The Lawcel Blog

Short, evidence-conscious articles on regulatory change, security governance, and how product velocity shows up in compliance posture - written for operators who ship weekly.

Adding AI to your app? Add these three disclosures to your privacy policy.
GDPR

Adding AI to your app? Add these three disclosures to your privacy policy.

Calling an LLM API adds three things to what GDPR Article 13 makes you disclose: the model vendor becomes a recipient o…

Ulf Aslak Lai · 19 Aug 2026

Enterprise buyers read your privacy policy before they read your pricing
GDPR

Enterprise buyers read your privacy policy before they read your pricing

Enterprise buyers are legally required to vet you: GDPR Article 28 lets a controller use only processors providing suff…

Kenneth Graupner · 18 Aug 2026

Remove "we may" or "possible" from your privacy policy. EU regulators call for plain language.
GDPR

Remove "we may" or "possible" from your privacy policy. EU regulators call for plain language.

Search your own privacy policy for "we may". I did it to 336 published policies from Product Hunt launches and 231 of t…

Ulf Aslak Lai · 18 Aug 2026

Starting September 11 2026, you have just 24 hours to report on-device vulnerabilities.
NIS2

Starting September 11 2026, you have just 24 hours to report on-device vulnerabilities.

The Cyber Resilience Act's reporting duties start on 11 September 2026. The CRA covers software that runs on the user's…

Ulf Aslak Lai · 17 Aug 2026

Continuous compliance in Lovable. No plugin required.
Drift

Continuous compliance in Lovable. No plugin required.

If someone on your team shipped a customer-facing tool in Lovable, connect the GitHub repository it already syncs to La…

Kenneth Graupner · 17 Aug 2026

The most upvoted Product Hunt launches are no more compliant than the least Product Hunt series
Strategy

The most upvoted Product Hunt launches are no more compliant than the least

I scanned 458 products launched on Product Hunt over 30 days in 2026 and split them by upvotes. Across a range from 4 t…

Ulf Aslak Lai · 11 Aug 2026

Only 45% of Product Hunt privacy policies name a legal basis Product Hunt series
GDPR

Only 45% of Product Hunt privacy policies name a legal basis

I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026. 397 published a readable pri…

Ulf Aslak Lai · 11 Aug 2026

60% of Product Hunt sites load a foreign vendor their policy never mentions Product Hunt series
Drift

60% of Product Hunt sites load a foreign vendor their policy never mentions

I scanned 458 products launched on Product Hunt over 30 days, loading each from inside the EU and reading its legal pag…

Ulf Aslak Lai · 11 Aug 2026

Only 17% of Product Hunt launches ask when they set tracking cookies Product Hunt series
GDPR

Only 17% of Product Hunt launches ask when they set tracking cookies

I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026, loading each site from an EU…

Ulf Aslak Lai · 11 Aug 2026

Charging a customer to take their data out stops being legal on 12 January 2027
Drift

Charging a customer to take their data out stops being legal on 12 January 2027

The EU Data Act's switching rules cover Software as a Service, not just connected machinery, and have applied since 12…

Kenneth Graupner · 6 Aug 2026

Two days from launch with no privacy policy. Twelve facts have to be true.
GDPR

Two days from launch with no privacy policy. Twelve facts have to be true.

Before you publish a Privacy Policy, GDPR Article 13 requires twelve items. Two are close to boilerplate and one is you…

Ulf Aslak Lai · 6 Aug 2026

Article 33 asks four things. The EDPB's new breach template asks 100.
GDPR

Article 33 asks four things. The EDPB's new breach template asks 100.

The EDPB's draft template for personal data breach notification, which went out for comment until 5 August 2026, turns…

Ulf Aslak Lai · 3 Aug 2026

Scraping the whole internet is the easy case. Your small, targeted scrape is not.
GDPR

Scraping the whole internet is the easy case. Your small, targeted scrape is not.

The EDPB's draft Guidelines 03/2026 cover web scraping for generative AI, and they reach the team that re-uses someone…

Ulf Aslak Lai · 3 Aug 2026

NIS2 is nearly two years late in four countries. It reached your sales cycle on time.
NIS2

NIS2 is nearly two years late in four countries. It reached your sales cycle on time.

NIS2 had to be in national law by 17 October 2024, and in July 2026 four member states were referred to the EU Court fo…

Kenneth Graupner · 3 Aug 2026

Your Privacy Policy says "anonymised". The EDPB just asked: for whom?
GDPR

Your Privacy Policy says "anonymised". The EDPB just asked: for whom?

The EDPB's draft Guidelines 02/2026, out for consultation until 30 October 2026, treat anonymity as relative: the same…

Kenneth Graupner · 31 Jul 2026

Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you
AI Act

Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you

Article 50 of the EU AI Act applies from 2 August 2026. The delay you read about in June covered high-risk uses such as…

Ulf Aslak Lai · 30 Jul 2026

The blog for teams that ship faster than their policies can keep up
Strategy

The blog for teams that ship faster than their policies can keep up

The Lawcel blog explains how GDPR, the EU AI Act, and NIS2 actually land in day-to-day SaaS delivery. We tie regulation…

Kenneth Graupner · 1 May 2026

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, so your legal pages always match what you actually ship.

Try for free