Nebulas
EN
Let's talk

Nebulas · Editorial

Knowledge that brings order

Operational answers, examples, checklists, and verifiable sources. From a question to the next useful action, without the jargon maze.

Articles
65
Topics
41
Updated
Daily

Corporate Compliance

How to Organize Orderly Business Record-Keeping Under the Civil Code

Anyone managing a commercial business will find here an overview of the record-keeping and retention duties set by the Civil Code, with a practical path for numbering, registering and archiving documents within correct timeframes. Useful for setting up internal procedures consistent with the law before validating them with your advisor.

Corporate Compliance5 min
Read

Administration and compliance

Invoice by invoice: what data makes a VAT process controllable

For those managing the invoicing cycle and returns, this article explains what invoice and archiving data make a VAT process verifiable. It shows an operational workflow, a reconstructed example, and a control checklist.

Administration and compliance5 min
Read

Artificial intelligence governance

How to document the purpose, data, and roles of an AI system under the AI Act

A practical guide for anyone building the documentation file for an AI system used in a company: roles, data types, and transparency obligations. Useful for people managing operations, IT, or compliance who want a repeatable method for each active system.

Artificial intelligence governance5 min
Read

Data Protection

Data Controller and Processor: How to Tell Them Apart Under GDPR

For those managing personal data in a business, understanding who is the controller and who is the processor clarifies who decides, who executes, and who signs what. The result is a compliant contract and a verifiable chain of responsibility.

Data Protection5 min
Read

Taxation and controls

What information makes a VAT correction traceable?

For those managing invoicing and accounting, this article explains which data and controls are needed to link a corrective invoice to the original one in a verifiable way. The goal is a flow that holds up to a tax audit without manual reconstructions.

Taxation and controls5 min
Read

Electronic Invoicing

Rejected Electronic Invoice: How to Make the Correction Traceable

An operational guide for anyone who needs to manage the rejection of an electronic invoice by the Exchange System (SdI) and wants to document the correction in a verifiable way. Useful for VAT-registered businesses and administrative teams managing the invoicing cycle.

Electronic Invoicing5 min
Read

Data Protection

How to prepare a clear procedure for a personal data breach

A guide for data controllers and processors who want to have ready, before it happens, a clear procedure for detecting, assessing and managing a personal data breach. It helps you understand which steps to document and when to notify the authority or the people involved.

Data Protection5 min
Read

Administration and compliance

Receipts, notifications and outcomes of electronic invoicing: the decision checklist

An operational guide for those who issue or receive electronic invoices in Italy and need to understand how to check rejections, deliveries and outcomes on the Invoices and Receipts portal. Useful for business owners, administrative staff and accounting managers who want an orderly and traceable verification workflow.

Administration and compliance8 min
Read

Corporate compliance

What information makes a corporate decision reconstructible

An operational guide for those drafting corporate minutes who want to ensure reconstructibility under the Italian Civil Code. Useful for directors, meeting secretaries, and those managing corporate documentation.

Corporate compliance5 min
Read

Administration and compliance

How to organize the operational cycle of electronic invoicing in Italy

A practical guide for business owners and administrative managers who need to structure the preparation, sending and storage of electronic invoices. The text indicates what to check at each stage to avoid rejections from the Interchange System.

Administration and compliance5 min
Read

Accounting and VAT

What data is needed to make a VAT process controllable

A practical guide for those managing invoicing and VAT returns who want to understand what data the European directive requires to make the process verifiable. Useful for building a consistent internal flow between invoices, accounting, and periodic returns.

Accounting and VAT5 min
Read

Compliance and data protection

How to set up a business process for managing data subject rights (GDPR)

For privacy officers and operational managers who must respond to data subject requests, this article describes a process based on clear roles, defined timelines, and traceability. The goal is a repeatable flow that meets the obligations set out in Regulation (EU) 2016/679.

Compliance and data protection5 min
Read

Administration and compliance

Electronic invoicing in Italy: how to assign responsibilities in the process

An operational guide for owners and administrative managers who need to distribute the tasks of preparing, sending and archiving electronic invoices. It helps clarify who controls the data, who transmits to the Exchange System, and who archives the files over time.

Administration and compliance5 min
Read

AI Governance and Compliance

How to plan AI literacy in the company

A guide for HR, compliance and IT managers on setting up an AI literacy plan consistent with Regulation (EU) 2024/1689. Useful for defining roles, training content and verification criteria.

AI Governance and Compliance5 min
Read

Data protection and compliance

What practical controls help an SMB manage personal data

An operational guide for data controllers and data handlers in SMBs who want to understand which organisational and technical controls to put in place. Readers get a concrete path, from risk assessment to a record of processing activities.

Data protection and compliance5 min
Read

Data Governance

Records of processing activities: what makes them truly useful

A practical guide for privacy managers and data controllers on what to include in a record of processing activities under the GDPR. It helps clarify what information is needed to demonstrate compliance and organize internal controls.

Data Governance5 min
Read

Corporate compliance

Orderly retention of business records: the Civil Code checklist

Anyone running a business can use this checklist to organize accounting books, minutes and archives according to the Italian Civil Code. Useful for entrepreneurs and administrative managers who need to set up or check their document archive.

Corporate compliance5 min
Read

Administrative Operations

What checks to prepare before sending an electronic invoice

A practical guide for business owners and administrative managers who need to verify an electronic invoice before transmitting it to the Interchange System. It explains what checks the SdI performs and how to organize yourself to avoid rejections.

Administrative Operations5 min
Read

Compliance and accounting

How to organize a document check before recording a VAT transaction

For those managing accounting and invoicing, this guide indicates which document checks to perform before recording a transaction subject to VAT. The goal is to ensure traceability and compliance with the requirements of the European VAT Directive.

Compliance and accounting5 min
Read

Data and Compliance

What principles guide the processing of personal data in a company

For anyone managing customer or employee data, this article sets out the six GDPR principles governing every processing activity and a practical path for applying them. Useful for organizing roles, instructions to suppliers, and retention periods.

Data and Compliance5 min
Read

Compliance and operations

What information makes a VAT adjustment traceable

For those managing accounting or invoicing, this article explains which data and roles make a VAT adjustment verifiable under Directive 2006/112/EC. An operational path linking the original invoice, the corrected amount, and archiving.

Compliance and operations5 min
Read

Governance and Compliance

AI Governance in Companies: Which Roles Are Needed Under the AI Act

Anyone leading a company that uses or develops AI systems will find here a map of the roles set out in the European regulation and an operational path for assigning them. The goal is to move from a regulatory requirement to a clear, traceable, and verifiable internal practice.

Governance and Compliance5 min
Read

Data Protection

How to prepare a clear procedure for a personal data breach

A guide for controllers and processors who need to understand how to detect, assess and document a personal data breach. It explains the essential steps required by GDPR and how to organize them into a verifiable internal procedure.

Data Protection5 min
Read

Administration and Invoicing

How to Make the Correction of a Rejected Electronic Invoice Traceable

An operational guide for those who receive a rejection notice from the Interchange System (SdI) and need to correct and retransmit the electronic invoice in a traceable way. Useful for VAT number holders and those who manage document administration in a company.

Administration and Invoicing5 min
Read

AI Compliance and Governance

How to Plan AI Literacy Required by the AI Act

A guide for HR and compliance leaders on designing AI literacy programs consistent with Article 4 of Regulation (EU) 2024/1689. It explains who needs training, on what, and how to link training to risk management.

AI Compliance and Governance5 min
Read

Compliance and data protection

What practical controls help an SMB manage personal data

An operational guide for SMB owners who need to organize personal data protection with limited resources. Explains which organizational and technical measures to adopt and how to document them.

Compliance and data protection5 min
Read

Corporate Governance

What information makes a corporate decision reconstructable

Anyone administering an Italian company can understand which data and corporate books make a decision verifiable years later. This article explains what is needed for a solid reconstruction, with an operational workflow and a practical checklist.

Corporate Governance5 min
Read

Business Operations

Electronic Invoicing in Italy: Who Does What, Step by Step

A practical guide for businesses and professional firms that need to assign clear roles in preparing, checking, sending and archiving electronic invoices. Useful for those who want to distribute tasks according to the Revenue Agency's rules without overlaps.

Business Operations5 min
Read

Compliance and financial controls

What business data is needed to make a VAT process controllable

A practical guide for administrative and finance managers on which data and records make a VAT process verifiable under the EU directive. Useful for building internal controls before transactions are recorded.

Compliance and financial controls5 min
Read

Governance and compliance

How to build an inventory of AI systems in your organization

An operational guide for those who need to map the AI systems used within an organization according to the definitions of Regulation (EU) 2024/1689. It offers a decision checklist to classify roles, purposes and controls linked to each system.

Governance and compliance5 min
Read

Compliance and data protection

Records of processing activities: what makes them truly useful

A practical guide for anyone building or reviewing the record of processing activities required by the GDPR. It explains what information is needed, who must keep it, and how to organize it so it can be checked.

Compliance and data protection5 min
Read

Compliance and operations

How to organize the orderly retention of business documentation

A control guide for entrepreneurs and administrative managers on mandatory books, numbering, digital retention and the ten-year terms set out in the Italian Civil Code. Useful for building a verifiable checklist with your professional advisor.

Compliance and operations5 min
Read

Data Protection

The GDPR principles that guide personal data processing in business

For anyone managing data on customers, employees, or suppliers, knowing the six principles of Article 5 of the GDPR is the starting point for organizing consistent processes. This article translates them into operational language, with a practical workflow and a hypothetical example applicable in business.

Data Protection5 min
Read

Administration and compliance

What checks to prepare before sending an electronic invoice

Anyone issuing electronic invoices in Italy can reduce rejections and delays by verifying mandatory data, amount consistency, and the sending channel before transmitting the file to the SdI. This article proposes a practical control flow based on the official rules of the Agenzia delle Entrate.

Administration and compliance5 min
Read

Tax Compliance

VAT Adjustment: What Information Makes It Traceable

For those handling invoicing and accounting, this article sets out the elements that the VAT directive links to the traceability of an adjustment. A practical path to connect the invoice, the original transaction, and the periodic return.

Tax Compliance5 min
Read

Data Protection and Compliance

Controller and Processor: How to Distinguish Them Under the GDPR

Whoever decides the purposes and means of processing personal data is the controller; whoever processes data on behalf of another is the processor. This guide clarifies the distinction and the practical steps to formalise it correctly.

Data Protection and Compliance5 min
Read