SchellmanCON is back! Join us for our virtual conference on March 6 & 7, 2025

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Blog

The Schellman Blog

Stay up to date with the latest compliance news from the Schellman blog.

Blog Feature

Privacy Assessments | ISO Certifications | ISO 42001

By: Schellman
September 26th, 2024

Within a few months of their latest update to their Data Protection Requirements (DPR) to address a coding incident (version 9.1), Microsoft released a draft or “pre-read” for their version 10 requirements that will be utilized for its Supplier Security and Privacy Assurance (SSPA) process as of the 2025 fiscal year. Arguably the largest update to the DPR since September 2018, v10’s new mandates address artificial intelligence (AI) and include important references to ISO 42001 that suppliers may want to take advantage of during their next compliance cycle.

Blog Feature

Privacy Assessments

By: CHRIS LIPPERT
August 1st, 2024

When Microsoft released version 9 of their Data Protection Requirements (DPR) back in October 2023, the new framework contained several important updates, as well as a few brand new requirements, including the addition of new considerations for suppliers processing protected health information (PHI).

Blog Feature

Privacy Assessments

By: Kathryn Young
April 5th, 2024

Amidst the evolving patchwork of data protection and privacy legislation in the United States, privacy remains a top priority for organizations. But protecting privacy also requires resources, and while not all organizations have that much to spare, it is possible to make do with only a small, dedicated team.

Blog Feature

Privacy Assessments

By: CHRIS LIPPERT
December 14th, 2023

Since the introduction of the new Data Privacy Framework (DPF) on July 17, 2023, many have begun familiarizing themselves with its seven principles as they ready themselves to comply. However, the DPF also features 16 supplemental principles, two of which—regarding self-certification and verification—also cover particularly important topics.

Blog Feature

Privacy Assessments

By: Kathryn Young
September 27th, 2023

Generally, privacy impact assessments (PIAs) are defined as evaluation tools that help to better understand how information is gathered, used, maintained, and shared. It’s a formal analysis used to assess what privacy risks exist within the information processing activities that drive specific products and services.

Blog Feature

Privacy Assessments

By: CHRIS LIPPERT
July 18th, 2023

In news that’s excited the privacy industry worldwide—the EU – U.S. Data Privacy Framework (DPF) was announced on Monday, July 10, 2023, and took near immediate effect. This comes after months of review and public comment, but now, with the DPF functioning as a new adequacy mechanism under General Data Protection Regulation (GDPR), organizations can once again transfer data under an adequacy decision if they adhere to and self-certify against the DPF.

Blog Feature

Privacy Assessments

By: CHRIS LIPPERT
December 15th, 2022

You’ve probably heard the classic idiom about “keeping up with the Joneses.” According to Miriam-Webster, it means “to show that one is as good as other people by getting what they have and doing what they do.” Generally, that’s usually meant people buying expensive cars or other things they can’t afford to try and maintain the same pace as their peers.

Blog Feature

Privacy Assessments | ISO Certifications

By: James Hunter
October 18th, 2022

If you’ve ever been in a car with someone who takes a speedbump anywhere above 10mph, at the time, you’ve probably thought, “didn’t you see that coming?!” Or maybe, “why didn’t they avoid that giant bump in the road?”

{