GDPR
The foundation: legal bases, data-subject rights, security obligations, and international transfer rules. Every other text on this page assumes GDPR is already in place.
Articles / EU Regulatory Map
A working map of the regulations and standards shaping data governance in Europe today: the transversal baseline, the sector-specific layers, and the professional frameworks behind them.
The regulatory perimeter around data governance keeps widening. Ten years ago, GDPR was close to the whole story. Today a governance lead also has to track how AI is regulated, how cybersecurity obligations reshape data classification and access control, and how sector rules — banking, energy — stack a second layer on top. This is the map I keep for myself, kept current as texts move: several deadlines below shifted again in 2026.
Six texts that apply regardless of sector, the moment an organisation processes personal data, runs critical systems, or deploys AI.
The foundation: legal bases, data-subject rights, security obligations, and international transfer rules. Every other text on this page assumes GDPR is already in place.
Regulates AI systems by risk tier. Prohibited practices and general-purpose AI obligations already apply; high-risk obligations were pushed back again in June 2026 — to December 2027 for standalone systems, August 2028 for product-embedded ones.
Cybersecurity risk management and incident reporting across 18 essential and important sectors, transposed in Belgium by the law of 26 April 2024.
Gives users access to data generated by their connected products, removes cloud-switching barriers, and sets fairness rules for B2B/B2G data sharing.
A framework for data-sharing intermediaries, data altruism, and the reuse of public-sector data.
Security-by-design requirements for products with digital elements. Vulnerability-reporting duties take effect on 11 September 2026; the full regime follows in December 2027.
Two sectors where a second regulatory layer sits on top of the baseline above.
NIS2's counterpart for the financial sector: ICT risk management, resilience testing, and oversight of critical third-party providers, including cloud.
Principles for risk data aggregation and reporting — accuracy, completeness, adaptability, governance. Not law, but close to a de facto requirement in banking data governance.
The overhaul of the payment services directive — open banking, fraud, payment-data access — still moving through EU institutions as of late 2026.
Energy is one of NIS2's "highly critical" sectors — the same risk-management and incident-reporting duties as any other essential entity, just under heavier scrutiny.
NIS2's physical-resilience counterpart for critical entities — energy, water, transport — covering asset mapping and operational continuity rather than cybersecurity.
None of these are legally binding, but they're what recruiters and auditors actually expect you to speak fluently.
Applies ISO 38500's IT-governance model directly to data: roles, accountability, and risk evaluation for data governance.
Data-quality standards covering syntactic and semantic accuracy, provenance, and quality-assured data exchange between systems.
The Data Management Body of Knowledge — not a standard, but the closest thing the profession has to a shared vocabulary across its eleven functions: quality, MDM, metadata, architecture, and more.
The first management-system standard for AI, modelled on ISO 27001: governance, lifecycle, and risk management for AI systems — the AI Act's management-system counterpart.
27001 covers information-security management — one of Belgium's three recognised NIS2 compliance routes. 27701 extends it to privacy, aligned with GDPR.
Other sectors carry their own layer too — healthcare has the European Health Data Space, insurance has Solvency II. Rather than covering all of them upfront, the useful habit in an interview is to ask which sector-specific framework sits on top of GDPR and NIS2 at that particular employer.
Working reference, not legal advice — dates and scopes shift; the AI Act's high-risk deadline alone moved twice in 2026. Confirm specifics with official sources before making a compliance decision.