Compliance & Frameworks
No regulation says the word TSCM. Several make you accountable for exactly what it controls. Framework by framework, here is where technical surveillance risk sits in the obligations you already carry — with primary sources cited.
European Union
NIS2 and Technical Surveillance Risk
NIS2 requires essential and important entities to protect the physical environment of their information systems on an all-hazards basis. Here is where covert surveillance and eavesdropping risk fits Article 21, what management bodies are personally accountable for, and what a defensible TSCM control looks like.
→United Kingdom
The UK Corporate Governance Code and Surveillance Risk
From financial years beginning on or after 1 January 2026, boards of premium-listed companies are expected to declare the effectiveness of their material internal controls under Provision 29 of the 2024 Code. The confidentiality of the boardroom itself is a control most companies have never tested.
→United Kingdom
UK GDPR Article 32 and Covert Surveillance of Personal Data
Article 32 requires security measures appropriate to the risk — including the confidentiality of processing. Spoken personal data in HR meetings, medical discussions and grievance hearings is processing too, and a covert device in the room is a personal data breach.
→International standard
ISO 27001 and Technical Surveillance Risk
ISO/IEC 27001:2022 does not say the word TSCM — but its risk assessment clause and Annex A physical controls leave certified organisations little room to ignore covert surveillance of the rooms where sensitive information is spoken.
→US framework guidance lives on the US edition of this site.
Switch edition →This guidance is general information, not legal advice. Regulatory obligations depend on your entity classification, jurisdiction and facts — confirm specifics with your counsel or compliance function.