Resources

Compliance guides and free tools,
and what to open first.

Everything we publish, arranged by the situation you are in rather than by what kind of document it is. The free tools need no account and send nothing to us; the guides are written to be useful rather than to rank, and are reviewed as the rules change.

A customer just asked for our privacy policy

Name your processors in it. "Trusted third parties" is the single most common finding in a privacy review, and the fix costs nothing at drafting time.

A cookie audit found trackers firing before consent

Scan first so the policy describes what the site does rather than what you remember. The scan output feeds the generator directly.

We have a DPDP deadline and no programme

Read the build order before the law. The obligations arrive in a sequence, and starting with policies because they are quick to write is how these programmes stall.

Someone asked whether the EU AI Act applies to us

Check the dates first: the Digital Omnibus moved standalone high-risk obligations to 2 December 2027, and a great deal of published guidance still says August 2026.

An enterprise deal is stuck in security review

The readiness check will tell you in five minutes which area the questionnaire is going to expose. Usually data mapping.

We need to know what non-compliance would cost

Note the structural difference: DPDP sets fixed rupee maxima, the AI Act scales with turnover, and for SMEs the AI Act applies the lower of the two figures rather than the higher.

We are adding a second framework

Ask what the delta actually is before committing to a date. Companies holding SOC 2 usually find most of ISO 27001 already evidenced and almost none of DPDP's notice and consent work.

We had a security incident and the clock is running

CERT-In's six hours usually expires first, often before the facts are known. Report what you know, then complete it; the DPDP 72-hour report comes later and needs the detail.

A customer asked for our SOC 2 report

If there is no report yet, say so and share a readiness summary and a date. A bridge letter only covers the gap after a report exists.

We are an AI start-up and buyers want proof

Security questions usually come first, so SOC 2 tends to lead; ISO 42001 answers the AI governance question when buyers start asking it.

We run a SaaS product with users in Europe or India

For customer data you are usually a processor, so most duties arrive through customers' contracts. For your own sign-ups and website you are the controller or fiduciary.

We do not know if we need a cookie banner

Anything beyond strictly necessary, such as analytics or ad pixels, needs consent before it loads for EU, UK and Indian visitors. California asks for an opt-out instead.

We are not sure the DPDP Act applies to us

It almost certainly does if you process digital personal data of people in India. The exemptions are narrower than most teams assume.

We are choosing a compliance tool or setting up a programme

Pick the tool after you know the frameworks, the evidence they need and who owns each control. Most of the cost is the work, not the software.

We sell to US customers

California sets the bar, and a dozen states now require honouring opt-out signals such as GPC. HIPAA applies only if you handle protected health information for a covered entity.

We sell into the EU or UK

For most SaaS companies GDPR arrives through customer DPAs and transfer clauses. NIS2 and DORA reach you if you are in scope yourself or supply someone who is.

We sell in Australia or the UAE

Australia's 2024 reforms added a statutory privacy tort and new transparency duties. In the UAE, which law applies depends on whether you sit inside a financial free zone.

An enterprise or public-sector buyer wants a VPAT, an SLA or proof of performance

Procurement asks the same things every time: security evidence, a DPA, an accessibility report and reliability evidence. Start with the readiness list.

A customer or auditor is asking about our vendors

SOC 2, ISO 27001, GDPR, DORA, NIS2 and APRA CPS 230 all ask the same core question: which suppliers touch your data or your service, and how you checked them. Tier by access, not spend.

We are doing a DPIA or building a risk register

A DPIA assesses risk to individuals from one processing activity; a risk register scores risk to the organisation. Findings from the first should feed the second, linked back.

01

How this material is maintained

Two things are worth knowing about anything you read here, because they determine how much weight to put on it.

Dates are verified, and dated. Regulatory timelines in this area move: the EU AI Act's high-risk deadline shifted by sixteen months in July 2026, and a large share of published guidance still quotes the old date. Where a page states a date it also states when that was last checked, so you can judge whether to re-verify.

None of it is legal advice, and the generators are starting points. A generated policy describes what you tell it you do. Whether your systems actually behave that way is the thing an auditor tests and the thing no document can establish. Have counsel review anything you publish.

02

What each kind of page is for

AnswersGood for
Guides/dpdp, /eu-ai-act, penalties pagesWhat the law requires, and whenUnderstanding an obligation, briefing a colleague, checking a date
Solutions/solutions/*What you do about it, in what order, and who owns each stepPlanning a programme, scoping the work, assigning it
Free tools/tools/*, /scanYour own situation, specificallyProducing a document or a score today, with no account
Product pages/platform, /consent, /riskHow the platform does itEvaluating whether to buy, and what it would replace

The split between a guide and a solutions page is deliberate: one carries the law, the other the work.

Questions

The things people ask us

Are the free tools really free?

Yes. No account, no email gate, no trial period. Four of the five run entirely in your browser and transmit nothing; the cookie scanner runs on our infrastructure because loading your site is the only way to observe what it does, and it asks for nothing but the URL.

What is the difference between a guide and a solutions page?

A guide explains what the law requires: obligations, tiers, dates, penalties. A solutions page explains what you do about it: the order of operations, which team owns each step, and what each step produces. They are written for different moments and deliberately do not repeat each other.

How current are the regulatory dates?

Each page states when its dates were last verified. This matters more than usual right now: the EU AI Act's standalone high-risk deadline moved from 2 August 2026 to 2 December 2027 under Regulation (EU) 2026/1744 in July 2026, and much published guidance has not been updated.

Can we use the generated documents commercially?

Yes, on your own site and under your own name, with no attribution required. They are starting points written to be edited, and should be reviewed by counsel against how your organisation actually processes data before you publish them.

Do you publish results from the cookie scanner?

Only in aggregate and anonymised. Results for a named company go to that company, privately.

Book a walkthrough

When the reading is done, see it running.

We connect one account live and show real evidence landing in the ledger before the call ends.