Digital Sovereignty

Lost in Regulation? Navigating the EU Cybersecurity and Data Law Jungle as a Tech Company

How FOSS helps you survive the EU regulatory stack

Seminar 1

17:4015 mins13/11/2026

The EU has produced one of the most ambitious digital regulatory frameworks in history — but for tech companies, developers, and SMEs trying to stay compliant, it increasingly feels like a jungle: overlapping obligations, staggered deadlines, conflicting definitions, and regulatory gaps that no single lawyer or consultant can fully map alone.

This talk gives a frank, practitioner-level overview of the regulatory landscape that any technology company operating in Europe must navigate today: GDPR (data protection and privacy), NIS-2 (cybersecurity obligations for essential and important entities), the EU AI Act (risk-based AI governance), the Cyber Resilience Act (security requirements for products with digital elements), and the Data Act (data access and interoperability). For each framework, the talk identifies who is actually affected, what the core obligations are, how the frameworks interact and conflict, and — critically — what a small or medium-sized tech company can realistically do to manage compliance without a team of lawyers.

The talk also highlights how open-source software and open standards reduce regulatory risk: transparent, auditable, and interoperable systems are structurally better positioned to meet the EU’s growing compliance requirements than proprietary black-box alternatives. Attendees leave with a practical mental model for mapping their own regulatory exposure and a set of open-source tools and practices that address multiple compliance obligations at once.