smb-it-en
-
Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
6 min read
Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.
-
GDPR DPIA Template: A Data Protection Impact Assessment an SMB Can Fill
6 min read
GDPR Article 35 requires a DPIA for high-risk processing — profiling, large-scale special-category data, systematic monitoring, new-technology employee tracking. Here is what the assessment must contain, a fill-in template, and a worked SMB example.
-
GDPR Data Subject Rights and the 72-Hour Breach Clock
6 min read
GDPR gives data subjects eight rights, and it gives you one month to answer them — and 72 hours to report a breach. Here is what each right requires, the response clock, and the breach-notification contents an SMB must assemble in three days.
-
GDPR Article 30: The Record of Processing Activities an SMB Can Build
6 min read
GDPR Article 30 requires controllers and processors to keep a record of processing activities. Most SMBs are exempt from documenting — and wrong to skip it. Here is what a RoPA contains and how an SMB builds one without a lawyer.
-
GDPR and AI Training Data: What an SMB Building a Model Needs to Know
6 min read
Training an AI model on personal data is processing under GDPR. The lawful basis, purpose limitation, minimisation, retention, and DPIA questions all apply — and the EDPB has signalled how it reads them. Here is what an SMB building or deploying a model must settle.
-
PCI DSS Targeted Risk Analysis: A Template an SMB Can Actually Fill
6 min read
PCI DSS v4.0.1 requires a targeted risk analysis (requirement 12.3.1) wherever a control’s frequency is flexible. Here are the elements the standard requires, a fill-in template, and a worked example for the 11.6.1 payment-page tamper-detection frequency.
-
PCI DSS Self-Assessment Questionnaire Guide: Pick the Right SAQ
6 min read
The SAQ you file is determined by how you handle card data. Pick the narrowest one that fits and your validation is a short form, not a full audit. Here is how an SMB chooses among the PCI DSS SAQs — and how scope reduction changes the answer.
-
PCI DSS Scope Reduction: 12 Controls That Shrink Your Audit Footprint
6 min read
PCI DSS v4.0.1 applies to the cardholder data environment and everything with unrestricted connectivity to it. Shrink the CDE and you shrink the audit. Here are 12 scope-reduction controls an SMB can apply, each tied to the standard’s scoping rules.
-
PCI DSS 6.4.3 and 11.6.1 Explained: Stopping Payment-Page Skimming
6 min read
PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 target Magecart-style payment-page skimming. 6.4.3 manages the scripts; 11.6.1 detects when they are tampered with. Here is what each requires and how an SMB implements both.
-
ISO 42001 and the EU AI Act: Where the Standard Meets the Regulation
6 min read
The EU AI Act regulates AI by risk tier; ISO 42001:2023 is the management system that helps an SMB demonstrate it meets those requirements. Here is where the two overlap, where 42001 falls short, and what to do for each tier.
-
Law 25 and GDPR: Parallelism and a Joint Programme for an SMB
Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.
-
GDPR DPIA Template: A Data Protection Impact Assessment an SMB Can Fill
GDPR Article 35 requires a DPIA for high-risk processing — profiling, large-scale special-category data, systematic monitoring, new-technology employee tracking. Here is what the assessment must contain, a fill-in template, and a worked SMB example.
-
GDPR Data Subject Rights and the 72-Hour Breach Clock
GDPR gives data subjects eight rights, and it gives you one month to answer them — and 72 hours to report a breach. Here is what each right requires, the response clock, and the breach-notification contents an SMB must assemble in three days.
-
GDPR Article 30: The Record of Processing Activities an SMB Can Build
GDPR Article 30 requires controllers and processors to keep a record of processing activities. Most SMBs are exempt from documenting — and wrong to skip it. Here is what a RoPA contains and how an SMB builds one without a lawyer.
-
GDPR and AI Training Data: What an SMB Building a Model Needs to Know
Training an AI model on personal data is processing under GDPR. The lawful basis, purpose limitation, minimisation, retention, and DPIA questions all apply — and the EDPB has signalled how it reads them. Here is what an SMB building or deploying a model must settle.
-
PCI DSS Targeted Risk Analysis: A Template an SMB Can Actually Fill
PCI DSS v4.0.1 requires a targeted risk analysis (requirement 12.3.1) wherever a control’s frequency is flexible. Here are the elements the standard requires, a fill-in template, and a worked example for the 11.6.1 payment-page tamper-detection frequency.
-
PCI DSS Self-Assessment Questionnaire Guide: Pick the Right SAQ
The SAQ you file is determined by how you handle card data. Pick the narrowest one that fits and your validation is a short form, not a full audit. Here is how an SMB chooses among the PCI DSS SAQs — and how scope reduction changes the answer.
-
PCI DSS Scope Reduction: 12 Controls That Shrink Your Audit Footprint
PCI DSS v4.0.1 applies to the cardholder data environment and everything with unrestricted connectivity to it. Shrink the CDE and you shrink the audit. Here are 12 scope-reduction controls an SMB can apply, each tied to the standard’s scoping rules.
-
PCI DSS 6.4.3 and 11.6.1 Explained: Stopping Payment-Page Skimming
PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 target Magecart-style payment-page skimming. 6.4.3 manages the scripts; 11.6.1 detects when they are tampered with. Here is what each requires and how an SMB implements both.
-
ISO 42001 and the EU AI Act: Where the Standard Meets the Regulation
The EU AI Act regulates AI by risk tier; ISO 42001:2023 is the management system that helps an SMB demonstrate it meets those requirements. Here is where the two overlap, where 42001 falls short, and what to do for each tier.