This website uses cookies

This website uses cookies to ensure you get the best experience. By using our website, you agree to our Privacy Policy

International In-house Counsel Journal logoInternational In-house Counsel Journal logo
Back to library search

Risk-Based Digital Compliance and Organisational Roles in EU Regulation

September 2025
RegulationConsultant

Abstract

This article examines the organizational side of digital compliance in companies operating under key EU regulations (GDPR, the AI Act, NIS2, and the DSA). A common thread across these regimes is the adoption of a risk-based compliance approach: organizations must conduct continuous risk assessments and implement controls proportional to identified risks. Equally, the governance ethos of these laws places accountability at the highest corporate levels. Notably, the NIS2 Directive imposes direct obligations on boards of directors and senior management to oversee and approve cybersecurity risk management measures. Similarly, the Digital Services Act requires top-level oversight by mandating independent compliance functions with direct reporting lines to the board. This elevates digital compliance from an IT or operational concern to a boardroom priority, underscoring that senior leadership must actively ensure adherence to these complex obligations. The article delineates the distinct roles of key officers in managing digital compliance. Data Protection Officers focus on GDPR privacy mandates, Chief Information Officers/Chief Information Security Officers (CIOs/CISOs) handle cybersecurity defences, Compliance Officers coordinate regulatory adherence, and Chief Financial Officers (CFOs) integrate compliance into enterprise risk and control frameworks. In-house legal counsel (General Counsel) provides broad oversight across these domains and regularly advises the board on compliance and risk matters, often supported by external advisors for specialized expertise. A practical challenge is that these functions often operate in silos with insufficient cross-functional coordination. The article argues that the General Counsel, by virtue of a wide remit and direct access to the board, is best positioned to orchestrate an integrated digital compliance strategy. It concludes that strengthened governance structures and legal leadership are vital to breaking down silos and aligning corporate practices with a holistic, risk-based compliance culture.

Author

Portrait image of Andrej Savin
Andrej Savin
Professor, CBS LAW, Copenhagen Business School, Denmark

Andrej Savin is a professor of IT Law and Internet Law at Copenhagen Business School. His main research interests lie in Information Technology Law, and in particular EU policymaking in the digital single market, the regulation of new business models and Internet governance in the US and in Europe. Andrej Savin also works on law and management in the legal environment, in particular with focus on the interplay between law, ethics, business and society in the digital world. His works include books EU Internet Law, EU Telecommunications Law, Research Handbook on EU Internet Law and others.

Company

CBS LAW, Copenhagen Business School logo

CBS LAW, Copenhagen Business School

CBS LAW is the law department at Copenhagen Business School.

Related Papers

The Era of Environmental Transparency: comparative analysis of green claims/greenwashing regulations in the European Union, United Kingdom, and United States (2024–2026)
This paper offers a strategic comparative analysis of the regulatory responses across the European Union (EU), the United Kingdom (UK), and the United States (USA) during the crucial 2024–2026 triennium....Read more
Portrait image of Giuseppe Labbozzetta
Giuseppe Labbozzetta
Legal Counsel, Ferretti Group, Italy
International Economic Sanctions (IES) and Contract Management
This document looks at how international economic sanctions affect the way contracts are managed, especially in global business settings. Economic sanctions are measures that countries or international organizations use to...Read more
Portrait image of Raphael Picard
Raphael Picard
Jurist Contract Manager Senior, Edenair GmbH, France
Legal Transformation? Business, AI, and New Suppliers are Key Drivers
Jake Campbell, a character in Hemingway’s The Sun Also Rises, explained how he went bankrupt: “Two ways. Gradually and then suddenly.” The humor of his observation masks its profound insight-and...Read more
Portrait image of Mark A. Cohen
Mark A. Cohen
Chief Executive Officer, Legal Mosaic, UK
Legal Transformation? Mirage Turned Reality
For those awaiting transformation of the legacy legal delivery model, it’s been a long, frustrating wait punctuated by high hopes and dashed expectations. The Economist raised legal transformation expectations in...Read more
Portrait image of Mark A. Cohen
Mark A. Cohen
Chief Executive Officer, Legal Mosaic, UK