Own the definitional queries privacy teams ask before they trust a site.
Definitional · FAQPage
What is PII? Direct vs indirect personal data under GDPR
Target query: what is pii gdpr personal data
PII is the everyday shorthand for what the GDPR calls "personal data" — any information relating to an identified or identifiable natural person (Art. 4(1)). Direct identifiers (name, account ID) name the person outright; indirect ones (IP, device fingerprint, cookie ID, VIN) single them out when combined. Recital 30 lists online identifiers as personal data; the CJEU (Breyer, C-582/14) held even dynamic IPs qualify where linkage is feasible.
refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://edpb.europa.eu/
Definitional + examples
GDPR compliance guide for a small site or app
Target query: gdpr compliance guide small business
Map every data flow to a lawful basis (Art. 6), write a transparent notice (Arts. 12–14), keep a record of processing (Art. 30), apply security measures (Art. 32), and plan breach notification (Arts. 33–34). Start with a data inventory, then close the gaps that carry the highest penalty exposure — consent and third-party trackers first.
refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://edpb.europa.eu/
Definitional + examples
Cookie consent best practices (GDPR / ePrivacy)
Target query: cookie consent best practices gdpr
Block non-essential tags until the user opts in, offer granular per-purpose choices, avoid pre-ticked boxes, and keep a consent log. ePrivacy and the GDPR require that analytics, advertising, and fingerprinting scripts do not fire before consent. Document each tag's purpose and legal basis.
refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://edpb.europa.eu/
How-to · HowTo
Data inventory (RoPA) best practices under Art. 30
Target query: data inventory gdpr article 30 ropa
A Record of Processing Activities lists what you collect, why, the lawful basis, who you share it with, and how long you keep it. Build it by walking every form, SDK, and export path. Keep it living — re-audit whenever you add a vendor or a new data field. It is also your fastest breach-readiness check.
refs: https://gdpr-info.eu/ · https://edpb.europa.eu/ · https://ico.org.uk/
How-to · HowTo
Data breach prevention checklist
Target query: data breach prevention checklist gdpr
Encrypt in transit and at rest, enforce least-privilege access, vendor-diligence your SDKs, cap retention, and rehearse your 72-hour Art. 33 notification. The cheapest breach is the one you never have — most SaaS incidents trace to an unpatched dependency or an over-shared dataset.
refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://www.nist.gov/privacy-framework
Long-form, cited explainers. Each carries 3+ authoritative privacy sources and a decision-support disclaimer.
A 2026 CCPA/CPRA compliance guide: the three business thresholds, the consumer rights (know, delete, correct, opt-out of sale/sharing, limit use of sensitive PI), the Global Privacy Control signal, the Jan. 1 2026 risk-assessment and cybersecurity-audit rules, and penalty exposure.
Cookie consent best practices for 2026 under the ePrivacy Directive Art. 5(3) and GDPR Art. 7: which cookies need consent, the five criteria for valid consent, blocking by default, consent records, and recent CNIL enforcement (Google 325M, Shein 150M in Sept 2025).
A data breach prevention checklist for the GDPR: the Art. 4(12) breach definition, Art. 32 security measures, the 72-hour Art. 33 notification duty, the Art. 34 individual-notification test, a preventive-controls table, and a response workflow.
How to build and maintain a GDPR data inventory / Record of Processing Activities (RoPA) under Art. 30: the mandatory contents, why the under-250-employee exemption rarely applies, a build-without-a-consultant process, and how the RoPA feeds DPIAs and breach response.
A practical GDPR compliance guide for a small site or app in 2026: territorial scope under Art. 3, lawful basis under Art. 6, transparency under Arts. 12 to 14, RoPA under Art. 30, security under Art. 32, and 72-hour breach notification under Arts. 33 to 34, with an 8-step checklist.
How to detect PII exposure in code, logs, and third-party scripts: common leak vectors, detection methods (static regex scan, dynamic intercept, log inspection, privacy code scanning), example tooling, pipeline integration, and the limits of automated detection.
When a DPIA / privacy risk assessment is required under GDPR Art. 35, the mandatory triggers in Art. 35(3), the EDPB nine-criteria screen, the Art. 35(7) content requirements, prior consultation under Art. 36, and why the DPIA is a living tool.
What PII (personally identifiable information) means under the GDPR: the Art. 4(1) definition, direct vs indirect identifiers, online identifiers such as IP addresses and cookie IDs, special categories under Art. 9, and why the definition triggers real compliance obligations.
Publish + syndicate per gtm-launch (IH + GEO indexes). Each post carries 3 authoritative refs.