Skip to content
EU Compliance

Software
that passes the audit.

WCAG, NIS2, AI Act, GDPR. We work with these regulations at the technical layer. From the first commit your system has RLS, audit logs, retention controls and subprocessor management. Formal opinions and certification we leave to auditors and law firms we partner with.

Regulations we work with

Five EU regulations that genuinely shape system architecture for regulated industries. Not all of them at once, not all of them for everyone. We tailor the scope to your company.

WCAG 2.2 / EAA

European Accessibility Act

Digital accessibility for websites and applications. Mandatory for most commercial services in the EU since June 2025. We run a technical review of existing systems and design new ones to the standard from day one.

  • WCAG 2.2 AA technical scan with a fix list
  • Components compliant with ARIA and keyboard navigation
  • Contrast, focus, prefers-reduced-motion
  • Technical report for your auditor or compliance team

NIS2

Cybersecurity Directive

IT infrastructure protection, risk management, incident reporting. We implement the technical controls the directive requires. Organizational and legal obligations stay with you or your NIS2 consultant.

  • IT system inventory and dependency map
  • Technical incident runbook and restore plan (RTO / RPO)
  • Security logs, MFA, application access controls
  • Technical support for the incident reporting process your compliance team runs

AI Act

Artificial Intelligence Regulation

AI risk classification, technical documentation, model oversight. We help on the technical side: how to document the system, what safety layers to add. Formal classification is owned by your compliance team or a law firm.

  • Technical support for the risk classification your compliance team runs
  • Technical system documentation and model card
  • Template of FRIA technical sections, for your compliance team to approve
  • Template of an in-application AI usage policy

GDPR

General Data Protection Regulation

Privacy by design at the code and database layer. Especially for special category data (Article 9): health, biometrics, ethnicity. Legal opinions and DPO decisions stay outside our scope.

  • Encryption at rest and in transit
  • Row-Level Security in the database
  • Audit log for every access to sensitive data
  • DPIA template for your DPO to approve, retention mechanics, subprocessor control

Four regulations on four drawings

As much as you need to know before we sit down to talk. Every drawing carries the same description in text below it, because a diagram about accessibility that a screen reader cannot read would be a joke at our own expense.

WCAG 2.2 and the EAA: conformance levels and the criteria websites fail most oftenBaseline: WCAG 2.2, 86 success criteria 31 at level A, 24 at AA, 31 at AAA. Four principles: Perceivable, operable, understandable, robust Every criterion belongs to one of them. Legal threshold: Level AA The Polish accessibility act of 4 April 2019 points to WCAG 2.1 AA and to EN 301 549, clauses 9, 10 and 11. The EAA has applied since 28 June 2025. Failure 1: Text contrast, criterion 1.4.3 4.5:1 for body text, 3:1 for large text. Failure 2: Image with no description, criterion 1.1.1 A gallery or a chart carries content, so it is not decoration. Failure 3: Form field without a label Criteria 1.3.1, 3.3.2 and 4.1.2, all at level A. Failure 4: Focus obscured, criterion 2.4.11 A sticky header covers the focused element. Failure 5: Target size, criterion 2.5.8 At least 24 by 24 CSS pixels, or spacing. Failure 6: Video without captions, criterion 1.2.2 Auto captions are raw material, not the result.BASELINEWCAG 2.2, 86 success criteria31 at level A, 24 at AA, 31 at AAA.FOUR PRINCIPLESPerceivable, operable,understandable, robustEvery criterion belongs to one of them.LEGAL THRESHOLDLevel AAThe Polish accessibility act of 4 April 2019points to WCAG 2.1 AA and to EN 301 549,clauses 9, 10 and 11. The EAA has appliedsince 28 June 2025.FAILURE 1Text contrast, criterion 1.4.34.5:1 for body text, 3:1 for large text.FAILURE 2Image with no description,criterion 1.1.1A gallery or a chart carries content,so it is not decoration.FAILURE 3Form field without a labelCriteria 1.3.1, 3.3.2 and 4.1.2,all at level A.FAILURE 4Focus obscured, criterion 2.4.11A sticky header covers the focused element.FAILURE 5Target size, criterion 2.5.8At least 24 by 24 CSS pixels, or spacing.FAILURE 6Video without captions, criterion 1.2.2Auto captions are raw material, not the result.

What decides a site conformance level, and which criteria it actually trips over.

Text description of the diagram
  1. Baseline: WCAG 2.2, 86 success criteria 31 at level A, 24 at AA, 31 at AAA.
  2. Four principles: Perceivable, operable, understandable, robust Every criterion belongs to one of them.
  3. Legal threshold: Level AA The Polish accessibility act of 4 April 2019 points to WCAG 2.1 AA and to EN 301 549, clauses 9, 10 and 11. The EAA has applied since 28 June 2025.
  4. Failure 1: Text contrast, criterion 1.4.3 4.5:1 for body text, 3:1 for large text.
  5. Failure 2: Image with no description, criterion 1.1.1 A gallery or a chart carries content, so it is not decoration.
  6. Failure 3: Form field without a label Criteria 1.3.1, 3.3.2 and 4.1.2, all at level A.
  7. Failure 4: Focus obscured, criterion 2.4.11 A sticky header covers the focused element.
  8. Failure 5: Target size, criterion 2.5.8 At least 24 by 24 CSS pixels, or spacing.
  9. Failure 6: Video without captions, criterion 1.2.2 Auto captions are raw material, not the result.
NIS2: decision path telling whether an entity is essential, important, or out of scopeQuestion 1: Is the sector listed in Annex I or II? Healthcare and ICT service management sit in Annex I. Answer no: Out of scope Legal services appear in neither annex, no matter how many lawyers you employ. Question 2: Is the entity covered regardless of its size? That is the case for public healthcare providers, for a provider running an emergency department, for cloud, hosting, data centres, DNS and qualified trust services. A managed security provider is covered from 10 people, 2 million EUR turnover. Answer yes: In scope by law Headcount and turnover thresholds do not apply. Question 3: 250 people or more, or turnover above 50 million EUR? Answer yes: Essential entity Full supervision, including a mandatory audit. Question 4: Between 50 and 249 people, or turnover between 10 and 50 million EUR? Answer yes: Important entity Same duties, supervision after the fact. Answer no: Under 50 people, usually out of scope Unless question two catches you. Calendar: Four dates from the amended Polish cybersecurity act 3 April 2026: incident reporting in the 24 hour, 72 hour, one month rhythm. 3 October 2026: entry in the register. 3 April 2027: information security management system in place. 3 April 2028: essential entities audited.QUESTION 1Is the sector listed in Annex I or II?Healthcare and ICT service management sitin Annex I.ANSWER NOOut of scopeLegal services appear in neither annex,no matter how many lawyers you employ.QUESTION 2Is the entity covered regardlessof its size?That is the case for public healthcareproviders, for a provider running anemergency department, for cloud, hosting,data centres, DNS and qualified trustservices. A managed security provider iscovered from 10 people, 2 million EUR turnover.ANSWER YESIn scope by lawHeadcount and turnover thresholds do not apply.QUESTION 3250 people or more, or turnoverabove 50 million EUR?ANSWER YESEssential entityFull supervision, including a mandatory audit.QUESTION 4Between 50 and 249 people, or turnoverbetween 10 and 50 million EUR?ANSWER YESImportant entitySame duties, supervision after the fact.ANSWER NOUnder 50 people, usually out of scopeUnless question two catches you.CALENDARFour dates from the amended Polishcybersecurity act3 April 2026: incident reporting in the24 hour, 72 hour, one month rhythm.3 October 2026: entry in the register.3 April 2027: information security managementsystem in place.3 April 2028: essential entities audited.

Four questions that place your entity in one of three categories, plus four dates from the implementation calendar.

Text description of the diagram
  1. Question 1: Is the sector listed in Annex I or II? Healthcare and ICT service management sit in Annex I.
  2. Answer no: Out of scope Legal services appear in neither annex, no matter how many lawyers you employ.
  3. Question 2: Is the entity covered regardless of its size? That is the case for public healthcare providers, for a provider running an emergency department, for cloud, hosting, data centres, DNS and qualified trust services. A managed security provider is covered from 10 people, 2 million EUR turnover.
  4. Answer yes: In scope by law Headcount and turnover thresholds do not apply.
  5. Question 3: 250 people or more, or turnover above 50 million EUR?
  6. Answer yes: Essential entity Full supervision, including a mandatory audit.
  7. Question 4: Between 50 and 249 people, or turnover between 10 and 50 million EUR?
  8. Answer yes: Important entity Same duties, supervision after the fact.
  9. Answer no: Under 50 people, usually out of scope Unless question two catches you.
  10. Calendar: Four dates from the amended Polish cybersecurity act 3 April 2026: incident reporting in the 24 hour, 72 hour, one month rhythm. 3 October 2026: entry in the register. 3 April 2027: information security management system in place. 3 April 2028: essential entities audited.
GDPR: the path personal data takes through a system and the duty attached to each stageStage 1: Collection Legal basis from article 6. Health data falls under article 9, and for healthcare the basis is article 9(2)(h), not patient consent. Information duty from article 13. Stage 2: Transit Encryption in transit on every leg, integrations included. Stage 3: Storage Encryption at rest and Row-Level Security in the database, not only in the application. Stage 4: Access Audit log: who reached what, and when. Immutable, timestamped. Stage 5: Processing on your behalf An article 28 agreement with every processor, a subprocessor list, and control over where their servers physically sit. Stage 6: Retention and deletion A schedule per table, not per system. In our own processing register a contact form message lives 12 months, a consent log 5 years. Path outside the cycle: Data subject request Articles 15 to 22. We answer within 30 days. Path outside the cycle: Personal data breach Article 33: notify the authority in 72 hours. Article 34: notify the people affected when the risk to them is high.STAGE 1CollectionLegal basis from article 6. Health data fallsunder article 9, and for healthcare the basisis article 9(2)(h), not patient consent.Information duty from article 13.STAGE 2TransitEncryption in transit on every leg,integrations included.STAGE 3StorageEncryption at rest and Row-Level Securityin the database, not only in the application.STAGE 4AccessAudit log: who reached what, and when.Immutable, timestamped.STAGE 5Processing on your behalfAn article 28 agreement with every processor,a subprocessor list, and control over wheretheir servers physically sit.STAGE 6Retention and deletionA schedule per table, not per system.In our own processing register a contact formmessage lives 12 months, a consent log 5 years.PATH OUTSIDE THE CYCLEData subject requestArticles 15 to 22. We answer within 30 days.PATH OUTSIDE THE CYCLEPersonal data breachArticle 33: notify the authority in 72 hours.Article 34: notify the people affected whenthe risk to them is high.

Six stages personal data goes through in a typical system, plus two paths that fire outside that cycle.

Text description of the diagram
  1. Stage 1: Collection Legal basis from article 6. Health data falls under article 9, and for healthcare the basis is article 9(2)(h), not patient consent. Information duty from article 13.
  2. Stage 2: Transit Encryption in transit on every leg, integrations included.
  3. Stage 3: Storage Encryption at rest and Row-Level Security in the database, not only in the application.
  4. Stage 4: Access Audit log: who reached what, and when. Immutable, timestamped.
  5. Stage 5: Processing on your behalf An article 28 agreement with every processor, a subprocessor list, and control over where their servers physically sit.
  6. Stage 6: Retention and deletion A schedule per table, not per system. In our own processing register a contact form message lives 12 months, a consent log 5 years.
  7. Path outside the cycle: Data subject request Articles 15 to 22. We answer within 30 days.
  8. Path outside the cycle: Personal data breach Article 33: notify the authority in 72 hours. Article 34: notify the people affected when the risk to them is high.
AI Act: classification path from the definition of an AI system to the duties that followQuestion 1: Is it an AI system within the meaning of article 3(1)? Regulation 2024/1689. Answer no: The regulation does not apply That is where epko.tech stands today, as recorded in our own audit. Question 2: Is the practice a prohibited one? Answer yes: The system may not be placed on the market The steepest penalties in the whole package: up to 35 million EUR or 7% of turnover. Question 3: Does the system fall under Annex III? We check employment, credit, critical infrastructure and administration of justice. Answer yes: High risk Technical documentation, human oversight, post-market monitoring. Question 4: Does a person interact with the system, or with content the system generated? Answer yes: Transparency duties from article 50 Labelling AI generated content. Remaining cases: Minimal risk under article 6(2) Where our role ends: Formal classification is run by your compliance team or your law firm We deliver the technical part: system documentation, a model card, oversight layers.QUESTION 1Is it an AI system within the meaningof article 3(1)?Regulation 2024/1689.ANSWER NOThe regulation does not applyThat is where epko.tech stands today,as recorded in our own audit.QUESTION 2Is the practice a prohibited one?ANSWER YESThe system may not be placedon the marketThe steepest penalties in the whole package:up to 35 million EUR or 7% of turnover.QUESTION 3Does the system fall under Annex III?We check employment, credit, criticalinfrastructure and administration of justice.ANSWER YESHigh riskTechnical documentation, human oversight,post-market monitoring.QUESTION 4Does a person interact with the system,or with content the system generated?ANSWER YESTransparency duties from article 50Labelling AI generated content.REMAINING CASESMinimal riskunder article 6(2)WHERE OUR ROLE ENDSFormal classification is run by yourcompliance team or your law firmWe deliver the technical part: systemdocumentation, a model card, oversight layers.

Four questions leading from the definition of an AI system to a concrete set of duties.

Text description of the diagram
  1. Question 1: Is it an AI system within the meaning of article 3(1)? Regulation 2024/1689.
  2. Answer no: The regulation does not apply That is where epko.tech stands today, as recorded in our own audit.
  3. Question 2: Is the practice a prohibited one?
  4. Answer yes: The system may not be placed on the market The steepest penalties in the whole package: up to 35 million EUR or 7% of turnover.
  5. Question 3: Does the system fall under Annex III? We check employment, credit, critical infrastructure and administration of justice.
  6. Answer yes: High risk Technical documentation, human oversight, post-market monitoring.
  7. Question 4: Does a person interact with the system, or with content the system generated?
  8. Answer yes: Transparency duties from article 50 Labelling AI generated content.
  9. Remaining cases: Minimal risk under article 6(2)
  10. Where our role ends: Formal classification is run by your compliance team or your law firm We deliver the technical part: system documentation, a model card, oversight layers.

What it looks like in code

Compliance is not a paragraph in a privacy policy. It is concrete architectural decisions we make on every project.

DPIA and risk assessment as a template

Every project with sensitive data starts with a DPIA. We have our own template that has passed DPO review. The client gets a ready document to approve.

Audit log in every system

Who accessed what and when. Immutable, timestamped, ready for a regulatory request. Standard, not an upsell.

RLS and data isolation in the database

Row-Level Security in PostgreSQL. One patient's data will not leak through an application bug because the database itself refuses to return it to an unauthorized context.

Incident runbook in the contract

Who calls whom, by when, what steps. RTO and RPO defined in the SLA. Business continuity plan (BCP), backups, escalation.

What we do not promise

  • We are not a law firm. We do not issue legal opinions.
  • We do not sell "GDPR certificates". We sell architecture and documentation that holds up to a regulator.
  • We do not run a 24/7 SOC. We have a defined response time in business hours, a runbook and escalation.

Will your system stand up to inspection in 6 months?

Book a call. In 30 minutes we will check where you are, what is missing and what it costs.

Book a consultation