DTG-DTE82 · Privacy Governance · 12 min

This Is Where AI Governance and Privacy Governance Collide

Your privacy program was built for data you can locate, correct, and delete. AI systems do not work that way. The gap between these two realities is the most significant…

DTG-PV33 · Privacy Governance · 4 min

Cross-Border Data Flows Are Still the Most Underestimated Compliance Risk

Ask the general counsel of a GDPR-subject organization whether their cross-border data transfers are compliant. The answer is yes. Ask them which systems send personal da…

DTG-PV32 · Privacy Governance · 4 min

Behavioral Advertising and the Consent Problem That Hasn't Gone Away

Behavioral advertising is the practice of targeting advertising to individuals based on their observed behavior — the websites they visit, the content they engage with, t…

DTG-PV31 · Privacy Governance · 5 min

The Privacy Risk Your Product Team Introduced Last Sprint

Last sprint, the product team shipped four features. One extended the data collected from users in the onboarding flow, adding three new fields that the product manager d…

DTG-PV27 · Privacy Governance · 4 min

Biometric Data Is in Your Systems. Is Your Governance Program Ready?

Biometric data enters enterprise systems through more pathways than most privacy programs have mapped. Building access systems that use fingerprint or facial recognition.

DTG-PV26 · Privacy Governance · 4 min

When the Breach Notification Clock Started and Nobody Realized It

Under GDPR Article 33, the 72-hour notification clock starts when the controller becomes aware of the breach. Awareness, in regulatory guidance and enforcement practice,…

DTG-PV24 · Privacy Governance · 4 min

The Employee Data You Collect and the Obligations That Come With It

Employee data is the most consistently underestimated category of personal data in enterprise privacy programs. Organizations that have invested significantly in customer…

DTG-PV17 · Privacy Governance · 5 min

The Difference Between Privacy Compliance and Privacy Culture

Privacy compliance is the set of activities an organization performs to satisfy regulatory requirements: maintaining records of processing activities, conducting data pro…

DTG-PV11 · Privacy Governance · 4 min

The Processing Activity Nobody Documented Because Nobody Owned It

The Article 30 record of processing activities is supposed to be comprehensive. It documents every processing activity the organization conducts on personal data.

DTG-PV09 · Privacy Governance · 4 min

Purpose Limitation in a Data Warehouse Is Not a Solved Problem

Purpose limitation under GDPR requires that personal data be collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with th…

DTG-PV08 · Privacy Governance · 5 min

The DSAR That Required Searching Seven Systems and Still Wasn't Complete

The data subject access request arrived on a Tuesday. By the following Monday the privacy team had searched the CRM, the support ticketing system, the email archive, the…

DTG-PV04 · Privacy Governance · 7 min

Data Minimization Is the Principle Everyone Claims and Nobody Operationalizes

Ask any privacy officer whether their organization practices data minimization. The answer is yes. Ask them to show you where data minimization requirements are enforced…

DTG-200 · Privacy Governance · 8 min

Privacy Programs Look Mature. Until You Test Them

Privacy program maturity assessments measure whether the right elements are in place: policies documented, processes defined, tools deployed, responsibilities assigned.

DTG-199 · Privacy Governance · 8 min

Privacy Metrics Are Reported. They Do Not Reflect Exposure

Privacy programs report on what they measure. They measure what they can count. What they can count is process activity: training completion rates, DPIA completion rates,…

DTG-196 · Privacy Governance · 8 min

Privacy Controls Are Designed. They Are Not Monitored

A privacy control that exists and functions is a governance achievement. A privacy control that exists and is not monitored for continued effectiveness is documentation o…

DTG-193 · Privacy Governance · 8 min

Third-Party Data Sharing Is Disclosed. It Is Not Controlled

Privacy notices disclose that data is shared with third parties. Data processing agreements govern how those parties are permitted to use data.

DTG-189 · Privacy Governance · 8 min

Deletion Requests Are Fulfilled. They Are Not Fully Completed

A deletion workflow that finds and removes data from the systems it was designed to search is a deletion workflow that works correctly within its defined scope.

DTG-187 · Privacy Governance · 11 min

Consent Is Captured. Usage Extends Beyond It

Consent creates a specific authorization for a specific processing activity. Organizations capture consent at a single point and then process data across dozens of system…

DTG-185 · Privacy Governance · 10 min

Data Minimization Is Declared. It Is Not Operationalized

Every privacy policy says it. Every framework requires it. Almost no enterprise has operationalized it at the level its operational data estate requires.

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center