- GDPR (General Data Protection Regulation)
- EU regulation (2016/679) on personal data protection. Applies to any company processing EU residents' data. Fines up to €20M or 4% of global turnover. Requires lawful basis, data subject rights, breach notification within 72 hours, and appointing a DPO for high-risk processing.
- EU AI Act
- EU regulation (2024/1689) classifying AI systems by risk (unacceptable, high, limited, minimal). Prohibited practices banned Feb 2025. High-risk system obligations start Aug 2026. Fines up to €35M or 7% of global turnover. General-purpose AI models have separate transparency obligations.
- NIS2 Directive
- EU directive (2022/2555) on cybersecurity for critical and important entities. Applies to medium+ companies (50+ employees or €10M+ turnover) in 18 sectors including digital infrastructure and SaaS. Requires 24-hour incident notification, board-level responsibility, and supply chain security. Fines up to €10M or 2% of turnover.
- Product Liability Directive (PLD 2024)
- Revised EU directive treating software and AI as "products" subject to strict (no-fault) liability. Extends to data damage. Member states must transpose by 9 December 2026. Shifts the burden of proof to defendants for complex products.
- SAFE (Simple Agreement for Future Equity)
- US instrument by Y Combinator that converts to equity at a future priced round. Not enforceable in most EU jurisdictions without adaptation. European alternatives: UK ASA (Advance Subscription Agreement), French BSA-AIR, German CLA (Convertible Loan Agreement).
- 28th Regime / S.EU Company
- Proposed European Commission framework (2025+) creating a unified pan-EU corporate structure for startups. Targets: 48-hour registration, €1 minimum capital, cross-border seat transfer without re-incorporation, single VAT ID. Complements — does not replace — national forms like Portuguese Lda. or German GmbH.
- Founder Vesting
- A schedule under which a founder's equity is earned over time, protecting the cap table if a co-founder leaves early. European standard: 4-year total with a 1-year cliff (nothing vests before month 12; then monthly). Often paired with single- or double-trigger acceleration on change of control.
- ESOP (Employee Stock Option Plan)
- Structured pool of options granted to employees, typically 10–15% of fully-diluted equity at seed. Tax treatment varies sharply across the EU: virtual options common in Germany (dual-class complexity), phantom shares in Portugal, and true options in France (BSPCE) and the UK (EMI).
- DPA (Data Processing Agreement)
- GDPR Article 28 contract between a data controller and a processor. Mandatory when a supplier processes personal data on your behalf (e.g. hosting, analytics, CRM). Must specify subject matter, duration, nature/purpose, data types, controller obligations, and security measures.
- IP Assignment
- Legal transfer of intellectual property rights (code, designs, trademarks) from an individual — usually a founder or contractor — to the company. Investors will refuse to fund a startup where IP still sits with individuals. Must be executed in writing before any fundraising due diligence.
- Cap Table
- Ledger showing who owns what percentage of a company, on both an issued and fully-diluted basis (including options and convertibles). Investors expect a clean, audit-ready cap table by Series A. Common mistakes: forgetting SAFE conversions, missing option grants, informal side letters.
- Term Sheet
- Non-binding summary of the key economic and control terms of a proposed investment (valuation, liquidation preference, board composition, protective provisions). Usually 3–6 pages. Once signed, deviates rarely on materials terms in the definitive documents.
- Liquidation Preference
- Right giving investors the return of their money (typically 1x, non-participating) before common shareholders receive anything on an exit. "Participating" preferences (double-dipping) are increasingly rare in EU seed/Series A deals. Multiples >1x are a red flag.
- DORA (Digital Operational Resilience Act)
- EU regulation (2022/2554) on ICT risk management for financial entities. In force since 17 January 2025. Covers banks, insurers, fintech, crypto-asset service providers, and their critical ICT third-party providers. Requires resilience testing, incident reporting, and third-party oversight.