What is a DPIA? A guide to Data Protection Impact Assessments

A Data Protection Impact Assessment is a structured review of a processing activity that identifies privacy risks to individuals and decides how to mitigate them. GDPR requires one for high-risk processing – including most uses of AI on personal data.

What is Third-Party Risk Management (TPRM)?

Third-Party Risk Management is the process of identifying, assessing and monitoring risks created by suppliers, processors, service providers, contractors and other external parties.

What is a TIA? A guide to Transfer Impact Assessments

A Transfer Impact Assessment evaluates whether personal data transferred outside the originating jurisdiction is afforded essentially equivalent protection. Required after Schrems II for most transfers from the EEA.

What is third-party due diligence?

Third-party due diligence is the evaluation of an external party – supplier, processor, vendor or service provider – before and during the relationship.

What is third-party privacy risk?

Third-party privacy risk is the risk that an external party processing personal data on your behalf fails to meet your obligations under privacy law.

What is AI third-party risk?

AI third-party risk is the risk arising from external AI capabilities – model providers, AI-enabled SaaS, AI consultants and AI service providers. Distinct from standard vendor risk because of the AI-specific dimensions involved.

What is GRC and operational risk?

GRC stands for Governance, Risk and Compliance – the discipline of running an organisation in a controlled, evidenced way. Operational risk is the sub-domain concerned with risks from internal processes, people, systems and external events.