Skip to content

Insights

Field notes on AI strategy, governance, and execution.

Editorial note: Research and drafting are AI-assisted. Methodology claims, regulatory citations, and recommendations are grounded in documented research — every article includes specific source references. Daniela Piskackova — Co-founder & AI Audit Lead — is the research methodology guarantor behind our work. This transparency matches who we are: an AI-native company.

An infomap branches a sealed email between a company, an individual and a consent checkpoint.

Can I Email Other Businesses Without Consent in the UK?

Can I email businesses without consent in the UK? Classify each subscriber, test the soft opt-in and record a defensible send or hold decision.

13 min readAug 26, 2026
A camera installer holds an unsecured CCTV unit against a workshop column while the owner checks the proposed view from an open olive folder.

CCTV Monitoring Employees: UK Law and Practical Steps

CCTV monitoring employees under UK law: define the purpose, assess necessity, complete any required DPIA, inform workers and control footage and access.

12 min readAug 26, 2026
An isometric planning hub routes data blocks from a decision desk to a separate service unit.

Controller or Processor? A Practical EU Activity Test

Use a per-activity test to decide controller, processor or joint control, then choose the right GDPR agreement and record the reasons clearly.

13 min readAug 26, 2026
Isometric browser window: three rails from a globe, a cloud and a server stack pass through small gates into the window, where two green toggles open barred gates that let beads through and a mauve toggle shuts a mauve door; three green buttons stand in front and two arrows leave on the right.

Cookie Banner Requirements for UK Small Businesses

Cookie banner requirements for UK small businesses: classify cookies, block consent-required scripts, obtain real consent and test reject and withdrawal paths.

14 min readAug 26, 2026
An icon-only workflow moves a small data-processing agreement through scope, instructions, safeguards, suppliers and review.

Data Processing Agreement Guide for EU Small Businesses

A practical data processing agreement for an EU small business: map the service, compare terms, use the free Commission clauses, complete annexes and test it.

15 min readAug 26, 2026
A spiral track: an outer ring of green discs under glass domes, one of them mauve, circles a dark inner ring of discs around a central stack of sheets; one disc drops into a shredder bin on the left while a barred gate with a tick releases discs to three cradles on the right, beside a safe holding stacked discs.

Do I Have to Delete Data from Backups Under the GDPR?

Do I have to delete data from backups? Apply Article 17, separate active and recovery copies, control restores, and retain evidence for each decision.

12 min readAug 26, 2026
A tactile mind map sends four distinct routes through one decision hub to an appointment token or a recorded assessment.

Data Protection Officer Requirements: When Is a DPO Mandatory?

Data protection officer requirements use three GDPR tests and national law. Decide whether to appoint a DPO, then document and revisit the outcome.

17 min readAug 26, 2026
A present-day workshop office with a light wood desk, a closed laptop connected to a charger, an open olive folder, a blank sheet with one unticked box, a lit lamp, an insulated bottle, a mesh chair and a window onto working machinery.

Do You Need a Data Protection Officer? UK Rules Explained

Do you need a data protection officer? Apply the UK GDPR tests, compare business examples, and record a defensible answer for either outcome.

12 min readAug 26, 2026
A framed board: two pale lanes from a desk scene and a delivery scene merge at a dark junction and pass a barred gate; a third lane loops around a garden with a telescope, carries a mauve section and joins the merge; a fourth plain lane skirts the edge of the board to a post outside the gate.

Does GDPR Apply Outside the EU? The Article 3 Test

Does GDPR apply outside the EU? Test EU establishment, targeted offers and monitoring, then decide whether an Article 27 representative is required.

13 min readAug 26, 2026
A worker pushes a parcel cage through a modern workshop loading bay towards an unbranded van, while an open parcel, blank dispatch sheet, scanner and olive customer-record folder remain inside.

Does UK GDPR Apply if Customers Are Outside the UK?

Does UK GDPR apply if customers are outside the UK? Test establishment and targeting, then assess representatives, transfers and any parallel EU GDPR scope.

12 min readAug 26, 2026
An exploded stack of blank template modules forms a reusable compliance toolkit.

GDPR Templates for Small Businesses: The Honest Minimum

GDPR templates small business teams can use: six living core records, conditional overlays, free EU clauses, and a practical test for generic packs.

16 min readAug 26, 2026
Hands hold an unresolved blank record bundle above an olive folder while a deep archive aisle leads toward storage and secure destruction.

How Long to Keep Personal Data in the UK: A Practical Guide

How long to keep personal data in the UK: identify the legal driver, set defensible retention periods, manage backups and delete records in practice.

12 min readAug 26, 2026
A text-free retention timeline moves records from active use through archive and legal hold to secure deletion.

How Long to Keep Personal Data Under EU GDPR: A Practical Guide

How long to keep personal data under EU GDPR: identify each legal driver, set defensible retention periods, manage backups and delete records in practice.

13 min readAug 26, 2026
An isometric sorting station separates a company building token from contact cards linked to individual people.

Is Business Contact Data Personal Data? An EU Field Test

Is business contact data personal data? Classify named work details, generic inboxes and business forms, then separate GDPR duties from marketing rules.

15 min readAug 26, 2026
A bicycle-shop owner locks a sealed customer envelope into a small cabinet while a colleague continues repairing a wheel beside the service counter.

Is GDPR Really a Problem for a Small Business in the UK?

Is GDPR really a problem for small business? See what 99 recent ICO actions show, what usually goes wrong, and which minimum UK controls matter in practice.

19 min readAug 26, 2026
A decision-tree infomap moves from awareness and containment through risk to separate ICO and people branches, with every outcome entering a record.

Is This a Reportable Data Breach in the UK? Decide Fast

Is this a reportable data breach in the UK? Start the 72-hour clock at awareness, assess risk, record the decision and notify people if high risk.

12 min readAug 26, 2026
Paper-cut landscape: a dark green stream carries a row of six square tiles and splits — one branch curls into a round green eddy holding four tiles, the other climbs the hill to a beacon tower with a mauve light.

Is This a Reportable Data Breach Under EU GDPR? A Decision Guide

Is this a reportable data breach? Start the 72-hour clock at awareness, assess risk, document the decision and notify the competent authority when required.

13 min readAug 26, 2026
Two isometric routes compare purpose, necessity and balance with choice and withdrawal, while an objection lever remains attached to the legitimate-interest route.

Legitimate Interests vs Consent in the UK: How to Choose

Legitimate interests vs consent in the UK: use the purpose, necessity and balancing tests, check PECR, and record why the chosen lawful basis fits.

13 min readAug 26, 2026
On a cream board a green winding path from a wooded landscape ends at a bay holding two grey weights, beside a round balance plate on a stem; a separate straight pale lane carries a small disc towards a slatted green gate with a mauve latch.

Legitimate Interests vs Consent Under EU GDPR: How to Choose

Legitimate interests vs consent under EU GDPR: apply purpose, necessity and balancing tests, check ePrivacy rules, and record why the chosen basis fits.

13 min readAug 26, 2026
Two colleagues map six connected process blocks into a living grid while a workshop scanner grounds the record in real work.

GDPR Records of Processing Activities: Article 30 Guide

GDPR records of processing activities must follow Article 30 role-specific fields. Build a living record and test the narrow under-250 exception.

17 min readAug 26, 2026
Top-down view: six trays — cards, folders, people figures, an envelope, documents, and a padlock with a key and a shield — connect by green rails that curve into an open ledger with ruled columns, tabbed pages and one mauve bookmark.

Records of Processing Activities: UK Article 30 Guide

Learn which records of processing activities UK GDPR Article 30 requires, what each record must contain, and how to build and maintain yours.

15 min readAug 26, 2026
Six hands work around a circular workshop table, sealing a parcel, reviewing blank records beside a tablet and filing an archive pouch into a central olive operating folder with one loose action card.

UK GDPR Small Business Guide: What to Do First in 2026

A practical UK GDPR small business guide: map personal data, choose lawful bases, write usable records, handle rights, secure data and review the system.

22 min readAug 26, 2026
A mind map sends one purpose into seven equal routes labelled consent, contract, duty, vital, public, interest and recognised.

What Is a Lawful Basis? Seven UK GDPR Routes Explained

What is a lawful basis under UK GDPR? Compare all seven routes, avoid treating consent as the default, and record the basis that fits each purpose.

7 min readAug 26, 2026
A tactile paper construction in which one blank purpose card meets six distinct routes and a single route aligns with a deep-olive folio.

What Is a Lawful Basis? Six EU GDPR Routes Explained

What is a lawful basis under EU GDPR? Compare all six routes, avoid treating consent as the default, and record the basis that fits each purpose.

7 min readAug 26, 2026
A present-day warehouse worker pauses with packing tape above two open parcels as a blank document bridges the wrong box and a supervisor approaches with an olive incident folder.

What Is a Personal Data Breach? EU GDPR Explained Clearly

What is a personal data breach under EU GDPR? Recognise confidentiality, integrity and availability failures, then take the right first-hour steps.

7 min readAug 26, 2026
A cascading workflow follows a request through verification, search, review, response and the final evidence record.

What Is a Subject Access Request? The UK GDPR Rules Explained

What is a subject access request under UK GDPR? Recognise one without magic words, start the one-month clock, search properly and respond lawfully.

6 min readAug 26, 2026
A layered-paper composition in which one blank request passes through five record stores and emerges as an open response packet beside a mauve clip.

What Is a Subject Access Request? An EU GDPR Guide

What is a subject access request under EU GDPR? Recognise one without magic words, start the one-month clock, search completely and respond lawfully.

7 min readAug 26, 2026
Two isometric data-origin paths feed a layered notice system whose icon modules pass through a timed delivery gate into an evidence archive.

What Must a Privacy Notice Say Under the EU GDPR Rules?

What must a privacy notice say? Compare Articles 13 and 14 GDPR, check every required field, fix timing, and retain practical evidence of delivery.

12 min readAug 26, 2026
An isometric route passes through three gates and nine screening tiles before reaching a grooved decision tile with a review loop.

When Is a DPIA Required? The EU GDPR Article 35 Test

When is a DPIA required? Apply Article 35's mandatory cases, the WP248 risk criteria and your authority's list, then record a reasoned decision.

17 min readAug 26, 2026
Five data-processing records, each with a different surface texture, feed through a single verification ring and emerge as one bound, checked GDPR accountability set.

GDPR Accountability: What EU Companies Must Document

GDPR accountability means proving compliance rather than claiming it. The records EU companies must hold — ROPA, DPIA, policies — and how to build the set.

14 min readJun 22, 2026
At a workbench, a woman sorts small tagged tiles from five separate piles into one compartmented box while an hourglass beside her runs.

How to Build an AI Register in 90 Minutes (EU AI Act)

How to build an AI register in ninety minutes, before the Article 26 deployer duties begin to apply in December 2027: the five steps, the starter columns, the owner rules and the pitfalls.

12 min readMay 20, 2026
Tiles travel along a track through a gate into a walled enclosure where they are sorted, while a dark tablet-shaped frame stands off the track and a small crate of loose tiles sits apart from the line.

Local LLM vs Cloud LLM Data Security: The Wrong Question (2026)

Local LLM vs cloud LLM data security is the wrong question: the real leak is staff pasting into personal accounts, which a local model never touches.

16 min readMay 13, 2026
Two technicians kneel at the open control panel of a factory machine and fit a small junction box into its live cabling while the line stands still.

AI Governance From Day One: What Retrofitting Compliance Costs

AI regulation is converging. Firms that build AI governance in from day one avoid the GDPR-style retrofit trap that cost the last cohort several times more.

22 min readMay 6, 2026