Sectors / Market

Sectors We Serve

Public administration, large enterprises, SMEs and regulated sectors: one method, adapted to each regulatory profile.

Market focus

12 Priority Sectors

Each sector page sets out the key obligations, our services and the related domains and regulated functions.

Public Administration

DPO, NIS2, whistleblowing and integrity in the public sector

Financial Services

DORA, AML and data protection for banks, insurers and investment firms

Real Estate & Investment Funds

AML, DORA for fund managers and tenant and investor data

Healthcare & Life Sciences

Health data, NIS2, AI in medical devices and the EHDS

Energy & Utilities

NIS2, critical entities resilience and sustainability

Transport & Logistics

NIS2, critical entities and supply-chain security

Manufacturing & Industry

NIS2, Cyber Resilience Act and supply-chain due diligence

Hospitality & Tourism

Guest data, CCTV, whistleblowing and pay transparency

Digital & Telecoms

NIS2, DSA and DMA, AI Act and DORA for ICT providers

Education & Research

Data of minors, AI in education and research security

Retail & Consumer

Customer data, marketplaces, cash limits and supply chain

Professional Services

AML gatekeepers, client confidentiality and AI use

One method, four regulatory profiles

The same rules apply differently depending on the nature, size and activity of the organisation. We adapt scope, depth and format to each profile.

Public administration

Municipalities, central and regional administration, public institutes and public companies combine general obligations with duties specific to the public sector:

  • data protection: the designation of a Data Protection Officer is mandatory for public authorities and bodies (GDPR, Article 37);

  • cybersecurity: certain public administration entities are covered by NIS2 and its national transposition;

  • whistleblowing: internal reporting channels, subject to the exemptions allowed for small municipalities and entities;

  • integrity and anti-corruption: in Portugal, the RGPC applies to public entities with 50 or more workers;

  • public procurement: our services can be contracted through public procurement procedures.

Large enterprises

Large companies and groups face the widest set of obligations and the closest scrutiny:

  • reporting: sustainability reporting under the revised CSRD scope and gender pay gap reporting;

  • cybersecurity and AI: NIS2 obligations and the governance of AI systems under the AI Act;

  • groups: consistent policies and controls across subsidiaries and Member States;

  • third parties: due diligence across complex supply chains.

SMEs

EU law applies proportionately, but SMEs are far from exempt:

  • GDPR: applies regardless of size;

  • thresholds of 50 workers: internal whistleblowing channels and, in Portugal, the RGPC compliance programme;

  • supply-chain pressure: questionnaires from larger customers on cybersecurity, data protection and sustainability;

  • accessible solutions: the fractional model and implementation kits make a credible programme affordable.

Regulated sectors

Sectors under specific supervision require domain expertise:

  • financial sector: DORA, AML and sectoral conduct rules;

  • essential and critical services: energy, transport, health, water and digital infrastructure under NIS2;

  • digital services: platforms and intermediaries under the DSA and DMA;

  • other obliged entities: professions and businesses subject to AML rules, such as accountants, estate agents and dealers in high-value goods.

Start with an assessment

A free express assessment identifies which domains apply to your organisation and where to begin.