Compliance Radar
Feed Frameworks Deadlines

Privacy Policy

Last updated: 2026-09-10

Compliance Radar has no accounts, no cookies, no analytics, and no third-party scripts. The only personal data we handle in the ordinary course of running this site is the access log your browser produces by connecting to it.

Who is responsible

Controller
Oleksii
Established in
Ukraine
Contact
sdnflsdn@gmail.com

The controller is established outside the European Union, and this policy is written to meet the GDPR anyway: we make the service available to people in the EU, which brings us within Article 3(2). Where the law of Ukraine imposes its own data-protection duties, those apply in addition, not instead.

What we collect

Access logs. Every request to this site is logged by our hosting provider: your IP address, the time, the URL you asked for, the HTTP status we returned, your browser's user-agent string, and the referring page if your browser sent one. An IP address is personal data under the GDPR, so we treat the whole log as personal data.

Filters on the feed are submitted with GET, which means the choices you make — framework, jurisdiction, severity, period — appear in the URL and therefore in that log. Nothing else about your visit is recorded.

Email you send us. If you write to the address above, we keep the message and your address for as long as it takes to deal with it, and no longer.

Nothing else. We have no sign-up, no login, no newsletter, no comment form, and no endpoint that accepts a POST. We do not fingerprint browsers, do not run A/B tests, and do not embed anything served by another company — no fonts from a CDN, no social buttons, no tag managers.

Cookies and other storage on your device

We set no cookies at all. One item is written to your browser's sessionStorage so the Back button works, and it disappears when you close the tab. The cookie page describes exactly what it is and why it needs no consent banner.

Why we process it, and on what legal basis

Access logs are processed to keep the service running, to diagnose faults, and to detect abuse such as scraping that degrades the site for everyone else. The legal basis is our legitimate interest in operating and defending the service, GDPR Article 6(1)(f). We do not use the logs to build profiles, to measure audiences, or to make decisions about individual visitors.

Correspondence is processed on the same basis, or on Article 6(1)(b) where you are writing about a contract with us.

We do not rely on consent for anything, because there is nothing here that would require it.

Personal data inside the changes we publish

This is worth stating plainly, because it is the one place where we process data about people who never visited the site. The documents we monitor are official publications — regulator decisions, enforcement notices, guidance — and some of them name individuals or organisations. We publish the title, a short summary, and a link back to the source. We do not enrich those records, cross-reference them against other datasets, or keep material a publisher has withdrawn.

The legal basis is our legitimate interest, and the public interest, in reporting accurately on regulatory developments that are already public. If you appear in such a record and object to our summary of it, write to us: we will look at it, and where the objection is well-founded we will remove or correct the entry. Note that we cannot change the underlying official publication — for that you have to go to the body that issued it.

Who else sees the data

Our hosting provider operates the servers and holds the access logs on our behalf, as a processor. Nobody else. We do not sell data, do not share it with advertisers, and do not send anything about visitors to an analytics service, because we do not use one.

We use a language model to summarise the official documents we collect. It is given those public documents and nothing else — no visitor data of any kind ever reaches it.

Because our hosting provider runs infrastructure outside the European Economic Area, access logs may be stored outside it. Those transfers rely on the standard contractual clauses in our agreement with the provider.

How long we keep it

We operate no log storage of our own: the application writes to standard output, and the hosting platform retains that stream under its own rolling retention policy before deleting it automatically. We do not export logs, copy them into a database, aggregate them, or archive them. In practice this means access logs survive days, not years, and nothing about a visit outlives that window.

Your rights

If the GDPR applies to you, you have the right to ask for access to your personal data, to have it corrected or erased, to have its processing restricted, to object to processing based on legitimate interest, and to receive it in a portable form. You also have the right to complain to your national supervisory authority.

Write to sdnflsdn@gmail.com and we will answer within one month. One honest caveat: a request about access logs is hard to satisfy usefully, because we hold no identifier that links a log line to you beyond the IP address you would have to tell us yourself, and we have no way to confirm it was yours.

Children

This service is aimed at security, legal, and compliance professionals. It is not directed at children, and we knowingly collect nothing from them.

Changes to this policy

If we change what we collect, we change this page first and update the date at the top. There is no mailing list to notify, by design.

This page describes our practices. It is not legal advice — see the Terms of Service.

Feed Frameworks Deadlines Sources Privacy Terms Cookies

Compliance Radar tracks published changes in standards and regulations. It is not legal advice.