Skip to content
EU Compliance

Which EU Regulations Apply to My Company?

5 min readUpdated 4 November 2026

The EU regulatory landscape in 2025–2026 is more complex than at any previous point. Multiple regulations have come into force or entered their application phase simultaneously — GDPR, AI Act, NIS2, DORA, CSRD, the Data Act, and the EU AI Liability Directive. Determining which ones apply to your specific company requires a systematic approach.


The Quick Determination: Six Questions

Work through these questions to identify your primary EU regulatory obligations.


Question 1: Do you process personal data of EU residents?

Yes → GDPR applies.

GDPR applies to any organisation — regardless of location — that processes personal data of individuals in the EU. This includes:

  • Collecting email addresses from EU website visitors
  • Processing customer data for EU-based customers
  • Managing EU-based employee data

If you are established in the EU: GDPR fully applies. You need a lawful basis for processing, privacy notice, data subject rights process, DPA with vendors, and records of processing.

If you are based outside the EU but target EU users: GDPR's Article 3(2) targeting criterion applies. You need an EU representative, and all GDPR obligations apply.


Question 2: Do you develop, deploy, or use AI systems in the EU?

Yes → EU AI Act applies (from February 2025 for prohibited AI; August 2025 for GPAI; August 2026 for high-risk).

Determine your role:

  • Provider (builds and places AI on the market): Full technical documentation, conformity assessment for high-risk, transparency obligations
  • Deployer (uses AI in a professional context): Human oversight implementation, fundamental rights impact assessment for certain uses, logging requirements
  • Both: Compound obligations

Determine your AI's risk tier:

  • Prohibited: Subliminal manipulation, social scoring, real-time biometric identification in public spaces (certain exceptions)
  • High-risk: Annex III categories — recruitment, credit scoring, safety systems, biometric identification, education, law enforcement, etc.
  • Limited risk: Chatbots, deepfakes — transparency requirements only
  • Minimal risk: Everything else — no specific AI Act obligations

Question 3: Are you in a critical sector?

NIS2 applies to essential and important entities in specific sectors. Check both conditions:

Sector check (Annex I — essential entities): Energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure (cloud providers, data centres, CDNs, internet exchange points, DNS providers, TLD registries), ICT service management (MSPs, MSSPs), public administration, space

Sector check (Annex II — important entities): Postal/courier, waste management, chemicals, food, manufacturing (medical devices, computers/electronics, machinery, vehicles, other transport equipment), digital providers (online marketplaces, search engines, social networks), research

Size check: Essential entities: 250+ employees OR €50M+ turnover AND €43M+ balance sheet Important entities: 50–249 employees OR €10M–50M turnover

Both conditions must be met. Check sector AND size.

If yes → NIS2 applies. Register with national competent authority, implement Article 21 security measures, comply with 24h/72h/30-day incident reporting.


Question 4: Are you a financial services company?

Yes → DORA applies (from January 2025).

DORA applies to:

  • Banks and credit institutions
  • Insurance and reinsurance undertakings
  • Investment firms
  • Payment institutions and e-money institutions
  • Crypto-asset service providers (CASPs)
  • Credit rating agencies, central counterparties, trading venues
  • And others — check Annex of the DORA regulation

If yes → Register of Information, ICT risk management, incident reporting (4-hour initial notification), TLPT for significant entities, Article 30 contract provisions for all ICT vendors.

Note: NIS2 does not apply separately to financial entities — DORA is lex specialis and satisfies NIS2 through DORA compliance.


Question 5: Do you manufacture connected products or hold IoT data?

Manufacturer or related service provider → EU Data Act applies (from September 2025).

  • Data access by default through device interface or app
  • Third-party sharing mechanism
  • No contractual restrictions on user data access

Cloud service provider → Data Act cloud switching provisions apply.

  • Support data portability
  • Eliminate switching barriers and lock-in contractual terms
  • Phase out egress fees (cost-only by September 2025, zero by September 2027)

Question 6: Are you a large company with significant EU operations?

250+ employees, €40M+ turnover, €20M+ assets (two of three) → CSRD applies (Wave 2, first report for FY 2025).

Or: €150M+ EU turnover with a large EU subsidiary → Wave 4 from FY 2028.


Regulation Applicability Summary Table

RegulationApplies when
GDPRYou process personal data of EU residents
UK GDPRYou process personal data of UK residents
EU AI ActYou develop or deploy AI systems in the EU
NIS2You are in a critical sector AND meet size thresholds
DORAYou are a financial entity as defined
Data ActYou manufacture connected products or provide cloud services in the EU
CSRDYou are a large company meeting size thresholds
Swiss FADPYou process personal data of Swiss residents

When Multiple Regulations Apply Simultaneously

Most companies with significant EU operations face multiple regulations. Common stacks:

SaaS company, any sector: GDPR (always) + EU AI Act (if AI features) + possibly NIS2 (if in digital infrastructure sector) + Data Act (if cloud or IoT)

Fintech / financial services SaaS: GDPR + DORA + EU AI Act (if AI) + CSRD (if large)

IoT manufacturer: GDPR + Data Act + EU AI Act (if AI embedded) + NIS2 (if in critical sector) + CSRD (if large)

Large enterprise: GDPR + CSRD + NIS2 (if in scope) + DORA (if financial services) + EU AI Act

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →