Resources

GDPR explained,
simply.

Plain-language guides for European business owners — no legal degree required. Cookie compliance, breach notification, AI governance, and what's actually changing in GDPR enforcement.

19 articles

Everything we've written
on GDPR and the AI Act.

Plain-language guides for European business owners — no legal degree required. Newest first.

AI Governance & GDPR
GDPR in the AI era: what 2026 is teaching compliance teams
Cumulative GDPR fines have passed €7 billion and the Digital Omnibus could make "legitimate interest" a legal basis for AI training. Here's what 2026 is actually teaching compliance teams.
August 2026
8 min read →
Data Security & GDPR Tools
Is a VPN Mandatory Under the GDPR?
The GDPR never names a VPN as required — Article 32 asks for risk-based security instead. What that actually means for EU businesses.
August 2026
7 min read →
Data Security & GDPR Tools
How a VPN Strengthens GDPR Compliance in 2026
IP protection, Article 32 encryption, and secure remote access — a practical guide to where a VPN fits into your GDPR compliance stack.
August 2026
6 min read →
AI Tools & GDPR
Your AI chatbot isn't anonymising anything
The EDPB says AI models are rarely anonymous — so the chatbot, CRM assistant and note-taker you already run need a DPIA, a legal basis and a disclosure of their own.
August 2026
9 min read
Industry Benchmark
GDPR Compliance Benchmark 2026: Readiness Scores by Industry
A composite GDPR readiness score for six industries, built from Verizon's 2026 breach data and CMS's 2026 GDPR fine tracker — full methodology and sources.
August 2026
10 min read →
AI & GDPR Compliance
AI Is 2026's Biggest GDPR Compliance Risk
Legitimate interest assessments, mandatory DPIAs for biometric AI, and Ireland's Grok inquiry show why AI has become GDPR's single largest source of risk in 2026.
August 2026
9 min read →
AI Training Data & GDPR
The "It Was Public" Excuse Is Over: GDPR Now Formally Covers AI Training Data
The EDPB's new guidelines end the assumption that scraped public data is fair game for AI training — with no grace period for datasets collected years ago.
August 2026
8 min read →
AI & GDPR Enforcement
Forget the AI Act — GDPR is already fining companies for AI mistakes
Three recent cases — Clearview AI (€30.5M), a German fintech (€492K), and Replika (€5M) — show regulators using GDPR, not the AI Act, to punish exactly the kind of AI mistakes any business could make.
August 2026
7 min read →
EU-US Data Transfers
Is “Schrems III” coming? A Supreme Court ruling shakes the Data Privacy Framework
A June 2026 ruling stripped FTC commissioners of removal protections — a pillar the EU cited 259 times to justify the EU-US Data Privacy Framework. Here's what's actually at risk.
August 2026
7 min read →
Digital Omnibus & GDPR Reform
Inside the EU's Digital Omnibus: what's actually changing for GDPR, and what just stalled
The Digital Omnibus would raise the RoPA exemption to 750 employees, add a one-click cookie reject button, and clarify AI legitimate interest. Only one of those three survived June's Council talks.
August 2026
9 min read →
GDPR Enforcement & Reform
GDPR in 2026: record fines, a reform in motion, and what to do now
GDPR fines have passed €7.1 billion and the EU's Digital Omnibus is rewriting cookie consent, breach notification, and DPIA rules. Here's what's actually changed, and what's still just a proposal.
August 2026
9 min read →
EU AI Act & GDPR
The AI Act just went live for high-risk systems — now you have two regulators
Since August 2, 2026, two separate EU penalty regimes apply in parallel to the same activity: processing personal data through an AI system. Where they overlap, and where they collide.
August 2026
8 min read →
AI & Business Strategy
AI news and insights: what's actually driving AI-driven business growth
AI spending will hit $2.59 trillion in 2026 — but only 5% of companies say their data is ready for it. What the latest numbers mean for your business.
July 2026
9 min read →
AI Governance
Why every SaaS company needs a DPIA before launching AI features
AI features change how a SaaS product collects, interprets and acts on personal data. A Data Protection Impact Assessment catches overcollection, permission leaks and output risk while they're still cheap to fix.
July 2026
7 min read →
EU AI Act
The AI Act delay doesn't cover your chatbot
The AI Act's high-risk rules were delayed to December 2027 — but Article 50's chatbot and AI-content transparency rules were not. Here's what still applies from August 2, 2026.
July 2026
8 min read →
Common Mistakes
The 10 biggest GDPR mistakes small businesses make
From over-collecting data to skipping a privacy policy entirely — the 10 most common (and costly) GDPR mistakes we see European SMBs make, and the practical steps to fix each one.
July 2026
9 min read →
Small Business Guide
Is my small business required to comply with GDPR?
"We're too small for GDPR" is one of the most common — and costly — misconceptions among European SMBs. Here's who actually needs to comply, and what it requires.
June 2026
11 min read →
Cookie Compliance
The 5 most common cookie banner mistakes — and how to fix them
78% of European SMB websites have illegal cookie banners. Most violations are simple to fix. We break down the Planet49 ECJ ruling and what it means for your website today.
June 2026
4 min read →
GDPR Basics
What is GDPR and does it apply to your small business?
GDPR applies to every business that processes data of EU residents — regardless of size or location. Here's what that means in practice, and the 5 things you need to do first.
June 2026
5 min read →
No articles match your search Try a different keyword, or clear the search.
Page 1 of 4
More guides coming soon · Get in touch →