How to choose the right GDPR software for your organisation? Most start with Excel — record of processing activities in a spreadsheet, authorisations in a separate file, retention deadlines somewhere in a calendar. It works at first. The problem appears after a few...
Blog
Expert articles, step-by-step guides and regulatory news on GDPR and data protection. We cover what actually affects the daily work of DPOs, controllers and compliance professionals — from the record of processing activities and risk assessments to legislative changes and supervisory authority decisions.
Processing Personal Data for Scientific Research — What the New EDPB Guidelines Clarify
2026 Apr 25 | GDPR Watch
On 16 April 2026, the European Data Protection Board (EDPB) adopted Guidelines 1/2026 on the processing of personal data for scientific research purposes. The document has been opened for public consultation — the deadline for comments is 25 June 2026. These are among...
Europrivacy as a Mechanism for International Data Transfers — What the EDPB Decision Changes
2026 Apr 25 | GDPR Watch
On 16 April 2026, the European Data Protection Board (EDPB) adopted two significant decisions regarding Europrivacy certification. First, it extended the scope of Europrivacy to controllers and processors established outside Europe who are subject to the GDPR under...
CEF 2026 — EDPB Launches Coordinated Enforcement on Transparency and Information Obligations
2026 Apr 25 | GDPR Watch
On 19 March 2026, the European Data Protection Board (EDPB) officially launched the fifth edition of the Coordinated Enforcement Framework (CEF) — a coordinated GDPR enforcement action carried out simultaneously by national supervisory authorities across Europe. The...
CCPA vs GDPR – Key Differences and What They Mean for Your Business
2026 Apr 21 | GDPR and iGDPR guides for practitioners and beginners
CCPA vs GDPR — these are the two most influential data privacy laws currently in force, and understanding how they differ is essential for any organization operating across the EU and the US. But they are not the same law, and compliance with one does not guarantee...
GDPR Compliance for US Companies – When It Applies and What to Do
2026 Apr 21 | GDPR and iGDPR guides for practitioners and beginners
GDPR compliance for US companies is not optional — and it is not a European problem alone. It is not. If your company collects, processes, or monitors the personal data of individuals located in the EU — regardless of where your business is incorporated or where your...
Digital Omnibus – What Changes to the GDPR and What the EDPB Says About It
2026 Apr 18 | GDPR Watch
On 19 November 2025, the European Commission published a legislative package known as the Digital Omnibus. It is the most comprehensive proposal for GDPR changes since the regulation entered into force in 2018. The package covers amendments to the GDPR,...
Personal Data Breaches Under GDPR – How the 72-Hour Rule Works Across Europe
2026 Apr 16 | GDPR and iGDPR guides for practitioners and beginners
A personal data breach is one of those events every organisation hopes will never happen — and one for which every organisation needs a documented procedure before it does. The GDPR introduced a mandatory 72-hour notification requirement that fundamentally changed how...
Employee Monitoring and GDPR – What Employers Can Do
2026 Apr 16 | GDPR and iGDPR guides for practitioners and beginners
Employee monitoring under GDPR is one of the areas most frequently scrutinised by supervisory authorities across the EU — and at the same time one of the most commonly applied by employers without full awareness of the legal boundaries. The GDPR does not regulate...
Email Marketing and GDPR – Consent, Legal Bases, and What Changes Under the ePrivacy Rules
2026 Apr 16 | GDPR and iGDPR guides for practitioners and beginners
Email marketing is one of the areas where compliance requirements change fastest — and where violations are easiest to detect. Every organisation running a newsletter, email campaigns, or any form of direct electronic marketing across the EU must navigate two parallel...
EDPB DPIA Template – What It Contains and What Changes for Organisations
2026 Apr 16 | GDPR Watch
On 14 April 2026, the European Data Protection Board (EDPB) published the first harmonised template for Data Protection Impact Assessments (DPIA) and opened it for public consultation. The deadline for comments is 9 June 2026. The deadline for comments is 9 June 2026....
Data Protection Officer – When Required, Responsibilities, and Common Pitfalls
2026 Apr 15 | GDPR and iGDPR guides for practitioners and beginners
The Data Protection Officer (DPO) is one of the most ambiguous roles in the organisational structure arising from the GDPR. In many organisations, the DPO is simply the person who "does GDPR" — writing documents, conducting training, answering employee questions. Yet...
Data Transfers Outside the EEA – When They Are Lawful and How to Safeguard Them
2026 Apr 15 | GDPR and iGDPR guides for practitioners and beginners
Every organisation using SaaS systems, cloud services, email marketing tools, CRM platforms, or HR software should ask itself one question: where are my customers' and employees' data actually processed? If a vendor's servers or technical operations are located...
GDPR Compliance Audit – How to Conduct One and What to Check
2026 Apr 15 | GDPR and iGDPR guides for practitioners and beginners
A GDPR audit is one of those tasks that sounds serious but is rarely carried out regularly in practice. The reason is simple: without proper structure, an audit becomes a one-off exercise — a document review that quickly becomes outdated once it is finished. Yet the...
NIS2 and GDPR – What They Have in Common and What You Need to Do
2026 Apr 15 | GDPR and iGDPR guides for practitioners and beginners
From 3 April 2026, the amended Act on the National Cybersecurity System (KSC), implementing the EU NIS2 Directive, is in force in Poland. For thousands of organisations across Europe, this means new cybersecurity obligations — regardless of whether they already comply...
Employee Personal Data – What You Can Process and for How Long
2026 Apr 15 | GDPR and iGDPR guides for practitioners and beginners
Employee personal data is one of the most extensive areas of GDPR in practice — and at the same time one of the most frequently overlooked during implementation. Organisations focus on customer data and forget that the employer-employee relationship generates a broad...
Privacy Policy – What It Must Contain and How to Write It
2026 Apr 15 | GDPR and iGDPR guides for practitioners and beginners
A privacy policy is one of those documents that most companies have — but which rarely serves its actual purpose. The most common scenario: the website owner copied a template from the internet, changed the company name, and published it. The document describes data...
GDPR Supervisory Authority Inspections – How to Prepare and What Authorities Check
2026 Apr 11 | GDPR and iGDPR guides for practitioners and beginners
A supervisory authority inspection is one of those events that organisations tend to treat as a distant risk — until it arrives. In reality, data protection authorities across Europe are increasingly active, coordinated and well-resourced. The cumulative total of GDPR...
GDPR and Ecommerce – Obligations for Online Store Owners
2026 Apr 8 | GDPR and iGDPR guides for practitioners and beginners
Running an online store inevitably involves processing the personal data of customers — from order placement, through payment and delivery, to returns and marketing communications. Each of these stages is a separate processing activity requiring an appropriate legal...
GDPR in Corporate Groups – Managing Data Protection Across Multiple Entities
2026 Apr 8 | GDPR and iGDPR guides for practitioners and beginners
GDPR corporate groups compliance is one of the most demanding organisational challenges in data protection. Each company within a group is a separate legal entity — and therefore, as a rule, a separate data controller under GDPR. You cannot manage compliance centrally...
