GDPR, PCI & Data Privacy Insights
Practical compliance guidance for IT administrators and security engineers. No filler, no legal boilerplate - just actionable advice for lean teams.
Which PCI SAQ applies to you, and why the wrong one gets picked
The self-assessment questionnaire you complete is determined by how you take payments, not by how big you are. Picking the wrong one produces an attestation that does not cover what you actually do.
What happens to personal data when an employee leaves
Offboarding checklists cover accounts, licences and hardware. They rarely cover the customer data in the leaver's local files, mailbox exports and downloads, which is still there when the machine is reissued.
Deployer or provider? How to work out your role under the EU AI Act
Most organisations using AI are deployers. Putting your name on a system, modifying it substantially, or changing what it is for can make you a provider, and the obligations are an order of magnitude heavier.
The six lawful bases, and how to choose one you can defend
Article 6 gives you six lawful bases and no ranking between them. Here's what separates them in practice, why the choice is harder to change than to make, and what you need to hold to justify it.
How long can you keep personal data? Building a retention schedule you can enforce
GDPR's storage limitation principle sets no fixed periods. Here's how to set ones you can justify, and how to check they held on endpoints as well as in the systems that have a delete button.
AI Act Article 50: what you must tell people about chatbots and AI-generated content
Article 50 applied on 2 August 2026 and attaches to how a system interacts with people, not to its risk tier. Two duties sit with providers, two with deployers. Here's which is which, and a checklist you can run this week.
The EU AI Act's high-risk deadline moved. Here's what still applied on 2 August 2026.
The Digital Omnibus deferred the Annex III high-risk obligations to December 2027. Article 50 transparency was not deferred. A plain reading of what is live now, what moved, and the dates that are closer than they look.
Best GDPR & sensitive data discovery tools for lean teams (2026)
Eight GDPR and sensitive-data discovery tools compared on deployment time, real pricing, and who each one actually fits - reviewed honestly, disclosure included.
What is a DSAR and how do you respond within GDPR's deadline?
A Data Subject Access Request (DSAR) gives individuals the right to see every piece of personal data you hold about them. Here's the practical IT admin's guide to responding on time.
GDPR Article 30: how to build a Record of Processing Activities without a spreadsheet
Article 30 requires every organisation with 250+ employees to maintain a formal ROPA - but even smaller teams should have one. Here's how to build an audit-ready record without drowning in spreadsheets.
PCI DSS 4.0 scope reduction: why endpoint scanning beats annual questionnaires
Reducing your PCI DSS cardholder data environment scope is the most effective way to cut compliance cost. Here's how endpoint scanning changes the game versus traditional SAQ approaches.
How to prepare for a GDPR audit: the IT admin's 11-point checklist
A practical 11-point checklist for IT administrators preparing for a GDPR audit or ICO investigation. Covers documentation, access controls, breach readiness, and data discovery.
Data breach notification under GDPR: what you must do in the first 72 hours
GDPR Article 33 gives you 72 hours to notify your supervisory authority after discovering a personal data breach. Here's a practical timeline and decision framework for IT teams.
See what personal data your endpoints are hiding
EmberHound scans your devices for GDPR and PCI data - no manual spreadsheet required.


