Blog · GEO

Privacy & GDPR, explained

Own the definitional queries privacy teams ask before they trust a site.

Definitional · FAQPage

What is PII? Direct vs indirect personal data under GDPR

Target query: what is pii gdpr personal data

PII is the everyday shorthand for what the GDPR calls "personal data" — any information relating to an identified or identifiable natural person (Art. 4(1)). Direct identifiers (name, account ID) name the person outright; indirect ones (IP, device fingerprint, cookie ID, VIN) single them out when combined. Recital 30 lists online identifiers as personal data; the CJEU (Breyer, C-582/14) held even dynamic IPs qualify where linkage is feasible.

refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://edpb.europa.eu/

Definitional + examples

GDPR compliance guide for a small site or app

Target query: gdpr compliance guide small business

Map every data flow to a lawful basis (Art. 6), write a transparent notice (Arts. 12–14), keep a record of processing (Art. 30), apply security measures (Art. 32), and plan breach notification (Arts. 33–34). Start with a data inventory, then close the gaps that carry the highest penalty exposure — consent and third-party trackers first.

refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://edpb.europa.eu/

Definitional + examples

Cookie consent best practices (GDPR / ePrivacy)

Target query: cookie consent best practices gdpr

Block non-essential tags until the user opts in, offer granular per-purpose choices, avoid pre-ticked boxes, and keep a consent log. ePrivacy and the GDPR require that analytics, advertising, and fingerprinting scripts do not fire before consent. Document each tag's purpose and legal basis.

refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://edpb.europa.eu/

How-to · HowTo

Data inventory (RoPA) best practices under Art. 30

Target query: data inventory gdpr article 30 ropa

A Record of Processing Activities lists what you collect, why, the lawful basis, who you share it with, and how long you keep it. Build it by walking every form, SDK, and export path. Keep it living — re-audit whenever you add a vendor or a new data field. It is also your fastest breach-readiness check.

refs: https://gdpr-info.eu/ · https://edpb.europa.eu/ · https://ico.org.uk/

How-to · HowTo

Data breach prevention checklist

Target query: data breach prevention checklist gdpr

Encrypt in transit and at rest, enforce least-privilege access, vendor-diligence your SDKs, cap retention, and rehearse your 72-hour Art. 33 notification. The cheapest breach is the one you never have — most SaaS incidents trace to an unpatched dependency or an over-shared dataset.

refs: https://gdpr-info.eu/ · https://ico.org.uk/ · https://www.nist.gov/privacy-framework

Deep-dives (GEO)

Long-form, cited explainers. Each carries 3+ authoritative privacy sources and a decision-support disclaimer.

CCPA/CPRA compliance guide for California privacy (2026)

A 2026 CCPA/CPRA compliance guide: the three business thresholds, the consumer rights (know, delete, correct, opt-out of sale/sharing, limit use of sensitive PI), the Global Privacy Control signal, the Jan. 1 2026 risk-assessment and cybersecurity-audit rules, and penalty exposure.

Cookie consent best practices: lawful banners under GDPR & ePrivacy (2026)

Cookie consent best practices for 2026 under the ePrivacy Directive Art. 5(3) and GDPR Art. 7: which cookies need consent, the five criteria for valid consent, blocking by default, consent records, and recent CNIL enforcement (Google 325M, Shein 150M in Sept 2025).

Data breach prevention checklist (GDPR Art. 32 & 33/34)

A data breach prevention checklist for the GDPR: the Art. 4(12) breach definition, Art. 32 security measures, the 72-hour Art. 33 notification duty, the Art. 34 individual-notification test, a preventive-controls table, and a response workflow.

Data inventory & RoPA best practices (GDPR Art. 30)

How to build and maintain a GDPR data inventory / Record of Processing Activities (RoPA) under Art. 30: the mandatory contents, why the under-250-employee exemption rarely applies, a build-without-a-consultant process, and how the RoPA feeds DPIAs and breach response.

GDPR compliance guide for a small site or app (2026)

A practical GDPR compliance guide for a small site or app in 2026: territorial scope under Art. 3, lawful basis under Art. 6, transparency under Arts. 12 to 14, RoPA under Art. 30, security under Art. 32, and 72-hour breach notification under Arts. 33 to 34, with an 8-step checklist.

How to detect PII exposure in code, logs & third-party scripts

How to detect PII exposure in code, logs, and third-party scripts: common leak vectors, detection methods (static regex scan, dynamic intercept, log inspection, privacy code scanning), example tooling, pipeline integration, and the limits of automated detection.

Privacy risk assessment & DPIA under GDPR Art. 35

When a DPIA / privacy risk assessment is required under GDPR Art. 35, the mandatory triggers in Art. 35(3), the EDPB nine-criteria screen, the Art. 35(7) content requirements, prior consultation under Art. 36, and why the DPIA is a living tool.

What is PII? Direct vs indirect personal data under GDPR

What PII (personally identifiable information) means under the GDPR: the Art. 4(1) definition, direct vs indirect identifiers, online identifiers such as IP addresses and cookie IDs, special categories under Art. 9, and why the definition triggers real compliance obligations.

Publish + syndicate per gtm-launch (IH + GEO indexes). Each post carries 3 authoritative refs.