[ DECISION GUIDE ]
A compliance hire, a consultancy, or Kortave?
Every EU company that processes personal data, ships software, or touches AI has the same three options for getting compliant. They differ by roughly two orders of magnitude in cost. This page lays out the honest trade-offs, including when Kortave is not the right answer.
Context for the timeline: the EU AI Act's main obligations apply from 2 August 2026. DORA has applied to financial entities since January 2025. GDPR enforcement has been running since 2018, with fines up to €20 million or 4% of global turnover.
| In-house compliance hire | Consultancy | Kortave | |
|---|---|---|---|
| Upfront cost | €60,000–90,000 / year salary | €10,000–50,000 per project | From €99 / month, no setup fee |
| Time to first documents | 2–4 months (hiring + ramp-up) | 4–12 weeks per engagement | Days |
| Regulations covered | Depends on the individual | Scoped per contract | All nine frameworks: GDPR, AI Act, NIS2, DORA, CRA, Data Act, DGA, DSA, ePrivacy |
| When the law changes | Covered, if they keep up | New engagement, new invoice | Documents updated continuously, included |
| Who does the work | One person, single point of failure | External team, then they leave | AI drafting + specialist review, always on |
| Scales with growth | Needs a second hire eventually | Costs scale linearly | Same subscription |
| Best for | Large-scale / high-risk processing | One-off complex matters, audits | SMEs needing complete, maintained documentation |
When Kortave is not the right choice
If GDPR Article 37 obliges you to appoint a Data Protection Officer — public authorities, large-scale systematic monitoring, or large-scale special-category data processing — you need the designated officer, and software does not substitute for that role. Kortave can still produce the documentation your DPO works from, but the appointment itself is yours to make.
If you are in active litigation, under an open supervisory investigation, or facing a genuinely novel legal question, you need a qualified lawyer, not a documentation platform. Kortave is a software service and does not provide legal advice.
For everyone else — the thousands of EU companies between 20 and 500 people with no compliance function and a stack of regulatory deadlines — the comparison above is the honest picture: the same deliverables, a fraction of the cost, maintained continuously.
See what the output actually looks like
Two complete, unredacted example deliverables — a GDPR Article 30 record and an EU AI Act Annex IV technical file.