Insights
Field notes on AI strategy, governance, and execution.
Editorial note: Research and drafting are AI-assisted. Methodology claims, regulatory citations, and recommendations are grounded in documented research — every article includes specific source references. Daniela Piskackova — Co-founder & AI Audit Lead — is the research methodology guarantor behind our work. This transparency matches who we are: an AI-native company.

Can I Email Other Businesses Without Consent in the UK?
Can I email businesses without consent in the UK? Classify each subscriber, test the soft opt-in and record a defensible send or hold decision.

CCTV Monitoring Employees: UK Law and Practical Steps
CCTV monitoring employees under UK law: define the purpose, assess necessity, complete any required DPIA, inform workers and control footage and access.

Controller or Processor? A Practical EU Activity Test
Use a per-activity test to decide controller, processor or joint control, then choose the right GDPR agreement and record the reasons clearly.

Cookie Banner Requirements for UK Small Businesses
Cookie banner requirements for UK small businesses: classify cookies, block consent-required scripts, obtain real consent and test reject and withdrawal paths.

Data Processing Agreement Guide for EU Small Businesses
A practical data processing agreement for an EU small business: map the service, compare terms, use the free Commission clauses, complete annexes and test it.

Do I Have to Delete Data from Backups Under the GDPR?
Do I have to delete data from backups? Apply Article 17, separate active and recovery copies, control restores, and retain evidence for each decision.

Data Protection Officer Requirements: When Is a DPO Mandatory?
Data protection officer requirements use three GDPR tests and national law. Decide whether to appoint a DPO, then document and revisit the outcome.

Do You Need a Data Protection Officer? UK Rules Explained
Do you need a data protection officer? Apply the UK GDPR tests, compare business examples, and record a defensible answer for either outcome.

Does GDPR Apply Outside the EU? The Article 3 Test
Does GDPR apply outside the EU? Test EU establishment, targeted offers and monitoring, then decide whether an Article 27 representative is required.

Does UK GDPR Apply if Customers Are Outside the UK?
Does UK GDPR apply if customers are outside the UK? Test establishment and targeting, then assess representatives, transfers and any parallel EU GDPR scope.

GDPR Templates for Small Businesses: The Honest Minimum
GDPR templates small business teams can use: six living core records, conditional overlays, free EU clauses, and a practical test for generic packs.

How Long to Keep Personal Data in the UK: A Practical Guide
How long to keep personal data in the UK: identify the legal driver, set defensible retention periods, manage backups and delete records in practice.

How Long to Keep Personal Data Under EU GDPR: A Practical Guide
How long to keep personal data under EU GDPR: identify each legal driver, set defensible retention periods, manage backups and delete records in practice.

Is Business Contact Data Personal Data? An EU Field Test
Is business contact data personal data? Classify named work details, generic inboxes and business forms, then separate GDPR duties from marketing rules.

Is GDPR Really a Problem for a Small Business in the UK?
Is GDPR really a problem for small business? See what 99 recent ICO actions show, what usually goes wrong, and which minimum UK controls matter in practice.

Is This a Reportable Data Breach in the UK? Decide Fast
Is this a reportable data breach in the UK? Start the 72-hour clock at awareness, assess risk, record the decision and notify people if high risk.

Is This a Reportable Data Breach Under EU GDPR? A Decision Guide
Is this a reportable data breach? Start the 72-hour clock at awareness, assess risk, document the decision and notify the competent authority when required.

Legitimate Interests vs Consent in the UK: How to Choose
Legitimate interests vs consent in the UK: use the purpose, necessity and balancing tests, check PECR, and record why the chosen lawful basis fits.

Legitimate Interests vs Consent Under EU GDPR: How to Choose
Legitimate interests vs consent under EU GDPR: apply purpose, necessity and balancing tests, check ePrivacy rules, and record why the chosen basis fits.

GDPR Records of Processing Activities: Article 30 Guide
GDPR records of processing activities must follow Article 30 role-specific fields. Build a living record and test the narrow under-250 exception.

Records of Processing Activities: UK Article 30 Guide
Learn which records of processing activities UK GDPR Article 30 requires, what each record must contain, and how to build and maintain yours.

UK GDPR Small Business Guide: What to Do First in 2026
A practical UK GDPR small business guide: map personal data, choose lawful bases, write usable records, handle rights, secure data and review the system.

What Is a Lawful Basis? Seven UK GDPR Routes Explained
What is a lawful basis under UK GDPR? Compare all seven routes, avoid treating consent as the default, and record the basis that fits each purpose.

What Is a Lawful Basis? Six EU GDPR Routes Explained
What is a lawful basis under EU GDPR? Compare all six routes, avoid treating consent as the default, and record the basis that fits each purpose.

What Is a Personal Data Breach? EU GDPR Explained Clearly
What is a personal data breach under EU GDPR? Recognise confidentiality, integrity and availability failures, then take the right first-hour steps.

What Is a Subject Access Request? The UK GDPR Rules Explained
What is a subject access request under UK GDPR? Recognise one without magic words, start the one-month clock, search properly and respond lawfully.

What Is a Subject Access Request? An EU GDPR Guide
What is a subject access request under EU GDPR? Recognise one without magic words, start the one-month clock, search completely and respond lawfully.

What Must a Privacy Notice Say Under the EU GDPR Rules?
What must a privacy notice say? Compare Articles 13 and 14 GDPR, check every required field, fix timing, and retain practical evidence of delivery.

When Is a DPIA Required? The EU GDPR Article 35 Test
When is a DPIA required? Apply Article 35's mandatory cases, the WP248 risk criteria and your authority's list, then record a reasoned decision.

GDPR Accountability: What EU Companies Must Document
GDPR accountability means proving compliance rather than claiming it. The records EU companies must hold — ROPA, DPIA, policies — and how to build the set.

How to Build an AI Register in 90 Minutes (EU AI Act)
How to build an AI register in ninety minutes, before the Article 26 deployer duties begin to apply in December 2027: the five steps, the starter columns, the owner rules and the pitfalls.

Local LLM vs Cloud LLM Data Security: The Wrong Question (2026)
Local LLM vs cloud LLM data security is the wrong question: the real leak is staff pasting into personal accounts, which a local model never touches.

AI Governance From Day One: What Retrofitting Compliance Costs
AI regulation is converging. Firms that build AI governance in from day one avoid the GDPR-style retrofit trap that cost the last cohort several times more.