Editor

Is Employee Monitoring Software Legal Under GDPR? Rules for Remote Teams

Is Employee Monitoring Software Legal Under GDPR? Rules for Remote Teams Employee monitoring software can be legal under GDPR, but only under specific conditions. The problem is that most monitoring tools employers buy off the shelf are configured by default to break those conditions. The default settings on commercial monitoring software are built for maximum […]

Is Employee Monitoring Software Legal Under GDPR? Rules for Remote Teams Read More »

Is Cold Emailing GDPR Compliant? The Definitive B2B Sales Guide

Is Cold Emailing GDPR Compliant? The Definitive B2B Sales Guide Yes, cold emailing is GDPR compliant, but only under specific conditions. The GDPR law does not ban cold email outright; it essentially regulates the personal data processing behind it. For B2B outreach, the legal basis is legitimate interest under Article 6(1)(f), reinforced by Recital 47,

Is Cold Emailing GDPR Compliant? The Definitive B2B Sales Guide Read More »

Can You Use ChatGPT with Personal Data? A GDPR Compliance Guide For Businesses

Can You Use ChatGPT with Personal Data? A GDPR Compliance Guide For Businesses Yes, you can use ChatGPT with personal data under GDPR. Businesses across the EU and UK do this legally every day. However, it depends on which version of ChatGPT is in use, what OpenAI’s agreement actually commits to once you read past

Can You Use ChatGPT with Personal Data? A GDPR Compliance Guide For Businesses Read More »

How to Write a Privacy Notice That Meets GDPR Requirements

How to Write a Privacy Notice That Meets GDPR Requirements If you’re collecting personal data, whether through a signup form, cookie banner, or checkout page, GDPR requires you to disclose what you’re doing with it before or at the point of collection, using a privacy notice. Confusing this with your general privacy policy, or missing

How to Write a Privacy Notice That Meets GDPR Requirements Read More »

7 Privacy Policy Mistakes That Are Getting Businesses Fined

7 Privacy Policy Mistakes That Are Getting Businesses Fined On 21 January 2019, France’s data protection authority fined Google €50 million. No servers were breached, and no user data was stolen. Investigators had simply followed the steps a new Android user would take when setting up their phone and creating a Google account. To find

7 Privacy Policy Mistakes That Are Getting Businesses Fined Read More »

GDPR Right to Erasure: How to Handle Deletion Requests (and When You Can Refuse)

GDPR Right to Erasure: How to Handle Deletion Requests (and When You Can Refuse) Most deletion requests are straightforward. Someone closes an account, asks you to remove their data, and you do. The complexity arrives when the data can’t be deleted, or legally shouldn’t be. The GDPR right to erasure, enshrined in Article 17, is

GDPR Right to Erasure: How to Handle Deletion Requests (and When You Can Refuse) Read More »

GDPR Cookie Consent: What Your Banner Must Do to Be Compliant

GDPR Cookie Consent: What Your Banner Must Do to Be Compliant Most cookie banners are legal theatre. They perform compliance while systematically nudging users toward acceptance, and European regulators have grown tired of the act. GDPR cookie consent has always carried teeth, but enforcement in 2026 looks nothing like the cautious early years of the

GDPR Cookie Consent: What Your Banner Must Do to Be Compliant Read More »

Why Organisations Fail the GDPR 72-Hour Breach Notification Rule

Why Organisations Fail the GDPR 72-Hour Breach Notification Rule Nobody plans to mishandle a data breach. But when one happens, there is usually a lot of pressure, and the information is almost never complete. In most cases, the systems are down, the security team is still trying to understand what happened, and at the same

Why Organisations Fail the GDPR 72-Hour Breach Notification Rule Read More »

X