Category: Articles


  • Cyber Resilience Act & UK: Does the CRA Apply to UK Companies?

    What the EU Cyber Resilience Act is, when it takes effect, and why Brexit does not put UK software and hardware companies outside its scope.

  • SBOM Requirements Under the EU Cyber Resilience Act

    What Annex I actually requires, why the September 2026 reporting deadline makes SBOMs urgent before they are legally mandatory, and how to build a compliant component inventory.

  • Cyber Resilience Act Vulnerability Reporting: A Step-by-Step Guide

    From 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe security incidents to ENISA reporting platform (SRP) and their national CSIRT under Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847). The CRA vulnerability reporting cascade runs on three deadlines: a 24-hour early…

  • UK GDPR vs EU GDPR: The 2026 Divergence Explained

    What the Data (Use and Access) Act 2025 changed, where the two regimes now differ, and what dual compliance actually requires. This guide reflects the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and the European Commission’s adequacy decisions as at August 2026.

  • GDPR DPA: What a Data Processing Agreement Must Contain (With Template)

    In GDPR, DPA is the Data Processing Agreement. Under Article 28 GDPR, a controller may only use a processor that provides sufficient guarantees, and the relationship must be governed by a written contract. That contract is the Data Processing Agreement, usually shortened to DPA. Most organisations have DPAs in place. Fewer have DPAs that would…

  • Your Guide to DORA Regulation: What It Is, Who It Applies To, and What It Requires

    A practical legal guide to the Digital Operational Resilience Act (Regulation (EU) 2022/2554)

  • What Is PCI Compliance in the UK? A Plain-English Guide for Businesses

    PCI compliance refers to adherence to the Payment Card Industry Data Security Standard (PCI DSS), a set of security requirements that applies to any organisation that stores, processes, or transmits payment card data. In the UK, PCI compliance is not a statutory legal obligation in the way that GDPR is, but it is a contractual…

  • EU Data Act Compliance Checklist for IoT Device Manufacturers

    A practical legal guide for manufacturers of connected products navigating Regulation (EU) 2023/2854 The EU Data Act has applied since 12 September 2025. It creates binding obligations for manufacturers of connected products and related service providers, covering data access rights, data sharing obligations, contractual fairness requirements, and cloud switching obligations. For IoT device manufacturers specifically,…

  • What Documents Do You Need for EU AI Act Compliance? (The Complete Checklist)

    By Yuliia Habriiel, Regulatory Lawyer. Last reviewed 12 August 2026, against the AI Act as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI). EU AI Act compliance requires between six and twenty-five documents, depending on your role and your risk tier. Every organisation using AI needs the same six baseline records: an AI system inventory,…

  • Essential FRAND Guide for the EU Data Act

    FRAND prohibits exploitative contracts, caps compensation costs for SMEs, and stops market incumbents from discriminating against competitors seeking data access.