Regingada
Sectors

Six profiles, six regulatory footprints

Sector profiles · Source: Funk corpus (CELEX/ELI-anchored) · Status: 2026-08

The same regulation lands differently on every company. A marketplace and a B2B application can both process personal data, rank content and store what their customers upload, and still owe almost disjoint duty lists — because the acts attach to services, roles and entity types rather than to industries. Each of the six profiles below takes one cut through EU digital law: which regimes actually run, which ones are deliberately switched off, and where the expensive seams sit between two acts that describe the same feature. Leaving a regime out is part of the answer; a duty list carrying obligations you do not owe is not more careful, it is less usable. None of this is a finding about your company — a profile describes a shape, not a case.

Curated for orientation. Not legal advice, not a legal assessment of your case.

The profiles

One corpus, six cuts through it

The six cuts are the ones that arrive most often. Each page names its regimes with the provisions attached, marks the ones that do not apply to that shape, and works through the seams where two acts reach for the same feature.

  • B2B SaaS · established in the Union

    B2B SaaS — GDPR first, AI Act next

    A provider that runs the systems its customers process their own data in sits on the processor side of the GDPR, and that side is contractual before it is technical: the Article 28 chain, the sub-processor authorisations, the transfer question. Everything else attaches conditionally, and an AI feature raises a role question that has to be answered per feature rather than per company.

    • GDPR · processor side
    • AI Act · only with AI functions
    • DSA · not activated
    Read the sector page →
  • Marketplaces · traders and consumers

    Marketplaces — the DSA stack, before designation

    Letting third parties sell on your own surface makes a service a hosting service and an online platform at once, so the duties arrive in layers rather than as one list. Chapter III applies without any designation as a very large platform — which is exactly where the effort gets underestimated — while ranking and matching on their own do not switch on the AI Act.

    • DSA · Chapter III
    • GDPR · active
    • AI Act · not activated by ranking alone
    Read the sector page →
  • Social · user-generated content

    Social and UGC — moderation as a legal system

    Where users publish, moderation stops being an operational matter and becomes a legal system: the terms have to describe the rules, every restriction owes a statement of reasons, and every decision opens a redress path with its own deadlines. Automated moderation adds AI Act transparency on top of what the DSA already requires — the Data Act, by contrast, stays out.

    • DSA · Chapter III
    • AI Act · only with automated moderation
    • Data Act · not activated
    Read the sector page →
  • AI providers · systems and GPAI models

    AI providers — role first, duties second

    Whoever places a system or a model on the Union market under their own name carries the provider role, and the AI Act attaches its duties to roles per system rather than to companies. The high-risk band is decided by Annex III or the product-safety route, not by model size, while the GDPR keeps running underneath training data, evaluation data and output about individuals.

    • AI Act · provider track
    • GPAI strand · model placed on the market
    • DSA · not activated by this profile
    Read the sector page →
  • Cloud · hosting · infrastructure

    Cloud and hosting — intermediary duties plus NIS2

    Storing customer content makes an infrastructure business a hosting service under the DSA, and the liability privilege that comes with the role is a condition rather than a status. NIS2 sits on top because digital infrastructure is a listed sector, the GDPR processor duties run alongside, and the Data Act switching chapter reaches into contracts, exit documentation and interfaces.

    • DSA · hosting service
    • NIS2 · digital infrastructure sector
    • AI Act · not activated by hosting alone
    Read the sector page →
  • EU-China · both directions

    The EU-China bridge — two regimes, one data flow

    One pipe, governed twice over: on the European side the GDPR asks who represents the company in the Union and under which instrument data leaves it; on the Chinese side the PIPL asks on what basis personal information is handled at all and which cross-border mechanism carries a provision abroad. Neither side accepts the other's paperwork as its own, so the documentation has to exist twice and stay consistent.

    The page reads in both directions: a Chinese provider serving the EU market, and a European company running operations in China.

    • GDPR · Art. 27 + Chapter V
    • PIPL · cross-border provision
    • NIS2 · not activated by a data flow alone
    Read the sector page →
No matching profile?

When none of the six fits

The six cuts are the ones that arrive most often; they are not a taxonomy of the market. A company sitting between two of them — or outside all of them — gets further with its own footprint than with the nearest profile.

Next step

From a profile to your own footprint

A sector page describes a shape of company, not yours. The pre-wizard takes five questions and the suite builds the map from your answers; everything it produces is orientation and carries a DRAFT mark. The legal assessment of it stays with the law firm, in a mandate.

Disclaimer

Orientation, not legal advice

These sector profiles and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.