Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » GDPR » EU-US and Swiss Privacy Shield

EU-US and Swiss Privacy Shield

The EU-US and Swiss Privacy Shield frameworks were designed by the European Commission and Swiss Administration and the U.S.Department of Commerce, respectively, to cater for companies on both sides of the Atlantic with a mechanism that complies with data protection requirements when personal data is transferred from the European Union as well as Switzerland to the United States in support of transatlantic Commerce.

Additional reading

Components of HIPAA: Understanding its Rules, Requirements, and Compliance Obligations

TL,DR: HIPAA is built on 5 rules: Privacy Rule (PHI use), Security Rule (ePHI safeguards), Breach Notification Rule (reporting), Transactions and Code Sets Rule (standardized electronic transactions), and Unique Identifiers Rule The Security Rule requires 3 safeguard categories: administrative (risk assessments, training), physical (facility controls, workstation security), and technical (access controls, encryption, audit controls) The…

ISO 27001 Risk Management Policy – Steps to Get Started

TL,DR: An ISO 27001 risk management policy is a mandatory ISMS document that outlines how your organization identifies, assesses, treats, monitors, accepts, and reviews information security risks. The policy should document your risk appetite, risk assessment methodology, risk acceptance criteria, legal and regulatory requirements, treatment approach, roles and responsibilities, documentation requirements, and review cadence. ISO…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.