Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
BAA
A Business Associate Agreement (BAA) is a signed agreement between covered entities and business associates. HIPAA privacy rule mandates that covered entities who share PHI with third party service providers specify the responsibilities of each party to secure PHI.
A BAA must describe the permitted rules to use or disclose PHI and require the business associate to implement appropriate safeguard to maintain the security of PHI.
Additional reading
5 Best CCPA Compliance Tools
California’s California Consumer Privacy Act (CCPA), as expanded by the California Privacy Rights Act (CPRA), now includes new regulations on cybersecurity audits, privacy risk assessments, and automated decision-making, which take effect on January 1, 2026, with phased compliance deadlines over the following years. The California Privacy Protection Agency (CPPA) can pursue penalties per violation that…
The Five Design Principles of Autonomous Trust
Most GRC platforms today face a structural problem because the world is moving faster than the tools designed to govern it. Frameworks are mapped, and evidence collection is automated, but proving that controls are effective right now still takes days of cross-team reconciliation. You’re still checking whether last quarter’s assessments hold up against what’s changed…
Corporate Compliance Program: Framework and Implementation
TLDR If you’re considering building a corporate compliance program, it’s likely driven by a few key factors. Perhaps a prospect has requested proof of your company’s ethics and security standards. Maybe regulatory requirements apply based on the services you provide, or you simply want to elevate your organization’s culture, ethics, and security practices. Whatever the…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.






