
Breach Notification: Two Thresholds, Two Clocks
GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you…
CART
No products in the cart.

GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you…

A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss…

GDPR Article 30 records of processing: the exemption almost never applies, controllers and processors keep different records, and…

A DPIA has four mandatory elements and two of them get skipped. What Article 35 requires, when Article…

TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and…

The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not…

SOX 404(a) applies to every issuer; 404(b) only to some. The public float and revenue tests that decide…

PCI SSC does not require PCI DSS validation — your acquirer or payment brand does. How scope really…

The NIST AI RMF is voluntary, widely referenced, and version 1.0 is being revised under the White House…

ISO 50001:2018 is confirmed and stable, but ISO 50100:2026 and the rebuilt ISO 50002 audit series changed the…

ISO 41001:2018 is current and certifiable, but its replacement has reached DIS stage. What the standard requires, the…

ISO 55001:2024 replaced the 2014 edition in July 2024. What the asset management system requires, why the SAMP…
September 8, 2026
September 8, 2026
September 8, 2026
September 8, 2026
September 8, 2026