Skip to content

    Articles tagged: International

    17 articles on International from the Top Floor insights library.

    • 2026-08-25

      Does the EU AI Act Require a Conformity Assessment for Your System?

      Every high-risk AI system needs one, but for most of Annex III it is a self-assessment with no notified body. The notified body enters in two places only, and the deadline moved when the Digital Omnibus on AI took effect.

    • 2026-08-25

      Do You Need a Notified Body Under the CRA?

      Only if your product's core functionality is an important or critical category and, for class I, no harmonised standard covers the risks of that core functionality. The Commission's guidance turns both of those into tests you can run.

    • 2026-08-25

      How Long Does DORA Readiness Take?

      There is no grace period to plan against: DORA has applied since January 2025 and provides no transitional period. The honest timeline is set by the regulation's recurring clocks and by the workstreams with external lead times, and it differs for a new entrant, a laggard, a vendor and a group.

    • 2026-08-25

      How Long Does EU CRA Conformity Take?

      About fifteen months to the main obligations, weeks to the reporting duties, and a conformity route whose duration nobody can quote yet, because the product-specific standards are still in approval and the notified body listing is still marked once available. What you control, what you do not, and the sequence that survives both.

    • 2026-08-23

      India DPDP: What Is in Force Now, and What Lands in 2027

      Eighteen months. That is the gap the Indian government wrote into G.S.R. 843(E) between establishing the Data Protection Board and switching on a single obligation that binds your company. As of August 2026 none of them are on, and the ones everybody is preparing for arrive together on 13 May 2027.

    • 2026-08-23

      What the DORA Register of Information Requires

      Fourteen linked tables, machine-validated, with the LEI as the only identifier that works. In the ESAs' dry run, 6.5% of registers passed every data quality check and 86.4% of the failures were an empty mandatory field.

    • 2026-08-23

      Does GDPR Apply to My US Company?

      GDPR reaches a US company with no EU office at exactly two triggers, and there is no revenue floor or headcount threshold under either. The targeting test, the fact patterns that put you outside the Regulation, and what changes the day you decide you are inside it.

    • 2026-08-23

      Does India's DPDP Act Apply to Your Company?

      It applies to any company anywhere that processes digital personal data in connection with offering goods or services to people in India, and the notified Rules set two hard dates. What the gazette actually says, what the breach rule demands, and what the penalty schedule really caps at.

    • 2026-08-22

      How Much Does an Outsourced DPO Cost?

      Published benchmarks put outsourced DPO services at EUR 1,150 to EUR 2,900 a month against EUR 80,000 to EUR 150,000 a year in salary for an in-house appointment. We work through the sourced numbers, the scope drivers, and the threshold question most buyers skip: whether you owe a DPO at all.

    • 2026-08-21

      EU Representative vs DPO: Which Does a US Company Need?

      Two different GDPR appointments, two different triggers, and roughly two orders of magnitude between their published prices. Which one a US company owes, why the same firm cannot be both, and the case where you owe neither.

    • 2026-08-20

      The EU CRA Reporting Clock: 24 Hours, 72 Hours, Then a Final Report

      Article 14 obliges manufacturers to report actively exploited vulnerabilities and severe incidents on a 24-hour, 72-hour and final-report clock, from 11 September 2026. It is the first CRA obligation to bind, and it reaches products you shipped years ago and have not touched since.

    • 2026-08-19

      Data Privacy Framework vs SCCs: Which Transfer Mechanism Do You Need?

      DPF self-certification costs $260 a year at the smallest revenue tier and removes the SCC paperwork for covered transfers. Then the Supreme Court decided FTC commissioners can be fired at will, and the durability question got sharper.

    • 2026-08-16

      Does DORA Apply to US Companies?

      Almost certainly not directly, and almost certainly yes in practice. DORA binds EU financial entities, not their overseas vendors, but Articles 28 to 30 mean it arrives at your door as a contract addendum with a signature deadline attached.

    • 2026-08-16

      DORA Incident Reporting: The 4, 24, and 72 Hour Clocks

      Three reports on three clocks, set by Commission Delegated Regulation (EU) 2025/301. The four-hour one is the surprise, because it starts at classification rather than at containment.

    • 2026-08-16

      Does the EU Cyber Resilience Act Apply to Your Product?

      If you place hardware or software on the EU market and it connects to anything, assume yes and work backwards. The scoping traps are remote data processing, the Annex III important classes, and products already on the market.

    • 2026-08-16

      Is Your Product Important Under the CRA? Annex III and the Conformity Routes

      Most products self-assess. Annex III class I products self-assess only if they apply harmonized standards in full, class II and critical products cannot. Which list you land on decides your budget and your timeline.

    • 2026-03-14

      Understanding the EU AI Act: What US Companies Need to Know

      The EU AI Act is the world's first comprehensive AI regulation, and its reach extends far beyond European borders. If your company develops, deploys, or distributes AI systems that touch the EU market, compliance is not optional. Here is what US organizations need to understand.