A configuration error exposed sensitive HR dossiers to dozens of managers
A Hamburg regulator's retailer decision shows how access configuration, retention, and sensitive workplace notes can become one connected governance problem.
Pillar 03
Accounts, data, code, licences and other invisible assets that the business assumes it can keep using.
Which critical permission or intangible right could fail under stress?
Guides and case lessons
A Hamburg regulator's retailer decision shows how access configuration, retention, and sensitive workplace notes can become one connected governance problem.
Canadian privacy findings involving an app's background location collection show how an abandoned business plan can leave a live data practice behind.
CNIL's platform provider decision shows why layered notices and consent design can become the practical object of regulatory scrutiny, not a footer detail.
A genetic-data investigation and later SEC filing connect credential stuffing, linked relatives and a completed Chapter 11 asset sale.
A Singapore breach decision split consequences between a healthcare data owner and its IT provider, exposing the limits of vendor transfer language.
A cyclone connectivity review reveals why offline workarounds need data-minimisation, custody and deletion rules before the network fails.
An FTC order split data-breach consequences between a former owner and buyer, turning privacy diligence into an operating handover.
A Google Cloud incident shows how extreme heat, cooling failure and recovery sequencing can reach systems that appear regionally resilient.
A Canadian laboratory breach investigation shows why payment, returned data and regulator findings answer different incident questions.
A health-privacy settlement shows why reputation response authority should be separated from access to customer facts.
An ICO penalty notice shows how a hidden spreadsheet tab turned a redaction mistake into a safety and workforce problem.
A voice-assistant order shows why a deletion request may have a different technical meaning once children's voice and location data feed algorithmic systems.
A list of AI tools becomes more useful when it records the decision use, affected people, data path, owner and material-change triggers.
A practical second lens for connecting a business-critical certificate or key to its service, owner, lifecycle triggers and replacement evidence.
A practical guide to separating a paper exit clause, an export capability and observed evidence from a controlled recovery exercise.
A NIST CSF Organizational Profile can expose ownership and trade-offs without becoming a certification, maturity score or legal safe harbour.
An evidence-aware guide to assigning ownership around email-authentication records, report routes, exceptions and review triggers.
A source-to-claim record for checking environmental statements received from suppliers before they reach products, sales material or customers.
A critical SaaS tenant needs a reviewable account-holder, privileged-role, recovery and handoff record—not confidence in one current login.
A versioned change record can separate a vendor announcement from the buyer's tested operational impact, decision and rollback path.
A DORA-related subcontracting map should connect an ICT service to its function, sub-provider, change route and exit dependency without assuming every vendor is in scope.
A regulatory-radar guide to mapping role, purpose, user journey, requested attributes, evidence, data boundaries and change governance before integration.
A supplier questionnaire can inform a NIS2-related review, but scope, supplier criticality, evidence, ownership and national implementation remain separate questions.
An EU-source-bounded analysis separating PLD liability from CRA cybersecurity while preserving version, evidence and unresolved product questions.
A release-evidence guide for connecting shipped components to licence records, notice treatment, named owners and visible exceptions.
A software build result is one release input; the decision record preserves the version, evidence, exception, owner, rollback condition and next review.
An SBOM can identify software components, but an owner still needs a versioned record of receipt, review, exceptions, changes and incident use.
Map what enters an AI service, what the vendor may retain or reuse, what leaves it, and which software and licence dependencies remain hidden.
A scoped guide to the European Accessibility Act for consumer e-commerce, including the service microenterprise exemption and national-law limits.
A dated owner’s map of the EU AI Act after the 2026 AI Omnibus, separating live transparency and GPAI rules from delayed high-risk duties.
A practical CRA preparation map for digital-product businesses, separating September 2026 reporting from the December 2027 main obligations.
What business owners should verify under the EU Data Act now, before the connected-product design and cloud switching milestones arrive.
A business-owner map of selected U.S. federal and state privacy and cyber triggers, including California’s 2026 rules and DROP duties.
A US Supreme Court decision separates breach from rescission when a bankrupt licensor rejects an ongoing contract.
A 2026 Delaware decision shows how a founder's post-sale role, customer influence and mass data removal can converge into an IP crisis.
Optional analytics
Privacy-limited Cloudflare Web Analytics is off unless you allow it. It is not used for advertising, cross-site tracking or profiling.
Analytics has not been selected.
Read the analytics details. You can change this choice at any time.