Blog

GDPR, PCI & Data Privacy Insights

Practical compliance guidance for IT administrators and security engineers. No filler, no legal boilerplate - just actionable advice for lean teams.

PCI DSS

Which PCI SAQ applies to you, and why the wrong one gets picked

The self-assessment questionnaire you complete is determined by how you take payments, not by how big you are. Picking the wrong one produces an attestation that does not cover what you actually do.

11 September 20268 min read
GDPR

What happens to personal data when an employee leaves

Offboarding checklists cover accounts, licences and hardware. They rarely cover the customer data in the leaver's local files, mailbox exports and downloads, which is still there when the machine is reissued.

10 September 20263 min read
EU AI Act

Deployer or provider? How to work out your role under the EU AI Act

Most organisations using AI are deployers. Putting your name on a system, modifying it substantially, or changing what it is for can make you a provider, and the obligations are an order of magnitude heavier.

9 September 20264 min read
GDPR

The six lawful bases, and how to choose one you can defend

Article 6 gives you six lawful bases and no ranking between them. Here's what separates them in practice, why the choice is harder to change than to make, and what you need to hold to justify it.

7 September 202611 min read
GDPR

How long can you keep personal data? Building a retention schedule you can enforce

GDPR's storage limitation principle sets no fixed periods. Here's how to set ones you can justify, and how to check they held on endpoints as well as in the systems that have a delete button.

3 September 20263 min read
EU AI Act

AI Act Article 50: what you must tell people about chatbots and AI-generated content

Article 50 applied on 2 August 2026 and attaches to how a system interacts with people, not to its risk tier. Two duties sit with providers, two with deployers. Here's which is which, and a checklist you can run this week.

2 September 20264 min read
EU AI Act

The EU AI Act's high-risk deadline moved. Here's what still applied on 2 August 2026.

The Digital Omnibus deferred the Annex III high-risk obligations to December 2027. Article 50 transparency was not deferred. A plain reading of what is live now, what moved, and the dates that are closer than they look.

26 August 20265 min read
Compliance

Best GDPR & sensitive data discovery tools for lean teams (2026)

Eight GDPR and sensitive-data discovery tools compared on deployment time, real pricing, and who each one actually fits - reviewed honestly, disclosure included.

10 August 20269 min read
DSAR

What is a DSAR and how do you respond within GDPR's deadline?

A Data Subject Access Request (DSAR) gives individuals the right to see every piece of personal data you hold about them. Here's the practical IT admin's guide to responding on time.

10 June 20269 min read
GDPR

GDPR Article 30: how to build a Record of Processing Activities without a spreadsheet

Article 30 requires every organisation with 250+ employees to maintain a formal ROPA - but even smaller teams should have one. Here's how to build an audit-ready record without drowning in spreadsheets.

3 June 20268 min read
PCI DSS

PCI DSS 4.0 scope reduction: why endpoint scanning beats annual questionnaires

Reducing your PCI DSS cardholder data environment scope is the most effective way to cut compliance cost. Here's how endpoint scanning changes the game versus traditional SAQ approaches.

27 May 20268 min read
Compliance

How to prepare for a GDPR audit: the IT admin's 11-point checklist

A practical 11-point checklist for IT administrators preparing for a GDPR audit or ICO investigation. Covers documentation, access controls, breach readiness, and data discovery.

20 May 20266 min read
GDPR

Data breach notification under GDPR: what you must do in the first 72 hours

GDPR Article 33 gives you 72 hours to notify your supervisory authority after discovering a personal data breach. Here's a practical timeline and decision framework for IT teams.

13 May 20269 min read

Want more of this in Google?

See what personal data your endpoints are hiding

EmberHound scans your devices for GDPR and PCI data - no manual spreadsheet required.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy