News & Resources

Data Protection Impact Assessment (DPIA) vs. Legitimate Interest Assessment (LIA...

A DPIA is required where processing is “likely to result in a high risk to the rights and freedoms of natural persons.” Triggers include: ...

Vulnerabilities and Threats in Terms of CIA Under ISO 27001, ISO 27002, and ISO ...

Information Security Management Systems (ISMS), as defined by ISO/IEC 27001:2022, are designed to preserve the Confidentiality, Integrity, and Availab...

Are Medical Practitioners an “Official Authority” under GDPR?

Under GDPR Article 6(1)(e), processing is lawful if it is: “necessary for the performance of a task carried out in the public interest or in the...

Access Fees under GDPR (Article 12(5))

The General Data Protection Regulation (GDPR) gives data subjects the right of access to their personal data (Article 15). Controllers must generally ...

Get Directions