Do not sell my personal data

Consumers in California are quickly getting familiar with this phrase: do not sell my personal information. It is one of the more noticeable effects of the CCPA; the right of consumers to opt-out of companies monetising their data. Companies that sell data are obliged to put a ‘do not sell’ link on their website. The right to opt-out is not part of the GDPR, instead the GDPR requires organisations to have a legal ground for Read more…

Privacy, urgent or important?

Recently I learned about the Eisenhower Matrix. Based on a quote by President Eisenhower, “I have two kinds of problems, the urgent and the important. The urgent are not important and the important are never urgent.”, it helps people organize their priorities. Unlike the former President, the matrix recognises four different types of issues: Urgent and important Urgent and not important Important and not urgent Not important and not urgent In the matrix these are Read more…

Six steps towards GDPR compliance

Setting up a privacy program from scratch, whether it’s GDPR or CCPA, or both (!) can feel a little overwhelming.Where to start? Which are my biggest risks? How will this impact my business? And when are we compliant enough? Some of the things we have learned from helping dozens of organizations with their privacy compliance is that you cannot go from 0 to 100% compliance in one go and that compliance is a continuous process Read more…

Cyber, InfoSec, Privacy, what’s the deal?

Audittrail is housed in the iCybercenter at bwtech@UMBC, yet we are anything but techies. How do privacy lawyers end up in a cyber environment? And what exactly is Information Security, or InfoSec? Well, the fields are all connected and they are, confusingly enough, often used interchangeably. Marketing departments love a buzzword, add to that the requirements of SEO and all of the sudden I’m a cyber expert with VPN tunnel vision. So let’s break it Read more…