Compliance GuidesWhat does a dual-compliance system cost for EU companies?
Running EU rules next to UK, US or Swiss rules usually means paying for the same control twice. Where the money actually goes, and what one central system should save you.
Co-Founder, Harpocrates Solutions GmbH
Jan has spent 30 years building and transforming financial services and technology businesses, from co-founding Call Center Europe and growing it to over 450 people, to deploying the EU’s secure TESTA networks for European institutions, EuroPol, SIS, VIS and member states, to running a €300M business unit at Orange Business Services, to heading Data & Analytics at Swiss Re. Across every role, he saw European organisations forced into compliance tooling that wasn’t built for their reality. He created Harpocrates to fill it, technology rooted in European regulatory reality, built here, for here.
Compliance GuidesRunning EU rules next to UK, US or Swiss rules usually means paying for the same control twice. Where the money actually goes, and what one central system should save you.
Compliance GuidesA search query led me here: someone drowning in DPIA templates. So let me actually answer them.
Compliance GuidesA DPIA is required before processing that is likely to result in a high risk to people’s rights. Here is the threshold, the three automatic triggers, what the assessment must contain, and when you must consult the regulator.
Compliance GuidesIf you manufacture outside the EU and sell into it, three regimes can reach you: NIS2, the Cyber Resilience Act, and your customers’ supply-chain requirements. Here is which one applies.
Compliance GuidesCompany owners outside Europe are sure EU law does not touch them because they have no EU office, and they are wrong. GDPR, the AI Act, DORA, and the product rules can all apply when you target the EU market. Here is what each one asks.
RegulationA US ruling on who controls the FTC has quietly unsettled the legal basis for moving European data across the Atlantic.
RegulationA US ruling on who controls the Federal Trade Commission has quietly removed a load-bearing assumption beneath every transfer of European data to the United States.
Compliance GuidesThe prospects who raise DORA with me usually think it does not reach them, and they are usually wrong. Two tests decide it, and here is what it requires once you are in scope.
Compliance GuidesFounders, company owners and CEOs ask me this before every raise and every audit. Which EU rules apply depends on four things, and here is how I scope them.
SovereigntyA short set of questions that separates genuine digital sovereignty from an EU region with a sovereignty label, applied honestly to ourselves as well.
ArchitectureThe industry standard is to pull a customer’s documents into the vendor’s cloud. For regulated European firms, that convenience is the exposure.
ArchitectureFor fifteen years European data protection has asked where information is stored. Artificial intelligence has changed the question to where regulation is understood.