adjusting parts of the AI Act, including timing of certain obligations. Recorded alongside the base act so results reflect the amended position.
Anyone in scope of the AI Act.
Guides: EU AI Act for Non-EU Companies: Provider, Deployer or Neither?
Official source (CELEX 32026R1744)·Verified 2026-08-17
CRA
Regulation (EU) 2024/2847 — Cyber Resilience Act
Cybersecurity requirements for products with digital elements placed on the EU market, including vulnerability handling and reporting duties across the supported lifetime of the product.
Manufacturers of software and connected hardware sold in the EU.
Guides: Does the Cyber Resilience Act Apply to SaaS?
Official source (CELEX 32024R2847)·Verified 2026-08-17
Data Act
Regulation (EU) 2023/2854 — Data Act
Rules on access to and sharing of data generated by connected products and related services, including user access rights and switching obligations for data processing services.
Connected-product makers and cloud/data-processing providers.
Guides: Which EU Regulations Apply to Non-EU SaaS Companies?
Official source (CELEX 32023R2854)·Verified 2026-08-17
ePrivacy Directive
Directive 2002/58/EC — ePrivacy Directive
Rules on confidentiality of communications and on storing or accessing information on a user's device: the legal basis for consent requirements around cookies and similar technologies.
Anyone running a website, app or analytics aimed at EU users.
Guides: GDPR compliance checklist for technology companies outside Europe
Official source (CELEX 32002L0058)·Verified 2026-08-17
V1 covers the EU-level framework. National implementation of directives can change how a requirement applies to you. (2026-08-v4, 2026-08-17)
General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.