News & Resources

Clause 5.6 of ISO/TS 22317:2021 — Identifying Resources and Dependencies ...

Once an organization has defined and prioritized its critical activities (Clause 5.5), it must determine what those activities need to function and re...

Clause 5.4 of ISO/TS 22317:2021 — Determining Product and Service Priorit...

After defining impact types, timeframes, and methodology in Clause 5.3, organizations are now ready to establish their continuity priorities. Clause 5...

Clause 5.5 of ISO/TS 22317:2021 — Determining the Prioritized Activities

Once top management has determined which products and services are most critical (Clause 5.4), the next step is to identify and prioritize the activit...

Clause 5.3 of ISO/TS 22317:2021 — Defining the Approach for an Effective ...

Clause 5.3 of ISO/TS 22317:2021 marks the critical stage where the Business Impact Analysis (BIA) moves from planning to execution. It requires the or...

The Applicability of the GDPR to the South African Road Accident Fund (RAF)

The RAF is a statutory public body in South Africa that collects, holds, and processes a lot of personal information (claimants, medical data, third p...

Vulnerabilities and Threats to GDPR Compliance and PII Protection

The General Data Protection Regulation (GDPR) requires controllers and processors to safeguard personal data through appropriate technical and organiz...

Examples of Unlawful Processing by a Controller (Beyond Lack of Consent)

GDPR requires one of six lawful bases under Article 6 (e.g., contract, legal obligation, legitimate interest, etc.). If none applies, processing is u...

Third-Party Compliance Oversight under GDPR

Article 5(2) GDPR (Accountability Principle): The controller remains responsible for ensuring that personal data is processed lawfully, even when pro...

In risk analysis and decision theory: Stochastic dominance is a method of compa...

In risk analysis and decision theory: Stochastic dominance is a method of comparing two uncertain outcomes (e.g., risk distributions) to see which is ...

Right to Rectification and “Undue Delay” (GDPR Article 16)

Article 16 GDPR states: “The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate...

Return on Control (RoC) in GDPR Context

RoC measures the effectiveness of a security or privacy control compared to its cost. It quantifies the reduction in risk exposure (both likelihood a...

Article 23 GDPR: Restrictions on Data Subject Rights and Processing

Article 23 GDPR allows Union or Member State law to restrict the scope of obligations and rights under GDPR by way of legislative measures (not just a...

Get Directions