Support

Frequently Asked Questions

Short, well-founded answers to the questions we hear most often from EU organisations.

Questions & answers

What organisations ask us

Is my organisation in scope of NIS2?

It depends on the sector and size of the organisation. NIS2 covers medium-sized and large entities in the sectors listed in its two annexes, and certain entities regardless of size. Obligations arise from each national transposing law, such as Decree-Law 125/2025 in Portugal. A Compliance Assessment determines whether you are an essential or an important entity, and which obligations apply. See Cybersecurity (NIS2).

Do we need an internal whistleblowing channel?

Under Directive (EU) 2019/1937, private entities with 50 or more workers and public-sector entities must have internal reporting channels, subject to the exemptions some Member States allow for small municipalities and entities. Reports must be acknowledged within seven days and followed up with feedback within three months. See Whistleblower Protection.

What changed in the AI Act in 2026?

Regulation (EU) 2026/1744, in force since 27 July 2026, postponed the high-risk obligations to 2 December 2027 for Annex III systems and to 2 August 2028 for systems embedded in regulated products. Prohibitions, AI literacy and the rules on general-purpose AI already apply, and the transparency obligations of Article 50 apply from 2 August 2026. See Artificial Intelligence.

Do we have to appoint a Data Protection Officer?

Yes, if you are a public authority or body, or if your core activities involve large-scale regular and systematic monitoring or large-scale processing of special categories of data (GDPR, Article 37). Other organisations may appoint one voluntarily. The role can be performed under a service contract. See Data Protection.

What does the new EU AML Regulation change, and when?

From 10 July 2027, Regulation (EU) 2024/1624 largely harmonises national rules through a single EU rulebook, while Directive (EU) 2024/1640 is transposed nationally for supervision and registers. The Regulation requires a member of the management body to be responsible for compliance and a compliance officer of sufficient seniority, and sets a EUR 10,000 limit on cash payments. AMLA will directly supervise selected institutions from 2028. See Anti-Money Laundering.

Is there now an EU law on corruption?

Yes. Directive (EU) 2026/1021 on combating corruption was published in May 2026 and must be transposed by 1 June 2028. It harmonises offences, establishes the liability of legal persons and treats effective compliance programmes as a mitigating factor. National regimes, such as Portugal's RGPC, already require compliance programmes. See Anti-Corruption.

Does the CSRD still apply to us after Omnibus I?

Following Directive (EU) 2026/470, CSRD reporting applies to EU companies with more than 1,000 employees and more than EUR 450 million in turnover, and to certain non-EU groups. Smaller companies are outside the mandatory scope but will continue to receive requests from customers and banks. See Sustainability.

When are the first gender pay gap reports due?

Under Directive (EU) 2023/970, employers with 150 or more workers must report by 7 June 2027, and employers with 100 to 149 workers by 7 June 2031. National laws may set lower thresholds. See Pay Transparency.

Can the Compliance Officer be external?

In many cases, yes. The fractional model provides an experienced, independent Compliance Officer on retainer and is well suited to SMEs and public bodies. Some roles must be held within the organisation, such as the AML compliance manager or, in Portugal, the person responsible for regulatory compliance under the RGPC, so the model supports those persons rather than replacing them. See Fractional Compliance Officer.

How do we access services in the Office?

You request a proposal, we send a tailored offer, and once the order is confirmed and invoiced, access to the Office is activated for the users you indicate. See Services & Products.