A non-EU SaaS company should not start EU compliance by assuming that GDPR, NIS2, DORA, the AI Act, and the European Accessibility Act all apply in the same way. Start with an entity-product-data-customer map, apply each law's own territorial and material scope, then build one control system for the obligations that actually apply.
The result should be a dated scope memo, assigned operator roles, a prioritised remediation plan, and evidence that sales, product, engineering, security, privacy, and support can operate the controls promised to EU customers.
Quick answer
| Framework | When it may matter to SaaS | Common mistake |
|---|---|---|
| GDPR | EU establishment, or offering goods/services to or monitoring people in the EU; also as an EU customer's processor | Treating all EU website access as targeting, or treating a DPA as proof of territorial scope |
| NIS2 | The company falls within a covered entity type and national implementing law; some non-EU digital providers need an EU representative | Assuming every B2B SaaS provider is in scope |
| DORA | Directly for listed financial entities; contractually for many ICT providers serving them; Union oversight for designated critical providers | Claiming every fintech vendor is a DORA-regulated financial entity |
| AI Act | Operator role, EU market/output nexus, prohibited practices, system class, GPAI role, and transparency duties | Using one “AI vendor” label instead of mapping roles and systems |
| European Accessibility Act | Covered consumer products/services, including e-commerce, as implemented nationally | Assuming every enterprise SaaS interface is automatically covered |
For a documented multi-law scope and implementation plan, see our EU regulatory compliance service.
Step 1: Map facts before laws
Create a fact sheet for every product and contracting entity:
- legal entity and establishment;
- EU countries targeted or served;
- customer type and regulated status;
- user and affected-person location;
- contract chain and resellers;
- categories and flows of personal data;
- hosting, support, and subprocessors;
- service functionality and critical dependencies;
- AI models, systems, purpose, branding, and modification;
- consumer versus enterprise use; and
- sales, onboarding, payment, support, and termination journeys.
Record contrary facts and uncertainty. Scope conclusions based only on marketing copy or billing address can fail when actual product use differs.
Step 2: Scope GDPR
Territorial reach
GDPR Article 3 can apply through:
- an establishment in the EU and processing in the context of its activities;
- offering goods or services to people in the EU; or
- monitoring their behaviour in the EU.
The EDPB's territorial-scope guidelines explain that accessibility of a website alone does not necessarily demonstrate targeting. Examine currencies, languages, delivery, campaigns, customer references, and the design of the service.
Controller and processor roles
Map roles per processing operation, not per company. A SaaS provider may be:
- a processor for customer-configured data;
- an independent controller for accounts, security, billing, or product analytics;
- a joint controller for a defined shared decision; or
- in different roles for different features.
Article 28 terms do not cure unclear purposes or unlawful processing. Maintain a data map, legal bases, transparency, retention, security, rights handling, breach response, and transfer mechanism.
Representatives and international transfers
An Article 27 representative may be required for certain non-EU controllers or processors subject to Article 3(2), subject to its exceptions. This is not the same role as a data protection officer.
Transfers from the EEA to a third country need a Chapter V route, such as an adequacy decision or appropriate safeguards, plus any assessment and supplementary measures required for the specific transfer. Hosting in the EU does not end the analysis if support or remote access exports data.
Where required, EU representative support should be scoped separately from DPO or general advisory work.
Step 3: Scope NIS2 through national law
NIS2 is a directive. The legal obligation comes through Member State implementation, so confirm the relevant national law, entity type, size rules, jurisdiction, registration, and competent authority.
Covered digital categories include, among others, cloud-computing, data-centre, content-delivery-network, managed-service, managed-security-service, online-marketplace, online-search-engine, and social-networking-platform providers. Definitions matter: calling a product “cloud SaaS” does not establish that it meets the directive's cloud-computing-service definition or a national category.
Under Article 26, specified providers that are not established in the EU but offer services in the EU must designate a representative in an EU Member State where services are offered. That NIS2 representative and a GDPR Article 27 representative arise under different laws; document each appointment and duty.
If in scope, build evidence for governance, risk-management measures, supply-chain security, incident handling and reporting, business continuity, vulnerability handling, cryptography, access control, and security training under the applicable national rules.
Step 4: Handle DORA customer requirements accurately
DORA has applied since 17 January 2025 to the financial entities listed in Article 2. A SaaS provider is not automatically such an entity because it sells to a bank, insurer, or investment firm.
Nevertheless, a financial-entity customer must manage ICT third-party risk and include specified contractual terms, especially for services supporting critical or important functions. Expect due diligence on:
- service and data locations;
- availability, integrity, confidentiality, and recovery;
- incident assistance;
- subcontractors;
- audit, access, and inspection;
- testing cooperation;
- concentration and substitutability;
- termination; and
- exit and data portability.
Do not promise unlimited audit access without an operational process, and do not use security certification as a blanket substitute for DORA-specific evidence. If the ESAs designate a provider as critical, a separate Union oversight framework applies.
Step 5: Apply the amended AI Act
For each AI-enabled feature, identify provider, deployer, importer, distributor, authorised-representative, and product-manufacturer roles. Then assess:
- territorial scope and output use in the EU;
- prohibited practices;
- Article 6(1)/Annex I and Article 6(2)/Annex III high-risk routes;
- Article 50 transparency;
- GPAI provider or downstream-provider duties;
- data protection, copyright, product, consumer, and employment rules; and
- contract information and change control.
At the review date, Article 50 transparency duties apply. A narrow Article 111(4) transition applies only to the provider duty in Article 50(2): providers of systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text content and were placed on the market before 2 August 2026 must take the necessary steps to comply with Article 50(2) by 2 December 2026.
Regulation (EU) 2026/1744 moved the main high-risk Chapter III requirements to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-related systems. Do not use the pre-amendment 2 August 2026 high-risk schedule.
Step 6: Check accessibility by service, not label
The European Accessibility Act applies through national law to specified products placed on the market and specified consumer services provided after 28 June 2025. Covered services include e-commerce, consumer banking, electronic communications, e-books, and specified transport and audiovisual-access services.
An enterprise SaaS product is not automatically covered merely because it has a website. Assess:
- whether the company provides a listed service to consumers;
- the national implementing law;
- microenterprise and other exclusions;
- transition rules;
- fundamental-alteration and disproportionate-burden conditions; and
- documentation and information duties.
Even outside direct EAA scope, accessibility may be required by procurement, sectoral, equality, or customer rules and is a sound product practice.
Step 7: Build one control architecture
Avoid five disconnected compliance programmes. Use shared control objects:
| Shared object | Frameworks it can support |
|---|---|
| Entity, service, system, and data inventory | GDPR, NIS2, DORA, AI Act, accessibility |
| Third-party register and due diligence | GDPR processors, NIS2 supply chain, DORA ICT providers, AI supply chain |
| Incident workflow | GDPR breach, NIS2 significant incident, DORA major incident, AI serious incident |
| Secure development and change management | GDPR security, NIS2, DORA, AI robustness, accessibility regression |
| Risk and decision register | All frameworks, with separate legal tests |
| Training and role matrix | Management, security, privacy, AI, support, accessibility |
| Evidence repository | Audits, customers, authorities, management review |
Shared controls do not mean shared conclusions. Preserve each law's role, threshold, reporting trigger, authority, timeline, and evidence.
A market-entry sequence
Before active sales
- approve the target-country and customer profile;
- complete the initial scope memo;
- publish accurate privacy and cookie information;
- put controller/processor and transfer terms in place;
- establish security, incident, and rights workflows;
- assess EU and NIS2 representatives where relevant; and
- remove marketing claims that operations cannot evidence.
Before the first regulated customer
- map the customer's regulatory status and critical functions;
- complete DORA/NIS2 contract and evidence gap analysis;
- agree audit and incident channels;
- validate business continuity, recovery, subcontracting, and exit;
- classify AI features and implement transparency; and
- align sales commitments with engineering capability.
During scale
- re-run scope when entering a country, acquiring an entity, changing hosting, adding AI, targeting consumers, or launching a regulated-sector feature;
- monitor national law and official guidance;
- test incident and rights scenarios; and
- maintain a controlled evidence package for due diligence.
Frequently asked questions
Do we need an EU entity to sell SaaS into the EU?
Not always, but establishment, tax, consumer, licensing, representative, employment, and customer-procurement questions must be assessed separately. A representative is not a general branch or distributor.
Does an EU data centre make us GDPR compliant?
No. Location is one fact. Purpose, legal basis, roles, security, retention, rights, transparency, and remote transfers still require analysis.
Can one representative cover GDPR, NIS2, and the AI Act?
One service provider may be capable of several appointments, but each law has different triggers, formalities, tasks, contacts, and conflicts. Use separate written analyses and mandates.
Should we promise “EU compliant” in sales material?
Only make specific, evidenced claims tied to a product, entity, scope, version, and date. A universal statement can be misleading where obligations depend on customer configuration and national law.
Sources and review
This playbook was substantively reviewed on 8 August 2026 against primary legal texts and official guidance. National implementation and product facts can change the result.
- Regulation (EU) 2016/679 — GDPR
- EDPB Guidelines 3/2018 — territorial scope of GDPR Article 3
- Directive (EU) 2022/2555 — NIS2
- Regulation (EU) 2022/2554 — DORA
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- Regulation (EU) 2026/1744 — Digital Omnibus on AI
- Directive (EU) 2019/882 — European Accessibility Act
- European Commission — European Accessibility Act
For a source-backed scope memo and prioritised market-entry plan, see Vision Compliance's regulatory compliance service.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.