Gu铆as
Gu铆as en lenguaje sencillo sobre las leyes que cubren nuestras evaluaciones. Con referencia a cada art铆culo, sin cifras alarmistas.
NIS2
Does NIS2 apply to my company? A five-minute checkSector, size and a short list of exceptions decide whether NIS2 applies to you, and whether you are an essential or an important entity. Here is how to work it out.
NIS2
NIS2 in Estonia: what the amended Cybersecurity Act requiresEstonia's amended Cybersecurity Act (K眉TS) has applied since 1 January 2026. Registration, board responsibility, incident reporting to RIA and the 2029 deadline, explained.
NIS2
NIS2 incident reporting: the 24-hour, 72-hour and one-month deadlinesWhat counts as a significant incident under NIS2, what goes in the early warning, the notification and the final report, and how to be ready before it happens.
NIS2
Not in scope of NIS2, but your customers are: what suppliers are asked forNIS2 makes in-scope organisations manage their suppliers' security. What that means for software vendors, IT providers and other suppliers who receive questionnaires and new contract clauses.
GDPR
Do small companies need a GDPR record of processing activities?Article 30 has an exemption for organisations with fewer than 250 employees, but it is narrower than most people think. When it applies, and why you probably still need a record.
GDPR
GDPR breach notification: when you must report within 72 hoursNot every personal data breach must be reported, but every one must be recorded. How to decide, what the notification must contain, and when to tell the people affected.
GDPR
Legitimate interests under the GDPR: when you can rely on it and how to document itLegitimate interests is the most flexible legal basis in the GDPR and the most often misused. The three-part test, what to write down, and when to use consent instead.
PDPL
La PDPL de los EAU en 2026: qu茅 se aplica ya a su empresa y qu茅 sigue pendienteEl Decreto-ley federal 45/2021 est谩 en vigor desde enero de 2022, pero su Reglamento Ejecutivo y sus multas siguen pendientes. Qu茅 significa esto en la pr谩ctica para las empresas de los EAU.
PDPL
PDPL frente a RGPD: 7 diferencias que invalidan una pol铆tica de privacidad copiadaMuchas empresas de los EAU reutilizan plantillas del RGPD. Estas son las diferencias de la PDPL de los EAU, empezando por la base jur铆dica en la que se apoyan la mayor铆a de las pol铆ticas de la UE y que la PDPL no contempla.
PDPL
Su cliente le ha enviado un cuestionario sobre la PDPL. Estos son los documentos que esperaLas grandes empresas y las entidades p煤blicas de los EAU ya preguntan a sus proveedores por la protecci贸n de datos. Cu谩les son las preguntas habituales y qu茅 documento responde a cada una.
PDPL
驴Necesita mi empresa en los EAU un delegado de protecci贸n de datos?El art铆culo 10 de la PDPL de los EAU establece tres condiciones para la designaci贸n obligatoria de un DPD. C贸mo saber si se aplican a su caso y qu茅 hacer si no es as铆.