PIPEDA Compliance: Canada’s Privacy Law Requirements for Businesses

Pipeda Compliance

Bottom Line Up Front If you’re reading this, one of three things probably just happened: you’re expanding into Canada and just realized privacy law applies to you, an enterprise customer’s procurement team flagged PIPEDA compliance as a contract requirement, or your organization collects personal information from Canadians and someone in legal finally asked “wait, are … Read more

UK GDPR Compliance: Post-Brexit Data Protection Requirements

Uk Gdpr Compliance

Bottom Line Up Front If you’re processing personal data of UK residents — whether you’re based in London or Los Angeles — UK GDPR compliance isn’t optional, and it hasn’t gone away just because Brexit happened. You’re probably reading this because a UK customer’s procurement team flagged a gap in your data protection documentation, your … Read more

NIST AI Risk Management Framework: Implementation Guide

Nist Ai Risk Management Framework

Bottom Line Up Front If you’re reading this, one of three things probably happened: an enterprise customer’s security questionnaire now includes a section on AI governance, your legal team flagged incoming AI regulation and asked “what are we doing about this,” or your product team shipped a generative AI feature before anyone thought about model … Read more

Biometric Data Privacy Laws: BIPA, GDPR, and Emerging Requirements

Biometric Data Privacy Laws

Bottom Line Up Front If you’re reading this, one of three things just happened: your product started scanning fingerprints, faces, or voiceprints and legal asked “wait, is that legal?”; a class-action headline about BIPA litigation made your general counsel nervous; or a customer’s security questionnaire asked how you handle biometric identifiers and you realized you … Read more

Cyber Incident Reporting Requirements: SEC, CIRCIA, and Beyond

Cyber Incident Reporting Requirements

Bottom Line Up Front If you’re reading this, one of three things happened: your legal team just flagged a new regulatory reporting obligation, you had a security incident and someone asked “wait, do we have to report this to anyone?”, or a customer contract now requires you to disclose breach notification timelines. Cyber incident reporting … Read more

GLBA Safeguards Rule: Cybersecurity Requirements for Financial Institutions

Glba Safeguards Rule

Bottom Line Up Front If you’re reading this, one of three things just happened: your organization was classified as a “financial institution” under GLBA and you’re scrambling to understand what that means, a bank or lending partner just sent you a security questionnaire referencing the GLBA Safeguards Rule, or a regulator (or a breach) made … Read more

Cyber Essentials Certification: UK Government Cybersecurity Standard

Cyber Essentials Certification

Cyber Essentials Certification: UK Government Cybersecurity Standard Bottom Line Up Front Cyber Essentials certification is the UK government’s cybersecurity baseline standard, and you’re probably here because a public sector contract requires it, a client mentioned it in their vendor questionnaire, or you’re expanding your business into the UK market. This certification demonstrates that your organization … Read more

SSAE 18: Understanding the Attestation Standard Behind SOC Reports

Ssae 18 Compliance

SSAE 18: Understanding the Attestation Standard Behind SOC Reports SSAE 18 compliance is the attestation standard that makes SOC 2 reports possible — and you’re probably here because a customer, partner, or auditor mentioned it. While SSAE 18 itself doesn’t define security requirements, it’s the framework that auditors use to examine and attest to your … Read more

Data Protection Officer Requirements: When and How to Appoint a DPO

Data Protection Officer Requirements

Data Protection Officer Requirements: When and How to Appoint a DPO Your legal team just told you that your organization might need a Data Protection Officer (DPO), or perhaps a European customer is asking about your DPO in their vendor security questionnaire. The GDPR’s data protection officer requirements are mandatory for certain organizations and optional … Read more

icon 4,206 businesses protected this month
J
Jason
just requested a PCI audit