Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » GDPR » Personal Data Breach

Personal Data Breach

Within the context of the GDPR, a personal data breach is an incident that occurs when an individual experiences a security lapse that causes the accidental or deliberate destruction, alteration, loss, exposure, or unlawful access of personal information. In the event of a data breach, the data controller must alert the supervisory authority within 72 hours of becoming aware of it.

This notification must specify the nature and category of the breach, the number of data subjects and records involved, the resulting impact, the measures proposed to mitigate risk, and the contact details of the data protection officer.

Additional reading

ISO 27001 Policy Template: Key Sections & Free PDF

TL,DR: ISO 27001 policy templates help document security expectations and risk-management responsibilities. Common templates cover access control, incident response, asset management, and business continuity. Each policy should define purpose, scope, roles, risk treatment, and training expectations. Implementing ISO 27001 can feel like staring at a blank page with a looming deadline. Defining security controls, documenting…

Compliance Audit Checklist: Preparing for a Smooth Audit

TL;DR  A compliance audit checklist ensures that all necessary documentation, processes, and policies are readily available and organized, reducing the time spent during the audit process. By outlining specific responsibilities for each audit area, the checklist fosters accountability across departments, ensuring that everyone knows their role in maintaining compliance. A checklist helps you spot gaps…

A Complete Guide to Vendor Governance

TL,DR: Vendor governance aligns third-party relationships with risk appetite, compliance needs, and business goals. It defines ownership, review cadence, accountability, and escalation before vendor risk slips. Strong programs classify vendors by risk tier and connect contracts, performance, and compliance. The weakest link in a company’s security chain usually wears another company’s logo. Most organizations trust…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.