Privacy, lawful basis, DPIAs, and operational GDPR practice for SaaS teams.
Italy's data protection authority fined IQVIA 7 million euros for treating a patient database as anonymous when each pa…
11 Oct 2026
Italy's data protection authority fined BBVA 5,508,000 euros after a customer switched off promotional notifications in…
10 Oct 2026
Sweden's data protection authority fined Miljödata, an HR software vendor, 1.8 million kronor (about 160,000 euros) und…
9 Oct 2026
When an AI agent reaches personal data that it, or the user it acts for, is not authorised to reach, GDPR counts it as…
8 Oct 2026
In 2026, 25 European data protection authorities are questioning recruiters, healthcare, finance, marketing and public…
7 Oct 2026
The EU's Digital Omnibus proposes fewer cookie banners, but it is not law. In August 2026 Parliament had not voted and…
2 Oct 2026
Under EU and UK law, every marketing email must offer a free, easy way out, and an opt-out has to take effect in every…
1 Oct 2026
If people in the EU can upload, publish or share content through your product, the Digital Services Act requires a way…
29 Sep 2026
After a breach likely to put people at high risk, GDPR Article 34 requires telling every affected person, including peo…
27 Sep 2026
Open-tracking pixels need the recipient's consent in France, wherever the sender is based. Two uses are exempt, securin…
26 Sep 2026
Spain's regulator fined Securitas Direct 100,000 euros for a paid 902 phone line on its camera signs, even though its p…
23 Sep 2026
The date you repaired a GDPR problem decides how much the repair is worth to you. One made before you learned an author…
22 Sep 2026
Giving a language model tools means the model decides at run time which companies receive personal data. GDPR Article 1…
21 Sep 2026
On 21 July 2026 the CNIL fined the IT consultancy EXTIA 300,000 euros over deletion requests, mostly because 166 people…
12 Sep 2026
Making personal data available to a separate company outside the EEA is a transfer, and GDPR Chapter V requires a named…
11 Sep 2026
On 21 August 2026 the Dutch data protection authority fined Uber 824,990,000 euros for switching off drivers' accounts…
8 Sep 2026
GDPR Article 28(2) requires your customer's written authorisation before a new or replacement vendor processes their da…
7 Sep 2026
Not on its own. Two rules apply to analytics, in order. Article 5(3) of the ePrivacy Directive, the rule behind cookie…
6 Sep 2026
Set a period for each category of data you hold, publish it, and build something that enforces it. GDPR Article 5(1)(e)…
4 Sep 2026
A data protection impact assessment (DPIA) is mandatory under GDPR Article 35 where processing is likely to result in a…
3 Sep 2026
No. GDPR Article 28(3) requires a written contract only where a vendor is your processor, meaning it handles the data o…
26 Aug 2026
Calling an LLM API adds three things to what GDPR Article 13 makes you disclose: the model vendor becomes a recipient o…
19 Aug 2026
Enterprise buyers are legally required to vet you: GDPR Article 28 lets a controller use only processors providing suff…
18 Aug 2026
Search your own privacy policy for "we may". I did it to 336 published policies from Product Hunt launches and 231 of t…
18 Aug 2026
Product Hunt seriesI scanned 458 products that launched on Product Hunt over 30 days in July and August 2026. 397 published a readable pri…
11 Aug 2026
I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026, loading each site from an EU…
11 Aug 2026
Before you publish a Privacy Policy, GDPR Article 13 requires twelve items. Two are close to boilerplate and one is you…
6 Aug 2026
The EDPB's draft template for personal data breach notification, which went out for comment until 5 August 2026, turns…
3 Aug 2026
The EDPB's draft Guidelines 03/2026 cover web scraping for generative AI, and they reach the team that re-uses someone…
3 Aug 2026
The EDPB's draft Guidelines 02/2026, out for consultation until 30 October 2026, treat anonymity as relative: the same…
31 Jul 2026