Leitfäden
Verständliche Leitfäden zu den Gesetzen, die unsere Bewertungen abdecken. Mit Quellenangabe bis zum Artikel, ohne Angstmacherei mit Zahlen.
NIS2
Does NIS2 apply to my company? A five-minute checkSector, size and a short list of exceptions decide whether NIS2 applies to you, and whether you are an essential or an important entity. Here is how to work it out.
NIS2
NIS2 in Estonia: what the amended Cybersecurity Act requiresEstonia's amended Cybersecurity Act (KüTS) has applied since 1 January 2026. Registration, board responsibility, incident reporting to RIA and the 2029 deadline, explained.
NIS2
NIS2 incident reporting: the 24-hour, 72-hour and one-month deadlinesWhat counts as a significant incident under NIS2, what goes in the early warning, the notification and the final report, and how to be ready before it happens.
NIS2
Not in scope of NIS2, but your customers are: what suppliers are asked forNIS2 makes in-scope organisations manage their suppliers' security. What that means for software vendors, IT providers and other suppliers who receive questionnaires and new contract clauses.
GDPR
Do small companies need a GDPR record of processing activities?Article 30 has an exemption for organisations with fewer than 250 employees, but it is narrower than most people think. When it applies, and why you probably still need a record.
GDPR
GDPR breach notification: when you must report within 72 hoursNot every personal data breach must be reported, but every one must be recorded. How to decide, what the notification must contain, and when to tell the people affected.
GDPR
Legitimate interests under the GDPR: when you can rely on it and how to document itLegitimate interests is the most flexible legal basis in the GDPR and the most often misused. The three-part test, what to write down, and when to use consent instead.
PDPL
UAE PDPL im Jahr 2026: Was jetzt für Ihr Unternehmen gilt und was noch ausstehtDas Bundesgesetzesdekret 45/2021 ist seit Januar 2022 in Kraft, aber die Ausführungsverordnung und die Bußgelder stehen noch aus. Was das in der Praxis für Unternehmen in den VAE bedeutet.
PDPL
PDPL vs. DSGVO: 7 Unterschiede, an denen eine kopierte Datenschutzrichtlinie scheitertViele Unternehmen in den VAE verwenden DSGVO-Vorlagen wieder. Hier unterscheidet sich das UAE PDPL, beginnend mit der Rechtsgrundlage, auf die sich die meisten EU-Richtlinien stützen und die das PDPL nicht kennt.
PDPL
Ihr Kunde hat einen PDPL-Fragebogen geschickt. Diese Dokumente erwartet erGroßunternehmen und Behörden in den VAE befragen Lieferanten inzwischen zum Datenschutz. Welche Fragen typisch sind und welches Dokument jede davon beantwortet.
PDPL
Braucht mein Unternehmen in den VAE einen Datenschutzbeauftragten?Artikel 10 des UAE PDPL legt drei Voraussetzungen für einen verpflichtenden DSB fest. Wie Sie erkennen, ob sie auf Sie zutreffen, und was zu tun ist, wenn nicht.