Support
EU institutions and national supervisory authorities relevant to the compliance function, by regulatory domain.
European Commission: proposes and enforces EU law, and supervises very large online platforms under the DSA and gatekeepers under the DMA;
European Data Protection Board (EDPB): ensures the consistent application of the GDPR and issues guidelines;
European Data Protection Supervisor (EDPS): supervises the EU institutions and bodies;
ENISA: the EU Agency for Cybersecurity, supporting the implementation of NIS2;
European AI Office: supervises general-purpose AI models under the AI Act;
AMLA: the EU Anti-Money Laundering Authority, based in Frankfurt;
EBA, ESMA and EIOPA: the European Supervisory Authorities, including oversight of critical ICT providers under DORA;
OLAF and the European Public Prosecutor's Office: fraud and corruption affecting the EU budget.
CNPD: data protection;
CNCS: national cybersecurity authority under the Cybersecurity Legal Regime;
MENAC: National Anti-Corruption Mechanism, supervising the RGPC;
Banco de Portugal, CMVM and ASF: financial supervision, including DORA and AML for their supervised entities;
ANACOM: electronic communications and Digital Services Coordinator under the DSA;
AEPD: data protection;
INCIBE: national cybersecurity institute;
SEPBLAC: financial intelligence unit and AML supervisor;
Independent Authority for the Protection of Whistleblowers (A.A.I.): created by Law 2/2023.
For other Member States, we identify the competent authorities as part of each Compliance Assessment.
Competences are summarised and may vary by sector and Member State. Confirm the competent authority for each case.