Руководства
Понятные руководства по законам, охватываемым нашими оценками. Со ссылками на статьи, без запугивающих цифр.
NIS2
Does NIS2 apply to my company? A five-minute checkSector, size and a short list of exceptions decide whether NIS2 applies to you, and whether you are an essential or an important entity. Here is how to work it out.
NIS2
NIS2 in Estonia: what the amended Cybersecurity Act requiresEstonia's amended Cybersecurity Act (KüTS) has applied since 1 January 2026. Registration, board responsibility, incident reporting to RIA and the 2029 deadline, explained.
NIS2
NIS2 incident reporting: the 24-hour, 72-hour and one-month deadlinesWhat counts as a significant incident under NIS2, what goes in the early warning, the notification and the final report, and how to be ready before it happens.
NIS2
Not in scope of NIS2, but your customers are: what suppliers are asked forNIS2 makes in-scope organisations manage their suppliers' security. What that means for software vendors, IT providers and other suppliers who receive questionnaires and new contract clauses.
GDPR
Do small companies need a GDPR record of processing activities?Article 30 has an exemption for organisations with fewer than 250 employees, but it is narrower than most people think. When it applies, and why you probably still need a record.
GDPR
GDPR breach notification: when you must report within 72 hoursNot every personal data breach must be reported, but every one must be recorded. How to decide, what the notification must contain, and when to tell the people affected.
GDPR
Legitimate interests under the GDPR: when you can rely on it and how to document itLegitimate interests is the most flexible legal basis in the GDPR and the most often misused. The three-part test, what to write down, and when to use consent instead.
PDPL
PDPL ОАЭ в 2026 году: что уже применяется к Вашему бизнесу и что ещё не принятоФедеральный декрет-закон № 45/2021 действует с января 2022 года, но его Исполнительные положения и штрафы до сих пор не приняты. Что это означает на практике для бизнеса в ОАЭ.
PDPL
PDPL и GDPR: 7 различий, из-за которых скопированная политика конфиденциальности не работаетМногие компании в ОАЭ используют шаблоны GDPR повторно. Вот чем отличается PDPL ОАЭ — начиная с правового основания, на которое опирается большинство политик ЕС и которого в PDPL нет.
PDPL
Ваш клиент прислал анкету по PDPL. Вот какие документы он ожидаетКрупные компании и государственные органы в ОАЭ теперь задают поставщикам вопросы о защите данных. Какие вопросы типичны и какой документ отвечает на каждый из них.
PDPL
Нужен ли моему бизнесу в ОАЭ инспектор по защите данных?Статья 10 PDPL ОАЭ устанавливает три условия обязательного назначения DPO. Как определить, применимы ли они к Вам, и что делать, если нет.