
Prohibited AI Practices: Article 5 Is Already In Force
The EU AI Act’s eight prohibited AI practices have applied since 2 February 2025, with fines up to…
CART
No products in the cart.

The EU AI Act’s eight prohibited AI practices have applied since 2 February 2025, with fines up to…

DORA, NIS2, ISO 27001 and sector schemes ask about the same suppliers in different formats. Build one inventory…

DORA’s register of information carries four obligations, and the forward-looking ones get missed. All arrangements, prescribed templates, and…

A DPO is mandatory in three cases, and all of them turn on core activities. What Article 38…

GDPR Chapter V has a strict order: adequacy, then safeguards, then situational derogations. Why the last route is…

Article 15 asks for the data plus eight further items. The extension you must claim inside month one,…

GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you…

A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss…

GDPR Article 30 records of processing: the exemption almost never applies, controllers and processors keep different records, and…

A DPIA has four mandatory elements and two of them get skipped. What Article 35 requires, when Article…

TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and…

The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not…
August 18, 2026
August 17, 2026
August 16, 2026
August 16, 2026
August 16, 2026