Privacy Assessments | ISO Certifications | ISO 42001
By:
Schellman
September 26th, 2024
Within a few months of their latest update to their Data Protection Requirements (DPR) to address a coding incident (version 9.1), Microsoft released a draft or “pre-read” for their version 10 requirements that will be utilized for its Supplier Security and Privacy Assurance (SSPA) process as of the 2025 fiscal year. Arguably the largest update to the DPR since September 2018, v10’s new mandates address artificial intelligence (AI) and include important references to ISO 42001 that suppliers may want to take advantage of during their next compliance cycle.
By:
CHRIS LIPPERT
August 1st, 2024
When Microsoft released version 9 of their Data Protection Requirements (DPR) back in October 2023, the new framework contained several important updates, as well as a few brand new requirements, including the addition of new considerations for suppliers processing protected health information (PHI).
By:
Kathryn Young
April 5th, 2024
Amidst the evolving patchwork of data protection and privacy legislation in the United States, privacy remains a top priority for organizations. But protecting privacy also requires resources, and while not all organizations have that much to spare, it is possible to make do with only a small, dedicated team.
By:
CHRIS LIPPERT
December 14th, 2023
Since the introduction of the new Data Privacy Framework (DPF) on July 17, 2023, many have begun familiarizing themselves with its seven principles as they ready themselves to comply. However, the DPF also features 16 supplemental principles, two of which—regarding self-certification and verification—also cover particularly important topics.
By:
Kathryn Young
September 27th, 2023
Generally, privacy impact assessments (PIAs) are defined as evaluation tools that help to better understand how information is gathered, used, maintained, and shared. It’s a formal analysis used to assess what privacy risks exist within the information processing activities that drive specific products and services.
By:
CHRIS LIPPERT
July 18th, 2023
In news that’s excited the privacy industry worldwide—the EU – U.S. Data Privacy Framework (DPF) was announced on Monday, July 10, 2023, and took near immediate effect. This comes after months of review and public comment, but now, with the DPF functioning as a new adequacy mechanism under General Data Protection Regulation (GDPR), organizations can once again transfer data under an adequacy decision if they adhere to and self-certify against the DPF.
By:
CHRIS LIPPERT
December 15th, 2022
You’ve probably heard the classic idiom about “keeping up with the Joneses.” According to Miriam-Webster, it means “to show that one is as good as other people by getting what they have and doing what they do.” Generally, that’s usually meant people buying expensive cars or other things they can’t afford to try and maintain the same pace as their peers.
Privacy Assessments | ISO Certifications
By:
James Hunter
October 18th, 2022
If you’ve ever been in a car with someone who takes a speedbump anywhere above 10mph, at the time, you’ve probably thought, “didn’t you see that coming?!” Or maybe, “why didn’t they avoid that giant bump in the road?”