The problem isn't that you haven't read enough. It's that nothing tells you what to do on Monday.
Long compliance books explain the law well and leave you exactly where you started: knowing more, holding nothing. Each of these takes a single operational question and follows it to the artefact at the end.
One question per guide
Each kit answers a single question end to end. Read the one that matches this week's problem and leave the other six until they matter.
Written for 2026, not 2018
The AI Act timeline, the Digital Omnibus negotiations and current enforcement reality — not the launch-week panic that most GDPR material still repeats.
Ends in an artefact
A vendor questionnaire, a response timeline, a one-page AI policy, an audit log. Something that exists when you close the file.
Seven questions, seven straight answers.
Sold as one collection — every guide below is included, delivered together as seven PDFs.
The European Solopreneur Compliance Stack
- The minimum viable compliance stack for a business with no legal team and no budget for one
- What you can defensibly skip when you are one person — and what you genuinely cannot
- The order to do things in, so the first week of effort covers the biggest exposure
- A one-page record set that satisfies the accountability principle without a documentation project
The AI Vendor Vetting Checklist
- The questions that establish whether your vendor is a processor or quietly a controller
- Training-data, retention and model-improvement questions vendors routinely leave unanswered
- Sub-processor chains and international transfers — what to ask and what evidence to keep
- A scoring sheet you can attach to the procurement decision as your Art. 28 diligence record
The DSAR Response Kit
- When the one-month clock actually starts, and the narrow cases where the extension applies
- Identity verification calibrated to genuine doubt, instead of blanket ID demands
- Six copy-paste response templates covering acknowledgement, extension, refusal and disclosure
- A tracking log so requests stop living in a shared inbox with no named owner
The Shadow AI Audit Kit
- How to discover the AI tools already in use, without a surveillance exercise that destroys trust
- Assessing what you find on risk, not on how it was discovered
- One page of policy that people will actually follow, instead of a ban they will route around
- An approval path that converts a blind spot into a supported, budgeted tool
EU AI Act, Without the Scare Tactics
- Which risk tier your use actually falls in — most small-team AI use is not high-risk
- Why the €35M / 7% headline applies to prohibited practices, not to most obligations
- Transparency duties under Art. 50, and how they sit alongside GDPR Art. 12–14
- What an SME genuinely owes, and the lower penalty ceiling that applies to it
GDPR Myths That Could Cost You €20M
- "We're too small for GDPR" and "we have no EU office" — why neither is an exemption
- Consent as a default legal basis, and the cases where it is the weakest option available
- Anonymised data that is not anonymous, and privacy policies mistaken for compliance
- The real compliance minimum: five artefacts, none of which need a consultant
The Digital Omnibus, Explained
- Why "the Digital Omnibus" refers to two packages that are routinely conflated
- What is already in force and binding on you today
- What is still in negotiation, and therefore not something to rebuild your processes around
- How to plan while the file moves, without betting on an outcome
Seven guides. One payment.
The questions that come up first when a small European business starts taking GDPR and the AI Act seriously — vendors, data requests, shadow AI, and the myths that send people in the wrong direction. Answered once, kept on your drive.
- The European Solopreneur Compliance Stack — 15 pages
- The AI Vendor Vetting Checklist — 12 pages
- The DSAR Response Kit — 15 pages
- The Shadow AI Audit Kit — 12 pages
- EU AI Act, Without the Scare Tactics — 15 pages
- GDPR Myths That Could Cost You €20M — 15 pages
- The Digital Omnibus, Explained — 13 pages
Before you ask —
What do I actually receive, and how?
Seven PDF guides, 97 pages in total, delivered together. Your download page appears immediately after checkout — nothing to wait for and no account to create.
Can I buy just one guide?
Yes — every guide has its own "Buy this guide" button for €9. Seven bought individually comes to €63; the Field Kit bundles all seven for €39, about 38% less.
How is this different from the Professional Compliance Series?
The Series is five long, sector-specific books — marketing, e-commerce, SaaS, HR, healthcare — each covering one industry in depth. The Field Kit is the opposite shape: seven short guides, each answering one operational question that applies whatever sector you are in.
Does it cover the EU AI Act as well as GDPR?
Yes. Three of the seven are AI Act-first — vendor due diligence, the risk tiers and penalty myths, and shadow AI inside your own team — and the Solopreneur Stack treats both regulations as one workflow, which is how they actually land on a small business.
I already bought the SAR Response Toolkit. Is the DSAR guide redundant?
They do different jobs. The SAR Response Toolkit is the editable document set — registers, letters, investigation worksheets. The DSAR Response Kit in this collection is the workflow and deadline logic around them: when the clock starts, when the extension applies, who owns the request. Useful together, and neither replaces the other.
Is this legal advice?
No. These are educational guides written by a compliance consultant. They will get a small business to a defensible baseline, but they are not a substitute for advice on your specific situation — and any guide that claims otherwise should worry you.
What if it isn't what I expected?
Email hello@gdprgard.eu within 14 days and you get a full refund. No form to fill in.
Seven questions you will hit anyway. Answers now, instead of at the deadline.
97 pages, seven guides, one consistent method — from the team behind GDPRGard.
Get the Field Kit — €39