Growing companies often conflate legal and compliance — treating them as the same function or assuming legal counsel handles both. They are related but distinct, and the confusion leads to gaps: legal counsel who should not be doing compliance operations, compliance tasks that never get done because they sit in no one's job description, and regulatory risks that fall through the cracks.
The Core Distinction
Legal is about advising on and managing legal risk — transactions, disputes, contracts, and interpreting the law. Legal counsel tells you what the law says and what it means for a specific situation.
Compliance is about implementing and operating processes to ensure the company consistently meets its regulatory obligations. Compliance is operational — it involves processes, documentation, controls, training, and monitoring.
In a large corporation, these are separate functions with different reporting lines, different skill sets, and different daily activities. In a 50-person company, both often sit with a single person — or neither is formally assigned.
What Legal Does
Contract drafting and review: MSAs, DPAs, commercial agreements, term sheets, employment contracts.
Legal advice on regulatory questions: "Does GDPR apply to this new product feature?" "Is this marketing campaign PECR-compliant?" "What are our obligations if we receive a DSAR?"
Corporate governance: Shareholder agreements, board resolutions, cap table management.
Dispute and enforcement response: Responding to ICO investigations, customer disputes, litigation.
Regulatory interpretation: Analysing what new regulations mean for the business.
Legal does not typically:
- Write and maintain the ROPA
- Operate the data subject rights request process day-to-day
- Conduct annual security policy reviews
- Track vendor DPAs and chase missing ones
- Deliver annual staff privacy training
- Run the incident response process
What Compliance Does
Policy and procedure development: Writing and maintaining the information security policy, data protection policy, acceptable use policy, DSAR procedure.
Documentation management: Maintaining the ROPA, sub-processor list, AI system register, NIS2 compliance records.
Vendor management: Tracking which vendors have signed DPAs, chasing missing agreements, reviewing vendor security assessments.
Training delivery: Organising and tracking annual compliance training for all staff.
Incident response operations: Running the response to a data breach or security incident — not advising on legal obligations, but operating the process.
Monitoring: Annual review of policies and controls, penetration test coordination, DSAR response time tracking.
Regulatory engagement: Responding to ICO correspondence, registering with NIS2 competent authority, filing regulatory notifications.
Compliance does not typically:
- Draft contracts or provide legal advice
- Interpret ambiguous regulatory requirements
- Advise on M&A or investment transactions
- Represent the company in disputes
Where They Overlap
Some activities genuinely require both:
Incident response: Legal counsel advises on notification obligations, privilege, and liability. Compliance operates the response process — containment, documentation, stakeholder communication.
DSAR response: Legal advises on whether a request is valid, whether exemptions apply, and how to respond to an ICO complaint. Compliance operates the process — tracking deadlines, collecting data, preparing responses.
New product or feature launch: Legal advises on regulatory implications. Compliance implements privacy by design, builds the DPIA if needed, and updates the ROPA.
Enterprise contract negotiation: Legal negotiates the terms. Compliance ensures the agreed terms are actually reflected in operational processes (e.g., if the contract requires a 4-hour incident notification, compliance must build that into the incident response process).
Common Gaps in SMBs
Gap 1: Legal counsel assumes they are doing compliance. The legal team reviews and advises on compliance questions but no one is operating the compliance processes. The ROPA is three years out of date. Vendor DPAs are missing for 40% of the vendor list. Staff training has never happened.
Gap 2: Compliance tasks sit in no job description. No one owns compliance. "Legal handles it" — but legal is external counsel who only engages when asked a question. Proactive compliance work doesn't happen.
Gap 3: Technical compliance not engaged. CTO builds the product; legal reviews contracts; but no one is ensuring privacy by design in product development, that the AI Act's technical documentation requirements are met, or that NIS2 security measures are implemented.
Who Does What in a 50-Person SaaS Company
Recommended model:
- CEO/COO: Compliance accountability (strategic ownership)
- Head of Operations or Legal Counsel (internal or external): Compliance lead for policy, documentation, and vendor management
- CTO: Technical compliance lead — security controls, AI governance, infrastructure compliance
- External Legal Counsel: Legal advice on specific questions, contract drafting, regulatory interpretation, enforcement response
This model works with a fractional or external legal resource and a designated internal compliance lead who is not a lawyer but owns the operational programme.