EU Compliance

All EU Compliance Regulations, One Platform

Navigate 19+ regulatory frameworks with structured, queryable access to every article, recital, and amendment — sourced verbatim from EUR-Lex.

The EU Regulatory Landscape

The European Union has the most comprehensive regulatory framework in the world. Every business operating in or serving EU customers must navigate a complex web of regulations covering data protection, cybersecurity, AI governance, financial services, sustainability, product safety, and digital markets. These regulations overlap, interact, and evolve constantly — making compliance a continuous challenge.

  • 19 active regulatory frameworks covering every sector and business activity
  • Extraterritorial reach — regulations apply to businesses worldwide if they serve EU customers
  • Combined fines exceeding €500 million already imposed under GDPR alone
  • Continuous amendments and updates from EUR-Lex require ongoing monitoring
  • Cross-regulation obligations — a single business activity may trigger requirements under multiple frameworks

19 Active Regulatory Frameworks

GDPRActive

General Data Protection Regulation

The GDPR (EU) 2016/679 is the cornerstone of data protection in the EU. It governs how organizations collect, process, and store personal data of EU residents, with fines up to €20M or 4% of global turnover.

NIS2Active

NIS2 Directive

The NIS2 Directive (EU) 2022/2555 strengthens cybersecurity requirements for essential and important entities across the EU, with fines up to €10M or 2% of global turnover and management liability.

CRAActive

Cyber Resilience Act

The CRA (EU) 2024/2847 establishes mandatory cybersecurity requirements for all products with digital elements sold in the EU, covering design, development, production, and the entire product lifecycle.

AI ActActive

AI Act

The EU AI Act (EU) 2024/1689 is the world's first comprehensive AI regulation, establishing a risk-based framework for AI systems placed on the EU market with fines up to €35M or 7% of global turnover.

DORAActive

Digital Operational Resilience Act

DORA (EU) 2022/2554 establishes uniform ICT risk management requirements for the EU financial sector, covering banks, insurers, investment firms, and their ICT third-party providers.

DSAActive

Digital Services Act

The DSA (EU) 2022/2065 establishes obligations for digital services providers in the EU, with specific rules for online platforms, marketplaces, and very large online platforms (VLOPs).

eIDASActive

eIDAS Regulation (EU) No 910/2014

The eIDAS Regulation establishes a legal framework for electronic identification, authentication, and trust services across the EU, enabling cross-border digital transactions.

eIDAS 2.0Active

European Digital Identity Regulation (EU) 2024/1183

eIDAS 2.0 amends the original eIDAS to introduce the EU Digital Identity Wallet, enabling citizens and businesses to store and share identity credentials across the EU.

DMAActive

Digital Markets Act (EU) 2022/1925

The Digital Markets Act imposes ex-ante obligations on gatekeepers — large platforms controlling core platform services — to ensure fair and contestable digital markets in the EU.

Data ActActive

EU Data Act (EU) 2023/2854

The EU Data Act establishes rules on fair access to and use of data generated by connected products and related services, empowering users and enabling data sharing.

DGAActive

Data Governance Act (EU) 2022/868

The Data Governance Act creates a framework for data intermediaries, data altruism, and re-use of protected public sector data, fostering trust in voluntary data sharing across the EU.

CERActive

Critical Entities Resilience Directive (EU) 2022/2557

The CER Directive establishes obligations for EU Member States and critical entities to enhance the physical resilience of essential services across 11 sectors.

PSD2Active

Payment Services Directive 2 (EU) 2015/2366

PSD2 regulates payment services in the EU, introducing open banking through mandatory access to bank accounts for third-party providers and strong customer authentication.

MiCAActive

Markets in Crypto-Assets Regulation (EU) 2023/1114

MiCA establishes a comprehensive regulatory framework for crypto-asset issuers and service providers in the EU, covering stablecoins, utility tokens, and CASPs.

CSAActive

EU Cybersecurity Act (EU) 2019/881

The EU Cybersecurity Act establishes a permanent mandate for ENISA and creates an EU-wide cybersecurity certification framework for ICT products, services, and processes.

ePDActive

ePrivacy Directive 2002/58/EC

The ePrivacy Directive governs privacy in electronic communications, establishing rules on cookies, direct marketing, traffic data, and confidentiality of communications.

REDActive

Radio Equipment Directive 2014/53/EU

The Radio Equipment Directive sets essential requirements for radio equipment placed on the EU market, including cybersecurity, privacy, and interoperability obligations.

CSRDActive

Corporate Sustainability Reporting Directive (EU) 2022/2464

The CSRD expands mandatory ESG disclosure requirements for EU companies, requiring detailed sustainability reporting aligned with European Sustainability Reporting Standards.

Why Comprehensive Compliance Matters

EU regulations don't operate in isolation. A single business may be subject to obligations under GDPR for data protection, NIS2 for cybersecurity, the AI Act for automated systems, the DSA for online services, and the CSRD for sustainability reporting. The real challenge isn't just complying with one regulation — it's understanding how they interact and where obligations overlap.

  • GDPR personal data processing intersects with NIS2 cybersecurity obligations
  • AI Act high-risk classification may trigger additional DPIA requirements under GDPR
  • DSA platform obligations complement GDPR transparency requirements
  • DORA financial ICT resilience builds on NIS2 cybersecurity baselines
  • CRA product cybersecurity requirements overlap with RED radio equipment provisions
  • CSRD sustainability reporting may require data governance practices under the Data Act

Frequently Asked Questions

How many EU compliance regulations are there?

There are 19+ active EU regulatory frameworks relevant to businesses, including GDPR, NIS2, AI Act, DORA, CRA, DSA, CSRD, MiCA, eIDAS, DMA, Data Act, Data Governance Act, CER, PSD2, ePrivacy, RED, CSA, and more. The exact number depends on your sector and activities.

Which EU regulations apply to my business?

Every business processing EU personal data must comply with GDPR. Cloud services face NIS2. AI systems fall under the AI Act. Financial entities comply with DORA. Connected products must meet CRA requirements. Online platforms face DSA obligations. Law4Devs helps you identify exactly which regulations apply to your specific activities.

How much does EU compliance cost?

Compliance costs vary by regulation and business size. Law4Devs provides access to all 19+ frameworks starting at €29/month — significantly less than the cost of separate legal consultations for each regulation.

Access All 19+ EU Regulations

One platform. Every regulation. Structured JSON from EUR-Lex — updated automatically.