Kenneth Graupner

Kenneth Graupner

Co-founder, Chief Product Officer

Kenneth is Co-founder and CPO at Lawcel. He focuses on product strategy and on shaping workflows so legal, engineering, and GTM teams can ship continuously without treating compliance as a late-stage gate.

  • Product strategy
  • Compliance operations
  • SaaS delivery

Articles by Kenneth Graupner

If your SaaS imports personal data, list its sources. The 2026 GDPR transparency check asks your customers.
GDPR

If your SaaS imports personal data, list its sources. The 2026 GDPR transparency check asks your customers.

In 2026, 25 European data protection authorities are questioning recruiters, healthcare, finance, marketing and public…

7 Oct 2026

An unsubscribe must stop marketing email from every tool you use, under EU and UK law
GDPR

An unsubscribe must stop marketing email from every tool you use, under EU and UK law

Under EU and UK law, every marketing email must offer a free, easy way out, and an opt-out has to take effect in every…

1 Oct 2026

The AI Act's AI literacy duty still applies to companies whose staff use ChatGPT
AI Act

The AI Act's AI literacy duty still applies to companies whose staff use ChatGPT

Article 4 of the EU AI Act still requires companies whose staff use AI tools such as ChatGPT to build their AI literacy…

25 Sep 2026

Every contact you publish for GDPR data requests must be easy to use on its own
GDPR

Every contact you publish for GDPR data requests must be easy to use on its own

Spain's regulator fined Securitas Direct 100,000 euros for a paid 902 phone line on its camera signs, even though its p…

23 Sep 2026

A GDPR fix counts for more if you made it before you heard from the regulator
GDPR

A GDPR fix counts for more if you made it before you heard from the regulator

The date you repaired a GDPR problem decides how much the repair is worth to you. One made before you learned an author…

22 Sep 2026

NIS2 supplier contracts need eight security clauses. A DPA covers five at best.
NIS2

NIS2 supplier contracts need eight security clauses. A DPA covers five at best.

NIS2's implementing regulation names eight things your supplier contracts have to specify. By my count a GDPR data proc…

20 Sep 2026

A connected device sold in the EU after 12 September 2026 must export its data to the user
Data Act

A connected device sold in the EU after 12 September 2026 must export its data to the user

For a connected device first sold in the EU after 12 September 2026, and the software it needs to work, the readings it…

19 Sep 2026

Your app sends personal data outside the EU. Each destination needs its own transfer mechanism.
GDPR

Your app sends personal data outside the EU. Each destination needs its own transfer mechanism.

Making personal data available to a separate company outside the EEA is a transfer, and GDPR Chapter V requires a named…

11 Sep 2026

Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.
AI Act

Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.

Most SaaS features are not high-risk under the EU AI Act. Two things make a system high-risk: it is, or is built into,…

10 Sep 2026

Swapping a vendor that touches customer data? Notify your customers before it goes live.
GDPR

Swapping a vendor that touches customer data? Notify your customers before it goes live.

GDPR Article 28(2) requires your customer's written authorisation before a new or replacement vendor processes their da…

7 Sep 2026

Does your new feature need a DPIA? Decide before you ship, and write the answer down.
GDPR

Does your new feature need a DPIA? Decide before you ship, and write the answer down.

A data protection impact assessment (DPIA) is mandatory under GDPR Article 35 where processing is likely to result in a…

3 Sep 2026

Shipping every week? Five changes that put your privacy policy out of date.
Drift

Shipping every week? Five changes that put your privacy policy out of date.

Privacy policy drift is a document written once against a product that ships every week. Regulators name five changes u…

1 Sep 2026

Do you need a DPA with every vendor? Sort your list into three groups first.
GDPR

Do you need a DPA with every vendor? Sort your list into three groups first.

No. GDPR Article 28(3) requires a written contract only where a vendor is your processor, meaning it handles the data o…

26 Aug 2026

Enterprise buyers read your privacy policy before they read your pricing
GDPR

Enterprise buyers read your privacy policy before they read your pricing

Enterprise buyers are legally required to vet you: GDPR Article 28 lets a controller use only processors providing suff…

18 Aug 2026

Your Lovable app needs a privacy policy at the first sign-up.
Drift

Your Lovable app needs a privacy policy at the first sign-up.

If you built your product in Lovable, connect the GitHub repository Lovable already syncs to, then turn on direct-push…

17 Aug 2026

Charging a customer to take their data out stops being legal on 12 January 2027
Data Act

Charging a customer to take their data out stops being legal on 12 January 2027

The EU Data Act's switching rules cover Software as a Service, not just connected machinery, and have applied since 12…

6 Aug 2026

NIS2 is nearly two years late in four countries. It reached your sales cycle on time.
NIS2

NIS2 is nearly two years late in four countries. It reached your sales cycle on time.

NIS2 had to be in national law by 17 October 2024, and in July 2026 four member states were referred to the EU Court fo…

3 Aug 2026

Your Privacy Policy says "anonymised". The EDPB just asked: for whom?
GDPR

Your Privacy Policy says "anonymised". The EDPB just asked: for whom?

The EDPB's draft Guidelines 02/2026, out for consultation until 30 October 2026, treat anonymity as relative: the same…

31 Jul 2026

The blog for teams that ship faster than their policies can keep up
Strategy

The blog for teams that ship faster than their policies can keep up

The Lawcel blog explains how GDPR, the EU AI Act, and NIS2 actually land in day-to-day SaaS delivery. We tie regulation…

1 May 2026