Business Law · Regulatory

Sub-Practice Regulatory &
Compliance.

We support businesses on GDPR, the AI Act, NIS2 and the DSA, as well as on sector-specific regulatory requirements and corporate governance obligations. We design compliance programmes around the business's activity, exposure and actual risks — not as a one-off exercise, but as a process that can be built into how it operates day to day.

GDPR · AI Act · NIS2 · DSAFull Coverage
8Jurisdictions (GC Experience)
3Languages
Compliance built to support the business, not to paralyse it
Regulatory requirements have to translate into procedures the business can actually apply. We rank the risks, propose specific measures and help build documentation and processes that can work in everyday business practice.
Not sure where your regulatory exposure lies?
Call us and we will map your regulatory exposure.
Request Consultation
Overview Scope of Service Process Experience

Regulatory Compliance

EU regulation now reaches deep
into how Greek businesses actually operate.

The regulatory framework for businesses in Greece and the European Union has widened considerably. The GDPR, the AI Act, NIS2 and the DSA each create different obligations, depending on the activity, the data, the systems and the services a business provides. The AI Act applies in stages, with certain prohibitions and obligations already in force and others following on set dates. NIS2 has widened the range of businesses subject to cybersecurity requirements and has now been transposed into Greek law. The DSA applies to a broad range of online intermediary services and platforms, with additional obligations for the largest platforms.

The challenge is not only knowing which rules exist. It is knowing which of them apply to your business and what has to change in practice. A compliance programme designed years ago may no longer match the business's activity, its systems or the framework now in force.

"The right question is not how many policies you have on file. It is whether the business actually operates in line with them."

Regulatory compliance differs considerably from sector to sector. Businesses in financial services, health, telecoms, energy and other regulated activities may be subject, beyond the horizontal European legislation, to specific licensing, supervisory and corporate governance requirements. We advise businesses on assessing the applicable framework, on designing and documenting compliance procedures, and on dealing with regulatory issues when they arise. The aim is a framework that can be applied in the day-to-day running of the business — with clear priorities, responsibilities and procedures. Compliance does not mean that every rule applies to everyone. The first step is to establish what actually applies. From the activity and the business model through to the data, the technology and the markets you operate in, we map the key regulatory requirements and rank the issues that need attention.

Who it affects
When regulatory support is needed
The need for regulatory compliance depends on the activity, the data the business processes, the technology it uses and the markets in which it operates. Depending on those factors, the GDPR, the AI Act, NIS2, the DSA or more than one framework may apply.
The Reality of Supervision
Fines are not theoretical
Supervisory authorities in Greece and the European Union impose fines and other administrative measures for breaches of the applicable rules. Assessing the regulatory exposure before an issue arises can therefore be an essential part of managing a business's legal position.
A Continuing Process
Compliance is not a one-off
Regulatory requirements, guidance and supervisory practice all develop. A compliance programme therefore has to be revisited whenever the activity, the technology or the applicable framework changes.
Cross-Border Activity
When the business operates in several countries
Operating in more than one state can create additional requirements because of differences in national implementation and supervisory practice. Experience in an international business environment and dual qualification in Greece and in England and Wales allow us to assess such questions from a cross-border perspective.

Scope of Service

From GDPR fundamentals
to AI Act, NIS2 and DSA.

GDPR & Data Protection Compliance
Mapping and assessing the processing of data, the legal basis, privacy policies and notices, data processing agreements, DPO support and breach response procedures. The compliance work is adapted to how the business actually operates and to its real needs.
GDPRDPOData Breaches
01
EU AI Act Compliance
Assessing AI systems and their risk category, checking whether any prohibited practices are engaged, and supporting the creation of the required documentation and governance procedures.
AI ActRisk ClassificationGovernanceDocumentation
02
NIS2 Cybersecurity & Critical Infrastructure
Assessing whether the business falls within the scope of NIS2 and supporting the implementation of the requirements on cybersecurity risk management, incident response and incident reporting.
NIS2CybersecurityIncident Reporting
03
DSA & Digital Platform Compliance
Legal support on the obligations the DSA creates for online platforms, marketplaces and other intermediary services, including transparency, content moderation and trader traceability.
DSAPlatformsMarketplacesTransparency
04
Licensing & Regulatory Approvals
Legal support on licensing and regulatory approvals in regulated sectors in Greece, together with the related notification, reporting and compliance obligations.
LicensingApprovalsRegulatory Obligations
05
Corporate Governance & Compliance Programmes
Designing and implementing corporate governance and compliance frameworks, with clear responsibilities, internal procedures, reporting lines, training and documentation of the key decisions.
Corporate GovernancePoliciesProceduresTraining
06

How We Work

Compliance as part of how the business runs day to day.

STEP 01
Assessing the Regulatory Requirements
We examine which regulatory framework applies to your business (GDPR, the AI Act, NIS2, the DSA and any sector-specific licensing requirements) and assess the existing practice and documentation. We identify the key gaps and rank the required actions by real risk.
STEP 02
Designing the Compliance Programme
We design a programme adapted to how the business operates — from policies and procedures through to data flows, governance structures and reporting lines. The aim is a framework that can be applied in practice, not a set of generic templates.
STEP 03
Implementation & Documentation
Drafting and implementing the policies, notices, contracts and internal documentation the programme requires, and training the people who have to apply it day to day.
STEP 04
Ongoing Monitoring & Updating
Compliance does not end when a file is handed over. On request, we review regulatory developments, new guidance or changes in the business's activity and assess whether the compliance programme needs updating.

Experience

Regulatory advice
grounded in experience from the business side.

In-House Experience · Fortune 50
General Counsel of a Fortune 50 group
Dionysis Pantazis, a partner of the firm, served for eleven years as General Counsel of a Fortune 50 technology group, with responsibility for four business divisions across eight countries.
AI Act · NIS2 · DSA
Experience in a regulatory framework that keeps moving
Applying the new European frameworks calls for an assessment of the specific activity, not a simple reference to the legislation. We examine the requirements that apply to the business and how they can be built into its existing procedures and operations.
NIS · Regulatory Assessment
Experience in assessing NIS obligations
We advised a group of companies on the extent of its obligations under the NIS Directive, examining which entities fell within scope and which security and incident reporting requirements applied.

Do you really know where your regulatory exposure lies?
Let's map it before a regulator does.

A confidential conversation about your activity, your data and systems, and your real regulatory exposure.