If you run a website that serves users in the European Union, you have probably heard three acronyms: GDPR, NIS2 and DORA. They all impose obligations on digital operations — but they apply to different entities, cover different risks, and require different things from your website.
This guide explains the differences in plain language, with a focus on what each regulation means for your website's compliance posture — and how to check all three with a single scan.
| Aspect | GDPR | NIS2 | DORA |
|---|---|---|---|
| Full name | General Data Protection Regulation | Network and Information Security Directive | Digital Operational Resilience Act |
| Effective | 25 May 2018 | 17 October 2024 | 17 January 2025 |
| Type | Regulation (directly binding) | Directive (must be transposed into national law) | Regulation (directly binding) |
| Who it covers | Any organisation processing EU personal data | Essential and important entities in 18+ critical sectors | Financial entities + ICT third-party providers |
| Primary focus | Protection of personal data and privacy | Cybersecurity and incident management for critical infrastructure | Operational resilience and ICT risk management in finance |
| Penalties | Up to €20M or 4 % of annual turnover | Up to €10M or 2 % of annual turnover | Up to €10M or 2 % of annual turnover (varies by entity) |
| Website-specific requirements | Privacy policy, cookie consent, data processing transparency, security measures (Art. 32) | Security measures, incident reporting, risk assessments | ICT risk management, resilience testing, incident reporting, business continuity |
GDPR is the broadest of the three. It applies to any organisation that collects or processes personal data from individuals in the EU — regardless of where the organisation is based. This means a single-person blog in Canada with EU readers, a Shopify store in Australia, and a SaaS company in the US all need GDPR-compliant websites.
Each EU member state's data protection authority (DPA). Examples: the Irish DPC, the French CNIL, the German DSK. Fines can reach €20 million or 4 % of global annual turnover — whichever is higher.
NIS2 is narrower than GDPR. It targets essential and important entities in sectors such as energy, transport, banking, health, water, digital infrastructure, and public administration. If you operate a small e-commerce site, NIS2 likely does not apply to you directly — but if you provide ICT services to a NIS2-regulated entity, you may be covered.
Even if you are not a NIS2 entity, if your customers are, your website and service become part of their supply chain. NIS2 pushes compliance requirements down the chain — so a compliance badge, documented security headers, and a published privacy policy are increasingly expected.
DORA is the most specific. It applies to financial entities — banks, investment firms, payment processors, insurance companies, and their ICT third-party providers. If your SaaS product serves a financial institution, DORA compliance will be in your contracts.
Financial-sector websites should demonstrate operational resilience at minimum: published security headers, HTTPS enforcement, a documented incident-reporting channel (security.txt recommended), and a business-continuity or resilience statement available on the site.
| Requirement | GDPR | NIS2 | DORA |
|---|---|---|---|
| Risk assessment | ✓ (Art. 32, 35) | ✓ (Art. 21) | ✓ (Art. 6–16) |
| Incident reporting | ✓ (72 h, Art. 33) | ✓ (24 h / 72 h) | ✓ (initial / intermediate / final) |
| Supply-chain oversight | ✓ (processor due diligence) | ✓ (supply chain security) | ✓ (third-party ICT risk) |
| Security measures | ✓ (Art. 32) | ✓ (Art. 21) | ✓ (ICT risk management) |
| Third-party contracts | ✓ (DPA, Art. 28) | ✓ (contractual measures) | ✓ (contractual clauses) |
| Penalties | €20M / 4 % | €10M / 2 % | €10M / 2 % |
In practice, if you are compliant with GDPR Article 32 (security measures) and Article 28 (data processing agreements), you already meet a significant portion of NIS2 and DORA's baseline expectations for website security. The main additional areas are incident-reporting procedures, resilience testing, and published operational documentation.
Regardless of which regulation applies to your organisation, the following checks cover the common ground across GDPR, NIS2 and DORA's website-related expectations:
The EUComply free scanner checks your site against GDPR, NIS2, DORA and EAA requirements in under 30 seconds. No sign-up, no installation, no platform lock-in — enter your URL, get the results.
Run free scan →The most practical starting point for any organisation is to get the technical basics right: HTTPS, cookie consent, privacy policy, security headers. The free EUComply scan tells you exactly where you stand, and the Pro tier turns those findings into the documented evidence that auditors and compliance officers expect.
📖 DORA Compliance Practical Guide — detailed walkthrough
📖 NIS2 Supply Chain Compliance — for vendors serving critical entities
📖 European Accessibility Act Guide — EAA requirements
📖 Compliance document templates — DPA, NIS2 clauses, NDA, EAA statement