What is a DPIA? A guide to Data Protection Impact Assessments
A Data Protection Impact Assessment is a structured review of a processing activity that identifies privacy risks to individuals and decides how to mitigate them. GDPR requires one for high-risk processing – including most uses of AI on personal data.
What is Third-Party Risk Management (TPRM)?
Third-Party Risk Management is the process of identifying, assessing and monitoring risks created by suppliers, processors, service providers, contractors and other external parties.
What is a TIA? A guide to Transfer Impact Assessments
A Transfer Impact Assessment evaluates whether personal data transferred outside the originating jurisdiction is afforded essentially equivalent protection. Required after Schrems II for most transfers from the EEA.
What is third-party due diligence?
Third-party due diligence is the evaluation of an external party – supplier, processor, vendor or service provider – before and during the relationship.
What is a ROPA? Records of Processing Activities explained
A Record of Processing Activities is the structured inventory of how an organisation processes personal data. Required by GDPR Article 30, it underpins almost every other privacy activity.
What is third-party privacy risk?
Third-party privacy risk is the risk that an external party processing personal data on your behalf fails to meet your obligations under privacy law.
What is DSAR management? A guide to handling data subject requests
DSAR management is the structured workflow for receiving, validating, fulfilling and recording data subject requests – access, deletion, portability, correction, objection and similar rights.
What is AI third-party risk?
AI third-party risk is the risk arising from external AI capabilities – model providers, AI-enabled SaaS, AI consultants and AI service providers. Distinct from standard vendor risk because of the AI-specific dimensions involved.
Privacy compliance software vs. spreadsheets – when to switch
Most privacy programmes start in spreadsheets. They rarely scale, and they almost never produce audit-grade evidence on demand. Here’s how to know when it’s time to move on.
What is GRC and operational risk?
GRC stands for Governance, Risk and Compliance – the discipline of running an organisation in a controlled, evidenced way. Operational risk is the sub-domain concerned with risks from internal processes, people, systems and external events.