GDPR remains the dominant data protection framework in Europe, but the EU AI Act (transparency from August 2026, high-risk in December 2027 following the June 2026 omnibus) and the NIS2 directive create new obligations in AI governance and cybersecurity.
Organizations must now simultaneously manage personal data compliance, AI system classification by risk level, and NIS2 requirements for essential and important entities.
GDPR, nLPD, UK GDPR
EU AI Act
NIS2, ISO 27001
+ 42 other European jurisdictions covered