Series
Compliance for Small Business
A plain-English series on the compliance obligations small businesses are actually asked about: what GDPR and NIS2 cover, how to assess the vendors you depend on, when a breach has to be reported, and what belongs in a privacy policy. Educational, not legal advice.
- NIS2 Requirements and GDPR for Small Business — What the NIS2 requirements are, how they sit alongside GDPR, and which parts realistically reach a small business — including the supplier questions that arrive from customers inside the directive's scope.
- What Is the NIS2 Directive? Scope, Sectors and Deadlines — A plain-English explanation of the NIS2 directive: what it is, which sectors and company sizes it covers, what it asks organisations to do, and how it reaches small businesses through their customers.
- Vendor Risk Assessment: A Practical Walkthrough — How to run a vendor risk assessment without a procurement team: which suppliers to assess, what to ask them, how to score the answers, and what to do when a critical vendor scores badly.
- Data Breach Notification Requirements: Who to Tell and When — Who a small business may need to notify after a data breach and how quickly: regulators, affected individuals, insurers, and customers. What the common timelines are, and how to decide before an incident forces it.
- Privacy Policy Template for Small Business: What to Include — What a small business privacy policy needs to contain, section by section, and why a generated template usually needs editing before it describes what your business actually does with data.