Blog - Page 8

Legal articles in easy to understand language.

What to Do When You Receive a DSR via Third Party (Like Privacy Tools or Brokers)

Responding to a data subject request (DSR) has become a routine obligation under privacy laws like the GDPR and the CCPA/CPRA. But when those requests come through third parties or privacy tools, it often raises questions about how to handle verification correctly. While most privacy laws allow third parties to act...

A Privacy Officer's Guide to Building Region-Specific Privacy Policies

If you're a Privacy Officer or compliance lead at a growing business with a global reach, there are a number of drawbacks to a one-size-fits-all Privacy Policy. Customers, regulators, and even app stores expect clear, region-specific disclosures that match the data protection rights of local users. Failing to do so creates...

Identity Verification Standards Under GDPR vs. CCPA/CPRA

If your business collects customer data, you're probably familiar with data subject (customer) requests. They often run along the lines of "I want to see the data you hold on me," or "I want you to delete everything you have on me." These requests are common, and it's your job to...

Choosing a Redaction Tool: Legal Requirements, Features to Demand, and Pitfalls to Avoid

Data privacy breaches can cost companies millions of dollars and erode customer trust overnight. Because of this, redaction has become a non-negotiable practice for businesses. Using a redaction tool helps you ensure that personal data, trade secrets, and confidential details stay permanently hidden. But not all redaction software is built equally....

Building a Redaction Policy: What Every Company Should Document Before Processing Requests

When an employee, customer, or regulator asks your company for information, how you respond can have serious legal and reputational consequences. Whether it's a Data Subject Access Request (DSAR) under privacy laws, an eDiscovery process in litigation, or an HR audit, your organization may need to share documents that contain...

Data Redaction Under GDPR: What Must Be Hidden Before You Respond to a DSAR

If you are subject to the European Union's (EU) General Data Privacy Regulation (GDPR), you will need to fulfill Data Subject Access Requests (DSARs). Certain personal data must be redacted before responding to DSARs. This legal and operational guide explains what the GDPR is and who it applies to, how DSARs...