Many companies — particularly financial services SaaS, healthcare technology, and digital infrastructure providers — face three major EU frameworks simultaneously: GDPR, NIS2, and DORA. Each has its own requirements, timelines, and enforcement mechanisms. The challenge is not managing three separate compliance programmes; it is building one integrated programme that satisfies all three efficiently.
The Three Frameworks: Quick Overview
GDPR: Personal data protection. Applies to any organisation processing EU personal data. Core obligations: lawful processing, transparency, data subject rights, security measures, processor management.
NIS2: Cybersecurity for critical sectors. Applies to essential and important entities in Annex I/II sectors. Core obligations: risk management measures, incident reporting (24/72h), supply chain security, board accountability, registration.
DORA: ICT operational resilience for financial entities. Applies to banks, insurers, investment firms, payment institutions, and other financial entities. Core obligations: ICT risk management framework, incident reporting (4h/72h/1 month), Register of Information, resilience testing, ICT third-party risk management.
Who Faces All Three?
Financial services SaaS / fintech companies:
- GDPR: always applies (processes customer personal data)
- DORA: applies as a regulated financial entity (if authorised as a payment institution, CASP, etc.)
- NIS2: DORA is lex specialis — financial entities satisfy NIS2 through DORA compliance
Cloud providers / managed service providers serving financial sector:
- GDPR: always applies
- NIS2: cloud providers are in Annex I (digital infrastructure) — NIS2 applies as essential entity
- DORA: not directly regulated as a financial entity, but obligations flow through customer contracts (DORA Article 30)
Healthcare technology companies:
- GDPR: applies (health data is special category data)
- NIS2: healthcare is an Annex I essential sector — NIS2 applies
- DORA: does not apply (healthcare entities are not financial entities)
The Overlap Map
Security Measures
All three frameworks require information security measures:
GDPR Article 32: "appropriate technical and organisational measures" — risk-based; no specific minimum standards prescribed.
NIS2 Article 21: Mandatory minimum measures including MFA, encryption, access control, vulnerability management, BCP, supply chain security.
DORA Article 9: ICT security measures covering authentication, encryption, endpoint protection, network security, incident detection.
How to handle the overlap: Build one security framework that satisfies the most prescriptive requirement. NIS2 Article 21 and DORA Article 9 are both more specific than GDPR Article 32. If you satisfy NIS2/DORA security requirements, GDPR Article 32 is satisfied simultaneously.
One security policy: Write a single Information Security Policy covering MFA, encryption, access control, vulnerability management, patch management, and BCP. Reference it in your GDPR records, NIS2 compliance documentation, and DORA ICT risk framework.
Incident Reporting
The frameworks have different incident reporting timelines and different reporting destinations:
| Framework | What triggers reporting | Timeline | To whom |
|---|---|---|---|
| GDPR | Personal data breach with risk to individuals | 72 hours | National DPA |
| NIS2 | Significant incident with impact on service continuity | Early warning: 24h; Notification: 72h; Report: 30 days | National competent authority |
| DORA | Major ICT incident (financial impact, reputation, business continuity) | Initial: 4h; Intermediate: 72h; Final: 1 month | Financial supervisory authority (ECB/NCA) |
How to handle the overlap: Build one incident classification and response framework that identifies all three trigger conditions:
- Does the incident involve personal data breach? → GDPR 72h notification
- Does the incident significantly impact service continuity for NIS2-regulated services? → NIS2 24/72h notification
- Does the incident materially affect ICT systems for DORA financial services? → DORA 4h initial notification
An incident can trigger all three simultaneously. A cloud provider (NIS2 essential entity) that suffers a breach affecting financial services customers' personal data triggers GDPR + NIS2 + DORA notifications simultaneously.
Practical solution: One incident response procedure with a decision tree for determining which notifications are required. One on-call process and one set of notification templates.
Processor/Third-Party Risk Management
All three frameworks create obligations around third-party vendors:
GDPR Article 28: Data Processing Agreements with all processors. Sub-processor management. Audit rights.
NIS2 Article 21(d): Supply chain security — assess ICT suppliers, impose security obligations in contracts.
DORA Article 30: Mandatory contract provisions for all ICT third-party service providers. Register of Information.
How to handle the overlap: Use one vendor assessment process with a tiered approach:
- For vendors that are processors under GDPR + ICT suppliers under NIS2 + DORA vendors: A combined DPA that includes GDPR Article 28 provisions, NIS2 security obligations, and DORA Article 30 clauses
- Maintain one vendor register that feeds the DORA Register of Information, NIS2 supply chain records, and GDPR processor register
Documentation and Records
GDPR: Records of Processing Activities (ROPA), DPIAs, DPAs
NIS2: Risk management documentation, incident reports, supply chain security records
DORA: Register of Information, ICT risk management documentation, testing results, incident reports
How to handle: One compliance document library with clearly indexed records serving all three frameworks. Avoid maintaining separate document sets for each regulation — they overlap significantly and diverge minimally.
The Integrated Compliance Programme Structure
Single policy framework:
- Information Security Policy (satisfies GDPR Art 32, NIS2 Art 21, DORA Art 9)
- Data Protection Policy (GDPR specific)
- ICT Risk Management Policy (DORA specific — financial entities only)
- Supply Chain Security Policy (NIS2 specific + DORA overlay)
Single vendor management process:
- Vendor assessment → feeds GDPR processor register + NIS2 supply chain records + DORA Register of Information
- Vendor contracts → combined DPA with GDPR, NIS2, and DORA provisions
Single incident response process:
- Detection → Classification → Response → Notification decision tree (GDPR/NIS2/DORA)
Single compliance owner:
- One person or function with visibility across GDPR, NIS2, and DORA obligations
- Regular reporting to management covering all three frameworks