How to ensure your international data transfers are lawful

How to ensure your international data transfers are lawful

Welcome to this week’s Security Spotlight, in which we shine a light on:???

???


Blog | GDPR: international data transfers using the IDTA, SCCs or BCRs?

The UK and EU GDPR (General Data Protection Regulation) restrict transfers of personal data outside the UK and EU respectively.?

Consequently, you must put an appropriate mechanism or safeguard in place to transfer personal data internationally, such as:?

  • The IDTA (international data transfer agreement)?

  • SCCs (standard contractual clauses)?

  • BCRs (binding corporate rules)?

This blog, by GRCI Law’s Natalie Whitney, takes a closer look at these mechanisms, and when and how to use them.?

Read the full blog?

?

Blog | 7 steps to prepare for PCI DSS audit success?

Organisations that process, transmit and/or store cardholder data or SAD (sensitive authentication data), or can affect their security, must comply with the PCI DSS (Payment Card Industry Data Security Standard).?

The more transactions you process, the more likely you need to be audited by a qualified external auditor – a QSA.?

If you’ve recently experienced a breach and were subject to a PCI forensic investigation, you’re also more likely to need to bring in a QSA.?

Sujith Parambath, our head of PCI and Cloud consulting services, explains how to ensure your audit is successful.?

Read the full blog?

?

?


Blog | How can organisations transition to ISO 27001:2022??

Organisations with ISO/IEC 27001:2013 certification must transition to ISO/IEC 27001:2022 by 31 October 2025.?

The biggest change for organisations is Annex A, which has been overhauled and includes 11 new controls.?

How can organisations best approach this new control set? What changes to the main clauses of the Standard tend to get overlooked? And what are common mistakes to avoid when transitioning??

Our head of GRC (governance, risk and compliance) consultancy, Damian Garcia, explains.?

Read the full blog?

?


Free case study | Air Ambulance Charity Kent Surrey Sussex?

Download our case study with Air Ambulance Charity Kent Surrey Sussex to understand how a thoughtful approach to data protection compliance has enabled its team to innovate in an extremely regulated industry.?

Find out how our bespoke consultancy service can be the perfect, flexible solution for organisations that require extra support for a wide range of data protection-related projects.?

Download now?

?

??

Free paper | Data Subject Access Requests (DSARs) – A concise guide?

DSARs are becoming increasingly common, and failure to respond?in accordance with the GDPR’s?(General Data Protection Regulation)?requirements?can lead to serious fines and sanctions.???

This free guide?explains?how to manage data subjects’ rights?in line with the GDPR?and?clarifies?the?new obligations?for organisations.???

Discover:?

  • The key changes for organisations responding to DSARs under the GDPR??

  • Who is responsible for handling DSARs??

  • What data needs to be provided and exceptions to consider??

  • A process for responding to DSARs?that?you can adapt to meet your needs and comply with the law?

Download now?

?

???

Free paper | The Data Protection Officer (DPO) Role – A beginner’s guide?

The GDPR requires many organisations to appoint a DPO. Are you one of them? Find out what a DPO does, whether you need to appoint one, and how to fill the role in this easy-to-read guide.?

This guide explains:?

  • What a DPO does?

  • When organisations are required to appoint a DPO?

  • Where they should appoint their DPO?

  • How the DPO fits into the organisation?

  • The experience and qualifications a DPO needs?

  • The benefits of outsourcing the DPO role?

Download now?


Free webinar | Start strong: leveraging your experience to start a career in data protection and privacy?

If you have some responsibility for data protection, could you do more? Is this a specialism and a career path worth investing in? Whether you’re transitioning from compliance, law, HR, IT or another field, this webinar is designed to help you leverage your existing experience and gain the skills needed to launch a successful career in privacy.?

Join us for practical guidance on the knowledge, certifications and career pathways that can position you as a valuable asset in this growing field.?

Thursday, 20 February, 15:00 – 16:00 (GMT)?

Register now?

?

?

Free webinar | Start strong: how to launch or transition into a career in cyber security?

If you are starting out, have IT experience without certifications, credentials without hands-on experience, or are transitioning from another industry, this webinar will help you bridge the gap and position yourself for success in this dynamic field.?

Join us to learn the steps to build your profile, understand skills and qualifications employers value, and explore proven pathways to start your cyber security career.??

Thursday, 27 February, 15:00 – 16:00 (GMT)?

Register now?

?


Set your organisation up for success?

This year brings many new challenges, including:?

  • Unsanctioned Cloud-based applications?

  • Ongoing privacy compliance?

  • Increasing regulatory pressures?

  • The double-edged sword of AI?

Whatever 2025 brings, at least you can control your cyber risks. If you’ve put off major projects because of recent challenges, now is the time to revisit them and implement the actions necessary to help your organisation thrive.?

Find out more?

??


Speak to an expert???

With 20+ years’ experience in information security and data privacy, we understand risk management.???

Our experts have implemented security and compliance programmes for hundreds of organisations across a multitude of industries in both the private and public sectors.???

New to the world of information security and data privacy, and need advice on how to get started????

Or updating an existing programme????

Our experts are here to help.???

Get in touch???

???


要查看或添加评论,请登录

IT Governance Ltd的更多文章