Several recently introduced regulations place particular emphasis on how data is collected, shared, reused and accessed across the European Union (EU).
This includes ensuring that any digital transformation is safe, fair and beneficial for citizens, while also supporting innovation and a competitive market.
The EU’s Data Act, Digital Operational Resilience Act, Public Country-by-Country Reporting rules and Empowering Consumers Directive bring an audit impact and other compliance attestation requirements auditors should be aware of.
The European Union Data Act
The EU Data Act, which applies to Member States including Ireland, became effective on 12 September 2025 with the aim of improving the accessibility of data for all market participants.
All entities that generate or store data are required by law to share it with other organisations in compliance with strict data protection regulations. Equally, this Act gives consumers more control over their data, with the aim of fostering greater trust in digital services.
The Data Act is expected to apply broadly to software-as-a-service, platform-as-a-service and infrastructure-as-a-service providers.
However, entities outside the technology sector may also find that they provide services that meet its definition of a data processing service.
Given the complexity and evolving interpretations associated with the EU Data Act, entities offering data processing services under this Act may find it necessary to consult with their legal counsel to assess whether this legislation applies to them – and, if so, how this may affect customer contracts.
There are various considerations of interest to auditors here. One of the important provisions of the EU Data Act is that it prohibits fees for switching providers but permits early termination fees. This implies that entities and their auditors may need to consider factors including:
1. Whether the terminating party is required to pay any compensation;
2. The amount of such compensation; and
3. The reason for the compensation (i.e. whether it is in addition to amounts due for goods and services already delivered).
The implications of the EU Data Act might be considered by auditors as part of their risk assessment for revenue.
This would include determining whether new risks of material misstatement are present and evaluating fraud risk assessment conclusions in view of potential impacts to the entity’s key performance indicators resulting from the EU Data Act.
Digital Operational Resilience Act
The Digital Operational Resilience Act (DORA) took effect on 17 January 2025, enforcing strict, harmonised information and communication technology (ICT) security standards across the financial sector.
Under DORA, critical ICT third-party providers are subject to direct EU-level oversight to ensure that the financial sector remains secure and resilient against ICT disruptions.
Article 2 of the Delegated Regulation (EU) 2024/1505 supplementing Regulation (EU) 2022/2554 covers the specific requirements regarding applicable turnover of critical ICT third-party service providers for the calculation of oversight fees.
It notes that turnover figures provided by third-party ICT service providers, to support the calculation of oversight fees, should be audited to ensure the accuracy of the financial information needed to calculate the associated oversight fees.
Similar to the EU Data Act, DORA applies to all EU Member States, including Ireland.
A technical alert on engagements related to DORA oversight fees issued by Chartered Accountants Ireland will provide relevant guidance to auditors.
Public Country by Country Reporting
The EU Public Country-by-Country Reporting Directive (EU Public CbCR) has been transposed into Irish company law via Statutory Instrument (S.I.) No. 322/2023 – European Union (Disclosure of Income Tax Information by Certain Undertakings and Branches) Regulations 2023.
These regulations require certain entities with annual revenue of more than €750 million to publish a report on income tax information.
The country-by-country report must be published within one year of the undertaking’s financial year-end and be made publicly available.
Regulation 17 in S.I. No. 322/2023 requires that – where the auditor’s report is prepared in accordance with the Companies Act 2014 for financial years beginning on or after 22 June 2025 – the statutory auditors’ report must include a statement on whether the entity was required to publish a report on income tax information for the financial year preceding that to which the auditor’s report relates.
If the entity was required to publish a report, the auditor’s report must also state whether or not it was published in accordance with the regulations outlined in S.I. No. 322/2023.
To assist auditors, IAASA’s Compendium of Illustrative Auditor’s Reports contains examples of relevant wording for audit reports, which may be used for the statement required by Regulation 17.

EmpCo
The Empowering Consumers for the Green Transition (EmpCo) Directive is an EU law against greenwashing and early obsolescence.
EmpCo has been transposed into Irish company law via Statutory Instrument (S.I.) No. 124/2026 – European Union (Empowering Consumers for the Green Transition) Regulations 2026, effective from 27 September 2026.
EmpCo has been introduced as a consumer protection measure:
• to address greenwashing in business-to-consumer communications;
• introduce changes to some existing consumer protection/unfair trade practices legislation; and
• prohibit generic environmental claims without recognised levels of excellence in environmental performance.
These regulations require the relevant entities to set out clear, objective, publicly available and verifiable commitments as part of a detailed and realistic implementation plan that includes measurable and time-bound targets and other relevant elements necessary to support their implementation.
The regulations also foresee that environmental claims should be regularly verified by an independent third-party expert, whose findings are made available to consumers.
The European Commission’s FAQs provide guidance (in response to Question 12), noting that this expert must be independent from the trader, free from conflicts of interest and possess experience and competence in environmental issues.
EmpCo does not specify whether the expert is required to be a public authority or a private entity. In practice, private auditors or consultancy companies can serve this role.
Overarching auditor’s responsibilities
For the relevant entities, the introduction of the EU Data Act, DORA, Public CbCR rules and EmpCo represent an opportunity as much as a challenge.
For auditors, in the audit of financial statements, the responsibility is to consider compliance with the relevant laws and regulations within financial statements, and to identify material misstatement resulting from noncompliance with laws and regulations in accordance with the auditing standards.
Arpan Bajaj is Director, Audit and Assurance Quality at Deloitte Ireland. He is a member of the Assurance and Audit Technical Committee and the Business Law Committee at Chartered Accountants Ireland