The Cross-Border Compliance Playbook: Mapping GDPR, DORA, NIS2 & Loi 25 in One View

One reference table for the four regulations that now govern data and digital resilience on both sides of the Atlantic — GDPR, DORA, NIS2, and Quebec’s Loi 25 — plus the one thing they all reward: build the control once, prove it everywhere.

A modern SaaS company rarely lives under one rulebook. Sell into Europe and you meet GDPR. Serve EU banks or fintechs and DORA lands on you as an ICT vendor. Operate in a regulated sector across the EU and NIS2 applies. Handle a single Quebecer’s data and Loi 25 is in play. Four regimes, four vocabularies, four sets of deadlines.

This playbook is the Rosetta stone. It puts all four side by side so you can see, at a glance, who’s in scope, what each demands, and — the part that saves you — where they overlap so completely that one well-run control satisfies all of them. New to one of these? Start with the GDPR guide for non-EU SaaS or the DORA regulation guide.

The Cross-Border Compliance Matrix

The whole landscape on one screen. Read a row across to compare how each regime handles the same question.

DimensionGDPRDORANIS2Loi 25
What it governsPersonal data & privacyICT / operational resilience of financeCybersecurity of essential & important entitiesPersonal data & privacy
JurisdictionEU (extraterritorial)EU financial sectorEU (per member-state law)Quebec, Canada
Who’s in scopeAnyone processing EU residents’ dataFinancial entities and their ICT providersEssential/important entities in 18 sectorsAnyone handling Quebec residents’ data
Territorial triggerOffering services to / monitoring EU peopleProviding ICT services to EU financeOperating in a covered sector in the EUDoing business with Quebec residents
Core obligationLawful, transparent, secure processingICT risk management & resilience testingRisk management + governance accountabilityConsent, transparency, PIAs, safeguards
Incident / breach clock72 hours to the supervisory authorityInitial notice within hours; staged reportsEarly warning 24h; notification 72hPrompt report to the CAI on serious risk
Third-party / vendor ruleDPAs with processors (Art 28)Register of ICT providers + oversight of critical onesSupply-chain security dutiesPIA before transfer outside Quebec
Supervisory authorityNational DPAs (e.g. CNIL, DPC)ESAs + national competent authoritiesNational CSIRTs / competent authoritiesCommission d’accès à l’information (CAI)
Max penalty€20M or 4% of global turnoverSet by member states; supervisory sanctionsUp to €10M or 2% (essential entities)Up to $25M or 4% of global turnover

Figures are indicative ceilings; exact thresholds and member-state transpositions vary. Treat this as an orientation map, not legal advice.

The Four Regimes, in Plain English

GDPR — the privacy baseline

The General Data Protection Regulation governs how personal data is collected, used, and protected. Its reach is extraterritorial: a company anywhere in the world is in scope if it offers goods or services to people in the EU or monitors their behavior. Obligations run from lawful basis and consent to records of processing, sub-processor DPAs, international-transfer mechanisms, data-subject rights, and 72-hour breach reporting. It’s the template much of the world’s privacy law now imitates — including Loi 25.

Full walkthrough: The Definitive GDPR Compliance Guide for Non-EU SaaS · GDPR compliance solution.

DORA — resilience for finance and its vendors

The Digital Operational Resilience Act has applied since January 2025 and entered its enforcement phase in 2026. It harmonizes ICT risk management for EU financial entities — banks, insurers, investment firms, crypto-asset providers — and, crucially, reaches their ICT third-party providers. If your SaaS runs anything material for an EU financial institution, DORA’s expectations flow down to you through contracts and the client’s register of information. Critical providers can even fall under direct EU oversight.

Deep dives: DORA Regulation: The Complete Guide · DORA vs NIS2: Key Differences · DORA compliance solution.

NIS2 — cybersecurity across critical sectors

The NIS2 Directive dramatically widened the EU’s cybersecurity net, covering “essential” and “important” entities across roughly eighteen sectors — energy, transport, health, digital infrastructure, cloud and managed services, and more. It mandates baseline risk-management measures, supply-chain security, layered incident reporting (a 24-hour early warning, then a 72-hour notification), and — new for NIS2 — direct management accountability, so leadership can be personally on the hook. Because it’s a directive, the specifics live in each member state’s transposition.

See: NIS2 directive compliance solution.

Loi 25 — Quebec’s GDPR-style privacy law

Quebec’s Law 25 is the strictest privacy regime in North America and closely mirrors GDPR: a designated privacy officer, privacy impact assessments, transparency about automated decisions, data portability, and — distinctively — a PIA before transferring personal information outside Quebec. Its penalties rival Europe’s, reaching up to $25 million or 4% of worldwide turnover. If you already run a GDPR program, Loi 25 is largely a mapping exercise rather than a rebuild.

See: Quebec Law 25 vs. PIPEDA · Loi 25 compliance solution.

Where They Overlap (This Is the Good Part)

Read the matrix again and a pattern jumps out. The vocabularies differ, but underneath, the four regimes ask for the same handful of things. Do these well and you’re most of the way to all four:

1

Risk assessment

Every regime starts with knowing your risks and documenting them.

2

Access control & MFA

Least-privilege access with strong authentication, evidenced.

3

Encryption

Data protected at rest and in transit, configuration on file.

4

Audit logging

Tamper-resistant logs that are actually reviewed.

5

Incident response

A tested plan that can hit a 72-hour (or faster) clock.

6

Vendor management

Due diligence and contracts flowing obligations down your supply chain.

Two Ways to Run Multi-Jurisdiction Compliance

❌ The Siloed Way

  • A separate project for each regime
  • The same control documented four times, four ways
  • Evidence re-gathered before every audit
  • Deadlines and reporting clocks tracked in spreadsheets
  • A new market means starting compliance from scratch
  • Gaps hide between the silos

✅ The Unified Way

  • One control library, mapped to every framework
  • Each control built and documented once
  • Evidence collected continuously, reused everywhere
  • Obligations and clocks tracked in one system of record
  • A new market is a mapping exercise, not a rebuild
  • One dashboard shows coverage across all four

One Control, Many Frameworks

This is the mapping that makes the unified approach real. Build each control once, then point it at every regime it satisfies.

Build this control once……and it satisfies
Risk assessment & treatmentGDPR Art 32/35 · DORA ICT risk framework · NIS2 risk measures · Loi 25 PIA
Access control + MFAGDPR Art 32 · DORA · NIS2 · Loi 25 safeguards
Encryption at rest & in transitGDPR Art 32 · DORA · NIS2 · Loi 25
Audit logging & monitoringGDPR · DORA detection & reporting · NIS2 · Loi 25
Incident-response planGDPR 72h · DORA staged reporting · NIS2 24h/72h · Loi 25 CAI report
Vendor / third-party managementGDPR Art 28 DPAs · DORA register & oversight · NIS2 supply chain · Loi 25 transfer PIA
Data inventory / recordsGDPR Art 30 · DORA register of information · NIS2 asset mgmt · Loi 25 inventory

Look down the right-hand column: the same seven controls appear again and again. That’s not a coincidence — it’s the entire argument for a single evidence engine. Map once, collect once, prove four times.

The Unified Cross-Border Readiness Checklist

If you can tick these with real artifacts behind them, you can face a regulator or a procurement team in any of the four jurisdictions.

  • A single, current risk assessment feeding all four programs
  • A control library mapped to GDPR, DORA, NIS2 & Loi 25
  • Access control + MFA enforced and evidenced org-wide
  • Encryption everywhere, with configuration exports on file
  • Centralized audit logging that’s genuinely reviewed
  • One incident-response plan tuned to the fastest applicable clock
  • A vendor register with DPAs and ICT-provider oversight
  • A live data inventory / RoPA that doubles as a DORA register
  • An owner for each regime’s reporting deadlines
  • A dashboard showing coverage and gaps across all four

Four Regulations. One Source of Truth.

A compliance automation platform maps one control library to GDPR, DORA, NIS2, and Loi 25, collects the evidence continuously, and shows your coverage across every border on one dashboard — so a cross-jurisdiction review becomes a link you send, not four fire drills you survive.

Map once. Prove everywhere.

See the Cross-Border Dashboard

Frequently Asked Questions

What’s the difference between GDPR, DORA, NIS2, and Loi 25?

GDPR and Loi 25 are privacy laws governing how personal data is handled — GDPR across the EU (with extraterritorial reach) and Loi 25 in Quebec. DORA is an EU regulation focused on the operational and ICT resilience of the financial sector and its technology vendors. NIS2 is an EU cybersecurity directive covering essential and important entities across many critical sectors. They differ in scope and vocabulary but converge on the same underlying security controls.

Can one company be subject to all four regulations at once?

Yes, and it’s increasingly common. A SaaS vendor could owe GDPR for its EU users, DORA obligations as an ICT provider to an EU bank, NIS2 duties if it operates in a covered sector, and Loi 25 for any Quebec residents’ data — simultaneously. The regimes stack rather than cancel out, and the strictest applicable requirement usually sets the bar.

Do GDPR, DORA, NIS2, and Loi 25 share the same security controls?

To a large degree, yes. All four expect risk assessment, access control with strong authentication, encryption, audit logging, tested incident response, and vendor/supply-chain management. The specific documentation and reporting timelines differ, but a single well-designed control can be mapped to satisfy the equivalent requirement in each framework, which is why a unified control library is far more efficient than four separate projects.

How do you manage compliance across multiple jurisdictions efficiently?

Build a single control library, map each control to every framework it satisfies, and collect the supporting evidence continuously rather than before each audit. Track all reporting deadlines and vendor relationships in one system of record, and use a dashboard to see coverage and gaps across every regime at once. This turns entering a new market into a mapping exercise instead of a compliance rebuild.

Which regulation has the highest penalties?

GDPR and Loi 25 carry the headline figures — GDPR up to €20 million or 4% of global annual turnover, and Loi 25 up to $25 million or 4% of worldwide turnover. NIS2 caps fines for essential entities at up to €10 million or 2% of turnover, while DORA penalties are set by member states alongside supervisory sanctions. Exact ceilings depend on the infringement and jurisdiction.