ABOUT OSTRAI
A specialist European practice for technology regulation, standards and market access.
OSTRAI works across law, standards, governance, implementation and market access.
We advise on the regulatory frameworks governing digital services, artificial intelligence, cybersecurity, data, connected products and access to European markets.
Our work combines legal and regulatory analysis, implementation, standardisation intelligence, conformity and regulatory representation. This allows us to address regulatory questions across disciplines that increasingly overlap rather than treating each framework as a separate compliance exercise.

WHAT DISTINGUISHES OSTRAI
A broader view of technology regulation.
European technology regulation is no longer divided neatly between privacy, cybersecurity, product compliance, digital regulation and artificial intelligence.
A single product, service or business model can engage several of those frameworks at the same time, together with technical standards, national implementation rules and regulatory authorities.
OSTRAI works across those intersections.
REGULATORY DEPTH
Specialist work across European technology regulation rather than a general advisory model.
STANDARDISATION INTELLIGENCE
Direct participation in European and international standardisation, combined with analysis of published standards, harmonisation and regulatory implementation.
IMPLEMENTATION
Advice that extends from legal interpretation into governance, controls, evidence, conformity and operational readiness.
REGULATORY INTERFACE
Experience with representative mandates, regulatory authorities, supervision, market access and cross-border implementation.
OUR EVOLUTION
Privacy Minders became OSTRAI when the name no longer reflected the work.
OSTRAI is the continuation of Privacy Minders.
Privacy and data protection were the foundation of the practice, but the work had already expanded substantially beyond those fields.
By the time OSTRAI was created, the practice was advising across artificial intelligence, cybersecurity, digital regulation, product regulation, regulatory representation, market access, standards and implementation.
The rebrand therefore did not mark a change in direction. It gave the practice an identity that better reflected the breadth of work already being carried out.
PRIVACY MINDERS
Privacy · Data protection · Regulatory compliance
OSTRAI
Technology regulation · Standards · Implementation · Market access
Privacy and data remain core areas of OSTRAI. They now sit within a broader technology-regulation practice.
OUR RELATIONSHIP WITH RAPHAEL LEGAL
Sister practices. Complementary capabilities.
OSTRAI and Raphael Legal are separate sister practices under the common leadership of Maria Raphael, Founder & Managing Director of OSTRAI and Managing Partner of Raphael Legal. They have distinct but complementary areas of work.
OSTRAI focuses on technology regulation, standards, regulatory implementation, conformity, market access and regulatory representation. Raphael Legal provides broader legal, transactional and contentious services.
Where a matter spans both regulatory and broader legal issues, the two practices can work alongside one another under separate scopes of engagement.
Our legal background gives us a close understanding of how regulatory obligations interact with liability, enforcement exposure and contractual risk. We bring that perspective into regulatory implementation, standards, conformity, market access and representation.
REGULATORY INTELLIGENCE
Understanding regulation as it develops.
Technology regulation develops across policy, legislation, implementation, standards and regulatory practice.
Implementing and delegated acts, national transposition, regulatory guidance, standards requests, European and international standards, conformity frameworks and supervisory practice can all affect how regulatory requirements are interpreted and implemented.
OSTRAI follows the regulatory environment from policy formation and legislative development through implementation, standardisation, conformity and practical impact.
This allows us to understand not only the law in force, but also the direction in which regulatory requirements are developing and how different initiatives may interact.
POLICY & REGULATORY DIRECTION
Strategies · Legislative proposals · Policy initiatives · Institutional priorities · Geopolitical context · Regulatory interactions
LAW
Regulations · Directives · National implementation
REGULATORY DEVELOPMENT
Implementing acts · Delegated acts · Guidance · Authority practice
STANDARDISATION
Standards requests · Standards development · European standards · Technical specifications
HARMONISATION & CONFORMITY
OJEU citation · Regulatory effect · Evidence · Market access
CLIENT IMPACT
Scope · Governance · Product design · Controls · Documentation · Representation
OSTRAI brings these layers together to understand the current regulatory position, the direction of implementation and the questions organisations need to prepare for as the framework develops.
STANDARDISATION
Standards are part of the regulatory picture.
OSTRAI participates directly in European and international standardisation environments relevant to cybersecurity, artificial intelligence, privacy engineering, digital regulation and technology products.
Our participation in European and international standardisation is undertaken in relevant expert, drafting and institutional capacities.
It gives OSTRAI a close understanding of the technical and implementation questions that accompany emerging regulatory frameworks.
We combine that perspective with analysis of legislation, published standards, harmonisation status, regulatory guidance and conformity requirements.
REGULATORY REQUIREMENT
What does the legislation require?
TECHNICAL INTERPRETATION
How is the requirement translated into technical or operational terms?
STANDARDISATION
Which standards and technical specifications are relevant?
REGULATORY EFFECT
What is their legal or conformity relevance?
IMPLEMENTATION
What should the organisation actually prepare, implement or evidence?
CROSS-REGULATORY PRACTICE
Technology regulation operates across intersecting regimes.
Products, services and business models increasingly sit across several technology-regulation frameworks at once.
AI SYSTEMS
AI Act · GDPR · Cybersecurity · Standards
CONNECTED PRODUCTS
CRA · Product regulation · Data Act · AI · Privacy
PLATFORMS & DIGITAL SERVICES
DSA · NIS2 · GDPR · Advertising · Consumer regulation
CLOUD & DIGITAL INFRASTRUCTURE
NIS2 · Data Act · GDPR · e-Evidence
EU MARKET ACCESS
Conformity · Economic operators · Representation · Standards
REGULATORY REPRESENTATION
Appointment · Compliance · Regulatory interface · Liability
OSTRAI analyses the regulatory position across the relevant frameworks before determining the appropriate implementation path.
HOW WE WORK
From regulatory position to implementation.
DETERMINE THE FRAMEWORK
Scope · Classification · Jurisdiction · Applicable rules
IDENTIFY THE REQUIREMENTS
Legal obligations · Standards · Guidance · National implementation
DESIGN THE RESPONSE
Governance · Controls · Contracts · Evidence · Conformity
IMPLEMENT
Policies · Processes · Product requirements · Regulatory arrangements
MAINTAIN
Monitoring · Regulatory change · Standards development · Continuing compliance
Our aim is not to produce regulatory documentation for its own sake. It is to establish a defensible regulatory position that can operate in practice.
INDEPENDENT JUDGEMENT
The regulatory position comes first.
OSTRAI assesses the applicable framework, underlying compliance position, implementation readiness and regulatory risk before recommending a course of action.
This is particularly important where an engagement involves formal regulatory responsibilities, market-facing roles, material compliance dependencies or heightened regulatory exposure.
The regulatory position determines the engagement, not the other way around.
EUROPEAN PRACTICE
European regulation. International businesses.
OSTRAI is based in Cyprus and works with organisations operating across European and international markets.
Our work frequently involves businesses established outside the European Union that need to understand European regulatory requirements, enter the European market, establish regulatory representation or coordinate EU obligations with other legal frameworks.
EUROPE
Technology regulation · Standards · Conformity · Regulatory interface
UNITED KINGDOM
Privacy · UK regulatory representation · Regulatory coordination
MIDDLE EAST
Privacy · Digital regulation · Multi-jurisdiction programmes
CROSS-BORDER MARKET ACCESS
European market access · Regulatory representation · Multi-jurisdiction implementation

LEADERSHIP
Maria Raphael
Founder & Managing Director
LinkedIn ↗Maria Raphael founded OSTRAI and leads its regulatory advisory, representation and standardisation work.
Her work focuses on the intersection of regulation, technology, standards and market access, with experience across privacy and data protection, artificial intelligence, cybersecurity, digital regulation and European regulatory frameworks.
She participates directly in European and international standardisation and regulatory environments, combining legal and regulatory analysis with practical experience in implementation, representation, conformity and market access.
EXPERTISE
Specialist work across the technology-regulation lifecycle.
AI & DIGITAL REGULATION
CYBERSECURITY & RESILIENCE
PRIVACY & DATA
MARKET ACCESS
STANDARDS
OSTRAI
Specialist regulatory work for technology businesses operating in Europe.
From regulatory scope and implementation to standards, conformity, market access and regulatory representation.
