What is a TIA? A guide to Transfer Impact Assessments
A Transfer Impact Assessment evaluates whether personal data transferred outside the originating jurisdiction is afforded essentially equivalent protection. Required after Schrems II for most transfers from the EEA.
What is third-party due diligence?
Third-party due diligence is the evaluation of an external party – supplier, processor, vendor or service provider – before and during the relationship.
What is a ROPA? Records of Processing Activities explained
A Record of Processing Activities is the structured inventory of how an organisation processes personal data. Required by GDPR Article 30, it underpins almost every other privacy activity.
What is third-party privacy risk?
Third-party privacy risk is the risk that an external party processing personal data on your behalf fails to meet your obligations under privacy law.
What is DSAR management? A guide to handling data subject requests
DSAR management is the structured workflow for receiving, validating, fulfilling and recording data subject requests – access, deletion, portability, correction, objection and similar rights.
What is AI third-party risk?
AI third-party risk is the risk arising from external AI capabilities – model providers, AI-enabled SaaS, AI consultants and AI service providers. Distinct from standard vendor risk because of the AI-specific dimensions involved.
Privacy compliance software vs. spreadsheets – when to switch
Most privacy programmes start in spreadsheets. They rarely scale, and they almost never produce audit-grade evidence on demand. Here’s how to know when it’s time to move on.
What is GRC and operational risk?
GRC stands for Governance, Risk and Compliance – the discipline of running an organisation in a controlled, evidenced way. Operational risk is the sub-domain concerned with risks from internal processes, people, systems and external events.
What is breach response and reporting?
Breach response is the structured handling of a privacy or security incident – discovery, evaluation, communication, recording and remediation. Tight regulator timeframes apply.
What is a risk register?
A risk register is the structured list of identified risks an organisation is tracking – with severity, likelihood, owner, treatment and review date.