What is a TIA? A guide to Transfer Impact Assessments

A Transfer Impact Assessment evaluates whether personal data transferred outside the originating jurisdiction is afforded essentially equivalent protection. Required after Schrems II for most transfers from the EEA.

What is third-party due diligence?

Third-party due diligence is the evaluation of an external party – supplier, processor, vendor or service provider – before and during the relationship.

What is third-party privacy risk?

Third-party privacy risk is the risk that an external party processing personal data on your behalf fails to meet your obligations under privacy law.

What is AI third-party risk?

AI third-party risk is the risk arising from external AI capabilities – model providers, AI-enabled SaaS, AI consultants and AI service providers. Distinct from standard vendor risk because of the AI-specific dimensions involved.

What is GRC and operational risk?

GRC stands for Governance, Risk and Compliance – the discipline of running an organisation in a controlled, evidenced way. Operational risk is the sub-domain concerned with risks from internal processes, people, systems and external events.

What is breach response and reporting?

Breach response is the structured handling of a privacy or security incident – discovery, evaluation, communication, recording and remediation. Tight regulator timeframes apply.

What is a risk register?

A risk register is the structured list of identified risks an organisation is tracking – with severity, likelihood, owner, treatment and review date.