Compliance guides

The regulations that matter, explained simply.

A reviewed orientation set for public laws and standards: what each instrument is, why it can matter operationally, and where to read the authority.

29 available guides 14 categories Authority links on every guide No legal advice Glossary: 58 terms defined

Current guides

AI governance 1

Cybersecurity 1

Data protection 2

Digital & platforms 1

ESG & supply chain 4

Employment & HR 1

Environmental 1

Financial crime 1

Financial services 4

Governance 1

Health & safety 1

Information security 3

Quality management 1

Sustainable finance 2

In-depth regulatory briefings

Long-form, source-led analysis maintained by the Saga editorial team.

Comparisons

Regimes that are routinely confused — or must be reconciled — set side by side.

NIS2 vs DORA

How the EU’s two cybersecurity regimes divide the territory: who each covers, whose incident clocks apply, and what happens when a group falls under both.

CSRD vs CSDDD

CSRD requires audited sustainability reporting; CSDDD requires action on human-rights and environmental impacts. Compare their scope, duties and dates.

ISO 27001 vs SOC 2

Compare ISO 27001 certification with SOC 2 attestation: what each proves, who requests it, audit cadence, and how one control set can support both.

GDPR vs AI Act

Compare personal-data duties with role- and risk-based AI duties, and see why one AI system can owe both.

GDPR vs NIS2

Compare protected interests, incident triggers, clocks, recipients, and the events that require both reports.

DORA vs ISO 27001

How a voluntary information-security management system supports—but cannot replace—DORA compliance.

NIS2 vs ISO 27001

Compare NIS2’s statutory cyber duties with an ISO 27001 management system and certification boundary.

CSRD vs SFDR

Compare corporate sustainability reporting with disclosures made by financial-market participants and advisers.

CSRD vs EU Taxonomy

How ESRS sustainability reporting relates to taxonomy eligibility, alignment, safeguards, and KPIs.

EUDR vs CSDDD

Compare product-specific deforestation due diligence with broader human-rights and environmental due diligence.

DSA vs GDPR

Compare online intermediary duties with personal-data duties across moderation, advertising, recommendations, and user rights.

MiCA vs MiFID II

Why classification comes first when a token or service may sit under crypto or traditional securities law.

EU AML vs MiCA

Compare crypto authorisation and customer protection with anti-money-laundering risk, customer due diligence, and reporting.

Whistleblowing vs GDPR

Reconcile protected reporting, restricted case access, investigation, retention, notices, and data-subject rights.

ISO 9001 vs ISO 27001

Compare quality and information-security management systems, their risks, controls, audits, and opportunities for one integrated system.

These guides are general information about public law, not legal advice. Requirements depend on the organisation and situation. Verify the current official source and obtain qualified advice where needed.