Deep TrustGovernance Series

Governance that holds up under pressure.

175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.

DTG-DTE82 · Privacy Governance · 12 min

This Is Where AI Governance and Privacy Governance Collide

Your privacy program was built for data you can locate, correct, and delete. AI systems do not work that way. The gap between these two realities is the most significant…

DTG-SC35 · Third-Party & Supply Chain · 4 min

Third-Party Data Flows Are the Biggest Unaudited Surface in Most Enterprises

Every internal data flow in a mature enterprise has some form of governance: a data architecture record, an access control, a monitoring capability, a retention policy.

DTG-SC33 · Third-Party & Supply Chain · 4 min

Holding Vendors Accountable Requires Evidence, Not Assurances

Vendor assurances are statements about what the vendor does. They appear in questionnaire responses, in sales presentations, in contract representations, and in certifica…

DTG-SC32 · Third-Party & Supply Chain · 4 min

Vendor Concentration Risk Is a Governance Problem, Not Just an Ops Problem

Vendor concentration risk is the risk that the organization's dependence on a small number of vendors for critical functions creates an exposure that the organization can…

DTG-SC31 · Third-Party & Supply Chain · 4 min

The Questionnaire Said Compliant. The Audit Said Different

The vendor completed the security questionnaire. Every question received a positive response. Multi-factor authentication: implemented. Encryption at rest: implemented.

DTG-SC29 · Third-Party & Supply Chain · 4 min

When the Cloud Provider Goes Down and Your BCP Assumed It Wouldn't

The business continuity plan was comprehensive. It covered data center fires, network outages, hardware failures, and cyberattacks. It covered regional disasters with fai…

DTG-SC28 · Third-Party & Supply Chain · 5 min

Inherited Data From an Acquisition Is Inherited Liability

The acquisition closed on a Thursday. By the following Monday, the acquiring organization had inherited the acquired company's customer base, their revenue contracts, the…

DTG-SC26 · Third-Party & Supply Chain · 4 min

How Shadow Procurement Creates Shadow Risk

Shadow IT is the technology adopted outside formal IT governance. Shadow procurement is the mechanism through which most shadow IT arrives: a business team identifies a t…

DTG-SC22 · Third-Party & Supply Chain · 4 min

The Difference Between a Vendor Contract and Vendor Accountability

The contract specifies what the vendor is required to do. It defines data handling obligations, security standards, breach notification timelines, audit rights, and remed…

DTG-SC19 · Third-Party & Supply Chain · 4 min

The Annual Vendor Review That Changes Nothing

The annual vendor review is scheduled, conducted, documented, and closed. The vendor completes the updated questionnaire. The questionnaire is scored.

DTG-SC16 · Third-Party & Supply Chain · 4 min

Why Procurement and Security Still Don't Talk About the Same Risks

Procurement manages vendor relationships through the lens of commercial risk: price, delivery, contract terms, supplier financial stability, and performance against servi…

DTG-SC13 · Third-Party & Supply Chain · 4 min

Continuous Vendor Monitoring Is Not Optional in a Dynamic Supply Chain

The argument for continuous vendor monitoring used to be a preference. Organizations with mature TPRM programs invested in ongoing monitoring because it was better practi…

DTG-SC08 · Third-Party & Supply Chain · 5 min

The Supply Chain Attack Nobody Modeled For

The threat model covered the obvious vectors. Direct attacks on internet-facing systems. Phishing campaigns targeting employees. Credential theft and lateral movement.

DTG-SC07 · Third-Party & Supply Chain · 5 min

What Happens to Your Data After It Leaves Your Environment?

This is not a rhetorical question. It is a governance question that most organizations cannot answer completely, and the completeness of the answer is a direct indicator…

DTG-PV33 · Privacy Governance · 4 min

Cross-Border Data Flows Are Still the Most Underestimated Compliance Risk

Ask the general counsel of a GDPR-subject organization whether their cross-border data transfers are compliant. The answer is yes. Ask them which systems send personal da…

DTG-PV32 · Privacy Governance · 4 min

Behavioral Advertising and the Consent Problem That Hasn't Gone Away

Behavioral advertising is the practice of targeting advertising to individuals based on their observed behavior — the websites they visit, the content they engage with, t…

DTG-PV31 · Privacy Governance · 5 min

The Privacy Risk Your Product Team Introduced Last Sprint

Last sprint, the product team shipped four features. One extended the data collected from users in the onboarding flow, adding three new fields that the product manager d…

DTG-PV27 · Privacy Governance · 4 min

Biometric Data Is in Your Systems. Is Your Governance Program Ready?

Biometric data enters enterprise systems through more pathways than most privacy programs have mapped. Building access systems that use fingerprint or facial recognition.

DTG-PV26 · Privacy Governance · 4 min

When the Breach Notification Clock Started and Nobody Realized It

Under GDPR Article 33, the 72-hour notification clock starts when the controller becomes aware of the breach. Awareness, in regulatory guidance and enforcement practice,…

DTG-PV24 · Privacy Governance · 4 min

The Employee Data You Collect and the Obligations That Come With It

Employee data is the most consistently underestimated category of personal data in enterprise privacy programs. Organizations that have invested significantly in customer…

DTG-PV17 · Privacy Governance · 5 min

The Difference Between Privacy Compliance and Privacy Culture

Privacy compliance is the set of activities an organization performs to satisfy regulatory requirements: maintaining records of processing activities, conducting data pro…

DTG-PV11 · Privacy Governance · 4 min

The Processing Activity Nobody Documented Because Nobody Owned It

The Article 30 record of processing activities is supposed to be comprehensive. It documents every processing activity the organization conducts on personal data.

DTG-PV09 · Privacy Governance · 4 min

Purpose Limitation in a Data Warehouse Is Not a Solved Problem

Purpose limitation under GDPR requires that personal data be collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with th…

DTG-PV08 · Privacy Governance · 5 min

The DSAR That Required Searching Seven Systems and Still Wasn't Complete

The data subject access request arrived on a Tuesday. By the following Monday the privacy team had searched the CRM, the support ticketing system, the email archive, the…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center