HIPAA Safeguards: Addressable Does Not Mean Optional Governance Docs16th August 2026 The HIPAA Security Rule labels specifications Required or Addressable. Addressable means assess, then implement or document why not… Read More
NIS2 Management Liability: Three Duties on Named People Governance Docs16th August 2026 NIS2 Article 20 makes management approve, oversee and be liable for cybersecurity measures — and Article 32(5) can… Read More
Bridge Letter: What It Covers, and What It Does Not Governance Docs16th August 2026 A SOC 2 bridge letter is written by management, not the auditor, and nothing in it is tested.… Read More
Complementary User Entity Controls: The Half You Must Do Governance Docs16th August 2026 A SOC 2 report lists controls the provider assumes you operate. Nobody tests them. How to extract, own… Read More
Prohibited AI Practices: Article 5 Is Already In Force Governance Docs16th August 2026 The EU AI Act's eight prohibited AI practices have applied since 2 February 2025, with fines up to… Read More
Third-Party Risk Management: One Inventory, Four Regimes Governance Docs16th August 2026 DORA, NIS2, ISO 27001 and sector schemes ask about the same suppliers in different formats. Build one inventory… Read More
Register of Information: What DORA Article 28(3) Requires Governance Docs16th August 2026 DORA's register of information carries four obligations, and the forward-looking ones get missed. All arrangements, prescribed templates, and… Read More
Data Protection Officer: When Article 37 Makes One Mandatory Governance Docs16th August 2026 A DPO is mandatory in three cases, and all of them turn on core activities. What Article 38… Read More
International Data Transfers: Chapter V in Priority Order Governance Docs16th August 2026 GDPR Chapter V has a strict order: adequacy, then safeguards, then situational derogations. Why the last route is… Read More
Data Subject Access Request: The Copy Is Only Half of It Governance Docs16th August 2026 Article 15 asks for the data plus eight further items. The extension you must claim inside month one,… Read More
Breach Notification: Two Thresholds, Two Clocks Governance Docs16th August 2026 GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you… Read More
Legitimate Interests Assessment: The Test and the Trap Governance Docs16th August 2026 A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss… Read More