What’s changing in EU SaaS regulation, in plain language.
A quarterly update on the laws and rulings that affect vendor selection
for European companies. Updated .
Next update .
United States · 2018IN FORCE
CLOUD Act
What it is
The Clarifying Lawful Overseas Use of Data Act allows US federal authorities to compel US-incorporated companies to disclose data they hold, regardless of where the data physically resides. Active and routinely invoked.
What it means for you
Any US-jurisdictional vendor in your stack — including subsidiaries — is exposed. EU data residency does not provide legal protection. Your DPIA and procurement criteria should reflect this. Read our explainer.
Status as of
EU · CJEU pipelinePENDING
Schrems III (anticipated)
What it is
A successor to Schrems II is widely expected to test the validity of the EU-US Data Privacy Framework (DPF) of 2023. Industry observers expect a ruling within 18-24 months. Outcome could invalidate DPF-based transfers to US providers.
What it means for you
If your vendor strategy depends on DPF for US-bound transfers, you should already have a contingency for invalidation. Sovereign-EU vendors are the contingency that doesn’t require re-architecting after the ruling lands.
Status as of
EU · 2024 transpositionIN FORCE
NIS2 Directive
What it is
NIS2 (the EU Network and Information Security Directive 2.0) requires essential and important entities to implement cybersecurity risk management measures and report incidents. Vendor-supply-chain risk is explicit in scope.
What it means for you
NIS2-covered customers must evaluate their supply-chain (which includes their SaaS vendors). Procurement criteria around vendor-incident reporting, audit rights, and security architecture have hardened. The compliance benefit of a sovereign-EU vendor is structural here, not just legal.
Status as of
EU · effective 2025-01-17IN FORCE
DORA
What it is
The Digital Operational Resilience Act applies to financial-services entities and their critical-third-party ICT providers. Establishes registries of critical providers, mandatory contractual clauses, and supervisory oversight.
What it means for you
Financial-services customers in scope must have DORA-compliant contracts with their SaaS providers. We support the standard DORA clauses (audit rights, exit assistance, incident notification timelines) on Enterprise tier — self-serve. Critical-third-party designation is a question for the regulator, not the vendor.
Status as of
EU · long-running negotiationPENDING
ePrivacy Regulation
What it is
The proposed successor to the ePrivacy Directive has been in negotiation since 2017. Coverage would extend to electronic communications including OTT services. Member-state disagreements continue to block adoption.
What it means for you
If adopted, ePrivacy Regulation would constrain certain analytics and cookie practices more tightly than GDPR alone. Vendors using no-cookie analytics (us, via Plausible) are positioned to comply without architectural changes. Vendors using third-party tracking would face operational changes.
Status as of
Our commitment
We update this page quarterly. If a major regulation changes status, ruling, or
trajectory, we update sooner. Past versions are tracked via the
changelog.
The point of this page is not to scare you into using us. The point is to give
European procurement teams a current-state read on the regulatory environment so
vendor decisions can be made with eyes open. If we got something wrong or out of
date, email hi@omniteam.eu and we’ll
correct on the next quarterly update.