PRACTICE
IT-Law & Compliance
Technology contracts, regulatory compliance, and AI governance. Legal advisory that understands both the contract and the code.
Regulation in layers
Technology now sits under an interwoven net of rules. The EU AI Act, NIS2, DORA, ISO 27001, the GDPR, and sectoral oversight frameworks act on each other. Contracts with SaaS providers, cloud vendors, and AI suppliers must carry this entire net; controls must work in production; and boards must be able to show that direction has been taken.
Rijker Advisory works at the intersection of contract, regulation, and implementation. Every piece of advice understands both the legal obligation and the operational reality in which that obligation must be delivered.
Contracts & technology
- SaaS, cloud, and licensing agreements: drafting, review, and negotiation.
- Procurement support for technology tenders and vendor selection.
- Open source compliance and licence auditing.
- Technical due diligence in mergers, acquisitions, and investments.
- Data arrangements between parties, including cross-border data sharing and joint controllership.
Regulatory compliance
- NIS2 implementation: scope determination, risk management, incident reporting, and supply chain controls.
- DORA: ICT risk management, incident classification, third-party management, and operational resilience testing.
- ISO 27001 implementation and certification, including scope definition, control selection, and audit preparation.
- BIO2 for the Dutch public sector, including control mapping and management measures.
- Board-level cyber reporting: risk registers, KPIs, and governance reporting lines.
AI Governance
- EU AI Act compliance: risk classification, high-risk system obligations, transparency, and human oversight.
- FRIA: Fundamental Rights Impact Assessment for government use of AI.
- AI register and inventory of internal and external AI use within the organisation.
- Shadow AI policy: detection, frameworks, and risk mitigation for unapproved AI tools.
- Preparation for ISO 42001 and NIST AI RMF implementation.
Frameworks
EU AI Act · NIS2 Directive · DORA Regulation · ISO 27001 · ISO 42001 · NIST AI RMF · GDPR · UAVG · BIO2 · sectoral supervisory frameworks of AFM, DNB, ACM, and the Dutch Data Protection Authority.
Relevant credentials
CIPP/E · CIPM · CIPT · FIP · CISM · CRISC · ISO 27001 Implementer · CEH · Registered DPO · LLM Technology Law (University of Groningen).