Category: Privacy
-

The Data Residency Question in 2026
The data residency question has become the question the enterprise has been quietly trying to answer, the question the procurement team has been asking, the question the regulator has been enforcing.
-

A Field Guide to the Data Loss Prevention Rule in 2026
The DLP rule the security team has been writing has become the rule the privacy team has been asking for, the rule the regulator has been citing, the rule the breach disclosure will describe as the rule the enterprise should have had.
-

Cookies Are Dead. Browser Fingerprinting Is Forever.
The privacy debate of 2014 was about cookies. The privacy debate of 2026 is about a thing most people have never heard of, and the marketers have been quietly using it for years.
-

The Data Your Browser Leaks Before You Click Anything
Before any JavaScript runs, before any consent banner, your browser is already giving the server enough information to identify you across visits. The cookie debate is over. The fingerprint debate is just starting.
-

The Data Classification Debate Nobody Wins
A field guide to data classification in 2026, with why the debate goes nowhere, what the practical minimum looks like, and the part about the schema the team is going to keep maintaining.
-

Privacy on Public WiFi in 2026
Public WiFi in 2026 sits as the WiFi the typical knowledge worker uses in the coffee shop, the airport, the hotel, the conference, the home of the friend. The privacy of the public WiFi in 2026 amounts to the privacy of a network the user does not control, the user does not trust, the user…
-

GDPR Enforcement 2026: The Fines, the Decisions, the Patterns
GDPR enforcement in 2026 is no longer the warning shot phase. The fines are landing, the precedent is being set, and the gap between the regulator’s interpretation of the regulation and the typical enterprise’s implementation of it is being measured in millions of euros per incident.
-

The Data Classification Problem Nobody Wants to Solve
Data classification in 2026 stands as the security work that everyone agrees needs to happen and that nobody wants to do. The work takes months, the work costs money, the work produces a taxonomy nobody uses, and the work does not get done. The 2026 state of the data classification problem amounts to a state…
-

The Privacy Impact Assessment You Are Skipping
The privacy impact assessment sits as the document that has become the regulatory requirement the enterprise knows about and skips. The PIA the team writes for the regulator gets the PIA the regulator accepts, and the PIA the regulator accepts does not reflect the actual data flow.
-

What Actual Data Minimization Looks Like
Data minimization has been a GDPR requirement since 2018. Most organisations have done almost nothing about it. Here is what it actually looks like when you do.