[ The Kortave Brief ]
EU Compliance Intelligence
Analysis, guides, and regulatory updates from the Kortave compliance team.
Every AI Tool Your Company Uses Is a GDPR Liability — Most Legal Teams Have Not Noticed Yet
Microsoft Copilot, ChatGPT Enterprise, and their equivalents process employee and client data at scale. Without DPAs, ROPAs entries, and transfer impact assessments in place, you are already non-compliant.
NIS2 in Practice: What a Compliant Incident Response Actually Looks Like
NIS2 has a 24-hour early warning requirement, a 72-hour notification, and a 1-month final report. Most companies discover their incident response process does not trigger fast enough. Here is what it needs to look like.
The Cyber Resilience Act: What Product Companies Must Do Before December 2027
The CRA makes cybersecurity a legal obligation for any hardware or software product sold in the EU. Here is what manufacturers and developers need to know — and do.
EU Data Act: What Changes for IoT Manufacturers and Cloud Providers in 2025
The EU Data Act applies from September 2025. It gives users the right to access device-generated data, requires fair B2B data-sharing terms, and reshapes cloud switching rules.
Cookie Consent in 2025: What ePrivacy Requires and Where Companies Are Still Getting It Wrong
Cookie consent fines exceeded €500M across the EU in the past two years. Most violations share the same root cause: ignoring what "freely given" consent actually means.
DORA Is Already in Force. Your ICT Contracts Probably Are Not Ready.
DORA's contractual requirements for ICT third-party arrangements are specific, mandatory, and not optional by agreement. Most financial firms are behind.
DGA and DSA: Two EU Laws That Are Already in Force and Still Widely Misunderstood
The Data Governance Act and Digital Services Act are both fully applicable. Here is what each law requires, who is in scope, and the enforcement actions you need to know about.
NIS2 Is Being Enforced. Here Is Who Is Actually Liable.
NIS2's management liability provision is the provision most companies have not read. Directors can be personally fined and temporarily banned from management roles.
GDPR in 2025: The Five Things SaaS Companies Keep Getting Wrong
Fines are up 143% year-on-year. Most of them trace back to the same five operational failures — none of which require a lawyer to fix.
EU AI Act Compliance: Your Checklist Before the August 2026 Deadline
High-risk AI obligations land in full on 2 August 2026. Most companies affected haven't started. Here's exactly what you need to have in place.
GDPR Data Transfers in 2025: What SCCs Actually Require You to Do
Standard Contractual Clauses are not a checkbox. They require a Transfer Impact Assessment before you sign them. Most companies skip this step entirely.
The EU AI Act and Foundation Models: What GPAI Compliance Actually Looks Like
General Purpose AI obligations under the AI Act apply to any model that can be used across multiple purposes. Most companies using LLM APIs are deployers, not providers — but the distinction matters.
NIS2 Is Being Enforced. Here's What Most Companies Haven't Done Yet.
The NIS2 Directive has been national law across most EU member states since late 2024. Supervisory authorities are already investigating. The gaps they're finding are predictable.
The EU AI Act: A Complete Guide to the World's First AI Regulation
History, risk tiers, high-risk AI obligations, GPAI model requirements, and key enforcement dates. Everything a business needs to know about the EU AI Act.
The General Data Protection Regulation: A Complete Guide for Businesses
Where GDPR came from, who it applies to, what the core principles mean in practice, and what it actually requires your organisation to do.
Your GDPR Deletion Backlog Is Your Biggest Legal Risk Right Now
Most companies know they have unprocessed erasure requests. Very few understand how their exposure compounds with each passing day — or how quickly it becomes a material fine.
NIS2 and DORA: The EU's Cybersecurity and Resilience Regulations Explained
NIS2 is enforced and management liability is real. DORA has been in force since January 2025. A comprehensive guide to both regulations — scope, obligations, and what to do.
Stay ahead of enforcement
Get our latest compliance analysis delivered to your inbox. No noise, just signal.