mcp-eu-compliance
# mcp-eu-compliance
**MCP** server exposing an **offline corpus of EU law** (EUR-Lex, full text) in local **SQLite FTS5**, with compliance tools. Snippets returned **verbatim** from the database (zero-LLM) - each with a **CELEX** id and EUR-Lex URL. Anti-hallucination by mechanism, not by trust in the model.
**Scope (14 regulations, digital/data/cyber):** GDPR, AI Act, DORA, NIS2, eIDAS 2.0, CRA, DSA, DMA, Data Act, DGA, LED, ePrivacy, Cybersecurity Act, CER.
Complementary to [`mcp-eu-sparql`](https://github.com/matematicsolutions/mcp-eu-sparql): that one discovers acts live (SPARQL Cellar), this one provides verbatim text + offline compliance analysis (no network at runtime).
## Installation
```bash
npm install # Node 22.5+ (node:sqlite built-in)
npm run fetch-corpus # downloads regulations.db (~36 MB) from Ansvar (Apache-2.0)
npm run build
npm start
```
Configuration in the MCP client (e.g. `mcp-servers.json`):
```json
{
"name": "eu-compliance",
"command": "node",
"args": ["/path/to/mcp-eu-compliance/dist/index.js"]
}
```
## Tools
| Tool | Description |
|---|---|
| `eu_search(query, regulations?, limit?)` | Full-text (FTS5) across articles, verbatim snippets. |
| `eu_article(regulation, article_number)` | Full article text + title + chapter + CELEX. |
| `eu_compare(query, regulations?)` | The same topic across several regulations at once (e.g. incident reporting DORA vs NIS2 vs CRA). |
| `eu_check_applicability(sector, subsector?)` | Which of the 14 regulations apply to a sector, with confidence level and basis article. |
| `eu_evidence(regulation, article?)` | Evidence artifacts (audit) - which document/log/certificate proves compliance. |
Each tool returns `structuredContent.citations` (regulation, CELEX, EUR-Lex URL, snapshot).
## Examples
- "Compare incident reporting timelines across DORA, NIS2, and CRA" -> `eu_compare`
- "What does GDPR Article 33 require?" -> `eu_article`
- "Which EU regulations apply to a bank?" -> `eu_check_applicability(sector=financial, subsector=bank)`
- "What audit evidence does DORA Article 17 require?" -> `eu_evidence`
## Disclaimers
- **Snapshot, not the authentic source.** The authentic version = Official Journal of the EU. The connector returns a point-in-time snapshot; verify currency in EUR-Lex (CELEX). Freshness -> `mcp-eu-sparql` (live).
- **Applicability rules are expert guidance**, not a binding legal assessment. Sector-specific realities may require your own analysis.
- **Reference material, not legal advice.**
## License and attribution
- **Code:** MIT - see [LICENSE](./LICENSE).
- **Corpus:** EUR-Lex content (reusable, Decision 2011/833/EU) + database file from [Ansvar-Systems/EU_compliance_MCP](https://github.com/Ansvar-Systems/EU_compliance_MCP) (Apache-2.0). Details: [THIRD_PARTY_INSPIRATIONS.md](./THIRD_PARTY_INSPIRATIONS.md).
Citation: *MateMatic Solutions (2026), mcp-eu-compliance, https://github.com/matematicsolutions/mcp-eu-compliance, MIT.*
TDQS
Scored across 5 tools
Each tool has a clearly distinct purpose: eu_article retrieves a specific article by ID, eu_check_applicability determines which regulations apply to a sector, eu_compare compares topics across regulations, eu_evidence provides audit evidence, and eu_search performs full-text search. There is no ambiguity between them.
All tools use the 'eu_' prefix, but the second part mixes verb and noun forms (e.g., eu_article vs eu_check_applicability). While readable and predictable, the pattern is not perfectly consistent, which lowers the score slightly.
With 5 tools, the server is well-scoped for its purpose of querying EU compliance regulations. Each tool provides essential functionality without redundancy or unnecessary bloat.
The tool set covers key operations: retrieving articles, checking applicability, comparing regulations, obtaining evidence, and searching. Missing a tool to list all articles by regulation, but that can be approximated via search. Minor gap, but overall coverage is solid.