19 articles in the Privacy Governance track of the Deep Trust Governance Series.
Your privacy program was built for data you can locate, correct, and delete. AI systems do not work that way. The gap between these two realities is the most significant…
Ask the general counsel of a GDPR-subject organization whether their cross-border data transfers are compliant. The answer is yes. Ask them which systems send personal da…
Behavioral advertising is the practice of targeting advertising to individuals based on their observed behavior — the websites they visit, the content they engage with, t…
Last sprint, the product team shipped four features. One extended the data collected from users in the onboarding flow, adding three new fields that the product manager d…
Biometric data enters enterprise systems through more pathways than most privacy programs have mapped. Building access systems that use fingerprint or facial recognition.
Under GDPR Article 33, the 72-hour notification clock starts when the controller becomes aware of the breach. Awareness, in regulatory guidance and enforcement practice,…
Employee data is the most consistently underestimated category of personal data in enterprise privacy programs. Organizations that have invested significantly in customer…
Privacy compliance is the set of activities an organization performs to satisfy regulatory requirements: maintaining records of processing activities, conducting data pro…
The Article 30 record of processing activities is supposed to be comprehensive. It documents every processing activity the organization conducts on personal data.
Purpose limitation under GDPR requires that personal data be collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with th…
The data subject access request arrived on a Tuesday. By the following Monday the privacy team had searched the CRM, the support ticketing system, the email archive, the…
Ask any privacy officer whether their organization practices data minimization. The answer is yes. Ask them to show you where data minimization requirements are enforced…
Privacy program maturity assessments measure whether the right elements are in place: policies documented, processes defined, tools deployed, responsibilities assigned.
Privacy programs report on what they measure. They measure what they can count. What they can count is process activity: training completion rates, DPIA completion rates,…
A privacy control that exists and functions is a governance achievement. A privacy control that exists and is not monitored for continued effectiveness is documentation o…
Privacy notices disclose that data is shared with third parties. Data processing agreements govern how those parties are permitted to use data.
A deletion workflow that finds and removes data from the systems it was designed to search is a deletion workflow that works correctly within its defined scope.
Consent creates a specific authorization for a specific processing activity. Organizations capture consent at a single point and then process data across dozens of system…
Every privacy policy says it. Every framework requires it. Almost no enterprise has operationalized it at the level its operational data estate requires.