Blogs

    Article 20 GDPR right to data portability
    ,
    Data Portability Under Article 20 GDPR
    TL,DR: GDPR Article 20 grants individuals the right to receive their personal data in a structured, commonly used, and machine-readable format for reuse or direct transfer between controllers Data portability applies only when processing is based on consent or contract performance and carried out by automated means. Manual paper records are excluded from this right…
    GDPR Article 15 Right of Access by the Data Subject
    ,
    GDPR Article 15 Right of Access by the Data Subject
    TL,DR: Article 15 of GDPR gives every data subject the legal right to request and receive all personal data an organization holds about them, with the first copy provided free of charge Organizations must disclose processing purposes, data categories collected, third-party recipients, and retention periods upon receiving a valid access request submitted orally, in writing,…
    GDPR Article 32: Security of Processing
    ,
    GDPR Article 32: Security of Processing
    TL,DR: GDPR Article 32 requires controllers and processors to implement technical and organizational security measures proportionate to the risk level, covering pseudonymization, encryption, system availability, and regular testing The article does not prescribe a fixed checklist. Organizations must assess the state of the art, implementation costs, processing scope, and risk severity to determine appropriate controls…
    Sprinto named as Security Compliance Leader in G2 Summer 2022 Report
    We’re thrilled to announce that Sprinto has been recognized as a Security Compliance Leader in the Summer 2022 Grid® Report by G2.  Sprinto also ranked #1 in Best Usability, Best Relationship and Best Price, outperforming the competition and collectively winning 9 badges across categories. G2 is one of the largest software marketplace and services review…
    Make Compliance Your Superpower
    ‘It is not our abilities that show us what we truly are. It is our choice.’ These sage words of Professor Dumbledore in ‘Harry Potter and the Chamber of Secrets’ best capture why you should mainstream compliance in your company. Most SaaS start-ups have had a good run so far. But what can they do to…
    PCI DSS compensating controls
    ,
    A Detailed Overview Of PCI DSS Compensating Controls
    If your business handles, stores, transmits, manages, or processes customers’ payment card information, it must comply with PCI DSS (Payment Card Industry Data Security Standard). This is an information security standard that outlines measures and controls for organizations to protect sensitive card details while processing transactions.  Implementing stringent compliance is not a piece of cake…