Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » GDPR » Data Controller

Data Controller

A Data Controller in GDPR is defined as the natural or legal person, public authority, agency, body who alone or in joint collaboration determines the means and purpose by which the data will be processed.

Additional reading

What Are GRC Processes? A complete Guide

TL,DR: GRC processes connect governance, risk, and compliance work through shared controls, evidence, and reporting. The article covers COSO, COBIT, ISO 31000, and the Learn, Align, Perform, Review cycle. Use it to reduce duplicate work, improve audit readiness, and make risk decisions faster. A compliance team spends weeks preparing for a SOC 2 audit while…

9 Limitations of Internal Controls And How to Mitigate Them

Internal controls are the building blocks of a company’s security posture. They shape the company’s security architecture and they can often be the difference between a secure company and a vulnerable one.  A recent study suggested that about 68% of occupational fraud occurred due to reasons relating to internal control loopholes—the reasons ranging from a…

Addressing HIPAA Concerns for AI Tools: What You Need To Know

As artificial intelligence rapidly proliferates into every aspect of technology, it will bring endless possibilities and conveniences never imagined.  While these possibilities aid medical staff and patients with speed and accuracy that exceed human capabilities, they also present new risks and realities. This particularly holds true when dealing with sensitive medical records that fall within…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.