WorldPrivacyAtlas
Laws by country

Sector-Specific Law

Digital Operational Resilience Act

DORA

European Union · January 17, 2025 (date of application, following a two-year implementation period)

DORA is a directly applicable Regulation covering a closed list of EU financial entities set out in Art. 2 — credit institutions, payment and electronic money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, trading venues, fund managers and more — plus ICT third-party providers designated critical by the European Supervisory Authorities. It imposes an ICT risk management framework, a classified ICT-incident reporting pipeline to competent authorities, digital operational resilience testing (including threat-led penetration testing for larger entities), and a register of information on all ICT third-party contractual arrangements, with prescribed contractual terms for those contracts. Two points that catch non-financial businesses out: DORA reaches ICT vendors indirectly through those mandated contract terms even when they are not themselves designated critical, and its incident reporting is separate from and additional to GDPR Art. 33 — an incident can trigger both pipelines on different clocks to different regulators.

Regulation (EU) 2022/2554Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.