Skip to content

Guide

EU regulations we cover

These are the instruments in the current dataset. Each entry is recorded against its official text, and the assessment decides which of them actually reach your company.

What kind of requirement it is

Direct legal obligation, customer-driven requirement, market expectation, or a possible requirement depending on facts.

GDPR

Regulation (EU) 2016/679 — General Data Protection Regulation

Europe's data protection regulation. It can apply to a company with no EU establishment where it offers goods or services to people in the EU, or monitors their behaviour, and it applies to processors handling EU personal data on a customer's instructions.

Anyone handling personal data of people in Europe.

Guides: GDPR compliance checklist for technology companies outside Europe

Official source (CELEX 32016R0679)Verified 2026-08-17

NIS2

Directive (EU) 2022/2555 — NIS2 Directive

Cybersecurity directive covering essential and important entities. Some digital service providers are in scope in their own right; many suppliers meet it as a supply-chain security requirement passed down by covered customers.

Digital infrastructure providers and suppliers to covered sectors.

Guides: Does NIS2 Apply to Non-EU Companies?

Official source (CELEX 32022L2555)Verified 2026-08-17

V1 covers the EU-level framework. National implementation of directives can change how a requirement applies to you. (2026-08-v4, 2026-08-17)

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.