Institute for Europe
Regulation Guide Last updated: Oct 2024

EU ESG Reporting Frameworks (CSRD)

Navigating the Corporate Sustainability Reporting Directive and European Sustainability Reporting Standards.

1. Overview

The European Union's approach to regulation is built on a specific philosophical foundation: protecting fundamental rights (like privacy and non-discrimination) while harmonising the single market. The EU ESG Reporting Frameworks (CSRD) is the latest manifestation of this approach.

Unlike directives, which require member states to draft their own national laws, a regulation (like the GDPR or AI Act) is a binding legislative act. It must be applied in its entirety across the EU from its effective date.

Key Figures & Dates

  • Status: Active (Entered into force)
  • Adopted: European Parliament & Council
  • Official Text: EUR-Lex Reference

2. Scope & Applicability (The "Brussels Effect")

A common mistake is assuming that EU regulations only apply to companies headquartered in Paris or Berlin. In reality, the EU ESG Reporting Frameworks (CSRD) applies extra-territorially based on market targeting.

If your company offers goods or services to data subjects or consumers situated in the Union, or monitors their behavior as far as their behavior takes place within the Union, you are in scope. This applies even if you have zero physical presence, employees, or servers in Europe.

3. Core Requirements

Compliance requires significant operational changes, not just an updated privacy policy or terms of service.

Obligation Description Deadline
Risk Assessment Conduct mandatory fundamental rights impact assessments prior to deployment. Pre-launch
Incident Reporting Notify the relevant national competent authority of severe breaches. 72 hours
Data Governance Maintain strict records of processing activities and data provenance. Ongoing

4. Fines & Penalties

The EU enforces its digital and sustainability regulations using a dual-tier fine structure tied to global annual turnover, not just EU revenue.

  • Tier 1 Infringements: Up to €10 million or 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher.
  • Tier 2 Infringements (Core principles): Up to €20 million or 4% of the total worldwide annual turnover.

See the regulatory fines database for historical context on how these maximums are applied in practice by authorities like the Irish DPC or French CNIL.

5. Frequently Asked Questions

Are small enterprises exempt?

Usually not completely, but obligations scale proportionately. SMEs often benefit from exemptions regarding the mandatory appointment of certain officers (like a DPO) or reduced documentation burdens, provided their core processing isn't high-risk.

Which National Competent Authority do I report to?

Under the "One-Stop-Shop" mechanism, if you have a main establishment in the EU, you deal primarily with that country's authority. If you have no EU presence, you must appoint an Article 27 Representative in a member state where your users are based, and that authority takes lead.