Solutions · Startups and small companies
Under fifty people, GDPR and the AI Act still apply. NIS2 mostly does not.
Below the medium-sized ceiling NIS2's size gate usually keeps you out, but GDPR applies to every controller and the AI Act's literacy duty applies to every employer using AI. Buyers ask anyway, so a trust center pays for itself early.
Typical profile
- Sector
- Software or SaaS (not a listed digital provider)
- Employees
- Under 50
- AI
- Uses AI tools
- Flags
- None
- Under 50 employees is below NIS2's size gate for most sectors.
- GDPR applies regardless of size; the 72-hour breach clock is yours.
- Using AI tools makes you a deployer: Article 4 literacy applies now.
Obligations to prove
8
Outside NIS2's size gate on this profile; GDPR and any AI Act duties still apply.
- Regulation (EU) 2016/679 — data protection3
Applies to every organisation established in the EU that processes personal data.
- Regulation (EU) 2024/1689 — artificial intelligence5
You build or use AI systems — Art 4 AI literacy already applies; other tiers depend on classification.
First statutory clock if something goes wrong: GDPR breach notification, 72 hours (GDPR Art 33(1)).
Computed by the platform's scope finder. A starting point, not a legal determination.
The modules that matter here
Start with these 8 obligations.
Sign up, confirm the scope in onboarding, connect your first system.
Start free →