The Lawcel Blog

Short, evidence-conscious articles on regulatory change, security governance, and how product velocity shows up in compliance posture - written for operators who ship weekly.

BBVA fined 5.5 million euros after an app opt-out never reached its marketing tool
GDPR

BBVA fined 5.5 million euros after an app opt-out never reached its marketing tool

Italy's data protection authority fined BBVA 5,508,000 euros after a customer switched off promotional notifications in…

Ulf Aslak Lai · 10 Oct 2026

A software vendor can be fined under GDPR for a breach of its customers' data
GDPR

A software vendor can be fined under GDPR for a breach of its customers' data

Sweden's data protection authority fined Miljödata, an HR software vendor, 1.8 million kronor (about 160,000 euros) und…

Ulf Aslak Lai · 9 Oct 2026

GDPR counts an AI agent reading personal data past its permissions as a breach
GDPR

GDPR counts an AI agent reading personal data past its permissions as a breach

When an AI agent reaches personal data that it, or the user it acts for, is not authorised to reach, GDPR counts it as…

Ulf Aslak Lai · 8 Oct 2026

If your SaaS imports personal data, list its sources. The 2026 GDPR transparency check asks your customers.
GDPR

If your SaaS imports personal data, list its sources. The 2026 GDPR transparency check asks your customers.

In 2026, 25 European data protection authorities are questioning recruiters, healthcare, finance, marketing and public…

Kenneth Graupner · 7 Oct 2026

Keep your cookie banner. The Digital Omnibus cookie reform is still a proposal.
GDPR

Keep your cookie banner. The Digital Omnibus cookie reform is still a proposal.

The EU's Digital Omnibus proposes fewer cookie banners, but it is not law. In August 2026 Parliament had not voted and…

Ulf Aslak Lai · 2 Oct 2026

An unsubscribe must stop marketing email from every tool you use, under EU and UK law
GDPR

An unsubscribe must stop marketing email from every tool you use, under EU and UK law

Under EU and UK law, every marketing email must offer a free, easy way out, and an opt-out has to take effect in every…

Kenneth Graupner · 1 Oct 2026

The EU KIDS Act would regulate general AI chatbots, not customer-support bots
AI Act

The EU KIDS Act would regulate general AI chatbots, not customer-support bots

The EU KIDS Act, proposed on 17 September 2026 and not yet law, would regulate AI chatbots that minors can reach and th…

Ulf Aslak Lai · 30 Sep 2026

A DSA illegal content report form should accept reports without a name or email
GDPR

A DSA illegal content report form should accept reports without a name or email

If people in the EU can upload, publish or share content through your product, the Digital Services Act requires a way…

Ulf Aslak Lai · 29 Sep 2026

In a high-risk data breach, GDPR says to tell everyone affected, not only your users
GDPR

In a high-risk data breach, GDPR says to tell everyone affected, not only your users

After a breach likely to put people at high risk, GDPR Article 34 requires telling every affected person, including peo…

Ulf Aslak Lai · 27 Sep 2026

Email tracking pixels need consent in France, even if you are not based there
GDPR

Email tracking pixels need consent in France, even if you are not based there

Open-tracking pixels need the recipient's consent in France, wherever the sender is based. Two uses are exempt, securin…

Ulf Aslak Lai · 26 Sep 2026

The AI Act's AI literacy duty still applies to companies whose staff use ChatGPT
AI Act

The AI Act's AI literacy duty still applies to companies whose staff use ChatGPT

Article 4 of the EU AI Act still requires companies whose staff use AI tools such as ChatGPT to build their AI literacy…

Kenneth Graupner · 25 Sep 2026

Every contact you publish for GDPR data requests must be easy to use on its own
GDPR

Every contact you publish for GDPR data requests must be easy to use on its own

Spain's regulator fined Securitas Direct 100,000 euros for a paid 902 phone line on its camera signs, even though its p…

Kenneth Graupner · 23 Sep 2026

A GDPR fix counts for more if you made it before you heard from the regulator
GDPR

A GDPR fix counts for more if you made it before you heard from the regulator

The date you repaired a GDPR problem decides how much the repair is worth to you. One made before you learned an author…

Kenneth Graupner · 22 Sep 2026

Your AI agent's tool list is the recipient list your privacy policy has to name
GDPR

Your AI agent's tool list is the recipient list your privacy policy has to name

Giving a language model tools means the model decides at run time which companies receive personal data. GDPR Article 1…

Ulf Aslak Lai · 21 Sep 2026

NIS2 supplier contracts need eight security clauses. A DPA covers five at best.
NIS2

NIS2 supplier contracts need eight security clauses. A DPA covers five at best.

NIS2's implementing regulation names eight things your supplier contracts have to specify. By my count a GDPR data proc…

Kenneth Graupner · 20 Sep 2026

A connected device sold in the EU after 12 September 2026 must export its data to the user
Data Act

A connected device sold in the EU after 12 September 2026 must export its data to the user

For a connected device first sold in the EU after 12 September 2026, and the software it needs to work, the readings it…

Kenneth Graupner · 19 Sep 2026

Fine-tuning rarely makes you a model's provider under the AI Act. The threshold is a third of the base model's compute.
AI Act

Fine-tuning rarely makes you a model's provider under the AI Act. The threshold is a third of the base model's compute.

The AI Act has two provider roles, and a fine-tune almost never moves the second one to you. Shipping an AI feature und…

Ulf Aslak Lai · 18 Sep 2026

NIS2 gives you 24 hours to report a full cloud outage longer than 30 minutes
NIS2

NIS2 gives you 24 hours to report a full cloud outage longer than 30 minutes

NIS2 gives you 24 hours from becoming aware of a significant incident to file a first report with your national cyber i…

Ulf Aslak Lai · 13 Sep 2026

GDPR gives you one month to answer a deletion request, even if the data is already deleted
GDPR

GDPR gives you one month to answer a deletion request, even if the data is already deleted

On 21 July 2026 the CNIL fined the IT consultancy EXTIA 300,000 euros over deletion requests, mostly because 166 people…

Ulf Aslak Lai · 12 Sep 2026

Your app sends personal data outside the EU. Each destination needs its own transfer mechanism.
GDPR

Your app sends personal data outside the EU. Each destination needs its own transfer mechanism.

Making personal data available to a separate company outside the EEA is a transfer, and GDPR Chapter V requires a named…

Kenneth Graupner · 11 Sep 2026

Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.
AI Act

Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.

Most SaaS features are not high-risk under the EU AI Act. Two things make a system high-risk: it is, or is built into,…

Kenneth Graupner · 10 Sep 2026

Uber fined 825 million euros for automatically banning drivers
GDPR

Uber fined 825 million euros for automatically banning drivers

On 21 August 2026 the Dutch data protection authority fined Uber 824,990,000 euros for switching off drivers' accounts…

Ulf Aslak Lai · 8 Sep 2026

Swapping a vendor that touches customer data? Notify your customers before it goes live.
GDPR

Swapping a vendor that touches customer data? Notify your customers before it goes live.

GDPR Article 28(2) requires your customer's written authorisation before a new or replacement vendor processes their da…

Kenneth Graupner · 7 Sep 2026

Is legitimate interest enough for product analytics? Check what your tool stores on the device first.
GDPR

Is legitimate interest enough for product analytics? Check what your tool stores on the device first.

Not on its own. Two rules apply to analytics, in order. Article 5(3) of the ePrivacy Directive, the rule behind cookie…

Ulf Aslak Lai · 6 Sep 2026

How long can you keep user data? Write down the period, then make something enforce it.
GDPR

How long can you keep user data? Write down the period, then make something enforce it.

Set a period for each category of data you hold, publish it, and build something that enforces it. GDPR Article 5(1)(e)…

Ulf Aslak Lai · 4 Sep 2026

Does your new feature need a DPIA? Decide before you ship, and write the answer down.
GDPR

Does your new feature need a DPIA? Decide before you ship, and write the answer down.

A data protection impact assessment (DPIA) is mandatory under GDPR Article 35 where processing is likely to result in a…

Kenneth Graupner · 3 Sep 2026

Shipping every week? Five changes that put your privacy policy out of date.
Drift

Shipping every week? Five changes that put your privacy policy out of date.

Privacy policy drift is a document written once against a product that ships every week. Regulators name five changes u…

Kenneth Graupner · 1 Sep 2026

Do you need a DPA with every vendor? Sort your list into three groups first.
GDPR

Do you need a DPA with every vendor? Sort your list into three groups first.

No. GDPR Article 28(3) requires a written contract only where a vendor is your processor, meaning it handles the data o…

Kenneth Graupner · 26 Aug 2026

An auditor keeps your security honest. Nothing keeps your privacy policy honest.
Strategy

An auditor keeps your security honest. Nothing keeps your privacy policy honest.

A SOC 2 audit examines the security controls you scoped into it, and platforms like Vanta collect the evidence for that…

Ulf Aslak Lai · 24 Aug 2026

Adding AI to your app? Add these three disclosures to your privacy policy.
GDPR

Adding AI to your app? Add these three disclosures to your privacy policy.

Calling an LLM API adds three things to what GDPR Article 13 makes you disclose: the model vendor becomes a recipient o…

Ulf Aslak Lai · 19 Aug 2026

Your Vercel app deploys on every merge. Its privacy policy is still on version one.
Drift

Your Vercel app deploys on every merge. Its privacy policy is still on version one.

Vercel's compliance covers Vercel's own service, not the app you deploy on it. From day one your privacy policy must di…

Ulf Aslak Lai · 19 Aug 2026

Enterprise buyers read your privacy policy before they read your pricing
GDPR

Enterprise buyers read your privacy policy before they read your pricing

Enterprise buyers are legally required to vet you: GDPR Article 28 lets a controller use only processors providing suff…

Kenneth Graupner · 18 Aug 2026

Remove "we may" or "possible" from your privacy policy. EU regulators call for plain language.
GDPR

Remove "we may" or "possible" from your privacy policy. EU regulators call for plain language.

Search your own privacy policy for "we may". I did it to 336 published policies from Product Hunt launches and 231 of t…

Ulf Aslak Lai · 18 Aug 2026

Starting September 11 2026, you have just 24 hours to report on-device vulnerabilities.
CRA

Starting September 11 2026, you have just 24 hours to report on-device vulnerabilities.

The Cyber Resilience Act's reporting duties start on 11 September 2026. The CRA covers software that runs on the user's…

Ulf Aslak Lai · 17 Aug 2026

Your Lovable app needs a privacy policy at the first sign-up.
Drift

Your Lovable app needs a privacy policy at the first sign-up.

If you built your product in Lovable, connect the GitHub repository Lovable already syncs to, then turn on direct-push…

Kenneth Graupner · 17 Aug 2026

The most upvoted Product Hunt launches are no more compliant than the least Product Hunt series
Strategy

The most upvoted Product Hunt launches are no more compliant than the least

I scanned 458 products launched on Product Hunt over 30 days in 2026 and split them by upvotes. Across a range from 4 t…

Ulf Aslak Lai · 11 Aug 2026

Only 45% of Product Hunt privacy policies name a legal basis Product Hunt series
GDPR

Only 45% of Product Hunt privacy policies name a legal basis

I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026. 397 published a readable pri…

Ulf Aslak Lai · 11 Aug 2026

60% of Product Hunt sites load a foreign vendor their policy never mentions Product Hunt series
Drift

60% of Product Hunt sites load a foreign vendor their policy never mentions

I scanned 458 products launched on Product Hunt over 30 days, loading each from inside the EU and reading its legal pag…

Ulf Aslak Lai · 11 Aug 2026

Only 17% of Product Hunt launches ask when they set tracking cookies Product Hunt series
GDPR

Only 17% of Product Hunt launches ask when they set tracking cookies

I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026, loading each site from an EU…

Ulf Aslak Lai · 11 Aug 2026

Charging a customer to take their data out stops being legal on 12 January 2027
Data Act

Charging a customer to take their data out stops being legal on 12 January 2027

The EU Data Act's switching rules cover Software as a Service, not just connected machinery, and have applied since 12…

Kenneth Graupner · 6 Aug 2026

Two days from launch with no privacy policy. Twelve facts have to be true.
GDPR

Two days from launch with no privacy policy. Twelve facts have to be true.

Before you publish a Privacy Policy, GDPR Article 13 requires twelve items. Two are close to boilerplate and one is you…

Ulf Aslak Lai · 6 Aug 2026

Article 33 asks four things. The EDPB's new breach template asks 100.
GDPR

Article 33 asks four things. The EDPB's new breach template asks 100.

The EDPB's draft template for personal data breach notification, which went out for comment until 5 August 2026, turns…

Ulf Aslak Lai · 3 Aug 2026

Scraping the whole internet is the easy case. Your small, targeted scrape is not.
GDPR

Scraping the whole internet is the easy case. Your small, targeted scrape is not.

The EDPB's draft Guidelines 03/2026 cover web scraping for generative AI, and they reach the team that re-uses someone…

Ulf Aslak Lai · 3 Aug 2026

NIS2 is nearly two years late in four countries. It reached your sales cycle on time.
NIS2

NIS2 is nearly two years late in four countries. It reached your sales cycle on time.

NIS2 had to be in national law by 17 October 2024, and in July 2026 four member states were referred to the EU Court fo…

Kenneth Graupner · 3 Aug 2026

Your Privacy Policy says "anonymised". The EDPB just asked: for whom?
GDPR

Your Privacy Policy says "anonymised". The EDPB just asked: for whom?

The EDPB's draft Guidelines 02/2026, out for consultation until 30 October 2026, treat anonymity as relative: the same…

Kenneth Graupner · 31 Jul 2026

Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you
AI Act

Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you

Article 50 of the EU AI Act applies from 2 August 2026. The delay you read about in June covered high-risk uses such as…

Ulf Aslak Lai · 30 Jul 2026

The blog for teams that ship faster than their policies can keep up
Strategy

The blog for teams that ship faster than their policies can keep up

The Lawcel blog explains how GDPR, the EU AI Act, and NIS2 actually land in day-to-day SaaS delivery. We tie regulation…

Kenneth Graupner · 1 May 2026

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.

Get started