GDPR DPO Designation: Article 37 Requirements Explained
When a DPO is mandatory under GDPR Article 37, how to appoint one, and recent EDPB enforcement findings.
Practical analysis on GDPR, privacy operations, DORA, NIS2 and the EU AI Act.
Page 1 of 12 — newest 18 of 208 articles in English
When a DPO is mandatory under GDPR Article 37, how to appoint one, and recent EDPB enforcement findings.
Only the DPO is regulated by the GDPR. See how the Data Protection Officer differs from a compliance officer, when it is mandatory, and who appoints one.
Understand GDPR supervisory authority powers, lead-authority rules and how Swiss FDPIC investigations and criminal fines differ.
An in-depth analysis of the GDPR's principle of accountability, including legal references, case studies, and practical implementation tips.
Read Article 20 with its official source: consent or contract, automated processing, provided data, usable exports and the one-month response period.
Article 5(1)(e) explained: purpose-based retention, justified periods, archives, backups, legal holds and a practical deletion-check example.
The seven GDPR principles explained through decisions, evidence and a hypothetical registration form: lawful basis, purpose, minimisation, accuracy, retention, security and accountability.
Implement GDPR data storage requirements: lawful purpose, retention rules, security, backups, processor contracts, transfers and deletion evidence.
Comprehensive guide to cyber privacy: definition, threats from AI and data brokers, IoT security, and practical defense strategies for your digital rights.
Understand how GDPR fines are calculated, see the largest penalties to date, and learn what steps your organisation should take to reduce enforcement risk.
Learn how GDPR data breach notification works, the 72-hour reporting rule, what to include, and how to avoid regulatory penalties.
Step-by-step guide to conducting a GDPR-compliant cookie audit. Covers discovery, classification, documentation, gap analysis, and ongoing monitoring.
Compare documented workflows, product limits, first-year cost, migration and evidence with a practical purchasing checklist for Legiscope and OneTrust.
Learn how NIS2 classifies essential and important entities, which sectors fall under each category, size thresholds, and how obligations and penalties differ.
Current EU AI Act calendar: Article 50 transparency, GPAI transitions, December 2027 and August 2028 high-risk dates, and role-specific planning.
Plan GDPR costs from scoped work, staffing, vendors, security and tooling. Includes a budget worksheet and a clearly hypothetical calculation.
Opt-in means ask first; opt-out means stop on request. When GDPR requires each, with a comparison table and examples for email, cookies, calls and data sharing.