gdpr
-
PIPEDA vs Loi 25 vs GDPR: The Cross-Border SMB Compliance Map
8 min read
A Canadian SMB that also serves EU or Quebec customers can trigger all three regimes at once. Side-by-side map of PIPEDA, Loi 25, and GDPR — scope, authority, officer, breach clock, access response, impact assessment, portability, transfers, and enforcement — grounded in the statute and regulation text.
-
Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
8 min read
Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.
-
GDPR DPIA Template: A Data Protection Impact Assessment an SMB Can Fill
8 min read
GDPR Article 35 requires a DPIA for high-risk processing — profiling, large-scale special-category data, systematic monitoring, new-technology employee tracking. Here is what the assessment must contain, a fill-in template, and a worked SMB example.
-
GDPR Data Subject Rights and the 72-Hour Breach Clock
8 min read
GDPR gives data subjects eight rights, and it gives you one month to answer them — and 72 hours to report a breach. Here is what each right requires, the response clock, and the breach-notification contents an SMB must assemble in three days.
-
GDPR Article 30: The Record of Processing Activities an SMB Can Build
8 min read
GDPR Article 30 requires controllers and processors to keep a record of processing activities. Most SMBs are exempt from documenting — and wrong to skip it. Here is what a RoPA contains and how an SMB builds one without a lawyer.
-
GDPR and AI Training Data: What an SMB Building a Model Needs to Know
8 min read
Training an AI model on personal data is processing under GDPR. The lawful basis, purpose limitation, minimisation, retention, and DPIA questions all apply — and the EDPB has signalled how it reads them. Here is what an SMB building or deploying a model must settle.
-
GDPR for SMBs: Why You Are Subject
8 min read
A pragmatic intro to the GDPR for solo and small-team IT admins — Article 3 territorial scope, the seven principles and six lawful bases, data-subject rights, the 72-hour breach rule, and a 90-day roadmap.
-
Running GDPR and ISO 27001 Together: One Program, Not Two
8 min read
An SMB subject to GDPR and pursuing ISO 27001 often runs the work twice. The two overlap on risk, security measures, incident response, and vendor management. Here is how to merge them into one program with shared evidence.
-
PIPEDA vs Loi 25 vs GDPR: The Cross-Border SMB Compliance Map
A Canadian SMB that also serves EU or Quebec customers can trigger all three regimes at once. Side-by-side map of PIPEDA, Loi 25, and GDPR — scope, authority, officer, breach clock, access response, impact assessment, portability, transfers, and enforcement — grounded in the statute and regulation text.
-
Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.
-
GDPR DPIA Template: A Data Protection Impact Assessment an SMB Can Fill
GDPR Article 35 requires a DPIA for high-risk processing — profiling, large-scale special-category data, systematic monitoring, new-technology employee tracking. Here is what the assessment must contain, a fill-in template, and a worked SMB example.
-
GDPR Data Subject Rights and the 72-Hour Breach Clock
GDPR gives data subjects eight rights, and it gives you one month to answer them — and 72 hours to report a breach. Here is what each right requires, the response clock, and the breach-notification contents an SMB must assemble in three days.
-
GDPR Article 30: The Record of Processing Activities an SMB Can Build
GDPR Article 30 requires controllers and processors to keep a record of processing activities. Most SMBs are exempt from documenting — and wrong to skip it. Here is what a RoPA contains and how an SMB builds one without a lawyer.
-
GDPR and AI Training Data: What an SMB Building a Model Needs to Know
Training an AI model on personal data is processing under GDPR. The lawful basis, purpose limitation, minimisation, retention, and DPIA questions all apply — and the EDPB has signalled how it reads them. Here is what an SMB building or deploying a model must settle.
-
GDPR for SMBs: Why You Are Subject
A pragmatic intro to the GDPR for solo and small-team IT admins — Article 3 territorial scope, the seven principles and six lawful bases, data-subject rights, the 72-hour breach rule, and a 90-day roadmap.
-
Running GDPR and ISO 27001 Together: One Program, Not Two
An SMB subject to GDPR and pursuing ISO 27001 often runs the work twice. The two overlap on risk, security measures, incident response, and vendor management. Here is how to merge them into one program with shared evidence.