Register of Information: What DORA Article 28(3) Requires Governance Docs16th August 2026 DORA's register of information carries four obligations, and the forward-looking ones get missed. All arrangements, prescribed templates, and… Read More
Data Protection Officer: When Article 37 Makes One Mandatory Governance Docs16th August 2026 A DPO is mandatory in three cases, and all of them turn on core activities. What Article 38… Read More
International Data Transfers: Chapter V in Priority Order Governance Docs16th August 2026 GDPR Chapter V has a strict order: adequacy, then safeguards, then situational derogations. Why the last route is… Read More
Data Subject Access Request: The Copy Is Only Half of It Governance Docs16th August 2026 Article 15 asks for the data plus eight further items. The extension you must claim inside month one,… Read More
Breach Notification: Two Thresholds, Two Clocks Governance Docs16th August 2026 GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you… Read More
Legitimate Interests Assessment: The Test and the Trap Governance Docs16th August 2026 A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss… Read More
Records of Processing: Why the 250-Employee Exemption Fails Governance Docs15th August 2026 GDPR Article 30 records of processing: the exemption almost never applies, controllers and processors keep different records, and… Read More
DPIA: What GDPR Article 35 Actually Requires Governance Docs15th August 2026 A DPIA has four mandatory elements and two of them get skipped. What Article 35 requires, when Article… Read More
TISAX Exchange: The Half of TISAX Suppliers Never Use Governance Docs15th August 2026 TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and… Read More
SWIFT CSCF: Your Independent Assessment Can Be Internal Governance Docs15th August 2026 The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not… Read More
SOX 404: Who Needs the Auditor Attestation Governance Docs15th August 2026 SOX 404(a) applies to every issuer; 404(b) only to some. The public float and revenue tests that decide… Read More
PCI DSS Validation: Who Requires It, and What to Do First Governance Docs15th August 2026 PCI SSC does not require PCI DSS validation — your acquirer or payment brand does. How scope really… Read More