Privacy Data Security — guides, checklists and articles
45 practical documents on Privacy Data Security, newest first.
By document type
- Toolkits (12)
- Checklists (11)
- Guides (11)
- Articles (11)
Documents
- Incident Response and Breach Notification Toolkit · Toolkit — A data breach is a legal problem disguised as a technical one, and the decisions that determine how it ends are made in the first four hours by people who do…
- Building a Biometric Compliance Program: A Practitioner's Guide to Notice, Consent, Retention, and Vendors · Guide — This guide builds a biometric compliance program from an empty page and remediates one that started without a release. It begins with the inventory, which is…
- Building a Digital Health Product: A Practitioner's Guide to HIPAA Boundaries, Breach Notification, Clinical Data, and Platform Terms · Guide — This guide builds the legal architecture a digital health product actually needs, starting with the determination that decides everything else: whether the…
- Building for Someone Who Cannot Consent: COPPA, Age Signals, and the New Design Duties · Article — The children's privacy regime asks a question no other privacy law asks - whether the product is for children at all - and the answer determines whether an…
- Retail Media and Shopper Data Checklist: Data Ownership and Basis, Supplier and Brand Terms, Measurement and Attribution Claims, Clean Room Arrangements, and Consumer Rights Handling · Checklist — A ten-phase working checklist for retailers building media networks, brands buying from them, agencies sitting between, and the vendors supplying the…
- Building a Privacy Compliance Program for a Consumer Brand: A Practitioner's Guide to Notices, Rights, and Adtech · Guide — A build guide for the privacy program a consumer brand actually needs, ordered by risk reduction per dollar rather than by statutory section. It starts with…
- Biometric and Sensitive Data Toolkit: Consent, Retention, and Litigation Exposure · Toolkit — Biometric privacy is the rare area where a technical foul carries damages large enough to end a company, and the foul is usually a missing piece of paper. This…
- Your Face as Data: Biometric Privacy Statutes and the Written Consent Requirement · Article — Biometric privacy is the rare area of privacy law where a technical foul carries damages large enough to end a company, and the foul is usually a missing piece…
- The App That Knows Your Diagnosis: Health Data Outside HIPAA and the Rules That Fill the Gap · Article — Most health data in the United States is not governed by the statute everyone names. This article maps the actual boundary of HIPAA — which reaches covered…
- State Privacy Law Applicability and Readiness Checklist: Thresholds, Notices, Rights Workflow, Assessments, and Processor Terms · Checklist — This checklist establishes whether a company is actually subject to the comprehensive state privacy statutes, then builds the capability to comply with them,…
- Consumer Genomics and Genetic Data Toolkit: Consent, Research Use, Databases, and Access Requests · Toolkit — A genetic sample is the only dataset that identifies people who never consented to anything, because it identifies relatives. This toolkit assembles the…
- The Data Behind the Marketing: Privacy Law for Brands · Article — Every consumer brand now runs a data-processing operation whether or not anyone at the company describes it that way, and the marketing stack is where the…
- Building a Retail Media or Shopper Data Business: A Practitioner's Guide to Data Rights, Supplier Terms, Measurement Claims, and Privacy Obligations · Guide — A working guide to standing up, defending, or buying from a retail media network. It opens with the intake that establishes what the client actually has. It…
- Standing Up a Multi-State Privacy Compliance Program: A Practitioner's Guide to Applicability, Notices, Rights, Assessments, and Contracts · Guide — This guide builds a multi-state privacy program in the order the work actually has to happen, which is not the order the statutes are written in. It starts…
- Retail Media and Shopper Data Toolkit: Data Rights, Clean Rooms, Measurement, and Consent · Toolkit — A supermarket knows what a household eats, when it runs out, and a great deal it was never told. Retailers have discovered that this information is worth more…
- The Aisle Is an Advertising Network: Retail Media, Shopper Data, and the Rights Inside a Basket · Article — Retailers discovered that the most valuable thing they own is not the shelf but the record of what left it. This article explains what a retail media network…
- Cybersecurity Governance and Disclosure Toolkit: SEC Rules, Safeguards, and Vendor Risk · Toolkit — Cybersecurity has become a disclosure and governance obligation as much as a technical one, and the legal exposure now attaches to what a company says about…
- Incident Response Checklist: Containment, Forensics, Notification Triggers, and Documentation · Checklist — The decisions that determine how a breach ends are made in the first four hours by people who do not know they are making them. This checklist runs the…
- Digital Health and Health Data Toolkit: HIPAA Boundaries, Apps, Clinical Data, and Enforcement · Toolkit — Health data is regulated by whoever holds it rather than by what it says, which means the same blood glucose reading is protected health information in one…
- Recruitment and Workforce Data Toolkit: Automated Decisions, Bias Audits, and Employee Rights · Toolkit — Human resources holds the most sensitive personal data in most organisations and was excluded from privacy programmes for structural rather than principled…
- The State Privacy Wave: What the Comprehensive Consumer Statutes Actually Require · Article — Twenty-odd states now have comprehensive consumer privacy statutes that share a common architecture and differ in the places that cost money. This article sets…
- Sports Technology and Athlete Data Toolkit: Consent, Wearables, League Rules, and Commercial Rights · Toolkit — A professional athlete is measured continuously by devices they did not choose, under terms they did not negotiate, by an employer whose decisions about them…
- Children's and Youth Privacy Toolkit: COPPA, Age Assurance, and Design Codes · Toolkit — Children's privacy is the area where the gap between a company's belief about its audience and the regulator's view of it produces the largest enforcement…
- Athlete Data Checklist: Consent and Collective Agreement Terms, Wearable and Sensor Vendor Rights, League and Competition Data Rules, Medical and Biometric Handling, and Commercial Licensing Controls · Checklist — A ten-phase working checklist for athlete data, usable by a club, a league, a sports technology vendor, or an athlete's adviser. Phase one establishes the…
- Privacy and Marketing Data Toolkit: Notices, Consent, Adtech, and Rights · Toolkit — Marketing runs on data, and the rules governing that data now come from a dozen state statutes, several sectoral regimes, a body of contract law, and a wave of…
- Running a Data Breach Response: A Practitioner's Guide to Forensics, Privilege, Notification, and Regulators · Guide — This guide runs a data breach from the first phone call to the post-incident review. It opens with the four hours in which containment, preservation, and the…
- Outbound Marketing Compliance Checklist: Channel Rules, Consent Evidence, Opt-Out Handling, and Vendor Flow-Down · Checklist — This checklist audits and then rebuilds an outbound messaging program, in the order the work has to happen and with gates at the points where a mistake creates…
- Genomic Data Checklist: Consent Scope and Withdrawal, Sample and Data Retention, Research and Commercial Use Terms, Third-Party Access Requests, and Reidentification Response · Checklist — A ten-phase working checklist for consumer genomics companies, clinical laboratories, biobanks, and the partners who license genomic databases. Phases one…
- State Privacy Compliance Toolkit: Applicability, Rights, and Assessments · Toolkit — The state privacy statutes look interchangeable in summary and differ in ways that decide compliance work, and building to a single strictest standard is…
- Advising a Sports Technology Business or Team: A Practitioner's Guide to Athlete Data Rights, Wearables, League Terms, and Commercial Exploitation · Guide — A practitioner's guide to advising in sports technology, written for the four clients who appear in this practice — a club, a league, a vendor, and an athlete.…
- Workforce Data Checklist: System Inventory and Classification, Automated Decision Screening, Bias Audit Records, Vendor and Subprocessor Terms, and Employee Rights Handling · Checklist — This checklist audits an organisation's workforce data estate in the order the work has to happen, beginning with the inventory because every later…
- The First Seventy-Two Hours: Data Breach Notification and What the Law Actually Requires · Article — A data breach is a legal problem disguised as a technical one, and most of the mistakes are made in the first three days by people trying to be helpful. This…
- Building a Marketing Communications Compliance Program: A Practitioner's Guide to Consent Capture, Suppression, Vendors, and Litigation Defense · Guide — This guide builds a messaging compliance program from an unaudited marketing list to one that can be defended, and it is written for the lawyer who will have…
- Children's Privacy Compliance Checklist: Audience Analysis, Age Gates, Parental Consent, Data Minimization, and Ad Tech · Checklist — This checklist audits a product for children's privacy exposure and then remediates it, starting where enforcement actually starts rather than where the…
- Advising a Genetic Testing or Genomics Business: A Practitioner's Guide to Consent Architecture, Research Use, Database Licensing, and Law Enforcement Requests · Guide — A working guide to acting for consumer genomics companies, clinical testing laboratories, biobanks, and the partners who license their databases. It opens with…
- Marketing Communications Toolkit: TCPA, CAN-SPAM, and Consent Records · Toolkit — Marketing communications carry the largest per-message statutory damages exposure in ordinary commercial practice, and the liability turns almost entirely on…
- Every Step Recorded: Sports Technology, Athlete Data, and the Body as a Data Source · Article — An athlete at the top of any professional sport is measured continuously — position, acceleration, heart rate, sleep, recovery, sometimes blood chemistry — by…
- Deploying Recruitment and Workforce Technology: A Practitioner's Guide to Automated Decisions, Bias Audits, Vendor Terms, and Employee Data · Guide — This guide takes a practitioner from an empty page to a functioning workforce data programme, in the order the work actually has to happen. It starts with the…
- Biometric Data Checklist: Inventory, Notice, Written Consent, Retention, and Deletion · Checklist — Biometric exposure enters a company through a purchase order and is discovered through a lawsuit. This checklist runs the compliance work in twelve phases:…
- Digital Health Data Checklist: Regulatory Classification, Business Associate Terms, Consent and Tracking, Breach Analysis, and Vendor Diligence · Checklist — This checklist builds a digital health data position starting from the determination that governs everything else: covered entity, business associate, or…
- Permission to Reach Someone: The TCPA, CAN-SPAM, and the Consent Records Nobody Keeps · Article — The federal statutes that govern calling, texting, and emailing customers are short, old, and carry per-message statutory damages that turn an ordinary…
- Building a Children's and Teen Privacy Program: A Practitioner's Guide to Age Assurance, Verifiable Parental Consent, and Product Design · Guide — This guide builds a children's and teen privacy program from an unexamined product to one that can answer a regulator, and it starts where the exposure…
- The Most Personal Data There Is: Consumer Genomics, Research Consent, and What Happens to a Sample · Article — A tube of saliva produces a dataset that identifies its subject permanently, implicates relatives who consented to nothing, and cannot meaningfully be…
- Marketing Privacy Compliance Checklist: Notices, Consent, Vendors, and Rights Requests · Checklist — Sixteen phases for the privacy work a consumer brand's marketing stack actually generates, ordered by risk reduction per dollar rather than by statute. Phase…
- Everything the Application Knows: Recruitment Technology, Workforce Data, and the Rules That Reached HR · Article — Human resources spent thirty years building a data estate nobody classified as regulated, and then the rules arrived from four directions at once. This article…