International Data Transfers: Chapter V in Priority Order Governance Docs16th August 2026 GDPR Chapter V has a strict order: adequacy, then safeguards, then situational derogations. Why the last route is… Read More
Data Subject Access Request: The Copy Is Only Half of It Governance Docs16th August 2026 Article 15 asks for the data plus eight further items. The extension you must claim inside month one,… Read More
Breach Notification: Two Thresholds, Two Clocks Governance Docs16th August 2026 GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you… Read More
Legitimate Interests Assessment: The Test and the Trap Governance Docs16th August 2026 A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss… Read More
Records of Processing: Why the 250-Employee Exemption Fails Governance Docs15th August 2026 GDPR Article 30 records of processing: the exemption almost never applies, controllers and processors keep different records, and… Read More
DPIA: What GDPR Article 35 Actually Requires Governance Docs15th August 2026 A DPIA has four mandatory elements and two of them get skipped. What Article 35 requires, when Article… Read More
TISAX Exchange: The Half of TISAX Suppliers Never Use Governance Docs15th August 2026 TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and… Read More
SWIFT CSCF: Your Independent Assessment Can Be Internal Governance Docs15th August 2026 The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not… Read More
SOX 404: Who Needs the Auditor Attestation Governance Docs15th August 2026 SOX 404(a) applies to every issuer; 404(b) only to some. The public float and revenue tests that decide… Read More
PCI DSS Validation: Who Requires It, and What to Do First Governance Docs15th August 2026 PCI SSC does not require PCI DSS validation — your acquirer or payment brand does. How scope really… Read More
NIST AI RMF: The Four Functions, and the Revision Underway Governance Docs15th August 2026 The NIST AI RMF is voluntary, widely referenced, and version 1.0 is being revised under the White House… Read More
ISO 50001: The Standard Held Still, the Family Did Not Governance Docs15th August 2026 ISO 50001:2018 is confirmed and stable, but ISO 50100:2026 and the rebuilt ISO 50002 audit series changed the… Read More