GDPR News & Updates
The EU Proposed Its Biggest GDPR Overhaul
In November 2025, the European Commission proposed its biggest GDPR overhaul yet - part of a wider Digital Omnibus package simplifying GDPR, the AI Act, the Data Act, and EU cybersecurity rules together.
GDPR & AI
The AI Act's High-Risk Deadline Has Moved
The EU AI Act's rules for standalone high-risk AI systems, originally due 2 August 2026, were pushed back to 2 December 2027 by Regulation (EU) 2026/1744, in force since 27 July 2026.
GDPR & AI
Training AI on your data is still processing
Using personal data to train an AI model counts as processing under GDPR, so the same lawful basis and data protection principles still apply.
GDPR News & Updates
Financial firms now answer to two EU regimes
Since January 2025, EU banks, insurers, and payment firms must comply with DORA alongside GDPR - a separate regime covering ICT risk, incident reporting, and resilience testing.
GDPR News & Updates
Cyprus now covers ten times more companies
Cyprus's NIS2 cybersecurity law now covers roughly ten times more organisations than its predecessor, extending far beyond critical infrastructure into public bodies, postal services, and digital infrastructure.
GDPR in a Nutshell
You must be able to prove your retention rules
Accountability under GDPR means a company must be able to demonstrate and document why it keeps personal data for as long as it does - "we've always done it this way" isn't a defence.
GDPR in a Nutshell
There is no set shelf life for your data
GDPR doesn't set a fixed retention period - instead, personal data can only be kept for as long as it's actually needed for the purpose it was collected for.
GDPR in a Nutshell
Seven principles run through GDPR
Every GDPR obligation traces back to seven core principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
Privacy by Design & Data Sharing
Collect only what you actually need
Data minimisation means only collecting personal data that is adequate, relevant, and limited to what's necessary for the purpose - nothing extra just in case.
Privacy by Design & Data Sharing
One court ruling reshaped global data transfers.
The 2020 Schrems II ruling invalidated the EU-US Privacy Shield framework overnight, forcing thousands of companies to rebuild how they transferred data across the Atlantic.
Privacy by Design & Data Sharing
Privacy has to be built in, not bolted on
Data protection by design means privacy safeguards have to be built into a system from the very start of development, not added on afterwards as an afterthought.
Data Subject Rights & Consent
Wrong details? You can demand a correction
If a company holds inaccurate or incomplete personal data about you, you have the right to have it corrected or completed, and they must act on it without undue delay.