#compliance
-
Pseudonymization vs Anonymization Under GDPR
Anonymized data leaves GDPR entirely, pseudonymized data does not. Where Recital 26, the CJEU SRB ruling and EDPB guidance put the line in practice.
-
Best GDPR Compliance Tools for AI: A Practitioner's Guide
Which platforms handle GDPR's toughest AI obligations: DPIA automation, Article 22 oversight, ROPA management, and data discovery for AI systems.
-
GDPR Compliance for Machine Learning Models: Practical Guide
GDPR requirements for machine learning models, covering lawful bases, DPIAs, Article 22 rights, anonymization, erasure, and rectification.
-
US State AI Laws 2026: Colorado, Texas, California, Illinois
The US state AI laws shaping 2026: Colorado's stalled SB 24-205, Texas TRAIGA, California AB 2013, and Illinois HB 3773, with their effective dates.
-
CCPA and CPRA ADMT Rules for LLM Products
California's finalized ADMT rules add pre-use notice, opt-out, appeal, and risk-assessment duties to automated decisionmaking, catching many LLM products.
-
Training Data Privacy: GDPR Data Subject Rights
EDPB Opinion 28/2024 and CNIL guidance reshaped how GDPR applies to AI training data, from model anonymity to legitimate interest and erasure requests.
-
AI Chat Assistant Privacy Risks: Training, Review, Retention
Consumer AI assistants increasingly default to using your conversations for training, human review and multi-year retention. Here is what actually changes.
-
Cross-Border LLM Data Transfers: SCCs After Schrems II
Most LLM deployments cross borders. How Standard Contractual Clauses, post-Schrems II case law, and supplementary measures apply to model inference.
-
DPIA Template for LLM Deployment: A Working Structure
A working Data Protection Impact Assessment structure for LLM workflows, covering the Article 35 risk factors and where the AI Act overlaps with GDPR.
-
EU AI Office Enforcement Priorities: 2026 Outlook
The AI Office has published no enforcement plan, but its staffing, working papers, and coordination with national DPAs show where the first cases land.
-
EU AI Act Article 50: Transparency Obligations Explained
Article 50 imposes disclosure obligations on anyone deploying chatbots, generating synthetic content, or running emotion-recognition systems.
-
GDPR Article 22 and LLM Automated Decision-Making
The analysis explains when LLM workflows trigger Article 22, what counts as a significant effect, and how meaningful human review and appeals work.
-
EU AI Act Article 52: A Provider's Disclosure Checklist
What Article 52 requires of general-purpose AI model providers, what the guidance clarifies, and how to operationalize disclosure in about 90 days.