Guides for the work, not the theory
Practical how-tos for GDPR, the EU AI Act and NIS2, framework comparisons and readiness checklists, written by practitioners and shown the way they work in Pritect.
- AI Governance9 min
Sequence before software: how legal and compliance functions actually become AI-enabled
Most functions buy the tool first, and then spend a year discovering that the tool was never the constraint. The order that works is candidates, then process, then software.
Perspective · Nicholai Pfeiffer - AI Governance3 min
Managing AI Risks: Inventory, Assessments and Evaluations
Three pillars make an AI governance programme defensible, the AI inventory that indexes every system, structured assessments that judge what could go wrong, and empirical evaluations that test how the system actually behaves.
Whitepaper · Federico Marengo - Enterprise Risk8 min
The governance organisation of tomorrow
Accountability is an operational discipline, not a documentation exercise. How the privacy operating model extends across privacy, cyber, and AI, and the system that makes it real.
Perspective · Nicholai Pfeiffer - Data Protection7 min
How to build a RoPA under GDPR
A practical, step-by-step approach to building a Record of Processing Activities that satisfies Article 30, and how to keep it accurate without living in a spreadsheet.
How-to · Magdalena Goralczyk - AI Governance7 min
EU AI Act readiness checklist
A pragmatic checklist for getting ready for the EU AI Act, from building an AI system inventory to classifying risk, assigning obligations, and connecting them to your existing governance.
Checklist · Federico Marengo - AI Governance8 min
AI governance in practice: from inventory to EU AI Act classification and ongoing assurance
A practical operating model for AI governance, covering how to inventory AI systems, classify them under the EU AI Act, run the right assessments, and keep them under control as they change.
Capability deep-dive · Federico Marengo - Cybersecurity7 min
NIS2 compliance: what is actually required
A clear breakdown of NIS2 obligations for in-scope organisations, the management accountability it introduces, the reporting clock, and how to evidence security maturity over time.
Guide · André Årnes - Data Protection8 min
International data transfers after the EU-US Data Privacy Framework
How EU-to-US data transfers work under the Data Privacy Framework, what EU exporters should actually do, and why keeping your transfer safeguards in place is still the prudent call.
Guide · Magdalena Goralczyk - Data Protection6 min
DPIA in practice: when and how to run one
When a Data Protection Impact Assessment is required, how to run one that holds up, and how to connect it to AI Act assessments instead of duplicating the work.
How-to · Magdalena Goralczyk - Data Protection7 min
Cookie consent and enforcement: what good looks like
What regulators now expect from cookie banners, why dark patterns are a liability, and a practical standard for consent that holds up across the EU.
Guide · Magdalena Goralczyk - Enterprise Risk6 min
Unified GRC vs point tools
Why stitching together separate tools for data protection, AI, cybersecurity, and risk creates reconciliation work, what a shared data model changes, and the honest trade-off.
Explainer · Nicholai Pfeiffer - Cybersecurity6 min
AI in cybersecurity: the double-edged sword
AI strengthens defence and sharpens attacks at the same time. A practical look at the new threat surface, why AI systems themselves need securing, and how to keep it governed.
Perspective · André Årnes - Data Protection8 min
Data protection across the GCC: KSA, the UAE, and DIFC Regulation 10
A practitioner's orientation to data protection in the Gulf, from Saudi Arabia's PDPL to the UAE's federal and free-zone regimes and the DIFC's certification rules for autonomous systems.
Guide · Magdalena Goralczyk - Data Protection6 min
How to evaluate OneTrust, Vanta and TrustArc alternatives
How Pritect compares to OneTrust, Vanta, and TrustArc across breadth, pricing transparency, and the unified data model, written for buyers doing real diligence.
Comparison · Magdalena Goralczyk - AI Governance6 min
Governing AI in the workplace
Employees are adopting AI faster than governance can track. A practical approach to acceptable use, shadow AI, human oversight, and the everyday governance that actually reduces risk.
Guide · Federico Marengo
