Practical knowledge, reports, and news on data protection, GDPR, and compliance — written and regularly reviewed by our team.
Original research and studies from simply Legal and Dieter.
Practical guides and explainers on data protection, GDPR, and compliance.

Poor availability, high costs, one PDF report per year: there are good reasons to switch your data protection officer. Legally it is straightforward, as long as termination, handover and the notification to the supervisory authority happen in the right order. The complete roadmap with a termination letter template, a handover checklist and the mistakes that happen most often when switching.
Read more →
All obligations under Regulation (EU) 2024/1689 structured by actor, risk class, and type — with filters for quick orientation.
Read more →
The record of processing activities is the first document a supervisory authority wants to see, the deletion concept the second. This guide explains who has to keep a record (almost everyone, despite the 250-employee exemption), which details Art. 30 GDPR requires, which retention periods determine the deletion periods and how to link the two so that they work in everyday business.
Read more →
A data processing agreement is mandatory as soon as a service provider processes personal data on your behalf: hosting, cloud, newsletters, CRM. With tax advisers, lawyers or banks, on the other hand, you don’t need one. This guide explains how to tell the difference, the mandatory contents under Art. 28 GDPR, how to deal with sub-processors and US providers, and how to check a provider’s DPA in ten minutes.
Read more →
Technical and organisational measures (TOM) are the part of the GDPR that decides over fines and data breaches. This guide explains the requirements of Art. 32 GDPR, the classic TOM catalogue with examples, how to rate your protection needs, which measures are realistic for a company of ten people and how to build the TOM document that authorities and clients want to see.
Read more →
Every website needs a privacy policy, because even loading a page processes personal data. This guide shows which information Art. 13 GDPR requires, how to describe services such as analytics, newsletters or Google Fonts correctly, what the TDDDG means for cookies and which mistakes most often lead to cease-and-desist letters.
Read more →