Compliance Guides

Plain-English Compliance

Practical guides to GDPR, privacy law, and business compliance — written for founders, small business owners, and new businesses, not lawyers.

32 articles found

LatestSmall BusinessJuly 2026 · 4 min read

Terms and Conditions for a Small Online Shop: A Plain-English UK Guide

The Consumer Rights Act, the 14-day cooling-off period, and the new fake-review rules - what your shop's T&Cs must cover to sell online in the UK without nasty surprises.

Read article
Small Business

Privacy Policy for a Small Business Website: What UK Law Actually Requires

A contact form is enough to trigger UK GDPR's transparency rules. The eight things your website privacy policy must cover - and the copied-template mistakes that get small businesses in trouble.

July 20263 min read
Small Business

The ICO Data Protection Fee: Does Your Small Business Have to Pay?

Most UK businesses that handle personal data owe the ICO an annual fee - and many small firms only find out when the penalty letter arrives. The tiers, the exemptions, and how to register.

July 20263 min read
Privacy

Do You Need a Privacy Policy for a Newsletter?

Collecting email addresses makes you a data controller - even for a free Substack. What PECR and UK GDPR require before you hit send, and what your policy must actually say.

July 20264 min read
GDPR

UK GDPR vs EU GDPR: What Actually Changed

Same rules, different regulators? Not quite. From the Data (Use and Access) Act 2025 to transfer paperwork and dual representation, here is where the two regimes now genuinely differ.

July 20264 min read
Small Business

Do I Need a Privacy Policy for My Shopify Store? (UK Guide)

Yes - and Shopify's auto-generated template is not enough on its own. Here is exactly what UK GDPR requires your store's privacy policy to say, in plain English.

July 20264 min read
Compliance

AI Governance Policies: What Your Company Needs in 2026

From model risk registers to human oversight requirements, AI governance is no longer optional. Here is what your internal AI policy must cover to satisfy regulators and protect your business.

April 20262 min read
Compliance

DORA Compliance for Financial Services: A Complete Guide

The Digital Operational Resilience Act is now enforceable across the EU. This guide covers ICT risk management, incident reporting, third-party oversight, and testing requirements for financial entities.

April 20261 min read
Privacy

Remote Work and Data Protection: What Employers Must Know

With distributed teams comes distributed data risk. Learn how to handle employee monitoring, cross-border data transfers, and BYOD policies without violating privacy laws.

April 20261 min read
Compliance

How to Build an AI Model Risk Register

The EU AI Act and NIST AI RMF both require documented risk assessments for AI systems. Here is how to build a risk register that satisfies auditors.

April 20261 min read
Privacy

How to Write an Effective Data Breach Response Plan

A data breach without a response plan turns a bad situation into a catastrophe. Learn how to build a plan that covers detection, containment, notification, and recovery before you need it.

March 20262 min read
Regulations

Employee Handbook Best Practices for Remote Teams

Remote work has changed what employee handbooks need to cover. From equipment policies to cross-border employment law, here is how to write a handbook that works for distributed teams.

March 20261 min read
Compliance

NIS2 Directive: What It Means for Your Business

The NIS2 Directive significantly expands cybersecurity obligations across the EU. Find out whether your organisation is in scope and what you need to do to comply.

March 20261 min read
GDPR

GDPR Compliance Checklist for SaaS Founders in 2026

A practical step-by-step checklist covering the six lawful bases, data subject rights, DPA obligations, and what actually triggers an ICO investigation.

March 20262 min read
Regulations

SLA Best Practices for SaaS Companies

Your Service Level Agreement defines uptime commitments, support response times, and remedies for breaches. Get it wrong and you are exposed to costly claims.

March 20261 min read
Privacy

Protecting Children Online: COPPA, UK Children's Code, and GDPR Article 8

If your product could be accessed by under-18s, you have specific legal obligations. This guide covers age verification, parental consent, and age-appropriate design.

March 20261 min read
Compliance

AML and KYC Policies: A Complete Guide for Fintechs

Anti-money laundering regulations are getting stricter globally. Learn what your AML policy must include and how to implement effective KYC procedures.

March 20261 min read
Privacy

Building a Privacy-First Product: Developer's Guide

Privacy by design is a legal requirement under GDPR, not just a best practice. This developer-focused guide covers data minimisation, purpose limitation, encryption, and privacy-preserving architecture patterns.

February 20262 min read
Compliance

Understanding the EU AI Act: Requirements for High-Risk AI Systems

The EU AI Act introduces a risk-based classification framework for artificial intelligence. Learn what qualifies as high-risk, what the compliance obligations are, and how to prepare your AI systems.

February 20261 min read
Privacy

7 Privacy Policy Mistakes That Will Get You Fined

Vague data retention periods, missing lawful basis disclosures, buried contact details - here are the most common compliance failures and how to fix them.

February 20262 min read
Regulations

What Every SaaS Terms of Service Must Include

From limitation of liability to acceptable use, subscription terms, and IP ownership - a founder's guide to writing a ToS that actually protects you.

February 20262 min read
Regulations

Whistleblowing Policies: EU Directive and UK Requirements

The EU Whistleblower Protection Directive requires internal reporting channels for companies with 50+ employees. Here is how to write a compliant policy.

February 20261 min read
GDPR

Data Retention Schedules: How Long Should You Keep Personal Data?

GDPR requires you to justify how long you retain personal data. This guide covers retention periods by data type and how to build a compliant retention schedule.

February 20261 min read
Regulations

Accessibility Policies: ADA and EAA Compliance Made Simple

Digital accessibility is now a legal requirement in both the US and EU. This guide breaks down ADA and European Accessibility Act obligations and how to write an accessibility policy that meets them.

January 20261 min read
Cookies

Cookie Consent in 2026: What's Changed and What You Need to Do

The ICO and CNIL have both issued new guidance on cookie consent banners. Here is what it means for your website and how to stay compliant.

January 20262 min read
Compliance

CCPA vs GDPR: Key Differences for Global Businesses

Selling to customers in both the US and EU? Here is a side-by-side comparison of your obligations under each regime and where they conflict.

January 20262 min read
Compliance

HIPAA Compliance for Healthcare Startups

Building a health tech product? HIPAA compliance is not optional. Learn about PHI handling, Business Associate Agreements, and the Security Rule requirements.

January 20261 min read
Regulations

Regulatory Requirements for E-commerce: A Global Overview

From consumer rights to distance selling regulations, every e-commerce business needs specific policies. This guide covers requirements across the EU, UK, US, and beyond.

January 20261 min read
Regulations

Why Your SaaS Needs an Acceptable Use Policy (And What to Put In It)

AUPs protect you from misuse, reduce support burden, and give you clear grounds for account termination. Here is how to write one properly.

December 20251 min read
Compliance

ISO 27001 Certification: What It Takes and Why It Matters

ISO 27001 is the global standard for information security management. Learn what the certification process involves and which policies you need to have in place.

December 20251 min read
Regulations

Social Media Policies for Employees: Protecting Your Brand

Employee social media activity can create legal liability for your business. Learn how to write a policy that protects your brand without overstepping.

December 20251 min read
GDPR

Cross-Border Data Transfers After Schrems II: What You Need to Know

Transferring personal data outside the EU or UK? Standard Contractual Clauses, adequacy decisions, and Transfer Impact Assessments explained.

December 20251 min read