Compliance guides
The regulations that matter, explained simply.
A reviewed orientation set for public laws and standards: what each instrument is, why it can matter operationally, and where to read the authority.
Current guides
AI governance 1
Cybersecurity 1
Data protection 2
Data protection
GDPR
The EU framework for protecting personal data and governing how organisations process it.
European UnionData protection
HIPAA
US federal privacy, security and breach-notification rules for covered entities and business associates handling protected health information.
United StatesDigital & platforms 1
ESG & supply chain 4
ESG & supply chain
CSDDD
EU rules for in-scope companies to address human-rights and environmental impacts in their chains of activities.
European UnionESG & supply chain
CSRD
EU rules for standardised corporate sustainability reporting, assurance and digital disclosure.
European UnionESG & supply chain
EUDR
EU due-diligence rules for specified commodities and products associated with deforestation and forest degradation.
European UnionESG & supply chain
Modern Slavery Act
UK legislation that includes transparency-in-supply-chains reporting for organisations meeting the statutory conditions.
United KingdomEmployment & HR 1
Environmental 1
Financial crime 1
Financial services 4
Financial services
DORA
The EU operational-resilience framework for in-scope financial entities and their ICT risk.
European UnionFinancial services
MiCA
EU rules for crypto-asset issuers and service providers, including authorisation and conduct requirements.
European UnionFinancial services
MiFID II
EU rules for investment firms and trading venues, market structure, conduct and investor protection.
European UnionFinancial services
PSD2
EU rules for payment services, account access, customer protection and strong customer authentication.
European UnionGovernance 1
Health & safety 1
Information security 3
Information security
ISO 27001
An international requirements standard for establishing and improving an information security management system.
International standardInformation security
PCI DSS
An industry security standard for organisations that store, process or transmit payment-card account data.
Global industry standardInformation security
SOC 2
An independent attestation framework for controls at service organisations against selected Trust Services Criteria.
United States / AICPAQuality management 1
Sustainable finance 2
Sustainable finance
EU Taxonomy
The EU classification system for determining when economic activities qualify as environmentally sustainable.
European UnionSustainable finance
SFDR
EU disclosure rules for how financial-market participants and advisers address sustainability risks and impacts.
European UnionIn-depth regulatory briefings
Long-form, source-led analysis maintained by the Saga editorial team.
CBAM — Carbon Border Adjustment Mechanism
A source-led guide to CBAM scope, the 50-tonne threshold, authorised declarants, emissions, certificates, and the definitive regime.
European Accessibility Act: scope and digital-service duties
A practical guide to European Accessibility Act scope, e-commerce duties, microenterprise relief, Swedish enforcement, and transition rules.
EU Battery Regulation: 2026 compliance guide
A practical guide to EU Battery Regulation scope, carbon-footprint rules, recycled content, due diligence, battery passports, producer duties, and deadlines.
EU Cyber Resilience Act (CRA)
A practical 2026 briefing on CRA scope, SaaS and remote processing, reporting deadlines, support periods, and the 2027 compliance date.
EU Data Act: cloud switching and SaaS obligations
A practical 2026 guide to EU Data Act cloud-switching duties for SaaS, contract terms, export rules, fees, exemptions, and key dates.
Comparisons
Regimes that are routinely confused — or must be reconciled — set side by side.
NIS2 vs DORA
How the EU’s two cybersecurity regimes divide the territory: who each covers, whose incident clocks apply, and what happens when a group falls under both.
CSRD vs CSDDD
CSRD requires audited sustainability reporting; CSDDD requires action on human-rights and environmental impacts. Compare their scope, duties and dates.
ISO 27001 vs SOC 2
Compare ISO 27001 certification with SOC 2 attestation: what each proves, who requests it, audit cadence, and how one control set can support both.
GDPR vs AI Act
Compare personal-data duties with role- and risk-based AI duties, and see why one AI system can owe both.
GDPR vs NIS2
Compare protected interests, incident triggers, clocks, recipients, and the events that require both reports.
DORA vs ISO 27001
How a voluntary information-security management system supports—but cannot replace—DORA compliance.
NIS2 vs ISO 27001
Compare NIS2’s statutory cyber duties with an ISO 27001 management system and certification boundary.
CSRD vs SFDR
Compare corporate sustainability reporting with disclosures made by financial-market participants and advisers.
CSRD vs EU Taxonomy
How ESRS sustainability reporting relates to taxonomy eligibility, alignment, safeguards, and KPIs.
EUDR vs CSDDD
Compare product-specific deforestation due diligence with broader human-rights and environmental due diligence.
DSA vs GDPR
Compare online intermediary duties with personal-data duties across moderation, advertising, recommendations, and user rights.
MiCA vs MiFID II
Why classification comes first when a token or service may sit under crypto or traditional securities law.
EU AML vs MiCA
Compare crypto authorisation and customer protection with anti-money-laundering risk, customer due diligence, and reporting.
Whistleblowing vs GDPR
Reconcile protected reporting, restricted case access, investigation, retention, notices, and data-subject rights.
ISO 9001 vs ISO 27001
Compare quality and information-security management systems, their risks, controls, audits, and opportunities for one integrated system.
These guides are general information about public law, not legal advice. Requirements depend on the organisation and situation. Verify the current official source and obtain qualified advice where needed.