Security and compliance in cloud ERP in 2026 rest on five pillars: certified infrastructure (ISO 27001, SOC 2), GDPR-compliant data processing with EU hosting, compliance with NIS2 and DORA, a completed DPIA for high-risk operations, and auditable logging of every change. For EU SMBs, this means demonstrable documentation, technical measures (2FA, encryption, retention policies), and contractual assurance from ICT suppliers — otherwise fines ranging from 10,000 € to 10 € million or 2% of turnover may result.
Cloud ERP has moved over the past five years from a “risky alternative” to default-choice status, even in conservative sectors such as construction, manufacturing, and healthcare. Along with this, the regulatory framework has changed — while GDPR in 2018 was the “first wave”, 2026 brings the second wave: NIS2, DORA, AI Act, and tightened EDPB guidelines. This pillar article summarises everything an EU SMB needs to know before selecting, deploying, and operating a cloud ERP system from a security and compliance perspective.
The article is divided into ten sections — from the legal framework through certifications, technical measures, audit logs, vendor due diligence, to practical examples from real Modulario deployments. At the end you will find an index to four deeper cluster articles dedicated to individual topics: ISO 27001 for SMBs, NIS2 in practice, DORA for the financial sector, and DPIA for ERP/CRM.
Why 2026 Is a Turning Point for Cloud ERP Security
Three factors converged in one time window and are fundamentally changing the game:
-
NIS2 transposition. National cybersecurity laws transposing NIS2 are in force across the EU from 2025/2026 and extend the regulated scope from dozens to thousands of companies. A mid-sized company with 50+ employees in manufacturing, transport, food distribution, ICT services, or digital infrastructure is very likely affected.
-
DORA (Digital Operational Resilience Act). In force from 17 January 2025. It applies not only to banks and insurers, but also to their ICT third-party providers — including SaaS ERP/CRM providers who serve regulated entities. This means your ERP vendor must meet DORA requirements if you serve banks or fintech clients.
-
EDPB guidelines 2025 + AI Act. The European Data Protection Board issued new guidelines in 2025 on AI systems processing personal data, cloud storage outside the EU, and supply chains. Simultaneously, the AI Act introduced obligations for high-risk AI systems (HR scoring, credit scoring) that are often part of ERP modules.
The result: regulatory pressure in 2026 is significantly higher than ever before and ignoring it is no longer a viable strategy. At the same time, the provider ecosystem has matured — modern EU-native ERP platforms like Modulario provide compliance “out of the box”, which is a far cheaper path than building your own infrastructure.
Legal Framework: EU vs. CLOUD Act
The most underestimated topic when selecting cloud ERP is the jurisdiction of the provider. This concerns not only where the servers physically run, but also the registered address of the parent company.
CLOUD Act and Schrems II
The American CLOUD Act (2018) allows US federal authorities to require US companies (including their European subsidiaries) to provide access to customer data regardless of where the data is stored. This means that even if AWS Frankfurt holds your data in Frankfurt, Amazon Web Services Inc. in Seattle can be legally compelled to hand it over.
The EU Court of Justice confirmed in Schrems II (C-311/18) that this is a problem — there is no equivalent protection for personal data of EU citizens transferred to the US. After the invalidation of the EU-US Data Privacy Framework in summer 2023, the only pragmatic solution for critical data remained: EU-native providers with EU-exclusive jurisdiction.
| Scenario | CLOUD Act risk | GDPR compliance |
|---|---|---|
| US provider + US data centre | High | Problematic |
| US provider + EU data centre (AWS Frankfurt, Azure DE) | Medium | Medium, requires SCC + TIA |
| EU provider + EU data centre | None | Full |
| EU provider + EU data centre + ISO 27001 + DPA | None | Full + auditable |
Modulario belongs in the last category — EU-incorporated company, hosting exclusively in the EU, ISO 27001 certification, standardised DPA.
Why This Matters for EU SMBs
Many SMBs think that CLOUD Act “does not affect them because they are not a bank”. The reality however is:
- B2B contracts. Large clients (major manufacturing groups, banks, public sector) in 2026 require a DPA in which the supplier explicitly confirms it is not subject to CLOUD Act. Without this you will not pass vendor due diligence.
- Sensitive employee data. Payroll, health, and HR data of EU citizens are among the most strictly regulated. Storing them with a US provider without a Transfer Impact Assessment (TIA) is a violation of GDPR Articles 44–49.
- Sector regulation. Public sector, healthcare, and the financial sector have in 2026 a de facto ban on US cloud for primary data.
For more on how Modulario addresses EU-exclusive jurisdiction, see Security.
ISO 27001: Why It Is Today’s Minimum Standard
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). For a cloud ERP provider in 2026, it is the de facto minimum entry ticket — without ISO 27001 you will not get through vendor due diligence of most mid-sized companies and all large ones.
What Certification Means in Practice
ISO 27001 is not just a piece of paper. A real audit covers:
- Policies and procedures (93 controls in Annex A): from employee onboarding through crisis management to hardware disposal.
- Risk analysis of every asset (server, database, human resource, supplier).
- Technical measures: encryption, network segregation, monitoring, MFA, backup.
- Organisational measures: training, code of conduct, vendor management, incident response.
- Regular audits: internal 1× per year, external surveillance audit 1× per year, recertification every 3 years.
Modulario achieved ISO 27001 certification in 2024 and actively maintains the complete documentation. A detailed description of the audit process, what it meant for the team, and what benefits it brings to clients is in the cluster article What ISO 27001 Means for SMBs.
ISO 27001 and SOC 2 Relationship
SOC 2 (Service Organization Control) dominates in the US context; ISO 27001 dominates in the EU. They are complementary — SOC 2 is an annual report from an auditing firm assessing trust services criteria (security, availability, confidentiality, processing integrity, privacy), while ISO 27001 is a management system certificate. The ideal provider has both; for EU SMBs, however, ISO 27001 is the priority because it is internationally recognised in EU B2B due diligence.
GDPR in Cloud ERP Context
GDPR (EU Regulation 2016/679) has several specifics in cloud ERP deployment that a standard checklist does not cover.
Roles: Controller vs. Processor
In an ERP/CRM system, your customer is the controller and you as the ERP provider are the processor. This relationship must be captured in a DPA (Data Processing Agreement) under Article 28 GDPR, specifying:
- subject matter, duration, and nature of processing,
- types of personal data and categories of data subjects,
- processor obligations (confidentiality, technical measures, sub-processors, audits),
- list of sub-processors (hosting provider, monitoring tools, email provider, etc.) with the controller’s explicit consent.
Modulario provides a standardised DPA as part of every contract — without the need for further negotiations with a lawyer.
Retention Policies: What Is New in 2026
EU accounting, tax, and archiving laws establish different periods for different types of data:
| Data category | Retention | Note |
|---|---|---|
| Invoices, accounting documents | 10 years | Tax legislation |
| Payroll records and time records | 50 years | Social insurance |
| Employment contract, personnel file | 70 years from birth | Archive legislation |
| Marketing consents | Until withdrawal / 24 months | GDPR + ePrivacy |
| Access logs (audit log) | Min. 6 months, recommended 3 years | NIS2 + sector-specific |
| Backup snapshots | Per retention policy | Consistent with primary data |
The ERP must enable automated deletion after retention expires while simultaneously not deleting data still required to fulfil a statutory obligation. Modulario addresses this through configurable retention policies at the attribute level.
Data Subject Access Requests (DSAR)
GDPR Articles 15–22 give a natural person the right to access, rectification, erasure, portability, and restriction. The ERP must enable export of all personal data about one person in a structured format within 30 days. In Modulario this is a native feature with an auditable log.
NIS2: The New Wave of Cybersecurity Regulation
NIS2 Directive (EU 2022/2555) entered into force on 16 January 2023 and member states had until 17 October 2024 to transpose it into national law.
Who Is Affected by NIS2
NIS2 extends the original NIS1 directive from 2016 from a handful of sectors to 18 sectors divided into essential and important entities. For EU SMBs the key change is:
- Medium-sized companies (50–250 employees / 10–50 million turnover) in affected sectors are automatically regulated.
- Sectors include: manufacturing, food distribution, transport, waste management, digital infrastructure, ICT services, public administration, healthcare, research.
- The exemption for smaller companies is narrow — if you are a “critical” supplier in a supply chain, it does not apply.
Main Obligations
A regulated entity must:
- Manage cyber risks — risk assessment, measures, documentation.
- Implement technical and organisational measures: MFA, encryption, backup, incident response, BCP/DRP, supply chain security.
- Report incidents to competent authorities within 24h (early warning) / 72h (incident notification) / 1 month (final report).
- Manage the supply chain — demonstrate that your key ICT suppliers (including SaaS ERP) meet adequate measures.
Penalties: up to 10 € million or 2% of global turnover (essential entities), 7 € million / 1.4% (important entities). Personal liability of directors is explicit in NIS2.
Detailed NIS2 guidance for EU SMBs including practical steps is in the cluster article NIS2 Directive: Company Obligations.
DORA: For the Financial Sector and Their ICT Suppliers
Digital Operational Resilience Act (EU Regulation 2022/2554) is in force from 17 January 2025 and applies directly (not via transposition). It affects regulated financial entities — banks, insurers, investment firms, crypto-asset platforms, payment institutions — but its reach via ICT third-party risk extends to their SaaS ERP/CRM suppliers.
Five Pillars of DORA
- ICT risk management — comprehensive framework, board-level responsibility.
- Incident management — reporting, classification, coordination.
- Digital operational resilience testing — including threat-led penetration testing (TLPT) for major entities.
- ICT third-party risk management — supplier register, critical functions, contractual requirements.
- Information sharing — voluntary but encouraged.
What This Means for SaaS ERP
If you sell ERP to banks, insurers, or fintech clients, you must:
- Conclude contracts with explicit DORA clauses (right to audit, exit strategy, sub-outsourcing rules, data location).
- Provide test environments for TLPT and operational resilience tests.
- Have a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) with defined RTO/RPO.
- Demonstrate data localisation in the EU.
For SMB clients outside the financial sector, DORA does not directly apply, but ICT suppliers that are DORA-ready offer a higher maturity standard from which non-financial companies also benefit.
The full DORA requirements checklist is in the cluster article DORA Regulation and ERP for the Financial Sector.
Audit Log: The Heart of Auditable Security
Without an audit log you have neither GDPR compliance, nor NIS2 reporting, nor SOC 2/ISO 27001 audit, nor forensic capability after an incident. The audit log is the technical backbone of everything else.
What an Audit Log Must Contain
For cloud ERP, the minimum scope is:
- Who — user account (including API and technical accounts).
- When — UTC timestamp with second precision, ideally with milliseconds.
- What — specific record (entity ID, attribute), before and after value.
- From where — IP address, user agent, session ID.
- Action — read / create / update / delete / export.
- Result — success / failure / authorisation denied.
The audit log must be immutable (or at least append-only with modification detection), encrypted, and stored outside the application database (typically write-only log storage).
Modulario Audit Log
Modulario provides a native audit log for every change in every module — from invoicing through warehouse to HR. Logs are accessible via UI (for administrators) and via API (for SIEM integrations). Retention is configurable, with a default of 12 months.
Practical example: if in the Finance module someone changes the amount on an invoice after it has been issued, the audit log retains both versions plus user identification plus timestamp. During a VAT inspection or internal audit you have a complete trail.
DPIA: When Is It Required and How to Complete It
Data Protection Impact Assessment (DPIA) under GDPR Article 35 is required when the processing of personal data is likely to result in a high risk to the rights and freedoms of data subjects. In the ERP/CRM context this applies primarily to:
- Systematic monitoring of employees (badge readers, camera systems linked to an HR module).
- Large-scale processing of sensitive categories (health data, biometrics).
- Automated decision-making with legal effect (HR scoring, credit scoring).
- Large-scale data on children or vulnerable groups.
- Innovative use of technologies (AI, IoT sensors identifying individuals).
DPIA Structure
A DPIA must contain under Article 35(7):
- Systematic description of the processing.
- Assessment of necessity and proportionality.
- Assessment of risks to data subjects.
- Measures to address the risks.
For Modulario ERP/CRM deployment, we provide a DPIA template with predefined controls and a description of technical measures (encryption, audit log, role-based access, retention). The client supplements it with their specifics (types of processing, legal basis, data subjects).
A full guide to DPIA for ERP/CRM deployment + template + common mistakes is in the cluster article DPIA for ERP/CRM Systems.
AI Act and Its Intersection with ERP
The EU AI Regulation (AI Act, 2024/1689) entered into force in August 2024 with phased application — prohibitions on certain practices apply from February 2025, obligations for high-risk systems from August 2026. For cloud ERP and CRM with AI features, this has several direct impacts.
AI Act Risk Categories
| Category | Examples in ERP/CRM | Obligations |
|---|---|---|
| Prohibited | Employee social scoring for HR decisions, real-time biometric identification for surveillance | Prohibition |
| High-risk | AI candidate scoring, customer credit scoring, predictive shift planning | Conformity assessment, registration, monitoring, transparency |
| Limited risk | Chatbots, AI document summaries, sentiment analysis | Transparency (inform user) |
| Minimal risk | Spam filter, automatic product categorisation | No specific obligations |
Overlap with GDPR DPIA
For high-risk AI systems in ERP that process personal data, a combined DPIA + AI conformity assessment is required. This means documentation not only of risks to data subjects, but also of the model’s technical documentation, datasets, bias, accuracy, and robustness.
Modulario AI Modules
Modulario AI features (text suggestions, document summarisation, anomaly detection in accounting) are designed to fall into the limited risk category — they inform the user that the output is AI-generated, and the user always has the option to override. This avoids the complex regulation of high-risk systems and the client does not need to conduct an AI conformity assessment.
If a client requires a high-risk AI use case (HR scoring, automated credit decisions), we provide documentation and support for the conformity assessment, but we highlight the regulatory complexity.
Vendor Due Diligence: How to Choose a Secure Supplier
Before signing a contract with a cloud ERP provider, verify at minimum the following:
| Area | Key question | Acceptable answer |
|---|---|---|
| Jurisdiction | Parent company registered address? | EU |
| Hosting | Where are the data centres? | EU (DE, FR, NL, PL) |
| Certifications | ISO 27001 / SOC 2? | Active ISO 27001 certification |
| DPA | Prepared template? | Yes, updated for 2026 |
| Sub-processors | Public list? | Yes + pre-approval for new ones |
| Audit log | Native? Retention? | Min. 12 months, immutable |
| 2FA / SSO | Mandatory for administrators? | Yes, SAML/OIDC supported |
| Encryption | At rest + in transit? | AES-256, TLS 1.3 |
| Backup / DR | RTO / RPO? | RTO < 8h, RPO < 1h |
| Incident response | SLA for notification? | < 24h |
| Exit strategy | Data export in standard format? | Yes (CSV, JSON, API) |
| GDPR DSAR | Native support? | Yes, < 30 days |
Tip: Ask the provider for a security whitepaper or trust centre. If they do not have one, that is a red flag.
Encryption, Keys, and Security Zones
Encryption in 2026 is already table stakes — no serious SaaS provider can offer commercial deployment without encryption at rest and in transit. The question has moved on: who holds the keys and how are they managed?
Encryption at Rest
In cloud ERP there are three practical models:
- Provider-managed keys (default). Keys are managed by the SaaS provider; the user does not see their rotation or storage. Simplest, least control. Suitable for 90% of SMBs.
- Customer-managed keys (BYOK). The client generates their own keys via their KMS (AWS KMS, Azure Key Vault, HashiCorp Vault) and provides them to the provider. More control, but more complex operation. Suitable for regulated sectors.
- Hold-your-own-key (HYOK). The client holds keys in their own HSM; the provider connects via a secure API per request. Highest control, but significantly slower and more expensive. Suitable for extremely sensitive use cases.
Modulario default provides provider-managed keys with AES-256 and transparent rotation every 90 days. For regulated clients we offer BYOK on request.
Encryption in Transit
TLS 1.3 is the minimum in 2026. TLS 1.0 and 1.1 have been deprecated since 2020; TLS 1.2 is tolerated only for legacy clients. For internal communications between microservices, mTLS (mutual TLS) with certificate rotation via internal PKI is used.
Modulario uses mTLS internally for all service-to-service calls and TLS 1.3 for external API and UI. HSTS with preload is activated for all public domains.
Backup Encryption and Immutability
Backups are a frequent target of ransomware attacks — if an attacker encrypts both primary data and backups, recovery without paying the ransom is impossible. The modern standard:
- Encrypted backups just like primary data (often a different key).
- Immutable storage (S3 Object Lock, Azure Immutable Blob) — cannot be deleted or modified during the retention period.
- Air-gapped copies — geographically and network-isolated from production.
Modulario backup architecture: daily full snapshots + hourly incrementals, AES-256 encryption, multi-region replication (DE + second EU region), 30-day retention, immutable storage for 7 days.
Identity, Authentication, and Authorisation
Three layers that are often confused but each addresses a different problem:
Authentication (Who You Are)
- Password + 2FA (TOTP/WebAuthn) — minimum for 2026.
- SSO via SAML 2.0 or OIDC — for enterprise deployments. Modulario supports Azure AD, Google Workspace, Okta, Keycloak, Auth0, ADFS.
- Passkeys (WebAuthn/FIDO2) — passwordless access, phishing-resistant. Modulario supports from 2025.
- Hardware tokens (YubiKey) — for extremely sensitive access.
Authorisation (What You Can Do)
- Role-Based Access Control (RBAC) — user has a role, role has permissions. Standard for 95% of use cases.
- Attribute-Based Access Control (ABAC) — granular permissions based on attributes (time, location, record type, sensitivity label). Advanced.
- Field-level security — some attributes of an entity are visible only to selected roles (e.g. salaries in a personnel file).
Modulario implements hybrid RBAC + attribute-based permissions via the People module, with field-level security for sensitive modules (HR, finance).
Identity Audit
Every authentication, authorisation, and permission change must be logged. In a NIS2/DORA incident, the regulator’s first question is: “Who had access to the affected data at that time?”
Backup, BCP, and DRP: Three Terms That Are Not Synonyms
Backup
A copy of data stored in a different location. Serves to restore after loss (technical failure, human error, ransomware). Defined by two metrics:
- RPO (Recovery Point Objective) — maximum acceptable data loss. Modulario default RPO < 1 hour (hourly incrementals).
- RTO (Recovery Time Objective) — maximum acceptable recovery time. Modulario default RTO < 8 hours (typically < 2 hours).
Business Continuity Plan (BCP)
A plan for how the company continues to operate during and after an incident. Covers not only IT, but also people, suppliers, communications, and alternative processes.
For SMBs, a minimum BCP contains:
- List of critical processes and their recovery priority
- Contact details of key people and suppliers
- Alternative working locations (work-from-home plan)
- Communication plan for customers and regulators
- BCP test at least 1× per year (table-top exercise)
Disaster Recovery Plan (DRP)
The technical part of BCP — how specifically you will restore IT systems. For cloud ERP clients, the provider executes most of the DRP; the client needs their own DRP for on-premise systems and integrations.
Modulario DR testing is performed 2× per year with documented results shared with clients at audits.
Incident Response and Forensics
Without a prepared process you will not meet the 24-hour NIS2/DORA deadline, the 72-hour GDPR notification, or an internal SLA to clients.
Incident Response Process Structure
- Detection — automated monitoring (SIEM, anomaly detection) + manual reports (employees, clients).
- Triage — classification (severity, scope, category).
- Containment — immediate limitation of spread (isolation of compromised account, blocking IP, disabling module).
- Eradication — removal of cause (patch, key rotation, account reset).
- Recovery — system restoration and integrity verification.
- Post-incident review — root cause analysis, lessons learned, update of measures.
Forensic Capability
After an incident you must be able to answer:
- When did it happen? (timeline)
- What data was affected? (scope)
- Who is responsible? (root cause)
- How to prevent it in the future? (remediation)
Without an immutable audit log with sufficient retention, forensics is impossible. The Modulario audit log is integrated and exportable to client SIEM systems (Splunk, Elastic, QRadar).
Incident Communication
- Internal — senior management, legal, PR, IT, affected teams.
- To regulators — competent national cybersecurity authority (NIS2), national data protection authority (GDPR), financial regulator (DORA for financial sector).
- To clients and data subjects — transparently, promptly, per contractual SLAs and GDPR Article 34.
A prepared communication template in the incident response runbook saves critical hours.
Practical Application: Security in Modulario
To prevent this remaining abstract, here is a concrete overview of how Modulario implements the above:
- EU-native jurisdiction — EU-incorporated company, no US sub-processors for primary data.
- ISO 27001 certification — active since 2024, annually re-audited.
- EU hosting — Frankfurt + second EU region (multi-region for HA), no data outside the EU.
- Native audit log in every module, 12-month retention, configurable.
- Role-based access control — granular rights at attribute level, configurable roles.
- 2FA / SSO — TOTP, WebAuthn, SAML 2.0, OIDC.
- Encryption — AES-256 at rest, TLS 1.3 in transit.
- DPA + sub-processor list — publicly available, standardised.
- Backup — daily full + hourly incrementals, 30-day retention, multi-region replication.
- DSAR support — export of personal data on request within 30 days via UI.
- GDPR retention policies — automated per module (invoices 10y, HR by type, marketing 24 months).
The Cost of Non-Compliance: Why the Investment Pays Off
Security and compliance investments look at first glance like pure cost. The realistic calculation however shows that non-compliance is 3–10× more expensive than compliance. Here is a model example for a mid-sized EU manufacturing company (80 employees, 12 € million turnover):
| Item | Compliance scenario | Non-compliance scenario |
|---|---|---|
| ISO 27001 implementation + audit | 15,000 € / first year | 0 € |
| GDPR process + DPA | 5,000 € / year | 0 € |
| ISO surveillance audit | 3,000 € / year | 0 € |
| Cyber insurance | 8,000 € / year | 16,000 € / year (higher rate) |
| Employee training | 2,000 € / year | 0 € |
| Total compliance | 33,000 € / year | 16,000 € / year |
| GDPR fine risk (5% probability) | 0 € | 25,000 € (expected value) |
| NIS2 fine risk (3%) | 0 € | 30,000 € (expected value) |
| Ransomware risk (12%) | 5,000 € (recovery from backup) | 60,000 € (downtime + ransom + reputation) |
| Lost tenders (requiring ISO/DPA) | 0 € | 100,000 € / year (model: 3 lost tenders) |
| Total risk-adjusted | 38,000 € / year | 231,000 € / year |
6:1 ratio in favour of compliance — and this does not include intangible benefits such as reputation, client trust, and the ability to attract investors.
Modulario provides a further saving in this model — because we provide an ISO 27001-certified platform with audit log, EU hosting, and a standardised DPA, the client does not need to build their own infrastructure, saving an additional 8,000–15,000 per year on the technical layer.
Cluster Index: Deeper into Individual Topics
This pillar article covers a broad agenda. If you are interested in a particular area in more detail, see these cluster articles:
- ISO 27001 for SMBs: What It Means — when certification is required, how the audit proceeds, what it means for clients.
- NIS2 Directive: Company Obligations — who it affects in the EU, key obligations, penalties, preparation steps.
- DORA Regulation: Financial Sector and ERP — who must comply, requirements for ICT third-party providers (including SaaS ERP), practical checklist.
- DPIA for ERP/CRM Systems — when it is required, how to complete it for a Modulario deployment, template, common mistakes.
Summary and Recommendations
Security and compliance in cloud ERP in 2026 is not nice-to-have — it is a prerequisite for existence. Pressure comes from all sides: regulators (NIS2, DORA, GDPR), B2B clients (vendor due diligence), insurers (cyber insurance requires evidence), banks (DORA via third-party risk).
For EU SMBs, there are three pragmatic paths:
- Build: in-house IT team, on-premise / private cloud, own certification. Cost: hundreds of thousands of euros per year. Suitable only for large companies with 200+ employees and highly sensitive data.
- Buy non-EU SaaS: cheap, fast, but with CLOUD Act risk and problematic GDPR. Suitable only for non-critical use cases.
- Buy EU-native SaaS with ISO 27001: the most sensible choice for 95% of SMBs. Compliance out of the box, predictable costs, EU-exclusive jurisdiction.
Modulario belongs in the third category. If you are interested in how to concretely achieve a GDPR + NIS2 ready state in 6–8 weeks instead of 6–12 months, see our security measures or contact us via a free consultation.
Frequently Asked Questions
Does every SMB need ISO 27001? No, ISO 27001 is not universally mandatory. However, it becomes de facto mandatory in B2B dealings with large clients (automotive, banks, public sector) and in NIS2-regulated sectors as evidence of adequate measures. For SMBs, it is often more efficient to choose an ERP/SaaS provider that already holds ISO 27001 than to build it in-house.
What is the difference between NIS2 and DORA? NIS2 is a horizontal directive for cybersecurity across 18 sectors in the EU (manufacturing, transport, energy, healthcare, ICT…). DORA is a sector-specific regulation only for the financial sector, but in practice stricter and with direct impact on ICT suppliers. Some entities fall under both — a bank is simultaneously a NIS2 essential entity and a DORA financial entity, with DORA taking precedence (lex specialis).
Is a cloud ERP hosted in the EU enough to comply with GDPR? EU hosting is a necessary but not sufficient condition. You also need: a DPA with the provider (Article 28 GDPR), a sub-processor list, retention policies, audit log, DSAR support, technical measures (encryption, 2FA, RBAC), and procedural measures (incident response, vendor management). Ideally also ISO 27001 certification from the provider as evidence of adequacy.
When do I need a DPIA for deploying a new ERP module? Whenever a new module presents high risk: large-scale processing of sensitive categories, systematic employee monitoring, automated decision-making, or innovative technologies (AI scoring, biometrics). For a standard accounting or warehouse module, a DPIA is usually not required, but a documented risk analysis is recommended. A full guide is in the cluster article on DPIA.
What are the maximum fines in 2026? GDPR: 20 € million or 4% of worldwide turnover (whichever is higher). NIS2: 10 € million or 2% of turnover (essential), 7 € million or 1.4% (important). DORA: up to 1% of daily turnover for the duration of the infringement (up to 6 months). AI Act: 35 € million or 7% of turnover for prohibited practices. Plus personal liability of directors under NIS2 and DORA.