Skip to content
EU Compliance

EU Compliance Glossary: 60 Terms Explained

8 min readUpdated 18 November 2026

EU compliance uses specialist terminology that can be confusing — particularly when the same concept appears under different names across different regulations. This glossary covers the 60 most important terms across GDPR, NIS2, DORA, AI Act, CSRD, and the Data Act.


A

Adequacy Decision: An EU Commission decision that a non-EU country provides an equivalent level of data protection to the EU, allowing personal data to flow there without additional safeguards. Current adequacy countries include Switzerland, the UK, Japan, and South Korea.

Article 28 Agreement: The contractual requirement under GDPR for controllers to have a written agreement with processors. Often called a Data Processing Agreement (DPA).

Article 30 Register: See Records of Processing Activities.


B

BCM (Business Continuity Management): The programme for identifying threats to business operations and building resilience. Required under NIS2 Article 21 and DORA Article 11.

BCP (Business Continuity Plan): A documented plan for maintaining operations during and after disruptive events. Required for NIS2-regulated entities and DORA-regulated financial entities.


C

CAIQ: Consensus Assessments Initiative Questionnaire — a Cloud Security Alliance framework for assessing cloud provider security practices.

CE Marking: The conformity marking applied to products that comply with EU standards. AI Act high-risk systems require CE marking after conformity assessment.

CISO (Chief Information Security Officer): The senior executive responsible for information security. Required to have clear accountability for NIS2 obligations.

Cloud Switching: The process of moving data and workloads from one cloud provider to another. EU Data Act requires cloud providers to support switching without excessive barriers.

Competent Authority: The national authority designated to supervise compliance with a specific regulation. ICO for UK GDPR; EDPB coordinates between national DPAs for GDPR; national NCAs for NIS2; ECB/NCAs for DORA.

Controller (GDPR): The legal or natural person that determines the purposes and means of processing personal data. Has the primary compliance obligations under GDPR.

Conformity Assessment: The formal process for assessing whether a high-risk AI system meets AI Act requirements before being placed on the market.

CSRD (Corporate Sustainability Reporting Directive): The EU directive requiring large companies to publish sustainability reports aligned with ESRS standards.

CTPP (Critical ICT Third-Party Provider): A category of ICT providers designated by European supervisory authorities as systemically important to the EU financial system. Subject to direct EU oversight under DORA Article 31.


D

Data Act: EU Regulation 2023/2854 governing data access, sharing, and cloud switching for connected products and cloud services. Applies from September 2025.

Data Controller: See Controller.

Data Holder (Data Act): A legal entity or natural person that has the right and technical ability to make data available.

Data Portability: The right to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller. GDPR Article 20; extended by Data Act for cloud services.

Data Processing Agreement (DPA): The mandatory written contract between a controller and processor under GDPR Article 28. Sets out the processor's obligations and restrictions.

Data Processor: See Processor.

DMA (Digital Markets Act): EU regulation governing large online platforms and search engines designated as "gatekeepers."

DORA (Digital Operational Resilience Act): EU Regulation 2022/2554 governing ICT risk management and operational resilience for financial entities. Applies from January 2025.

Double Materiality: The two-sided materiality test under CSRD — assessing both how a company impacts the environment and society (impact materiality) and how sustainability issues affect the company financially (financial materiality).

DPA (abbreviation): Data Processing Agreement, or Data Protection Authority — context-dependent.

DPF (Data Privacy Framework): The EU-US Data Privacy Framework — adequacy arrangement for US-EU data transfers. Replaced Privacy Shield. Requires self-certification by US companies.

DPIA (Data Protection Impact Assessment): A structured risk assessment required under GDPR Article 35 for high-risk processing activities, particularly involving systematic profiling, large-scale special category data, or systematic monitoring of public areas.


E

EDPB (European Data Protection Board): The body that coordinates GDPR supervision across EU member states and issues guidance on GDPR interpretation.

EFRAG: European Financial Reporting Advisory Group — the body that developed the ESRS standards under CSRD.

Egress Fees: Charges applied when cloud customers download their data for switching to another provider. EU Data Act requires elimination by September 2027.

EED (Energy Efficiency Directive): EU Directive 2023/1791 — requires energy audits for large enterprises and mandatory sustainability reporting for data centres above 500 kW IT load.

Essential Entity (NIS2): Organisations in Annex I sectors (energy, transport, banking, health, digital infrastructure, etc.) above the large enterprise threshold. Subject to proactive supervision under NIS2.

ESRS (European Sustainability Reporting Standards): The mandatory reporting standards for CSRD, covering environmental, social, and governance topics.

EU AI Act: Regulation 2024/1689 — the EU's horizontal regulation on artificial intelligence, creating risk-based obligations for AI providers and deployers.


F

FDPIC (Federal Data Protection and Information Commissioner): Switzerland's national data protection authority, responsible for enforcing FADP.

FRAND (Fair, Reasonable, and Non-Discriminatory): The standard that applies to B2B data sharing terms under the EU Data Act.

FRIA (Fundamental Rights Impact Assessment): An assessment required under the EU AI Act for certain deployers of high-risk AI systems, particularly in public sector contexts.


G

GDPR (General Data Protection Regulation): EU Regulation 2016/679 — the primary EU framework for personal data protection. Applies in all EU member states.

GPAI (General Purpose AI): AI models and systems that can perform a wide range of tasks — including large language models and multimodal foundation models. Subject to specific obligations under AI Act Chapter V.


H

High-Risk AI System: An AI system classified under EU AI Act Annex III categories as presenting significant risks to health, safety, or fundamental rights. Subject to the most stringent AI Act obligations.


I

IDTA (International Data Transfer Agreement): The UK mechanism for international personal data transfers — equivalent to EU SCCs but specific to UK GDPR.

Important Entity (NIS2): Organisations in Annex II sectors (postal, manufacturing, digital providers, etc.) above the small enterprise threshold. Subject to reactive (complaint-triggered) supervision under NIS2.

Incident Response Plan: A documented procedure for identifying, responding to, and recovering from security incidents. Required under NIS2 Article 21, DORA, and strongly implied by GDPR Article 32.

ISMS (Information Security Management System): A systematic approach to managing sensitive company information — ISO 27001 is the international standard.


L

Lead Supervisory Authority (LSA): For companies established in multiple EU member states, the DPA in the member state of the company's main EU establishment. Leads investigations under GDPR's one-stop-shop mechanism.

Legitimate Interest: One of the six GDPR lawful bases for processing personal data — Article 6(1)(f). Requires a three-part assessment (purpose, necessity, balancing test).


M

Materiality (CSRD): The assessment of which sustainability topics require disclosure — based on double materiality (impact and financial materiality).

Market Surveillance Authority: The authority designated under the AI Act to enforce AI Act requirements. Varies by member state.


N

NIS2 (Network and Information Security Directive 2): EU Directive 2022/2555 — the EU's cybersecurity framework for essential and important entities. Required to be transposed by member states by October 2024.

Notified Body: An independent organisation accredited to perform conformity assessments for high-risk AI systems that require third-party assessment (rather than self-assessment).


P

PAI Indicators (SFDR): Principal Adverse Impact indicators — sustainability metrics that financial market participants must disclose about how their investments negatively affect sustainability.

Personal Data: Any information relating to an identified or identifiable natural person (data subject) under GDPR.

Processor: A legal or natural person that processes personal data on behalf of a controller, under the controller's instructions.

PUE (Power Usage Effectiveness): The ratio of total data centre energy to IT equipment energy. A PUE of 1.2 means 20% overhead for cooling and power conditioning. Required metric under EU EED data centre reporting.


R

Register of Information (DORA): The ICT third-party risk register that financial entities under DORA must maintain, covering all ICT service providers and the services they deliver.

ROPA (Records of Processing Activities): The internal register required under GDPR Article 30 documenting all personal data processing activities.

RPO (Recovery Point Objective): The maximum acceptable amount of data loss measured in time. A RPO of 4 hours means no more than 4 hours of data can be lost in a disaster.

RTO (Recovery Time Objective): The maximum acceptable time to restore a system or service after a failure.


S

SCCs (Standard Contractual Clauses): Pre-approved contract clauses issued by the European Commission for international personal data transfers. 2021 version replaced the 2010 version.

SFDR (Sustainable Finance Disclosure Regulation): EU regulation requiring financial market participants and advisers to disclose how sustainability risks are integrated into investment decisions and products.

SIG (Standardised Information Gathering): A comprehensive vendor security questionnaire framework maintained by Shared Assessments.

Special Category Data: Sensitive categories of personal data under GDPR Article 9 — health, biometrics, race/ethnicity, religion, political opinion, sexual orientation, trade union membership, criminal convictions.

Sub-Processor: A processor engaged by another processor to carry out processing on behalf of the controller.


T

TIA (Transfer Impact Assessment): An analysis required alongside SCCs, assessing whether the legal framework of the destination country undermines the SCCs' protections.

TLPT (Threat-Led Penetration Testing): Advanced penetration testing based on real threat intelligence, required for significant financial entities under DORA and aligned with the TIBER-EU framework.

TRIR (Total Recordable Incident Rate): A workforce health and safety metric — number of recordable incidents per 100 full-time equivalent workers per year. Required disclosure under ESRS S1.

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →