A plain-English handbook for SMEs — and how the AI Act, Data Act and a wave of new regulation now sit on top of it.
Who this is for. Founders, operators and teams who process personal data but don't have a legal department. No jargon, no scare tactics — just what the rules mean, how they connect, and the concrete steps that keep you on the right side of them.
ℹ️ This guide is general information, current to mid-2026 — not legal advice. Confirm specifics for your jurisdiction and sector.
The one idea that carries everything: GDPR isn't about paperwork — it's about being able to answer three questions at any moment.
What personal data do we hold? Why are we allowed to hold it? Could we hand it back or delete it if asked?
Get those three answers straight and the rest of this guide — including the new AI and data laws — becomes far easier to follow.
The General Data Protection Regulation governs how organisations handle personal data — anything that can identify a living person, directly or indirectly. A name, an email, an IP address, a cookie ID, a photo. If you can tie it to a person, it counts.
You're a controller when you decide why and how data is used (your customer list). You're a processor when you handle data on someone else's behalf (a payroll tool running for a client). Most SMEs are both, in different moments.
If you offer goods or services to — or monitor — people in the EU/EEA, GDPR applies even if you're based in New York or Nairobi. This "extraterritorial" reach is why a small US SaaS firm still needs to care.
Every decision you make about data should trace back to one of these.
You need one before you process.
What individuals can ask of you.
Since 2024 the EU has shipped a stack of digital laws that all touch personal data. Master the GDPR mindset and each new law is an extension, not a restart.
You don't need everything at once. Work through these three phases in order.
Build the foundations once and the new laws slot in cleanly. If you'd like a hand mapping your data, assessing your AI, or standing up the safeguards, that's the kind of infrastructure work we do.
Book a call with Avanti →This guide is general information, accurate to the best of our knowledge as of mid-2026, and does not constitute legal advice.
Screen a product against the EU AI Act and GDPR in minutes and generate an auditable gap report with legal references — a self-assessment tool, not legal advice.
Choosing where AI belongs is an engineering trade-off across accuracy, cost, complexity and risk. A CXO framework for humans, rules, machine learning and generative AI.
What pre-training, post-training and evaluation involve — and what they mean for compute, data governance and talent decisions in Ireland and the EU.