
Compliance Library
Everything you need to stay compliant – data protection, cybersecurity, and compliance in one library.
All whitepapers

Privacy Policy for Websites: Checklist | heyData
Use our checklist to review which information belongs in your privacy policy — from cookies and legal bases to data subject rights.

Cyber Resilience in the Energy Sector: NIS2 & ISO 27001 | heyData
Learn how energy companies reduce cyber risks, implement NIS2 and ISO 27001, and sustainably strengthen their security of supply.

Cyber Resilience for SaaS Companies: NIS2 & ISO 27001 | heyData
Learn how SaaS companies reduce cyber risks, implement NIS2 and ISO 27001, and build lasting cyber resilience with clear processes.

NIS2 Compliance with ISO 27001: A Practical Guide | heyData
Learn how ISO 27001 supports your NIS2 implementation, which gaps remain, and how to build a resilient information security and compliance system.

GDPR in Marketing: A Guide to Compliant Campaigns | heyData
Learn how to make your marketing campaigns GDPR-compliant, avoid common mistakes, and turn data protection into a competitive advantage.

The 10 Most Common GDPR Mistakes SaaS Providers Make | heyData
Discover the 10 most common GDPR mistakes SaaS providers make — from data mapping and consent to third-party vendors, data breaches, and privacy by design.

Data Protection for Tax Advisors: Checklist for Firms | heyData
Use our data protection checklist to see whether your tax firm is set up to be GDPR-compliant — from ROPA and TOMs to DPAs and DPIAs.

Data Protection in HR: GDPR Guide for HR Teams | heyData
Learn how HR teams process applicant and employee data in a GDPR-compliant way — including ROPA, TOMs, DPIAs, DPAs, and the EU AI Act.

TOM Checklist: Technical and Organizational Measures | heyData
Use our TOM checklist to check whether your company protects personal data with appropriate technical and organizational measures.

GDPR Checklist for People & Culture | heyData
Use our HR data protection checklist to see how securely you manage employee data — from roles and deletion periods to encryption and training.

ISO 27001:2022 Certification Guide | heyData
Learn how to build an ISMS in line with ISO 27001:2022, prepare your company for the audit, and achieve certification in a structured way.

IT Compliance for IT Consultants: 10-Point Checklist | heyData
Review your IT compliance with our 10-point checklist for IT consultants — covering GDPR, NIS2, ISO 27001, the EU AI Act, and a scorecard.

Data Protection for Start-ups and SMEs in Austria | heyData
Discover 10 key data protection measures for start-ups and SMEs in Austria — from audits and policies to deletion concepts and incident response plans.

GDPR in 30 Minutes: A Guide for Small Businesses | heyData
Understand the GDPR in 30 minutes: key obligations, DPAs, TOMs, deletion periods, and practical checklists for founders and small teams.

nFADP Guide: Implementing Data Protection in Switzerland | heyData
Learn how companies implement the Swiss nFADP — with data mapping, risk assessment, security measures, checklists, and practical tips.

NIS2 Guide: Requirements, Implementation & Cyber Resilience | heyData
Learn who NIS2 applies to, which obligations companies must meet, and how to implement compliance, reporting deadlines, and cyber resilience in a structured way.

EU AI Act: Guide to AI Compliance | heyData
Learn what the EU AI Act requires of companies and how to manage AI risks, documentation, oversight, and governance in a structured way.

Data Protection for Start-ups: GDPR Guide | heyData
Learn how start-ups implement the GDPR pragmatically, use SaaS tools securely, and turn data protection into a competitive advantage.

Data Protection in Fundraising: GDPR Guide for Start-ups | heyData
Learn how start-ups share personal data securely, sparingly, and in a GDPR-compliant way during funding rounds and due diligence processes.

Data Protection for Companies: GDPR Beginner's Guide | heyData
Learn the key GDPR basics for companies — from mandatory documents and technical and organizational measures to DPAs, data subject rights, and data breaches.

Cyber Resilience for FinTechs: DORA, NIS2 & ISO 27001 | heyData
Learn how FinTechs reduce cyber risks, implement DORA and NIS2, and build robust cyber resilience with ISO 27001.

Data Protection for Medical Practices: GDPR Guide with Checklist | heyData
Check whether your medical practice is set up to be GDPR-compliant — with a checklist covering patient data, consents, your website, TOMs, DPAs, and DPIAs.

WhatsApp Business GDPR Compliance Checklist | heyData
Use our checklist to check whether you're using WhatsApp Business in a GDPR-compliant way — from consent and DPAs to security, deletion, and employee training.
Additional Resources
Everything you need to make informed compliance decisions.

Provider Comparison

Compliance Blog

Studies & Reports

Customer Stories


