About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Category: Articles

What addressable means in the HIPAA safeguards under 45 CFR 164.306

HIPAA Safeguards: Addressable Does Not Mean Optional

Governance Docs16th August 2026

The HIPAA Security Rule labels specifications Required or Addressable. Addressable means assess, then implement or document why not…
Read More
The NIS2 management liability duties under Articles 20 and 32

NIS2 Management Liability: Three Duties on Named People

Governance Docs16th August 2026

NIS2 Article 20 makes management approve, oversee and be liable for cybersecurity measures — and Article 32(5) can…
Read More
What a SOC 2 bridge letter is and what it is not

Bridge Letter: What It Covers, and What It Does Not

Governance Docs16th August 2026

A SOC 2 bridge letter is written by management, not the auditor, and nothing in it is tested.…
Read More
The three control populations in a SOC 2 report including complementary user entity controls

Complementary User Entity Controls: The Half You Must Do

Governance Docs16th August 2026

A SOC 2 report lists controls the provider assumes you operate. Nobody tests them. How to extract, own…
Read More
The eight prohibited AI practices under EU AI Act Article 5

Prohibited AI Practices: Article 5 Is Already In Force

Governance Docs16th August 2026

The EU AI Act's eight prohibited AI practices have applied since 2 February 2025, with fines up to…
Read More
How four regimes each approach third-party risk management

Third-Party Risk Management: One Inventory, Four Regimes

Governance Docs16th August 2026

DORA, NIS2, ISO 27001 and sector schemes ask about the same suppliers in different formats. Build one inventory…
Read More
What DORA Article 28(3) requires in the register of information

Register of Information: What DORA Article 28(3) Requires

Governance Docs16th August 2026

DORA's register of information carries four obligations, and the forward-looking ones get missed. All arrangements, prescribed templates, and…
Read More
When a data protection officer is mandatory under GDPR Article 37

Data Protection Officer: When Article 37 Makes One Mandatory

Governance Docs16th August 2026

A DPO is mandatory in three cases, and all of them turn on core activities. What Article 38…
Read More
The GDPR Chapter V routes for international data transfers

International Data Transfers: Chapter V in Priority Order

Governance Docs16th August 2026

GDPR Chapter V has a strict order: adequacy, then safeguards, then situational derogations. Why the last route is…
Read More
What GDPR Article 15 requires in response to a data subject access request

Data Subject Access Request: The Copy Is Only Half of It

Governance Docs16th August 2026

Article 15 asks for the data plus eight further items. The extension you must claim inside month one,…
Read More
GDPR breach notification thresholds, audiences and timing

Breach Notification: Two Thresholds, Two Clocks

Governance Docs16th August 2026

GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you…
Read More
The legitimate interests assessment test under GDPR Article 6(1)(f)

Legitimate Interests Assessment: The Test and the Trap

Governance Docs16th August 2026

A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss…
Read More
    ←
  • 1
  • …
  • 26
  • 27
  • 28
  • 29
  • 30
  • …
  • 45
  • →

Recent Posts

FSSC 22000 certification cost in 2026: auditor-day calculation, Foundation fees and Version 7 upgrade
FSSC 22000 Certification Cost in 2026: Complete Breakdown

September 15, 2026

Saudi PDPL implementing regulations — Saudi PDPL Implementing Regulations: The 38 Articles Mapped
Saudi PDPL Implementing Regulations: The 38 Articles Mapped

September 14, 2026

Saudi standard contractual clauses — Saudi Standard Contractual Clauses: Transfers With No Adequacy List
Saudi Standard Contractual Clauses: Transfers With No Adequacy List

September 14, 2026

SDAIA registration — SDAIA Registration: The National Data Governance Platform Explained
SDAIA Registration: The National Data Governance Platform Explained

September 14, 2026

Saudi PDPL vs GDPR — Saudi PDPL vs GDPR: The 11 Differences That Change What You Do
Saudi PDPL vs GDPR: The 11 Differences That Change What You Do

September 14, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
  • Manage cookies
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA