
Privacy notices do not belong in the mailbox
Data protection records are auditable only if Processing, so that risk, approval, version, and action remain clearly linked. Why email, Teams, and drives are often insufficient for this purpose.

Data protection records are auditable only if Processing, so that risk, approval, version, and action remain clearly linked. Why email, Teams, and drives are often insufficient for this purpose.

A model card describes the purpose, data, limitations, and risks of an AI model. For AI governance and the EU AI Act, it is more than Documentation, because it provides a basis for decision-making.

Personal data, which were obtained unlawfully, are not automatically inadmissible as evidence. The European Court of Justice has clarified this. The proceedings centered on the question of whether a court may consider evidence that personal data contains items that may fall under Infringement against the GDPR were obtained.

A model card describes the purpose, data, limitations, and risks of an AI model. For AI governance and the EU AI Act, it is more than Documentation, because it provides a basis for decision-making.

An external data protection officer needs more than just expertise. Why roles, escalation procedures, project intake, and evidence of the impact of a DPO mandate are crucial.

Excel is often a good starting point for data protection. But when it comes to RoPA, approvals, version control, documentation, and audits, a spreadsheet alone isn't enough in the long run.

Starting August 2, 2026, the key transparency requirements of the European AI Act will take effect. Under these requirements, companies will be required in certain cases to disclose whether content has been generated by Artificial Intelligence were generated or manipulated. What companies need to know now.

Many AI projects get off to a fast start technically but lack organizational oversight. Why AI governance requires a collaborative decision-making process involving the CIO, DPO, Legal, Security, and business units.

Who is the data controller under data protection law when Advertising sent through a mailing list provider? Is it the advertising company that defines the target audience, or the mailing list provider that selects the recipients and processes the address data? The Berlin Administrative Court had to address this question.
Contact us
Phone: +1 (954) 852-1633
Mail: info@2b-advice.com