Articles / EU Regulatory Map

Data Governance — The EU Regulatory Map

A working map of the regulations and standards shaping data governance in Europe today: the transversal baseline, the sector-specific layers, and the professional frameworks behind them.

Diagram connecting GDPR, the AI Act, NIS2, the Data Act, DORA and ISO standards around a central data governance node

The regulatory perimeter around data governance keeps widening. Ten years ago, GDPR was close to the whole story. Today a governance lead also has to track how AI is regulated, how cybersecurity obligations reshape data classification and access control, and how sector rules — banking, energy — stack a second layer on top. This is the map I keep for myself, kept current as texts move: several deadlines below shifted again in 2026.

The transversal baseline

Six texts that apply regardless of sector, the moment an organisation processes personal data, runs critical systems, or deploys AI.

Regulation (EU) 2016/679 · in force since 2018

GDPR

The foundation: legal bases, data-subject rights, security obligations, and international transfer rules. Every other text on this page assumes GDPR is already in place.

Regulation (EU) 2024/1689 · phased 2024–2028

AI Act

Regulates AI systems by risk tier. Prohibited practices and general-purpose AI obligations already apply; high-risk obligations were pushed back again in June 2026 — to December 2027 for standalone systems, August 2028 for product-embedded ones.

Directive (EU) 2022/2555 · BE deadline April 2026

NIS2

Cybersecurity risk management and incident reporting across 18 essential and important sectors, transposed in Belgium by the law of 26 April 2024.

Regulation (EU) 2023/2854 · applicable since Sept 2025

Data Act

Gives users access to data generated by their connected products, removes cloud-switching barriers, and sets fairness rules for B2B/B2G data sharing.

Regulation (EU) 2022/868 · applicable since Sept 2023

Data Governance Act

A framework for data-sharing intermediaries, data altruism, and the reuse of public-sector data.

Regulation (EU) 2024/2847 · reporting from Sept 2026

Cyber Resilience Act

Security-by-design requirements for products with digital elements. Vulnerability-reporting duties take effect on 11 September 2026; the full regime follows in December 2027.

Sector layers

Two sectors where a second regulatory layer sits on top of the baseline above.

Banking & finance · Regulation (EU) 2022/2554 · applicable since Jan 2025

DORA

NIS2's counterpart for the financial sector: ICT risk management, resilience testing, and oversight of critical third-party providers, including cloud.

Banking & finance · Basel Committee principles · since 2013

BCBS 239

Principles for risk data aggregation and reporting — accuracy, completeness, adaptability, governance. Not law, but close to a de facto requirement in banking data governance.

Banking & finance · in the legislative pipeline

PSD3 / PSR

The overhaul of the payment services directive — open banking, fraud, payment-data access — still moving through EU institutions as of late 2026.

Energy · same directive as above

NIS2 for energy operators

Energy is one of NIS2's "highly critical" sectors — the same risk-management and incident-reporting duties as any other essential entity, just under heavier scrutiny.

Energy · Directive (EU) 2022/2557 · BE transposition in progress

CER Directive

NIS2's physical-resilience counterpart for critical entities — energy, water, transport — covering asset mapping and operational continuity rather than cybersecurity.

Frameworks behind the law

None of these are legally binding, but they're what recruiters and auditors actually expect you to speak fluently.

Standard · 2017

ISO/IEC 38505

Applies ISO 38500's IT-governance model directly to data: roles, accountability, and risk evaluation for data governance.

Standard series · data quality

ISO 8000

Data-quality standards covering syntactic and semantic accuracy, provenance, and quality-assured data exchange between systems.

De facto industry reference

DAMA-DMBOK

The Data Management Body of Knowledge — not a standard, but the closest thing the profession has to a shared vocabulary across its eleven functions: quality, MDM, metadata, architecture, and more.

Standard · 2023

ISO/IEC 42001

The first management-system standard for AI, modelled on ISO 27001: governance, lifecycle, and risk management for AI systems — the AI Act's management-system counterpart.

Standards · security & privacy

ISO/IEC 27001 & 27701

27001 covers information-security management — one of Belgium's three recognised NIS2 compliance routes. 27701 extends it to privacy, aligned with GDPR.

Other sectors carry their own layer too — healthcare has the European Health Data Space, insurance has Solvency II. Rather than covering all of them upfront, the useful habit in an interview is to ask which sector-specific framework sits on top of GDPR and NIS2 at that particular employer.

Further reading

Working reference, not legal advice — dates and scopes shift; the AI Act's high-risk deadline alone moved twice in 2026. Confirm specifics with official sources before making a compliance decision.