
All Posts
- Who HIPAA Actually Covers
A fitness tracker holds more health information than a dentist and answers to a different regulator. This piece sets out the three categories of covered entity, what makes a business associate, and which federal rule reaches the apps HIPAA never did. - Data Classification That Drives Controls
Public, internal, confidential, restricted. Four labels, applied once, and nothing downstream changes. A federal standard shows the alternative: rate impact separately across three objectives, take the highest, and let that decide the controls. - Privacy By Design Without Trade-Offs
Seven foundational principles, and the fourth one is the argument. Full functionality means positive-sum rather than zero-sum, which rules out the trade-off framing product teams reach for first. This piece works through what that principle demands and how the exam tests it. - The Safe Deactivation of an AI System
Every AI governance programme plans the launch. Far fewer plan the stop. Two instruments treat the ability to halt a system as something built in advance rather than improvised, and the AIGP exam tests the difference between suspending, recalling and decommissioning. - What Article 28 Contracts Must Contain
Most processor contracts copy the eight subparagraphs of the GDPR into a template and stop there. The regulator has said plainly that this fails. This piece covers what the contract must set out, what has to happen before it, and what continues afterwards. - The BIPA Private Right Of Action
Illinois gave individuals the right to sue over biometric data and set liquidated damages without requiring proof of injury. An August 2024 amendment capped repeated collections at a single recovery. This piece separates the duties from the remedy. - Privacy Metrics For The Right Audience
A board paper full of ticket volumes tells directors nothing. A team dashboard full of risk exposure tells staff nothing they can act on. This piece works through the three reporting tiers a regulator expects and which measure belongs at each. - What LINDDUN Threat Modelling Actually Does
Seven letters, seven privacy threat types, and two sets of names in circulation. This piece works through what each LINDDUN category covers, how the method runs against a data flow diagram, and the one thing the framework deliberately leaves to you. - The Four NIST AI RMF Functions
Govern, Map, Measure and Manage look like a sequence and are not one. This piece works through what each function of the NIST AI RMF actually covers, why governance sits across the other three, and how the distinction shows up in AIGP questions.
