Zum Inhalt springen
Subject Access Requests in 2026: What the Updated ICO Guidance Means

EINBLICKE & NEWS

Subject Access Requests in 2026: What the Updated ICO Guidance Means

The Data (Use and Access) Act 2025 codified the reasonable and proportionate search standard. Deadlines, identity checks, exemptions, redaction and a 30-day workflow.

Operations9 Min. Lesezeit
AI Web Scraping Under GDPR: What the EDPB's 2026 Guidance Means
Regulierung8 Min. Lesezeit

Neueste Artikel

AI Web Scraping Under GDPR: What the EDPB's 2026 Guidance Means

Publicly available does not mean freely usable. What the EDPB's draft Guidelines 03/2026 require before scraping personal data to train generative AI.

Weiterlesen →
Anonymised or Still Personal Data? The EDPB's New Three-Part Test
Regulierung8 Min. Lesezeit

Neueste Artikel

Anonymised or Still Personal Data? The EDPB's New Three-Part Test

Removing names does not make data anonymous. How to apply the three-part test in draft Guidelines 02/2026: no record isolation, no linkage, no inference.

Weiterlesen →
EU AI Act: Where Data Controllers Stand After the 2026 Omnibus
AI Act6 Min. Lesezeit

Neueste Artikel

EU AI Act: Where Data Controllers Stand After the 2026 Omnibus

The EU has finalised the AI Act simplification package, moving high-risk deadlines to Dec 2027. What deployers and controllers should do now.

Weiterlesen →
Cookie Compliance: 5 Evidence Gaps Auditors Keep Finding
Web-Compliance5 Min. Lesezeit

Neueste Artikel

Cookie Compliance: 5 Evidence Gaps Auditors Keep Finding

CMP logs, consent scope, dark patterns, and what “proof” looks like in practice across EU/UK guidance.

Weiterlesen →
Vendor Risk in SaaS: SCCs, TIAs & Practical Controls
Lieferantenrisiko7 Min. Lesezeit

Neueste Artikel

Vendor Risk in SaaS: SCCs, TIAs & Practical Controls

How to operationalise vendor reviews without slowing teams down — a tiered approach that works.

Weiterlesen →
DPIA Done Right: Risk Triggers Your Teams Will Actually Use
Betrieb6 Min. Lesezeit

Neueste Artikel

DPIA Done Right: Risk Triggers Your Teams Will Actually Use

Turn DPIAs into a lightweight guardrail — where they sit in tickets, PRs, and launch checklists.

Weiterlesen →
Security Baselines Every Privacy Programme Should Adopt
Sicherheit6 Min. Lesezeit

Neueste Artikel

Security Baselines Every Privacy Programme Should Adopt

From hardening and identity to logging and encryption — privacy-by-design in action.

Weiterlesen →
Outsourced DPO: What “Good” Looks Like
DPO5 Min. Lesezeit

Neueste Artikel

Outsourced DPO: What “Good” Looks Like

Scope, independence, reporting lines and cadence — what to expect from an effective DPO engagement.

Weiterlesen →
Company Formation: KYC Evidence Clients Forget
Unternehmen4 Min. Lesezeit

Neueste Artikel

Company Formation: KYC Evidence Clients Forget

A short checklist to avoid back-and-forth with banks and corporate service providers.

Weiterlesen →

Machen Sie aus Einblicken Taten.

Steht eines dieser Themen auf Ihrer Roadmap, machen wir daraus einen konkreten Plan — mit prüfungsfesten Nachweisen ab Tag eins.

„Diese Einblicke haben unsere DSFA und unseren Lieferanten- Review-Prozess geprägt. Wir bekamen konkrete Formulierungen und Kontrollen, die direkt in unsere Abläufe passten.“

Compliance-Leiterin, europäisches SaaS