Where data is stored and processed. EU/EEA location may support a chosen architecture, but is not a general GDPR requirement and does not alone exclude foreign legal demands.
See also:Data sovereignty, CLOUD Act, EU Data Boundary, Self-hosted
Glossary
Regulatory and technical terms used on this site, reviewed in October 2026. Dates distinguish entry into force, application and transitional arrangements.
Where data is stored and processed. EU/EEA location may support a chosen architecture, but is not a general GDPR requirement and does not alone exclude foreign legal demands.
See also:Data sovereignty, CLOUD Act, EU Data Boundary, Self-hosted
Legal and operational control over data, including applicable jurisdictions and access. EU residency alone does not ensure exclusive EU control or immunity from foreign demands; ownership alone does not determine exposure.
See also:Data residency, CLOUD Act, Self-hosted
An Alternative Investment Fund Manager: a legal person whose regular business is managing one or more AIFs, such as private-equity, hedge, real-estate or credit funds. In Greece, relevant managers fall under HCMC supervision, subject to applicable home/host rules.
Directive 2011/61/EU governs AIFM authorisation and supervision, risk, delegation, depositaries and reporting. AIFMD II (Directive (EU) 2024/927) entered into force on 15 April 2024; the transposition deadline was 16 April 2026, with specified reporting amendments applying from 16 April 2027. It updates delegation, liquidity and loan-origination rules.
See also:AIFM (ΔΟΕΕ), HCMC, DORA
Regulation (EU) 2022/2554, applicable from 17 January 2025, sets proportionate ICT risk-management, incident-reporting, resilience-testing and third-party-risk rules for in-scope financial entities, alongside EU oversight of designated critical ICT providers.
See also:ICT third-party risk, Exit plan (DORA), AIFMD
Directive 2014/65/EU governs investment firms, trading venues, investor protection, product governance and business conduct. It operates through national implementing law, alongside directly applicable EU measures.
Regulation (EU) No 600/2014 complements MiFID II with directly applicable transparency and transaction-reporting rules. Regulation (EU) 2024/791 revises it, including the framework for consolidated tapes.
Regulation (EU) 2016/679 governs personal-data processing through lawfulness, purpose limitation, minimisation, security, accountability and individual rights. It defines pseudonymisation and provides for DPIAs and processing records.
See also:DPIA, RoPA, Tokenisation / pseudonymisation, Data processor / sub-processor
Regulation (EU) 2024/1689 follows a risk-based approach. In force from 1 August 2024, its original prohibitions apply from 2 February 2025, GPAI rules from 2 August 2025 and the Regulation generally from 2 August 2026, subject to exceptions. Regulation (EU) 2026/1744 postpones the principal high-risk provisions to 2 December 2027 for Article 6(2)/Annex III systems and 2 August 2028 for Article 6(1)/Annex I systems.
See also:GDPR, LLM gateway
Regulation (EU) 2019/2088 requires relevant entities and products to disclose sustainability-risk integration and whether and how adverse impacts are considered. Articles 6, 8 and 9 underpin common market categories, not sustainability certifications; Article 6 also applies to Article 8 and 9 products.
Anti-money-laundering rules require obliged entities to verify clients and beneficial owners, monitor activity and report suspicions to the FIU. The 2024 EU package includes Regulations (EU) 2024/1624 and 2024/1620 and Directive (EU) 2024/1640. AMLA began operations on 1 July 2025; AMLR generally applies from 10 July 2027, and AMLA direct supervision of selected financial entities starts in 2028. National authorities retain responsibilities.
Regulation (EU) No 596/2014 prohibits insider dealing, unlawful disclosure and market manipulation. It requires qualifying issuers' disclosures under Article 17 and suspicious order and transaction reports under Article 16. It covers specified regulated-market, MTF and OTF instruments and related instruments, including relevant off-venue activity.
Regulation (EU) 2023/1114 governs in-scope crypto-asset offers, issuers and service providers, with differentiated authorisation, disclosure, conduct and reserve or safeguarding rules. ART/EMT provisions apply from 30 June 2024; general application began on 30 December 2024. CASP transitional periods ended by 1 July 2026. Crypto-assets qualifying as financial instruments are excluded.
GNU Affero GPL version 3 is a strong copyleft licence. Section 13 requires modifiers to prominently offer corresponding source, free of charge, to users interacting remotely with the modified version over a network, even without distributing copies. This supports source inspection, not verification of the entire running service.
See also:Open-core, Self-hosted
A business model combining an open-source core with paid add-ons, often under proprietary licences. Users can inspect and run the open part; security-critical features may sit outside it. Commercial revenue can fund development.
See also:AGPLv3, Self-hosted
Software operated on customer-controlled infrastructure rather than as a supplier-run service. Data location and external dependencies depend on deployment, support and integrations; self-hosting alone guarantees neither EU residency nor sovereignty or compliance.
See also:Data residency, Data sovereignty, LLM gateway
A control point mediating application requests to language models, with routing, logging and configured policy and data-protection controls. Coverage depends on routing all relevant traffic through it and preventing bypass.
See also:Tokenisation / pseudonymisation, Data egress, EU AI Act
Tokenisation substitutes data values. GDPR Article 4(5) pseudonymisation requires attribution to need separately held additional information protected by appropriate measures. Reversible substitution can hide supported identifiers from a model provider, but residual context may still be personal data; it is not necessarily anonymisation.
See also:GDPR, Data egress, LLM gateway
Data crossing a controlled environment's boundary, such as a prompt sent to an external API. Egress controls detect and govern the actual transfer rather than merely prescribe a policy.
See also:LLM gateway, Tokenisation / pseudonymisation, Data residency
A Data Protection Impact Assessment under GDPR Article 35, required before processing likely to create high risk. It assesses operations, necessity, proportionality, risks and safeguards; unresolved high residual risk may require prior supervisory consultation under Article 36.
Records of Processing Activities under GDPR Article 30. Controllers record specified purposes, categories, recipients, transfers, retention and security information; processors record processing categories for each controller. Limited exceptions apply, not a blanket exemption for small firms.
Greece's capital-market authority, supervising relevant investment firms and AIFMs within its remit. It enforces MiFID II and AIFMD through implementing national law, and directly applicable MAR with national enforcement measures. Responsibilities are allocated with other authorities, including the Bank of Greece.
See also:AIFM (ΔΟΕΕ), AIFMD, MiFID II
W3C's Web Content Accessibility Guidelines use four principles (perceivable, operable, understandable and robust) and cumulative A, AA and AAA levels. WCAG 2.2 became a Recommendation on 5 October 2023. EN 301 549 V3.2.1, cited under the Web Accessibility Directive, incorporates WCAG 2.1 and more. V4.1.1, adopted on 24 August 2026 and published as 2026-09, incorporates WCAG 2.2. Its presumption under the European Accessibility Act requires the relevant Official Journal citation and covers only mapped requirements. EAA national measures generally apply from 28 June 2025, with exceptions and transitions.
The US Clarifying Lawful Overseas Use of Data Act (2018) clarifies covered providers' disclosure duties for data in their possession, custody or control, wherever stored, under valid US legal process. What counts is whether the provider is subject to US jurisdiction and has possession, custody or control of the data, not where the data is stored. It is one reason EU residency does not ensure exclusive EU legal control.
See also:Data sovereignty, Data residency, EU Data Boundary
DORA Article 28(8) requires exit strategies and documented, sufficiently tested plans for ICT services supporting critical or important functions, preserving continuity and regulatory compliance. Feasible alternatives, data migration and transition terms matter. Open, self-hostable software can help, not guarantee, portability.
See also:DORA, ICT third-party risk, AGPLv3
Risk arising from third-party ICT services and subcontractors. DORA Chapter V requires proportionate assessment, contractual safeguards, monitoring and concentration-risk evaluation, alongside ESA oversight of designated critical providers. Self-hosting and source access may reduce particular dependencies, not necessarily overall ICT risk.
See also:DORA, Exit plan (DORA), Self-hosted
Microsoft's contractual and technical commitment for specified data and services within EU/EFTA, subject to configuration and documented exceptions. It is not an absolute no-transfer guarantee or immunity from foreign legal demands. Coverage and access must be assessed under the applicable terms.
See also:Data residency, Data sovereignty, CLOUD Act
A GDPR processor acts on a controller's behalf, normally under documented instructions. A sub-processor performs delegated processing with prior specific or general written authorisation. Each link requires appropriate guarantees and oversight. Genuine in-house processing may reduce external exposure, but self-hosting alone does not eliminate processors or security duties.
See also:GDPR, RoPA, Data egress