News & Resources

Privacy by Design and by Default (GDPR Article 25)

Privacy by Design (PbD): Embedding data protection principles into the design of systems, processes, and technologies before they are deployed. Priva...

Re-requesting Personal Data Already Held by the Controller

Data Minimisation (Art. 5(1)(c)): Only collect what is necessary for the specified purpose. Accuracy (Art. 5(1)(d)): Personal data must be accurate a...

Legal Grounds for Processing Data in the Public Interest (GDPR)

GDPR explicitly provides “public interest” as one of the six lawful bases for processing: “Processing is necessary for the performan...

Key GDPR Definitions and Principles: An In-Depth Perspective

The General Data Protection Regulation (GDPR), formally known as Regulation (EU) 2016/679, establishes clear definitions and guiding principles for th...

Data Protection Impact Assessment (DPIA) vs. Legitimate Interest Assessment (LIA...

A DPIA is required where processing is “likely to result in a high risk to the rights and freedoms of natural persons.” Triggers include: ...

Vulnerabilities and Threats in Terms of CIA Under ISO 27001, ISO 27002, and ISO ...

Information Security Management Systems (ISMS), as defined by ISO/IEC 27001:2022, are designed to preserve the Confidentiality, Integrity, and Availab...

Are Medical Practitioners an “Official Authority” under GDPR?

Under GDPR Article 6(1)(e), processing is lawful if it is: “necessary for the performance of a task carried out in the public interest or in the...

Access Fees under GDPR (Article 12(5))

The General Data Protection Regulation (GDPR) gives data subjects the right of access to their personal data (Article 15). Controllers must generally ...

Whistleblower Policy in Security Operations under ISO 18788

A Whistleblower Policy is a cornerstone of transparency, accountability, and ethical conduct in security operations. In high-risk environments where m...

Whistle-blower Policy in Security Operations under ISO 18788

In security operations, misconduct, corruption, and even human rights abuses can go unreported if personnel and stakeholders fear retaliation. A Whist...

Weapons Authorization in Security Operations under ISO 18788

Weapons are among the most sensitive tools in security operations. Their presence introduces significant risks—legal, ethical, operational, and...

The Use of Force in Security Operations

The use of force is one of the most sensitive and high-risk aspects of security operations. Mismanagement can result in human rights violations, legal...

Get Directions