← All services Our services

European software regulation

GDPR and the AI Act are not the only laws that touch your software. Depending on what you build and for whom, NIS2, the Cyber Resilience Act, the accessibility directives, the Data Act or DORA apply too. I work out which ones apply to you and what has to happen next.

The hard part about these laws is not the text, it is knowing which ones apply. A webshop faces different rules than a healthcare app or a banking integration. I work from a fixed questionnaire that decides per law whether you fall under it. Only then do we look at the articles that actually matter, which saves months of reading. Amending acts count too: in July 2026 the Digital Omnibus amended both the AI Act and the Machinery Regulation, and the EHDS Regulation amended the Cyber Resilience Act. Changes like that only reach the consolidated EUR-Lex texts months later.

What you get

Applicability scan: which European and Dutch laws genuinely touch your software Security and reporting duties: NIS2, the Dutch Wbni and the Cyber Resilience Act Accessibility: the European Accessibility Act for webshops and services, WCAG for public-sector sites Cookies and tracking under the ePrivacy Directive and its national implementation Data, platforms and identity: Data Act, DSA, eIDAS and product liability Health data: the EHDS Regulation for applications handling health records

Priced per case. The applicability scan is a short engagement at a fixed price. What follows depends on how many laws turn out to apply, so you get the scan first and a proposal for the rest afterwards.

Does your AI fall under the EU AI Act?

Free · 10 questions · 3 minutes

Start the quickscan →
European software regulation

Questions and answers about this service

Which European laws apply to software?

That depends on what you build and for whom. Besides the GDPR and the EU AI Act, laws that may apply include NIS2 and its national implementation, the Cyber Resilience Act, the European Accessibility Act, the ePrivacy rules on cookies, the Data Act, the DSA, eIDAS, product liability, DORA and, for health apps, the EHDS Regulation. Using a fixed questionnaire I determine per law whether you fall under it.

Who is the applicability scan for?

For organisations that build, sell or offer software as a service. A webshop faces different rules than a health app, a SaaS product or a banking integration. The scan makes clear which laws apply to your software before you spend months in legal texts.

How does the applicability scan work?

It is a short engagement at a fixed price that determines per law whether you fall under it. Only then do we look at the articles that matter for you and you get a proposal for what needs to happen. How much work that is depends on how many laws turn out to apply.

Do amendments to laws count?

Yes. In July 2026 the Digital Omnibus amended both the EU AI Act and the Machinery Regulation, and the EHDS Regulation amended the Cyber Resilience Act. Changes like that often reach the consolidated texts on EUR-Lex only months later, so I work from the amending acts themselves.

What does this have to do with security?

NIS2 and the Cyber Resilience Act require that your security and reporting duties are demonstrably in order. A penetration test provides evidence for that: findings can be mapped to NIS2, ISO 27001, OWASP and the GDPR, so you can use them in an audit file.

Thinking along, arranging it, staying inside the law

Three things that don't fit in a service list, but that decide how working with me feels.

I think along with you

You're not hiring a pair of hands that builds whatever the brief says. If I think your question isn't your real problem, I'll say so. Often there's a simpler or cheaper route, and sometimes the answer is that you shouldn't build this yet. Sparring over that choice is part of the work.

You don't have to figure it out

I run the whole track: choice of technology, the build, integrations with your existing systems, testing with real cases, explaining it to your team and maintenance afterwards. One point of contact, and one person responsible when something breaks. No vendors pointing at each other.

Compliant, and provably so

Everything I build has to survive current legislation: GDPR, the EU AI Act and the Data Act. That means agreeing up front which data the system may see, where it is processed, retention periods, a data processing agreement and a log of what the system did. So you can explain it when somebody asks.

Other services

AI voice agents and telephony

An agent that answers the phone after hours, at peak moments and when everyone is already on a call. It recognises why someone is calling, books an appointment in your calendar, transfers when unsure and emails you the rest.

View this service →

Process automation

The work nobody enjoys: retyping invoices, moving data from system A to system B, producing the same report every Monday. I map the steps and build the chain that runs without you.

View this service →

Custom software, SaaS & AI assistants

For when off-the-shelf doesn't fit: a portal, an internal tool, or an assistant that answers from your own documents and data. Built around your way of working, not a vendor's.

View this service →

AI audit & AI training

The cheapest way to start. I come to you, and afterwards you get a report with the processes that return the most, what each costs, what it saves and what goes wrong if you approach it badly. I also run AI training for teams: what the technology can and cannot do, how to use it safely, and where the gains sit in your own work.

View this service →

GDPR & privacy in order

Mapping what happens to personal data and delivering the documents you need to be able to show: a record of processing activities, a DPIA where one is required, processor agreements and a working method for data breaches and data subject requests.

View this service →

EU AI Act: from scan to dossier

For anyone using AI or shipping AI inside their own product. We determine per system which risk category it falls into, which role you hold and what that means in obligations. Then we build the dossier that goes with it.

View this service →

Penetration testing and security testing

I attack your own software with your written permission, looking for what an attacker would find: logging in without the right password, reaching another customer's data, changing an amount in an order. Whatever works, you get on paper with the evidence attached and with the check that proves later on that it is really closed.

View this service →

Ready to see what's being left on the table?

Book a free thirty-minute call. You'll get an honest answer, even when that answer is “don't do this yet”.

Book your free intro call → Free · 30 minutes · no obligations