ABOUT OSTRAI

A specialist European practice for technology regulation, standards and market access.

OSTRAI works across law, standards, governance, implementation and market access.

We advise on the regulatory frameworks governing digital services, artificial intelligence, cybersecurity, data, connected products and access to European markets.

Our work combines legal and regulatory analysis, implementation, standardisation intelligence, conformity and regulatory representation. This allows us to address regulatory questions across disciplines that increasingly overlap rather than treating each framework as a separate compliance exercise.

Sunlit Mediterranean cloister reflected in a still courtyard pool

WHAT DISTINGUISHES OSTRAI

A broader view of technology regulation.

European technology regulation is no longer divided neatly between privacy, cybersecurity, product compliance, digital regulation and artificial intelligence.

A single product, service or business model can engage several of those frameworks at the same time, together with technical standards, national implementation rules and regulatory authorities.

OSTRAI works across those intersections.

  1. REGULATORY DEPTH

    Specialist work across European technology regulation rather than a general advisory model.

  2. STANDARDISATION INTELLIGENCE

    Direct participation in European and international standardisation, combined with analysis of published standards, harmonisation and regulatory implementation.

  3. IMPLEMENTATION

    Advice that extends from legal interpretation into governance, controls, evidence, conformity and operational readiness.

  4. REGULATORY INTERFACE

    Experience with representative mandates, regulatory authorities, supervision, market access and cross-border implementation.

OUR EVOLUTION

Privacy Minders became OSTRAI when the name no longer reflected the work.

OSTRAI is the continuation of Privacy Minders.

Privacy and data protection were the foundation of the practice, but the work had already expanded substantially beyond those fields.

By the time OSTRAI was created, the practice was advising across artificial intelligence, cybersecurity, digital regulation, product regulation, regulatory representation, market access, standards and implementation.

The rebrand therefore did not mark a change in direction. It gave the practice an identity that better reflected the breadth of work already being carried out.

PRIVACY MINDERS

Privacy · Data protection · Regulatory compliance

OSTRAI

Technology regulation · Standards · Implementation · Market access

Privacy and data remain core areas of OSTRAI. They now sit within a broader technology-regulation practice.

REGULATORY INTELLIGENCE

Understanding regulation as it develops.

Technology regulation develops across policy, legislation, implementation, standards and regulatory practice.

Implementing and delegated acts, national transposition, regulatory guidance, standards requests, European and international standards, conformity frameworks and supervisory practice can all affect how regulatory requirements are interpreted and implemented.

OSTRAI follows the regulatory environment from policy formation and legislative development through implementation, standardisation, conformity and practical impact.

This allows us to understand not only the law in force, but also the direction in which regulatory requirements are developing and how different initiatives may interact.

  1. POLICY & REGULATORY DIRECTION

    Strategies · Legislative proposals · Policy initiatives · Institutional priorities · Geopolitical context · Regulatory interactions

  2. LAW

    Regulations · Directives · National implementation

  3. REGULATORY DEVELOPMENT

    Implementing acts · Delegated acts · Guidance · Authority practice

  4. STANDARDISATION

    Standards requests · Standards development · European standards · Technical specifications

  5. HARMONISATION & CONFORMITY

    OJEU citation · Regulatory effect · Evidence · Market access

  6. CLIENT IMPACT

    Scope · Governance · Product design · Controls · Documentation · Representation

OSTRAI brings these layers together to understand the current regulatory position, the direction of implementation and the questions organisations need to prepare for as the framework develops.

STANDARDISATION

Standards are part of the regulatory picture.

OSTRAI participates directly in European and international standardisation environments relevant to cybersecurity, artificial intelligence, privacy engineering, digital regulation and technology products.

Our participation in European and international standardisation is undertaken in relevant expert, drafting and institutional capacities.

It gives OSTRAI a close understanding of the technical and implementation questions that accompany emerging regulatory frameworks.

We combine that perspective with analysis of legislation, published standards, harmonisation status, regulatory guidance and conformity requirements.

  1. REGULATORY REQUIREMENT

    What does the legislation require?

  2. TECHNICAL INTERPRETATION

    How is the requirement translated into technical or operational terms?

  3. STANDARDISATION

    Which standards and technical specifications are relevant?

  4. REGULATORY EFFECT

    What is their legal or conformity relevance?

  5. IMPLEMENTATION

    What should the organisation actually prepare, implement or evidence?

Explore Standards & Standardisation

CROSS-REGULATORY PRACTICE

Technology regulation operates across intersecting regimes.

Products, services and business models increasingly sit across several technology-regulation frameworks at once.

  1. AI SYSTEMS

    AI Act · GDPR · Cybersecurity · Standards

  2. CONNECTED PRODUCTS

    CRA · Product regulation · Data Act · AI · Privacy

  3. PLATFORMS & DIGITAL SERVICES

    DSA · NIS2 · GDPR · Advertising · Consumer regulation

  4. CLOUD & DIGITAL INFRASTRUCTURE

    NIS2 · Data Act · GDPR · e-Evidence

  5. EU MARKET ACCESS

    Conformity · Economic operators · Representation · Standards

  6. REGULATORY REPRESENTATION

    Appointment · Compliance · Regulatory interface · Liability

OSTRAI analyses the regulatory position across the relevant frameworks before determining the appropriate implementation path.

HOW WE WORK

From regulatory position to implementation.

  1. DETERMINE THE FRAMEWORK

    Scope · Classification · Jurisdiction · Applicable rules

  2. IDENTIFY THE REQUIREMENTS

    Legal obligations · Standards · Guidance · National implementation

  3. DESIGN THE RESPONSE

    Governance · Controls · Contracts · Evidence · Conformity

  4. IMPLEMENT

    Policies · Processes · Product requirements · Regulatory arrangements

  5. MAINTAIN

    Monitoring · Regulatory change · Standards development · Continuing compliance

Our aim is not to produce regulatory documentation for its own sake. It is to establish a defensible regulatory position that can operate in practice.

INDEPENDENT JUDGEMENT

The regulatory position comes first.

OSTRAI assesses the applicable framework, underlying compliance position, implementation readiness and regulatory risk before recommending a course of action.

This is particularly important where an engagement involves formal regulatory responsibilities, market-facing roles, material compliance dependencies or heightened regulatory exposure.

The regulatory position determines the engagement, not the other way around.

EUROPEAN PRACTICE

European regulation. International businesses.

OSTRAI is based in Cyprus and works with organisations operating across European and international markets.

Our work frequently involves businesses established outside the European Union that need to understand European regulatory requirements, enter the European market, establish regulatory representation or coordinate EU obligations with other legal frameworks.

  1. EUROPE

    Technology regulation · Standards · Conformity · Regulatory interface

  2. UNITED KINGDOM

    Privacy · UK regulatory representation · Regulatory coordination

  3. MIDDLE EAST

    Privacy · Digital regulation · Multi-jurisdiction programmes

  4. CROSS-BORDER MARKET ACCESS

    European market access · Regulatory representation · Multi-jurisdiction implementation

Maria Raphael, Founder and Managing Director of OSTRAI

LEADERSHIP

Maria Raphael

Founder & Managing Director

LinkedIn ↗

Maria Raphael founded OSTRAI and leads its regulatory advisory, representation and standardisation work.

Her work focuses on the intersection of regulation, technology, standards and market access, with experience across privacy and data protection, artificial intelligence, cybersecurity, digital regulation and European regulatory frameworks.

She participates directly in European and international standardisation and regulatory environments, combining legal and regulatory analysis with practical experience in implementation, representation, conformity and market access.

EXPERTISE

Specialist work across the technology-regulation lifecycle.

  1. AI & DIGITAL REGULATION

  2. CYBERSECURITY & RESILIENCE

  3. PRIVACY & DATA

  4. MARKET ACCESS

  5. STANDARDS

Explore all expertise

OSTRAI

Specialist regulatory work for technology businesses operating in Europe.

From regulatory scope and implementation to standards, conformity, market access and regulatory representation.