Reference
The compliance legislation library
Every framework we cover, explained in plain language and linked to the official source. Browse the articles and obligations behind the requirements.
EU AI Act
19 articlesRegulation (EU) 2024/1689 on artificial intelligence
The EU Artificial Intelligence Act is the world's first comprehensive AI law. It classifies AI systems by risk and sets obligations for providers and deployers of high-risk systems, from risk management and data governance to human oversight, transparency, and post-market monitoring.
Browse EU AI Act →GDPR
8 articlesRegulation (EU) 2016/679 on data protection
The General Data Protection Regulation governs how personal data of people in the EU is collected, processed, and protected. It sets out lawful bases, data subject rights, breach notification duties, and the accountability obligations organisations must be able to demonstrate.
Browse GDPR →UK GDPR
6 articlesUK data protection after Brexit
The UK GDPR is the United Kingdom's version of the GDPR, retained in domestic law alongside the Data Protection Act 2018. It mirrors the EU regime closely while being enforced by the ICO under UK jurisdiction.
Browse UK GDPR →CCPA
9 sectionsCalifornia Consumer Privacy Act (as amended by the CPRA)
The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over the personal information businesses collect about them, including the right to know, delete, correct, and opt out of sale or sharing.
Browse CCPA →ISO 42001
13 clausesISO/IEC 42001 AI management system
ISO/IEC 42001 is the international standard for an Artificial Intelligence Management System (AIMS). It provides a certifiable framework for governing AI responsibly across its lifecycle, covering leadership, planning, controls, and continual improvement.
Browse ISO 42001 →NIST AI RMF
13 subcategorysNIST AI Risk Management Framework
The NIST AI Risk Management Framework is a voluntary US framework for managing risks from AI systems. It is organised around four functions, Govern, Map, Measure, and Manage, to help organisations build trustworthy and responsible AI.
Browse NIST AI RMF →DORA
13 articlesDigital Operational Resilience Act
The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems across EU financial entities and their critical ICT third-party providers, covering ICT risk management, incident reporting, resilience testing, and supplier oversight.
Browse DORA →NIS2
5 articlesDirective (EU) 2022/2555 on cybersecurity
The NIS2 Directive strengthens cybersecurity across essential and important entities in the EU. It raises risk-management, governance, and incident-reporting requirements and holds management bodies accountable for compliance.
Browse NIS2 →ISO 27001
10 clausesISO/IEC 27001 information security management
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It defines requirements for establishing, maintaining, and continually improving information security, backed by the Annex A control set.
Browse ISO 27001 →ISO 23894
5 clausesISO/IEC 23894 AI risk management guidance
ISO/IEC 23894 provides guidance on managing risk specific to AI, aligning the ISO 31000 risk management process with the particular challenges of developing and using artificial intelligence.
Browse ISO 23894 →Reading the law is the easy part
eurocompliant turns these obligations into tracked tasks, evidence, and regulator-ready documents across every framework at once.
Start free trial