Skip to content

Guides

The reading, turned into practice.

Plain-language writing on the EU AI Act, DPIAs, children's-safety and privacy regulation for the people who build and sign off products. Every regulatory claim is grounded in the same source obligations Landfall maps — with links straight into the obligation explorer so you can check the primary material yourself.

Looking for the in-app user guides (EN/NL)? Read them here.

EU AI Act and DPIA

Scoping, classification and the duties that follow, for deployers in the public sector and regulated industries.

EU AI Actrisk classification

EU AI Act Risk Tiers Explained for Deployers

What high-risk means under Regulation (EU) 2024/1689, the Annex III areas, how provider and deployer duties differ, and the Art. 2(3) and 2(6) exclusions.

5 September 2026

EU AI Actscoping

Does the EU AI Act Apply to My Project?

A scoping walk-through: AI system or not, provider or deployer, Annex III areas, exclusions, body type, Art. 50 features, and what out of scope means.

5 September 2026

EU AI ActFRIA

FRIA Under Article 27 for Public Bodies

Who must perform a fundamental rights impact assessment, the six elements it contains, how it relates to a GDPR DPIA, and how the Dutch IAMA fits.

5 September 2026

EU AI ActArticle 49

Registering High-Risk AI as a Public Authority Deployer

The Art. 49(3) EU database duty for public authorities, the Dutch Algoritmeregister entry, what a tool can pre-fill, and which fields always need a human.

5 September 2026

GDPRDPIA

DPIA Screening Criteria for AI Systems

The nine WP248 criteria for a GDPR Art. 35 DPIA, how they behave when an AI system is involved, and when Art. 36 prior consultation is possible.

5 September 2026

EU AI ActArticle 5

Prohibited AI Practices Under Article 5

The eight practices Regulation (EU) 2024/1689 bans outright, in force since 2 February 2025, and why a screening tool should say review rather than pass.

5 September 2026

EU AI ActArticle 50

Transparency Duties Under Article 50

Art. 50 disclosure duties for chatbots, emotion recognition, biometric categorisation, deep fakes and AI-generated public text, and how to evidence them.

5 September 2026

EU AI Actcode scanning

Finding AI in a Codebase

What static detection of ML frameworks, LLM SDKs, model artifacts, scoring logic and agent frameworks can and cannot tell you about AI Act scope.

5 September 2026

data residencyGDPR

Keeping PII Out of US-Hosted Models

EU-hosted and local model options, a per-project residency policy that fails closed, and the questions to put in an AI provider procurement checklist.

5 September 2026

Children's safety and privacy

Age-appropriate design codes and privacy statutes, read as engineering work.

IEEE 2089age-appropriate design

IEEE 2089 requirements: what the age-appropriate design standard actually asks of your product

A plain-engineering read of IEEE 2089-2021 — its fifteen obligations grouped into the themes an engineering team can act on, and how the voluntary standard lines up with binding law like the UK AADC.

23 July 2026

COPPAUK AADC

AADC vs COPPA: why 'under 18' and 'under 13' are different compliance universes

COPPA is a data-privacy statute that gates collection from under-13s behind parental consent; the UK AADC is a design code protecting every under-18 through age-appropriate defaults. The gap is where teams get caught.

23 July 2026

UK AADCChildren's Code

The UK Children's Code: Fifteen Standards as a Checklist

The ICO's Age Appropriate Design Code, in force since September 2021, turned standard by standard into the product decision each one asks for.

5 September 2026

COPPAparental consent

COPPA Verifiable Parental Consent Methods

COPPA parental-verification methods, their notice and disclosure conditions, the 2025 dates, and the distinction between voice recordings and biometric identifiers.

5 September 2026

CAADCAAB 2273

California's Age-Appropriate Design Code: What Still Applies

AB 2273, the NetChoice v. Bonta injunctions, which provisions have been enjoined, and what a product team should still build while the litigation runs.

5 September 2026

UK OSAOfcom

UK Online Safety Act Duties for Children's Services

Children's access assessment, children's risk assessment, the Protection of Children Codes and highly effective age assurance, with Ofcom's 2025 deadlines.

5 September 2026

EU DSAArticle 28

DSA Article 28: Protecting Minors on Online Platforms

The four paragraphs of Art. 28, who counts as accessible to minors, and the Commission's July 2025 guidelines on age assurance, defaults and recommenders.

5 September 2026

age assuranceage verification

Age Assurance Methods Compared

Self-declaration, age estimation, age verification and parental attestation: what the UK AADC, UK OSA and EU DSA expect, and how to keep the data minimal.

5 September 2026

default settingsUK AADC

High-Privacy Defaults for Child Accounts

Visibility, contact, geolocation, profiling, nudge techniques and parental controls, set feature by feature under AADC standards 7 to 13 and DSA Art. 28.

5 September 2026

AU OSAeSafety

Australia's Under-16 Social Media Minimum Age

The Social Media Minimum Age Act 2024, in effect from 10 December 2025: reasonable steps, which services are in scope, and the eSafety Commissioner's role.

5 September 2026

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations