Privata Vox® Blog

Filter by Topic:

All
  • All
  • Data Controllers
  • Data Processors
  • General
  • Regulatory
  • Risk Mitigation

Flawed ITAM: Known Cyber Security Risks Spell Trouble for CISOs and Boards

Yesterday’s SEC release alleging that software developer SolarWinds Corp. and its Chief Information Security Officer (CISO) T. Brown misled investors about known cybersecurity risks and vulnerabilities is yet another in a series of Commission actions regarding cybersecurity that should be setting off alarms for CISOs, CIOs, and the boards at all publicly traded companies and…

Read More about Flawed ITAM: Known Cyber Security Risks Spell Trouble for CISOs and Boards

Data Controller/Data Processor Contracts #2:
Regulatory Alignment

This is the second blog in an ongoing series examining the often-overlooked nuances of data controller/data processor contracts. Regulatory alignment is one of the primary reasons regulations require contracts between data controllers and data processors. And, yet, despite its primacy, many contracts make the mistake of establishing this linkage with an overly simplistic clause stating…

Read More about Data Controller/Data Processor Contracts #2:Regulatory Alignment

Data Controller/Data Processor Contracts #1:
Applicability

This blog explains why and when organizations should require contracts with service providers that have access to customer or employee personal information. One of the most underappreciated aspects of data controller/data processors contracts is when they are needed. This results from either 1) a lack of awareness of their necessity, or 2) the failure to…

Read More about Data Controller/Data Processor Contracts #1:Applicability

Why “Segregation of Duties” Should be Applied to ITAM-ITAD

Segregation of Duties (SODs), a.k.a. Separation of Duties, is the basic fiduciary mechanism that prevents an individual or department from having full custody of process integrity where there is an inherent conflict of interest or an opportunity for fraud. As the name denotes, to mitigate these potential problems, the duties related to those processes are…

Read More about Why “Segregation of Duties” Should be Applied to ITAM-ITAD

What Does a DPO Do?

Faced with the requirement of retaining a Data Protection Officer (DPO), it is important to understand their role. Regulatory language describing the duties of a DPO list the following: Monitor compliance with relevant regulations and with the company’s own policies in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and…

Read More about What Does a DPO Do?

The Dangers of Uncontrolled Records & Old Electronics

This blog describes how squirreled-away or forgotten documents and electronic equipment 1) undermine an organization’s records retention policy, 2) constitute a security risk, 3) complicate legal discovery compliance, and 4) violate new privacy regulations. __________ What are Uncontrolled Records and Old Electronics? The legal definition of a “business record” is any and all information recorded…

Read More about The Dangers of Uncontrolled Records & Old Electronics

How to Mitigate the ITAD Whistleblower Challenge

A series of recent Security and Exchange Commission (SEC) announcements point to the increasing risk of whistleblowers stemming from improper IT asset disposal (ITAD) practices. First, over the past year, the SEC has issued a number of statements and proposals indicating its intentions to hold organizations (and boards) under its jurisdiction accountable for cybersecurity. At…

Read More about How to Mitigate the ITAD Whistleblower Challenge

SEC-Blackbaud Enforcement Showcases Two Emerging Trends

On March 9, 2023, the Securities and Exchange Commission (SEC) reached a $3 million settlement with Blackbaud–a client relationship management (CRM) service provider–reflecting two trends in SEC’s enforcements which data controllers and data processors should watch. Trend #1: The enforcement action is the most recent in a series of SEC settlements for matters NOT being…

Read More about SEC-Blackbaud Enforcement Showcases Two Emerging Trends

The SEC’s Proposed New Data Security Rules

A March 15 proposal by the Security and Exchange Commission (SEC) to amend the Gramm-Leach-Bliley Act Safeguard’s Rule will require financial institutions and their data processors (i.e., secure shredders, ITADs, managed service providers, etc.) to seriously rethink and retool their data protection contracts, recordkeeping, and policies and procedures. Here’s What it Looks Like The proposal…

Read More about The SEC’s Proposed New Data Security Rules

Subscribe to stay up to date with new blog posts, speaking appearances, and more.

Subscribe To Updates

Email(Required)