Plain-English Compliance
Practical guides to GDPR, privacy law, and business compliance — written for founders, small business owners, and new businesses, not lawyers.
32 articles found
Terms and Conditions for a Small Online Shop: A Plain-English UK Guide
The Consumer Rights Act, the 14-day cooling-off period, and the new fake-review rules - what your shop's T&Cs must cover to sell online in the UK without nasty surprises.
Read articlePrivacy Policy for a Small Business Website: What UK Law Actually Requires
A contact form is enough to trigger UK GDPR's transparency rules. The eight things your website privacy policy must cover - and the copied-template mistakes that get small businesses in trouble.
The ICO Data Protection Fee: Does Your Small Business Have to Pay?
Most UK businesses that handle personal data owe the ICO an annual fee - and many small firms only find out when the penalty letter arrives. The tiers, the exemptions, and how to register.
Do You Need a Privacy Policy for a Newsletter?
Collecting email addresses makes you a data controller - even for a free Substack. What PECR and UK GDPR require before you hit send, and what your policy must actually say.
UK GDPR vs EU GDPR: What Actually Changed
Same rules, different regulators? Not quite. From the Data (Use and Access) Act 2025 to transfer paperwork and dual representation, here is where the two regimes now genuinely differ.
Do I Need a Privacy Policy for My Shopify Store? (UK Guide)
Yes - and Shopify's auto-generated template is not enough on its own. Here is exactly what UK GDPR requires your store's privacy policy to say, in plain English.
AI Governance Policies: What Your Company Needs in 2026
From model risk registers to human oversight requirements, AI governance is no longer optional. Here is what your internal AI policy must cover to satisfy regulators and protect your business.
DORA Compliance for Financial Services: A Complete Guide
The Digital Operational Resilience Act is now enforceable across the EU. This guide covers ICT risk management, incident reporting, third-party oversight, and testing requirements for financial entities.
Remote Work and Data Protection: What Employers Must Know
With distributed teams comes distributed data risk. Learn how to handle employee monitoring, cross-border data transfers, and BYOD policies without violating privacy laws.
How to Build an AI Model Risk Register
The EU AI Act and NIST AI RMF both require documented risk assessments for AI systems. Here is how to build a risk register that satisfies auditors.
How to Write an Effective Data Breach Response Plan
A data breach without a response plan turns a bad situation into a catastrophe. Learn how to build a plan that covers detection, containment, notification, and recovery before you need it.
Employee Handbook Best Practices for Remote Teams
Remote work has changed what employee handbooks need to cover. From equipment policies to cross-border employment law, here is how to write a handbook that works for distributed teams.
NIS2 Directive: What It Means for Your Business
The NIS2 Directive significantly expands cybersecurity obligations across the EU. Find out whether your organisation is in scope and what you need to do to comply.
GDPR Compliance Checklist for SaaS Founders in 2026
A practical step-by-step checklist covering the six lawful bases, data subject rights, DPA obligations, and what actually triggers an ICO investigation.
SLA Best Practices for SaaS Companies
Your Service Level Agreement defines uptime commitments, support response times, and remedies for breaches. Get it wrong and you are exposed to costly claims.
Protecting Children Online: COPPA, UK Children's Code, and GDPR Article 8
If your product could be accessed by under-18s, you have specific legal obligations. This guide covers age verification, parental consent, and age-appropriate design.
AML and KYC Policies: A Complete Guide for Fintechs
Anti-money laundering regulations are getting stricter globally. Learn what your AML policy must include and how to implement effective KYC procedures.
Building a Privacy-First Product: Developer's Guide
Privacy by design is a legal requirement under GDPR, not just a best practice. This developer-focused guide covers data minimisation, purpose limitation, encryption, and privacy-preserving architecture patterns.
Understanding the EU AI Act: Requirements for High-Risk AI Systems
The EU AI Act introduces a risk-based classification framework for artificial intelligence. Learn what qualifies as high-risk, what the compliance obligations are, and how to prepare your AI systems.
7 Privacy Policy Mistakes That Will Get You Fined
Vague data retention periods, missing lawful basis disclosures, buried contact details - here are the most common compliance failures and how to fix them.
What Every SaaS Terms of Service Must Include
From limitation of liability to acceptable use, subscription terms, and IP ownership - a founder's guide to writing a ToS that actually protects you.
Whistleblowing Policies: EU Directive and UK Requirements
The EU Whistleblower Protection Directive requires internal reporting channels for companies with 50+ employees. Here is how to write a compliant policy.
Data Retention Schedules: How Long Should You Keep Personal Data?
GDPR requires you to justify how long you retain personal data. This guide covers retention periods by data type and how to build a compliant retention schedule.
Accessibility Policies: ADA and EAA Compliance Made Simple
Digital accessibility is now a legal requirement in both the US and EU. This guide breaks down ADA and European Accessibility Act obligations and how to write an accessibility policy that meets them.
Cookie Consent in 2026: What's Changed and What You Need to Do
The ICO and CNIL have both issued new guidance on cookie consent banners. Here is what it means for your website and how to stay compliant.
CCPA vs GDPR: Key Differences for Global Businesses
Selling to customers in both the US and EU? Here is a side-by-side comparison of your obligations under each regime and where they conflict.
HIPAA Compliance for Healthcare Startups
Building a health tech product? HIPAA compliance is not optional. Learn about PHI handling, Business Associate Agreements, and the Security Rule requirements.
Regulatory Requirements for E-commerce: A Global Overview
From consumer rights to distance selling regulations, every e-commerce business needs specific policies. This guide covers requirements across the EU, UK, US, and beyond.
Why Your SaaS Needs an Acceptable Use Policy (And What to Put In It)
AUPs protect you from misuse, reduce support burden, and give you clear grounds for account termination. Here is how to write one properly.
ISO 27001 Certification: What It Takes and Why It Matters
ISO 27001 is the global standard for information security management. Learn what the certification process involves and which policies you need to have in place.
Social Media Policies for Employees: Protecting Your Brand
Employee social media activity can create legal liability for your business. Learn how to write a policy that protects your brand without overstepping.
Cross-Border Data Transfers After Schrems II: What You Need to Know
Transferring personal data outside the EU or UK? Standard Contractual Clauses, adequacy decisions, and Transfer Impact Assessments explained.