Juhendid
Lihtsas keeles juhendid seaduste kohta, mida meie hindamised hõlmavad. Viidetega artiklitele, ilma hirmutavate numbriteta.
NIS2
Does NIS2 apply to my company? A five-minute checkSector, size and a short list of exceptions decide whether NIS2 applies to you, and whether you are an essential or an important entity. Here is how to work it out.
NIS2
NIS2 in Estonia: what the amended Cybersecurity Act requiresEstonia's amended Cybersecurity Act (KüTS) has applied since 1 January 2026. Registration, board responsibility, incident reporting to RIA and the 2029 deadline, explained.
NIS2
NIS2 incident reporting: the 24-hour, 72-hour and one-month deadlinesWhat counts as a significant incident under NIS2, what goes in the early warning, the notification and the final report, and how to be ready before it happens.
NIS2
Not in scope of NIS2, but your customers are: what suppliers are asked forNIS2 makes in-scope organisations manage their suppliers' security. What that means for software vendors, IT providers and other suppliers who receive questionnaires and new contract clauses.
GDPR
Do small companies need a GDPR record of processing activities?Article 30 has an exemption for organisations with fewer than 250 employees, but it is narrower than most people think. When it applies, and why you probably still need a record.
GDPR
GDPR breach notification: when you must report within 72 hoursNot every personal data breach must be reported, but every one must be recorded. How to decide, what the notification must contain, and when to tell the people affected.
GDPR
Legitimate interests under the GDPR: when you can rely on it and how to document itLegitimate interests is the most flexible legal basis in the GDPR and the most often misused. The three-part test, what to write down, and when to use consent instead.
PDPL
AÜE PDPL 2026. aastal: mis kehtib Teie ettevõttele juba praegu ja mis on veel ootelFöderaalne dekreetseadus 45/2021 on jõus alates 2022. aasta jaanuarist, kuid selle rakendusmäärused ja trahvid on veel ootel. Mida see AÜE ettevõtetele praktikas tähendab.
PDPL
PDPL vs IKÜM: 7 erinevust, mis muudavad kopeeritud privaatsuspoliitika kasutuskõlbmatuksPaljud AÜE ettevõtted kasutavad IKÜMi dokumendipõhju. Siin on kohad, kus AÜE PDPL erineb, alustades õiguslikust alusest, millele enamik ELi poliitikaid tugineb ja mida PDPL-is ei ole.
PDPL
Teie klient saatis PDPL-i küsimustiku. Need on dokumendid, mida ta ootabAÜE suurettevõtted ja riigiasutused küsivad nüüd tarnijatelt andmekaitse kohta. Millised on tüüpilised küsimused ja milline dokument vastab igaühele neist.
PDPL
Kas minu AÜE ettevõte vajab andmekaitseametnikku?AÜE PDPL-i artikkel 10 sätestab kolm tingimust, mille korral andmekaitseametnik on kohustuslik. Kuidas teha kindlaks, kas need kehtivad Teile, ja mida teha, kui ei kehti.