Compliance Guides
Which EU regulations does my company need to comply with?
Founders, company owners and CEOs ask me this before every raise and every audit. Which EU rules apply depends on four things, and here is how I scope them.

Photo: Christian Lue / Unsplash
New to the topic? Start with What sovereign compliance actually means.
I get asked this on almost each and every call with potential clients, and they are usually very uncomfortable: which of these EU rules actually apply to us, and which can we leave for later? It is a fair question, and the honest answer is that it depends on four things: your sector, your size, the data you handle, and the activities you carry out. Almost every business in the EU shares a common core of data protection, employment, consumer and product rules, then picks up sector-specific regimes on top. What follows is how I scope it, a table mapping common business types to the regulations they usually trigger, and a note on when EU law reaches companies with no office in Europe at all.
Scope it with four questions
- Sector. Are you in a regulated industry: finance, insurance, health, energy, telecoms? Regulated sectors carry the heaviest and most specific requirements, and the regulator expects you to know that going in.
- Size. Headcount and turnover decide whether the thresholds bite. Many regimes exempt or soften the rules for micro and small enterprises, so your size alone can move you in or out of scope.
- Data. Do you process personal data, special-category data, or run large-scale monitoring? That pulls in GDPR, and more and more, the AI Act.
- Activity. Do you sell to consumers, build or deploy AI, run essential digital services, or place products on the EU market? Each activity triggers its own regime.
A map from business type to likely EU regulations
| Business type | Regulations it usually triggers |
|---|---|
| Any company processing personal data | GDPR; ePrivacy (cookies / marketing) |
| Company building or deploying AI | EU AI Act (risk tier depends on use) + GDPR |
| Bank, insurer, investment or payment firm | DORA, plus sector rules (CRR/CRD, Solvency II, PSD2/3, MiCA for crypto) |
| Operator of essential / important digital or infrastructure services | NIS2 |
| Manufacturer placing products on the EU market | Product-specific rules (e.g. MDR for medical devices, CE-marking regimes), plus the Cyber Resilience Act for products with digital elements |
| Anyone selling to EU consumers | Consumer-protection and distance-selling rules; accessibility (EAA) |
Treat this as a starting map rather than a ruling. The exact list turns on the specifics of each of the four questions above.
The horizontal rules almost everyone should check
- GDPR. If you process personal data of people in the EU, in almost any capacity, you are in scope.
- EU AI Act.If you build, sell, or use AI systems, your requirements scale with the system's risk tier. See does the EU AI Act apply to us.
- NIS2 and DORA. Cybersecurity and operational-resilience regimes for in-scope sectors and their IT suppliers. See does DORA apply to my company and does NIS2 apply to my business.
- Consumer, employment, and accessibility law. Broad-based, and the easiest to overlook until someone complains.
Sector-specific regimes
Regulated sectors stack their own regimes on top of the horizontal ones. Financial services carry DORA, MiCA, PSD2/3 and Solvency II. Health carries MDR and IVDR. Energy and telecoms carry their own rules. If you sit in one of these sectors, that regime is usually where most of your requirements live, and where an audit tends to start.
If your company is outside the EU
This is the part companies based outside Europe usually get wrong. Plenty assumed that having no office here kept them clear, and it didn't. EU law reaches non-EU companies far more than they expect. If you offer goods or services to people in the EU, monitor their behaviour, place products on the EU market, or supply IT services to EU financial entities, you can fall directly within GDPR, the AI Act, the Cyber Resilience Act, or DORA's third-party provisions, with no EU establishment at all. Doing business in Europe means meeting European requirements, wherever your head office sits. We cover this in detail in non-EU company selling into the EU.
Keeping the list current, and where COMPLY.Reg fits
Reading a single regulation is the easy bit. Working out which of them apply to your specific business, breaking each one into concrete requirements, and keeping that current as the laws change is where the time goes. That work is slow and easy to get wrong by hand, and it was never really a spreadsheet job.
This is the job we built COMPLY.Reg to do, and I will be honest that it is much of the reason the company exists. It scans your business profile against European regulatory sources, works out which requirements apply to you, and turns them into audit-ready, traceable controls. Your source documents stay on your own systems, and your compliance data is processed in the EU, which for me is not negotiable. It is built for European companies and for companies outside Europe that still have to do business here.
Frequently asked questions
- Do EU regulations apply to companies outside the EU?
- Yes, and more often than companies expect. If you offer goods or services to people in the EU, monitor their behaviour, place products on the EU market, or supply EU financial entities, rules such as GDPR, the AI Act, or DORA can apply with no EU establishment at all.
- What is the difference between a regulation and a directive?
- A regulation applies directly across the EU as written. A directive is transposed into each member state's national law, so the detail can vary by country.
- Which EU regulation applies to almost every business?
- The GDPR. Nearly any organisation handling personal data of people in the EU falls within it.