United States · 2018 IN FORCE

CLOUD Act

What it is

The Clarifying Lawful Overseas Use of Data Act allows US federal authorities to compel US-incorporated companies to disclose data they hold, regardless of where the data physically resides. Active and routinely invoked.

What it means for you

Any US-jurisdictional vendor in your stack — including subsidiaries — is exposed. EU data residency does not provide legal protection. Your DPIA and procurement criteria should reflect this. Read our explainer.

Status as of

EU · CJEU pipeline PENDING

Schrems III (anticipated)

What it is

A successor to Schrems II is widely expected to test the validity of the EU-US Data Privacy Framework (DPF) of 2023. Industry observers expect a ruling within 18-24 months. Outcome could invalidate DPF-based transfers to US providers.

What it means for you

If your vendor strategy depends on DPF for US-bound transfers, you should already have a contingency for invalidation. Sovereign-EU vendors are the contingency that doesn’t require re-architecting after the ruling lands.

Status as of

EU · 2024 transposition IN FORCE

NIS2 Directive

What it is

NIS2 (the EU Network and Information Security Directive 2.0) requires essential and important entities to implement cybersecurity risk management measures and report incidents. Vendor-supply-chain risk is explicit in scope.

What it means for you

NIS2-covered customers must evaluate their supply-chain (which includes their SaaS vendors). Procurement criteria around vendor-incident reporting, audit rights, and security architecture have hardened. The compliance benefit of a sovereign-EU vendor is structural here, not just legal.

Status as of

EU · effective 2025-01-17 IN FORCE

DORA

What it is

The Digital Operational Resilience Act applies to financial-services entities and their critical-third-party ICT providers. Establishes registries of critical providers, mandatory contractual clauses, and supervisory oversight.

What it means for you

Financial-services customers in scope must have DORA-compliant contracts with their SaaS providers. We support the standard DORA clauses (audit rights, exit assistance, incident notification timelines) on Enterprise tier — self-serve. Critical-third-party designation is a question for the regulator, not the vendor.

Status as of

EU · long-running negotiation PENDING

ePrivacy Regulation

What it is

The proposed successor to the ePrivacy Directive has been in negotiation since 2017. Coverage would extend to electronic communications including OTT services. Member-state disagreements continue to block adoption.

What it means for you

If adopted, ePrivacy Regulation would constrain certain analytics and cookie practices more tightly than GDPR alone. Vendors using no-cookie analytics (us, via Plausible) are positioned to comply without architectural changes. Vendors using third-party tracking would face operational changes.

Status as of

Our commitment

We update this page quarterly. If a major regulation changes status, ruling, or trajectory, we update sooner. Past versions are tracked via the changelog.

The point of this page is not to scare you into using us. The point is to give European procurement teams a current-state read on the regulatory environment so vendor decisions can be made with eyes open. If we got something wrong or out of date, email hi@omniteam.eu and we’ll correct on the next quarterly update.

— BEGIN —

Start your workspace in 60 seconds.

Free for teams up to 10. No credit card. No call required.

Create your workspace →

or read the security model first →