Guides
Des guides en langage clair sur les lois couvertes par nos évaluations. Sources citées à l'article près, sans chiffres alarmistes.
NIS2
Does NIS2 apply to my company? A five-minute checkSector, size and a short list of exceptions decide whether NIS2 applies to you, and whether you are an essential or an important entity. Here is how to work it out.
NIS2
NIS2 in Estonia: what the amended Cybersecurity Act requiresEstonia's amended Cybersecurity Act (KüTS) has applied since 1 January 2026. Registration, board responsibility, incident reporting to RIA and the 2029 deadline, explained.
NIS2
NIS2 incident reporting: the 24-hour, 72-hour and one-month deadlinesWhat counts as a significant incident under NIS2, what goes in the early warning, the notification and the final report, and how to be ready before it happens.
NIS2
Not in scope of NIS2, but your customers are: what suppliers are asked forNIS2 makes in-scope organisations manage their suppliers' security. What that means for software vendors, IT providers and other suppliers who receive questionnaires and new contract clauses.
GDPR
Do small companies need a GDPR record of processing activities?Article 30 has an exemption for organisations with fewer than 250 employees, but it is narrower than most people think. When it applies, and why you probably still need a record.
GDPR
GDPR breach notification: when you must report within 72 hoursNot every personal data breach must be reported, but every one must be recorded. How to decide, what the notification must contain, and when to tell the people affected.
GDPR
Legitimate interests under the GDPR: when you can rely on it and how to document itLegitimate interests is the most flexible legal basis in the GDPR and the most often misused. The three-part test, what to write down, and when to use consent instead.
PDPL
Le PDPL des EAU en 2026 : ce qui s'applique déjà à votre entreprise, et ce qui reste en attenteLe décret-loi fédéral n° 45/2021 est en vigueur depuis janvier 2022, mais son règlement d'application et ses amendes sont toujours attendus. Ce que cela signifie concrètement pour les entreprises aux EAU.
PDPL
PDPL et RGPD : 7 différences qui rendent caduque une politique de confidentialité recopiéeDe nombreuses entreprises aux EAU réutilisent des modèles RGPD. Voici en quoi le PDPL des EAU diffère, à commencer par la base juridique sur laquelle reposent la plupart des politiques européennes et que le PDPL ne prévoit pas.
PDPL
Votre client vous a envoyé un questionnaire PDPL. Voici les documents qu'il attendLes grandes entreprises et les entités publiques des EAU interrogent désormais leurs fournisseurs sur la protection des données. Quelles sont les questions habituelles, et quel document répond à chacune.
PDPL
Mon entreprise aux EAU a-t-elle besoin d'un délégué à la protection des données ?L'article 10 du PDPL des EAU fixe trois conditions rendant un DPO obligatoire. Comment savoir si elles s'appliquent à vous, et que faire si ce n'est pas le cas.