Sasha Ehrlich
Compliance · EU residency
Scrie pentru Elido din septembrie 2024
Sasha leads compliance and EU data residency posture at Elido. They previously spent four years as a privacy associate at a Frankfurt-based commercial law firm advising SaaS exporters on Article 28 data processing agreements and Schrems II remediation, and a year as data protection counsel at a Berlin fintech.
They write the compliance posts — GDPR Article 3 territorial scope, ISO 27001 vs SOC 2 Type II in EU procurement, sub-processor disclosure obligations — and review every other post for compliance claims that need toning down. If a claim about "GDPR compliant" sneaks past Sasha, it's because the post was published on a Friday afternoon.
Sasha sits on the editorial committee for an EU-focused privacy newsletter and is a non-practising solicitor (England & Wales).
Expertiză
- GDPR territorial scope and Article 3 application
- Schrems II remediation and EU-US data transfer mechanics
- ISO 27001, SOC 2 Type II, HIPAA BAA flow
- Sub-processor disclosure and DPA drafting
Articole de Sasha Ehrlich
Atacul homograf: cum te păcălește un domeniu clonă
Un atac homograf ascunde un domeniu falsificat în spatele codării xn-- din punycode și al caracterelor care seamănă vizual. Cum funcționează trucul și cum verifici mai întâi un link.
ConformitateExportul datelor din linkuri scurte: cele patru lucruri pe care le poți lua cu tine
Un scurtător de linkuri păstrează patru clase de date, dar doar două se transferă în mod fiabil: ce poți exporta din datele linkurilor scurte și cum verifici o extragere completă înainte să te bazezi pe ea.
MigrareAccesibilitatea codurilor QR: WCAG, contrast și alternative
Un cod QR este o imagine fără text alternativ și o țintă la care nimeni nu poate ajunge cu tab-ul. Ce cer regulile de accesibilitate, și soluția de rezervă tipărită care rezolvă cea mai mare parte a problemei.
ConformitateRetenția datelor de clic: cât timp păstrezi jurnalele de analiză
GDPR-ul nu dă un număr pentru datele de clic. Cum stabilești ferestre de retenție justificabile pentru fiecare clasă de date, cum le documentezi și cum ștergi fără să pierzi raportarea.
ConformitateQR Codes and GDPR: What a Scan Collects and What You Owe
The printed code collects nothing. The redirect behind it processes an IP address, which is personal data. What that means for lawful basis and retention.
ConformitateEvent Ticket QR Code Fraud: How to Prevent Screenshots
Event ticket QR code fraud runs on screenshots of static codes. Dynamic single-scan codes, rotating codes, and signatures stop duplication. How each works.
IndustriiDigital Product Passport QR Codes: The EU ESPR Rules
The EU Digital Product Passport puts a QR code on your products by law. What the ESPR requires, the 2027 battery and textile deadlines, and how to comply.
ConformitateCookie Consent for Short Links: What the EU Requires
Do short links need a cookie banner? A DPO explains when redirect tracking triggers ePrivacy consent, and when a cookieless, EU-resident setup avoids it.
ConformitateBitly Assist AI: What It Does With Your Click Data
Bitly Assist is an AI chat over your link and QR data. What it does, and the DPO question about where your EU click data actually gets processed.
ComparațiiIs Google Analytics GDPR Compliant? EU Answer
Google Analytics is not banned, but EU regulators ruled it broke GDPR by sending data to the US. What the Data Privacy Framework changed, plus EU alternatives.
ConformitateIs Bitly GDPR Compliant? A DPO's Honest Answer
Bitly has a DPA, standard contractual clauses, and Data Privacy Framework certification. Compliant, yes - but not the same as EU-only data residency.
ConformitateEU Alternatives to US SaaS: A Sovereignty Guide
Why EU teams are replacing US SaaS with European alternatives, the CLOUD Act vs GDPR conflict, and how to pick tools that keep data under EU jurisdiction.
ConformitateAre QR Codes Safe? Quishing and How to Stay Protected
QR codes are safe to scan - the risk is where they lead. How quishing works, how to spot a malicious QR code, and what to do if you scanned a fake one.
ConformitateThe best EU URL shorteners in 2026 (and why it matters)
Which URL shorteners actually host in the EU, what their sub-processor lists look like, and how to read a residency claim against the underlying infrastructure
ComparațiiAre URL Shorteners Safe? A Balanced Answer for 2026
Reputable URL shorteners are safe; the real risk is opaque destinations and abuse, both manageable. How to check a short link and choose a safe provider
ConformitateGDPR for URL shorteners: what your DPO actually wants to see
A working DPO's read on the GDPR articles that apply to URL shorteners - Articles 3, 6, 28, 30, 32, 35, sub-processor disclosure, and the DPA clauses
ConformitateArticol de bazăSOC 2 and HIPAA for link tracking: a procurement answer
What enterprise security questionnaires actually ask about a URL shortener: SOC 2 controls mapped to link infrastructure and where HIPAA stops applying
ConformitateConsent Mode v2 for link tracking: what the DMA changed
Consent Mode v2 and the Digital Markets Act rewrote short-link analytics: what the four signals mean, how server-side recovery works, and what EDPB and CJEU say
ConformitateElido vs Cuttly: EU URL shorteners, where each wins
Both Elido and Cuttly keep your link data in Europe. Where they differ - multi-region edge, SSO tier, audit log, HA - decides which is right for you.
ComparațiiSCIM and SSO for marketing tools: what enterprise IT actually asks
SAML 2.0 + OIDC + SCIM 2.0 - the procurement-checklist version. IdP compatibility, deprovisioning as audit artefact, and the marketing-tool gap
FuncționalitățiSchrems II and tracking pixels: where the DPF leaves you in 2026
Schrems II invalidated Privacy Shield. The EU-US Data Privacy Framework restored adequacy in 2023. What this actually means for marketing pixels under GDPR Article 44+
ConformitateEU data residency for marketing tools: what your DPO actually asks
What 'EU data residency' means under GDPR Article 3 + Schrems II - where marketing tools leak, the server-side fix, and a procurement checklist
ConformitateArticol de bazăCookieless attribution explained: what still works in 2026
Two attribution paths survive third-party cookie sunset - server-side identifiers and first-party redirects. A pragmatic stack for marketers who need real numbers
ConformitateSafari ITP and click attribution in 2026: what still works
Every ITP version broke another tracking workaround. The full timeline, what each change killed, and the server-side redirect pattern that survives them all.
ConformitateWebhooks vs polling for click tracking: pick the pattern
When to use webhooks and when to poll the analytics API for click data: hidden costs of each, code in TypeScript and Python, plus the hybrid pattern.
IntegrăriURL shortener security checklist: 9 things to verify first
A concrete checklist for vetting any URL shortener: malware scanning, webhook signing, API key storage, rate limits, bot filtering, audit logs, and takedowns.
ConformitateGDPR-friendly URL shorteners - what to look for in 2026
A practical checklist for evaluating URL shorteners under GDPR: EU data residency, IP truncation, DPA availability, right to erasure, and US-tool traps.
Conformitate