Blog: How to

Page 1

TCPA Compliance for SMS Marketing: How to Avoid Fines

Businesses can avoid Telephone Consumer Protection Act (TCPA) fines by taking steps such as providing disclosures, honoring opt-out requests, and getting express written consent before sending Short Message Service (SMS) marketing texts. This article explains what the TCPA is, whether it applies to SMS messages, the differences between how SMS messages...

Vendor Management for GDPR: How to Audit Your Third-Party Tools

Organizations that rely on third-party tools to handle personal data should audit vendors to meet the European Union's (EU) General Data Protection Regulation (GDPR) requirements. This article explains what the GDPR is, why organizations are liable for vendor noncompliance, and how to conduct a GDPR vendor audit to reduce compliance risk. What...

How to Create a Data Breach Response Plan (Before You Need It)

A data breach response plan is a written, step-by-step playbook that tells your business who does what, in what order, and how fast when you suspect customer, employee, or company data has been exposed. Creating a plan before an incident occurs can help you cut downtime, reduce legal risk, and...

AI Transparency and Privacy Notices: Preparing for the EU AI Act and Beyond

If your business uses AI to make decisions about people, like screening job applicants or approving loans, you must disclose this in your Privacy Policy or Privacy Notice. The EU AI Act, GDPR, and CCPA all require transparency about automated decision-making, with penalties up to €35 million for non-compliance under...

The Rise of Class Actions in Data Protection: What Companies Should Expect

Class action lawsuits are on the rise, and laws such as the European Union's (EU) Directive 2020/1828 make it easier for consumers to bring collective action against companies that breach EU privacy and data protection laws. This article explains what data protection class actions are, the role of Directive 2020/1828, common...

What to Do When You Receive a DSR via Third Party (Like Privacy Tools or Brokers)

Responding to a data subject request (DSR) has become a routine obligation under privacy laws like the GDPR and the CCPA/CPRA. But when those requests come through third parties or privacy tools, it often raises questions about how to handle verification correctly. While most privacy laws allow third parties to act...