Skip to content
EU Compliance

Compliance Due Diligence for Series A Fundraising

4 min readUpdated 11 November 2026

Series A due diligence now includes a compliance review. Institutional investors — particularly those with ESG mandates, financial services LPs, or portfolios in regulated sectors — are conducting compliance assessments as a standard part of the diligence process. Compliance gaps discovered during a fundraising process delay deals, reduce valuations, and in serious cases kill transactions.


Why Compliance Due Diligence Has Increased

Five years ago, legal due diligence in a Series A focused on corporate structure, cap table, IP ownership, and material contracts. Compliance was a minor component. The change drivers:

GDPR enforcement maturity: GDPR has been enforced for six years. Investors have seen portfolio companies receive ICO notices, face EDPB investigations, and incur significant remediation costs. Compliance due diligence reduces post-investment surprises.

AI regulation: Investors in AI companies are assessing AI Act exposure as part of diligence — particularly for high-risk AI systems that could require expensive conformity assessment or EU AI database registration.

NIS2 and DORA: Financial services and infrastructure-focused investors need to understand their portfolio companies' regulatory exposure.

ICO enforcement register: The ICO's public enforcement register is one of the first things investors check. A reprimand or monetary penalty notice on the register is a diligence finding.

Data room expectations: Series A data rooms now include a compliance section alongside financial statements, IP documentation, and customer contracts.


What Investors Check in the Compliance Data Room

GDPR

  • Privacy notice: Published, current, compliant with GDPR Articles 13/14?
  • Cookie consent: Correct implementation — no pre-ticked boxes, reject option equal to accept?
  • Data Processing Agreements: Signed DPAs in place with all vendors accessing personal data?
  • ROPA: Records of Processing Activities maintained and current?
  • DSAR process: Procedure in place? Any outstanding DSARs?
  • Breach history: Any reported breaches? How were they handled?
  • ICO register check: Any enforcement actions, reprimands, or monetary penalties?
  • International transfers: Transfer mechanism in place for non-EEA data processors?

Red flags:

  • No DPA with major SaaS tools (AWS, Salesforce, Hubspot, Stripe)
  • Cookie banner that does not have a reject option
  • A breach that was not reported to the ICO but probably should have been
  • An outstanding DSAR that is past the 30-day deadline

Security

  • ISO 27001 or SOC 2: Certification status and scope?
  • Penetration testing: Most recent test date and findings summary?
  • MFA: Is MFA in place for all critical systems?
  • Incident history: Any material security incidents? How were they handled?

Red flags:

  • No certifications and no plan to achieve them (for enterprise-targeting SaaS)
  • Last penetration test was more than 18 months ago
  • Unpatched critical vulnerabilities discovered in due diligence

AI (for AI companies)

  • AI Act classification: Has the company assessed which AI risk tier applies?
  • Technical documentation: Does the company have Annex IV documentation for high-risk AI?
  • EU AI database registration: Completed for high-risk systems?
  • Prohibited AI check: Any AI systems that might fall under Article 5 prohibited categories?

Red flags:

  • An unrecognised high-risk AI system — recruitment AI, credit scoring AI, or medical AI — with no compliance programme
  • Chatbot with no Article 50 disclosure

Data and IP

  • Customer data in training: Does the company use customer data to train AI models? On what legal basis?
  • IP ownership of AI outputs: Clear ownership of model outputs?
  • Data licences: Are training datasets properly licensed?

Building a Compliance Data Room

For a Series A fundraising process, prepare the following:

GDPR section:

  • Privacy notice (link or PDF)
  • Cookie consent implementation screenshot
  • Standard DPA (published or PDF)
  • Sub-processor list (current)
  • ROPA (summary — full document on request)
  • Breach history summary (confirming no material unresolved breaches)
  • ICO register confirmation (no enforcement actions)

Security section:

  • ISO 27001 certificate or SOC 2 report (current)
  • Penetration test date confirmation and brief findings summary
  • Security policy (summary)

AI section (if applicable):

  • AI system inventory with risk classification
  • AI Act compliance assessment summary
  • Prohibited AI confirmation

Regulatory exposure summary:

  • One-page summary of which regulations apply and current compliance status
  • Any known compliance gaps and remediation plan

Fixing Gaps Before Fundraising

If compliance due diligence reveals gaps, investors will either:

  • Require remediation before closing
  • Adjust valuation to reflect compliance risk
  • In serious cases, withdraw

The most common gaps that can be remediated quickly:

  • Missing vendor DPAs: typically 1–4 weeks to obtain
  • Outdated privacy notice: 1–5 days to update
  • Cookie consent fix: 1–2 weeks developer time
  • Missing ROPA: 2–5 days to complete

The most common gaps that take longer:

  • Penetration test: 4–8 weeks end-to-end
  • ISO 27001 certification: 6–12 months
  • AI Act high-risk compliance programme: 3–6 months

Start compliance preparation at least 3 months before beginning a fundraising process.

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →