Reference

The compliance legislation library

Every framework we cover, explained in plain language and linked to the official source. Browse the articles and obligations behind the requirements.

EU AI Act

19 articles

Regulation (EU) 2024/1689 on artificial intelligence

The EU Artificial Intelligence Act is the world's first comprehensive AI law. It classifies AI systems by risk and sets obligations for providers and deployers of high-risk systems, from risk management and data governance to human oversight, transparency, and post-market monitoring.

Browse EU AI Act →

GDPR

8 articles

Regulation (EU) 2016/679 on data protection

The General Data Protection Regulation governs how personal data of people in the EU is collected, processed, and protected. It sets out lawful bases, data subject rights, breach notification duties, and the accountability obligations organisations must be able to demonstrate.

Browse GDPR →

UK GDPR

6 articles

UK data protection after Brexit

The UK GDPR is the United Kingdom's version of the GDPR, retained in domestic law alongside the Data Protection Act 2018. It mirrors the EU regime closely while being enforced by the ICO under UK jurisdiction.

Browse UK GDPR →

CCPA

9 sections

California Consumer Privacy Act (as amended by the CPRA)

The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over the personal information businesses collect about them, including the right to know, delete, correct, and opt out of sale or sharing.

Browse CCPA →

ISO 42001

13 clauses

ISO/IEC 42001 AI management system

ISO/IEC 42001 is the international standard for an Artificial Intelligence Management System (AIMS). It provides a certifiable framework for governing AI responsibly across its lifecycle, covering leadership, planning, controls, and continual improvement.

Browse ISO 42001 →

NIST AI RMF

13 subcategorys

NIST AI Risk Management Framework

The NIST AI Risk Management Framework is a voluntary US framework for managing risks from AI systems. It is organised around four functions, Govern, Map, Measure, and Manage, to help organisations build trustworthy and responsible AI.

Browse NIST AI RMF →

DORA

13 articles

Digital Operational Resilience Act

The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems across EU financial entities and their critical ICT third-party providers, covering ICT risk management, incident reporting, resilience testing, and supplier oversight.

Browse DORA →

NIS2

5 articles

Directive (EU) 2022/2555 on cybersecurity

The NIS2 Directive strengthens cybersecurity across essential and important entities in the EU. It raises risk-management, governance, and incident-reporting requirements and holds management bodies accountable for compliance.

Browse NIS2 →

ISO 27001

10 clauses

ISO/IEC 27001 information security management

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It defines requirements for establishing, maintaining, and continually improving information security, backed by the Annex A control set.

Browse ISO 27001 →

ISO 23894

5 clauses

ISO/IEC 23894 AI risk management guidance

ISO/IEC 23894 provides guidance on managing risk specific to AI, aligning the ISO 31000 risk management process with the particular challenges of developing and using artificial intelligence.

Browse ISO 23894 →

Reading the law is the easy part

eurocompliant turns these obligations into tracked tasks, evidence, and regulator-ready documents across every framework at once.

Start free trial