Tagged: gdpr
8 posts · all posts
- Handling a data subject access request, explained
1 September 2026
A step-by-step way to answer a GDPR data subject access request when the app holding the data was AI-built and nobody owns it.
- GDPR-compliant backups: the retention policy
28 August 2026
How to write a backup retention policy that satisfies GDPR: how long to keep backups, when to delete, and how restores square with the right to erasure.
- The 72-hour GDPR breach notification clock
25 August 2026
How the 72-hour GDPR breach deadline works, what starts the clock, and why apps built fast on AI platforms are the ones that blow it.
- EU hosting for AI apps: the checklist
21 August 2026
The EU hosting and data-residency questions a customer security questionnaire will ask about your AI-built app, and how to answer them before they do.
- EU data residency and AI app builders: who hosts where
18 August 2026
Where popular AI app builders store data by default, why it usually lands in the US, and how to check where your own app's data actually sits.
- DPA vs terms of service: not the same thing
14 August 2026
A data processing agreement and terms of service do different jobs. Here's how to tell them apart and check you actually have the one GDPR requires.
- Free GDPR record-of-processing template
11 July 2026
A fill-in Record of Processing Activities template (Article 30 GDPR), sized for a solo founder running a Lovable, Bolt, or Cursor app.
- GDPR-compliant hosting for AI-generated apps
7 July 2026
A practical GDPR checklist for the AI-built internal tools your team relies on: DPAs, data residency, and compliance questions to expect.