Jul 09 2026

GDPR Isn’t a Cookie Banner: The Audit Findings That Actually Get Companies Fined

Category: GDPRdisc7 @ 10:44 am


GDPR Isn’t a Cookie Banner: The Audit Findings That Actually Get Companies Fined

Seven years after GDPR took effect, most organizations still treat it like a checkbox they ticked in 2018. They dropped in a cookie banner, published a privacy policy their own lawyers haven’t read since, and moved on. Then a data subject access request lands, or a breach hits, or a regulator comes knocking — and suddenly the gap between “we have a privacy policy” and “we can actually demonstrate compliance” becomes very, very expensive. The uncomfortable truth I keep running into in audits is that GDPR failures rarely look dramatic. They’re not master hackers exfiltrating databases. They’re mundane, systemic gaps that sat quietly in plain sight until the day they didn’t. And with AI now feeding on personal data for marketing, sales, and product decisions, the old gaps have gotten wider and the new ones are appearing faster than most compliance programs can track.

Here’s what I actually find when I open the hood — and, more importantly, how to fix it.

Finding #1: No Defensible Lawful Basis (Especially for AI)

What I find: Organizations collect personal data across forms, chat, analytics, and enrichment tools without a documented lawful basis for each processing activity. When AI enters the picture, this gets worse — data collected for support or account management quietly gets repurposed to train or run marketing models, with no fresh basis and no assessment. “Legitimate interest” is invoked as a magic phrase, but no Legitimate Interest Assessment (LIA) exists to back it up.

Why it matters: Lawful basis is the foundation of the entire regulation. Without it, every downstream activity is built on sand — and repurposing data for AI without a compatible basis is one of the fastest-growing enforcement themes in Europe.

How to remediate: Build a processing inventory that maps each data type to a specific lawful basis. Where you rely on legitimate interest, write the LIA — a genuine three-part balancing test, not a paragraph. For any AI use, treat it as its own processing activity: document the basis for feeding personal data into the model, and never assume that consent for one purpose covers another.

Finding #2: The Privacy Notice Doesn’t Match Reality

What I find: The privacy policy describes a company that stopped existing years ago. It doesn’t mention the AI tools now processing customer data, doesn’t name key processors, and says nothing about profiling or automated decision-making. It’s transparency theater — technically present, functionally useless.

Why it matters: Transparency is a legal obligation, not a courtesy. If you’re using AI to score, segment, or make decisions about people, they have a right to know — in plain language — what’s happening and what it means for them.

How to remediate: Rewrite the notice to reflect current reality. Disclose AI processing explicitly, describe what the AI does with personal data, name your processor categories, and clearly explain any profiling and its likely consequences. Then put a recurring review on the calendar — a privacy notice is a living document, not a monument.

Finding #3: Data Subject Rights Requests Can’t Reach the AI Layer

What I find: The company can pull a record from the CRM when someone files an access or erasure request — but has no idea how to locate that person’s data inside the AI system, its logs, or its training set. Worse, when someone objects to marketing or profiling, the objection updates a flag in one system while the AI keeps processing them unchanged.

Why it matters: Rights that stop at the CRM aren’t rights. “We can’t delete that from the model” is a finding, not an acceptable answer — and an objection that doesn’t actually stop processing is a live violation every day it persists.

How to remediate: Map where personal data flows across every system, including the AI layer and its logs. Build rights fulfillment that propagates: an objection or erasure request must reach — and take effect in — the AI system, not just the primary database. Where model training makes deletion technically hard, document your handling approach in advance rather than improvising under a 30-day clock.

Finding #4: Vendor Contracts and Transfers Left Unmanaged

What I find: Personal data flows to a stack of third parties — AI vendors, ad platforms, analytics, enrichment services — often without signed Article 28 Data Processing Agreements. The AI vendor’s terms are unread, meaning nobody actually knows whether the vendor is training its own models on the company’s data. And data routinely leaves the EEA (frequently via US-based AI providers) with no valid transfer mechanism and no Transfer Impact Assessment.

Why it matters: You remain accountable for personal data even after it leaves your systems. An unread AI vendor contract that permits training on your data can turn your customers’ information into someone else’s product — and undocumented international transfers are a well-established enforcement target.

How to remediate: Inventory every processor and sub-processor. Get signed DPAs in place, and read the AI vendor’s terms specifically for whether your data trains their models — get that prohibited in writing if it isn’t already. For any transfer outside the EEA, confirm a valid mechanism (SCCs or adequacy) and complete a Transfer Impact Assessment for high-risk vendors.

Finding #5: No DPIA for High-Risk Processing

What I find: The organization is doing exactly the kind of large-scale profiling and automated decision-making that makes a Data Protection Impact Assessment mandatory under Article 35 — and no DPIA exists. There’s also no Record of Processing Activities that includes the AI, so when a regulator asks the company to demonstrate compliance, there’s nothing to hand over.

Why it matters: GDPR runs on accountability. It’s not enough to be compliant; you have to be able to prove it. A missing DPIA on high-risk AI processing is both a violation in itself and a signal to any regulator that the deeper controls probably aren’t there either.

How to remediate: Run the DPIA before scaling the AI initiative, not after. Document the processing, the risks to individuals, and the mitigations — and consult your DPO. Update the Article 30 Record of Processing Activities to include the AI. These artifacts are the evidence that turns “we think we’re compliant” into “here’s the file.”

My Perspective

After enough of these audits, a pattern becomes impossible to ignore: GDPR compliance almost never fails on the technology. It fails on the paper trail and the follow-through. The encryption is usually fine. What’s missing is the documented lawful basis, the honest privacy notice, the rights process that actually reaches every system, and the evidence that ties it all together. GDPR is, at its core, an accountability regime — and accountability is exactly the muscle most organizations skipped building.

AI has raised the stakes considerably. The same discipline GDPR has demanded since 2018 — know your data, justify your processing, honor people’s rights, prove it — is now the same discipline that frameworks like ISO 42001 and the EU AI Act demand for AI systems. That’s not a coincidence; it’s convergence. The companies that treated GDPR as a genuine data-governance practice rather than a cookie banner are the ones now absorbing AI governance almost effortlessly. The ones that faked it in 2018 are discovering there’s nothing underneath to build on.

My advice is simple and unglamorous: stop auditing for the banner and start auditing for the evidence. Can you produce your lawful basis, your DPIA, your vendor DPAs, and your rights-fulfillment records on demand? If yes, you’re most of the way there. If not, that gap won’t announce itself — until the day a request, a breach, or a regulator forces it into the open. Fix it while it’s still your choice.


AI Attack Surface ScoreCard

AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

Your Shadow AI Problem Has a Name-And Now It Has a Score

Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

Schedule a consultation & Feel free to contact DISC InfoSec for a GDPR assessment: info@deurainfosec.com

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Security

DISC InfoSec blog | DISC InfoSec Site

Tags: Audit Findings, gdpr


Jun 24 2026

GDPR Isn’t a Checkbox. It’s the Privacy Standard Your Organization Can’t Afford to Ignore

Category: GDPR,Information Securitydisc7 @ 9:46 am

AI Attack Surface ScoreCard

AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

Your Shadow AI Problem Has a Name-And Now It Has a Score

Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

Schedule a consultation or drop a note below: info@deurainfosec.com

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Security

Tags: gdpr, Privacy Standard


Jul 15 2023

List of mandatory documents required by EU GDPR

Category: Information Securitydisc7 @ 2:28 pm

Article by Dejan Kosutic

The General Data Protection Regulation (GDPR) has already raised many controversies, and one of the biggest ones is certainly which documents are required. For example, often you see companies who think having a privacy policy and a consent form on their website is enough; however, this is only a small part of the documents that are required to be fully compliant with this new privacy regulation.

Therefore, we created a list of GDPR documentation requirements to help you find all mandatory documents at one place . Please note that the names of the documents are not prescribed by the GDPR, so you may use some other titles; you also have a possibility to merge some of these documents.

Mandatory documents and records required by EU GDPR

Here are the documents that you must have if you want to be fully GDPR compliant:

  • Personal Data Protection Policy (Article 24) – this is a top-level document for managing privacy in your company, which defines what you want to achieve and how. See also: Contents of the Data Protection Policy according to GDPR.
  • Privacy Notice (Articles 1213, and 14) – this document (which can also be published on your website) explains in simple words how you will process personal data of your customers, website visitors, and others.
  • Employee Privacy Notice (Articles 1213 and 14) – explains how your company is going to process personal data of your employees (which could include health records, criminal records, etc.).
  • Data Retention Policy (Articles 51317, and 30) – describes the process of deciding how long a particular type of personal data will be kept, and how it will be securely destroyed.
  • Data Retention Schedule (Article 30) – lists all of your personal data and describes how long each type of data will be kept.
  • Data Subject Consent Form (Articles 67, and 9) – this is the most common way to obtain consent from a data subject to process his/her personal data. Learn more here: Is consent needed? Six legal bases to process data according to GDPR.
  • Parental Consent Form (Article 8) – if the data subject is below the age of 16 years, then a parent needs to provide the consent for processing personal data.
  • DPIA Register (Article 35) – this is where you’ll record all the results from your Data Protection Impact Assessment. See this webinar: Seven steps of Data Protection Impact Assessment (DPIA) according to EU GDPR.
  • Supplier Data Processing Agreement (Articles 2832, and 82) – you need this document to regulate data protection with a processor or any other supplier.
  • Data Breach Response and Notification Procedure (Articles 433, and 34) – it describes what to do before, during, and after a data breach. See also: 5 steps to handle a data breach according to GDPR.
  • Data Breach Register (Article 33) – this is where you’ll record all of your data breaches. (Hopefully, it will be very short.)
  • Data Breach Notification Form to the Supervisory Authority (Article 33) – in case you do have a data breach, you’ll need to notify the Supervisory Authority in a formal way.
  • Data Breach Notification Form to Data Subjects (Article 34) – again, in case of a data breach, you’ll have the unpleasant duty to notify data subjects in a formal way.


Sep 22 2022

Second Course Exam for Free – ISO 9001, ISO 14001, ISO 27001 & EU GDPR

Category: Information Security,ISO 27kDISC @ 8:30 am

I just wanted to inform you that, at the end of September, Advisera launched “Second Course Exam for Free” promotional campaign. The campaign will start on September 22, and end on September 29, 2022.

Take the ISO 9001 course exam and get the ISO 14001, ISO 13485, or 45001 course exam for free


In this promotion the second course exam is completely FREE OF CHARGE.

The bundles are displayed on two landing pages, one with bundles related to ISO 9001 and another with bundles related to ISO 27001.

Take the ISO 27001 course exam and get the EU GDPR course exam for free

Foundations course exam bundles:

ISO 9001 Foundations exam + ISO 14001 Foundation exam

ISO 9001 Foundations exam + ISO 27001 Foundation exam

ISO 9001 Foundations exam + ISO 13485 Foundation exam

ISO 9001 Foundations exam + ISO 45001 Foundation exam

ISO 14001 Foundations exam + ISO 45001 Foundation exam

Internal Auditor course exam bundles:

ISO 9001 Internal Auditor exam + ISO 14001 Internal Auditor exam

ISO 9001 Internal Auditor exam + ISO 27001 Internal Auditor exam

ISO 9001 Internal Auditor exam + ISO 13485 Internal Auditor exam

ISO 9001 Internal Auditor exam + ISO 45001 Internal Auditor exam

ISO 14001 Internal Auditor exam + ISO 45001 Internal Auditor exam

Lead Auditor course exam bundles:

ISO 9001 Lead Auditor exam + ISO 14001 Lead Auditor exam

ISO 9001 Lead Auditor exam + ISO 13485 Lead Auditor exam

ISO 9001 Lead Auditor exam + ISO 45001 Lead Auditor exam

ISO 14001 Lead Auditor exam + ISO 45001 Lead Auditor exam

Lead Implementer course exam bundles:

ISO 9001 Lead Implementer exam + ISO 14001 Lead Implementer exam

ISO 9001 Lead Implementer exam + ISO 13485 Lead Implementer exam

ISO 9001 Lead Implementer exam + ISO 45001 Lead Implementer exam

ISO 14001 Lead Implementer exam + ISO 45001 Lead Implementer exam

2/ ISO 27001/EU GDPR-related bundles:

ISO 27001 Foundations exam + EU GDPR Foundations exam

ISO 27001 Foundations exam + ISO 9001 Foundation exam

ISO 27001 Internal Auditor exam + EU GDPR Data Protection Officer exam

ISO 27001 Internal Auditor exam + ISO 9001 Internal Auditor exam

ISO 27001 Lead Auditor exam + ISO 9001 Lead Auditor exam

ISO 27001 Lead Implementer exam + ISO 9001 Lead Implementer exam

Take the ISO 9001 course exam and get the ISO 14001, ISO 13485, or 45001 course exam for free

Take ISO 27001 course exam and get the EU GDPR course exam for Free

Take the ISO 27001 course exam and get the EU GDPR course exam for free

Tags: EU GDPR, ISO 13485, ISO 14001, iso 27001, ISO 45001, iso 9001


Feb 10 2022

French data protection authority says Google Analytics is in violation of GDPR

Category: data security,GDPRDISC @ 10:28 pm
French data protection authority says Google Analytics is in violation of GDPR

French data protection authority says Google Analytics is in violation of GDPR

The French national data protection authority, CNIL, issued a formal notice to managers of an unnamed local website today arguing that its use of Google Analytics is in violation of the European Union’s General Data Protection Regulation, following a similar decision by Austria last month

The root of the issue stems from the website’s use of Google Analytics, which functions as a tool for managers to track content performance and page visits. CNIL said the tool’s use and transfer of personal data to the U.S. fails to abide by landmark European regulations because the U.S. was deemed to not have equivalent privacy protections.

European regulators including CNIL have been investigating such complaints over the last two years, following a decision by the EU’s top court that invalidated the U.S.’s “Privacy Shield” agreement on data transfers. NOYB, the European Center for Digital Rights, reported 101 complaints in 27 member states of the EU and 3 states in the European Economic Area against data controllers who conduct the transatlantic transfers.  

Privacy Shield, which went into effect in August of 2016, was a “self-certification mechanism for companies established in the United States of America,” according to CNIL. 

Originally, the Privacy Shield was considered by the European Commission to be a sufficient safeguard for transferring personal data from European entities to the United States. However, in 2020 the adequacy decision was reversed due to no longer meeting standards. 

An equivalency test was used to compare European and U.S. regulations which immediately established the U.S.’s failure to protect the data of non-U.S. citizens. European citizens would remain unaware that their data is being used and how it is being used, and they cannot be compensated for any misuse of data, CNIL found. 

CNIL concluded that Google Analytics does not provide adequate supervision or regulation, and the risks for French users of the tool are too great.

“Indeed, if Google has adopted additional measures to regulate data transfers within the framework of the Google Analytics functionality, these are not sufficient to exclude the possibility of access by American intelligence services to this data,” CNIL said. 

The unnamed site manager has been given a month to update its operations to be in compliance with GDPR. If the tool cannot meet regulations, CNIL suggests transitioning away from the current state of Google Analytics and replacing it with a different tool that does not transmit the data. 

The privacy watchdog does not call for a ban of Google Analytics, but rather suggests revisions that follow the guidelines. “Concerning the audience measurement and analysis services of a website, the CNIL recommends that these tools be used only to produce anonymous statistical data, thus allowing an exemption from consent if the data controller ensures that there are no illegal transfers,” the watchdog said. 

source: https://

/french-data-protection-authority-says-google-analytics-is-in-violation-of-gdpr/

GDPR Practitioner Guide

Tags: French data protection authority, gdpr, GDPR Practitioner Guide, Google Analytics


May 24 2021

GDPR compliance without the complexity

Category: GDPRDISC @ 12:53 pm
GDPR Toolkit

Most management systems, compliance, and certification projects require documented policies, procedures, and work instructions. GDPR compliance is no exception. Documentation of policies and processes are vital to achieve compliance.

ITG GDPR Documentation Toolkit gives you a complete set of easily customizable GDPR-compliant documentation templates to help you demonstrate your compliance with the GDPR’s requirements quickly, easily, and affordably.


“Having recently kicked off a GDPR project with a large international organisation I was tasked with creating their Privacy Compliance Framework. The GDPR toolkit provided by IT Governance proved to be invaluable providing the project with a well organised framework of template documents covering all elements of the PIMS framework. It covers areas such as Subject Access Request Procedure, Retention of Records Procedure and Data Protection Impact Assessment Procedure helping you to put in practice policies and procedures to enable the effective management of personal information on individuals. For anyone seeking some support with their GDPR plans the toolkit is well work consideration.”

– Chris Prantl

Tags: #GDPR #DataBreachNotification, gdpr compliance, GDPR implementation, GDPR toolkit


Feb 19 2021

66% of Workers Risk Breaching GDPR by Printing Work-Related Docs at Home

Category: GDPRDISC @ 10:27 pm

Two-thirds of remote workers risk potentially breaching GDPR guidelines by printing out work-related documents at home, according to a new study from Go Shred.

The confidential shredding and records management company discovered that 66% of home workers have printed work-related documents since they began working from home, averaging five documents every week. Such documents include meeting notes/agendas (42%), internal documents including procedure manuals (32%), contracts and commercial documents (30%) and receipts/expense forms (27%).

Furthermore, 20% of home workers admitted to printing confidential employee information including payroll, addresses and medical information, with 13% having printed CVs or application forms.

The issue is that, to comply with the GDPR, all companies that store or process personal information about EU citizens within EU states are required to have an effective, documented, auditable process in place for the collection, storage and destruction of personal information.

However, when asked whether they have disposed of any printed documents since working from home, 24% of respondents said they haven’t disposed of them yet as they plan to take them back to the office and a further 24% said they used a home shredding machine but disposed of the documents in their own waste. This method of disposal is not recommended due to personal waste bins not providing enough security for confidential waste and therefore still leaving employers open to a data breach and potential fines, Go Shred pointed out.

Most concerning of all, 8% of those polled said they have no plans to dispose of the work-related documents they have printed at home, with 7% saying they haven’t done so because they do not know how to.

Source: 66% of Workers Risk Breaching GDPR by Printing Work-Related Docs at Home via Infosecurity Magazine

Tags: GDPR by Printing


Aug 22 2019

‘2019 is the year of enforcement’: GDPR fines have begun

Category: GDPRDISC @ 2:57 pm

The Information Commissioner’s Office levied fines against British Airways and Marriott International for violating the GDPR.

Source: ‘2019 is the year of enforcement’: GDPR fines have begun – Digiday

British Airways faces $230 million fine over GDPR breach
httpv://www.youtube.com/watch?v=CUVrcuIvBOY

Marriott Faces GDPR Fines: A DPO and CISO Discussion
httpv://www.youtube.com/watch?v=5KKXLSnW9Zc

Steps to GDPR Compliance




Archived GDPR posts

Subscribe to DISC InfoSec blog by Email





Jul 29 2019

5 ways to avoid a GDPR fine

Category: GDPRDISC @ 10:04 am

After the ICO issues $450 million of GDPR fines in a week, be sure you’re not next.
Source: 5 ways to avoid a GDPR fine

GDPR For Consultants – Training Webinar

 

What You Need to Know about General Data Protection Regulation

DISC InfoSec – Previous articles in GDPR category


Enter your email address:

Delivered by FeedBurner




Tags: #GDPR #DataBreachNotification, gdpr compliance, GDPR Privacy


Jul 26 2019

How to write a GDPR data breach notification procedure – with template example

Category: Data Breach,GDPR,Information PrivacyDISC @ 2:05 pm

Discover how to write a GDPR data breach notification procedure to help you with your GDPR compliance. Including a free template example. Read now

Source: How to write a GDPR data breach notification procedure – with template example – IT Governance Blog

Personal data breach notification procedures under the GDPR

Organizations must create a procedure that applies in the event of a personal data breach under Article 33 – “Notification of a personal data breach to the supervisory authority – and Article 34 of the GDPR – “Communication of a personal data breach to the data subject.

Help with creating a data breach notification template

The picture above is an example of what a data breach notification might look like – available from the market-leading EU GDPR Documentation Toolkit – which sets out the scope of the procedure, responsibilities and the steps that will be taken by the organization to communicate the breach from:

  • Data processor to data controller;
  • Data controller to supervisory authority; and
  • Data controller to data subject.

 

GDPR Implementation Bundle

 


Enter your email address:

Delivered by FeedBurner




Tags: #GDPR #DataBreachNotification


Sep 25 2018

Privacy notice under the GDPR

Category: GDPRDISC @ 8:58 pm

 


A privacy notice is a public statement of how your organisation applies data protection principles to processing data. It should be a clear and concise document that is accessible by individuals.

Articles 12, 13 and 14 of the GDPR outline the requirements on giving privacy information to data subjects. These are more detailed and specific than in the UK Data Protection Act 1998 (DPA).

The GDPR says that the information you provide must be:

  • Concise, transparent, intelligible and easily accessible;
  • Written in clear and plain language, particularly if addressed to a child; and
  • Free of charge.

Help with creating a privacy notice template

The privacy notice should address the following to sufficiently inform the data subject:

  • Who is collecting the data?
  • What data is being collected?
  • What is the legal basis for processing the data?
  • Will the data be shared with any third parties?
  • How will the information be used?
  • How long will the data be stored for?
  • What rights does the data subject have?
  • How can the data subject raise a complaint?

Below is an example of a customisable privacy notice template, available from IT Governance here.

GDPR Privacy Notice Template - Example from the EU GDPR Documentation Toolkit

Example of the privacy notice template available to purchase from IT Governance

If you are looking for a complete set of GDPR templates to help with your compliance project, you may be interested in the market-leading EU GDPR Documentation Toolkit. This toolkit is designed and developed by expert GDPR practitioners, and has been used by thousands of organisations worldwide. It includes:

  • A complete set of easy-to-use and customisable documentation templates, which will save you time and money and ensure GDPR compliance;
  • Helpful dashboards and project tools to ensure complete GDPR coverage;
  • Direction and guidance from expert GDPR practitioners; and
  • Two licences for the GDPR Staff Awareness E-learning Course.





Tags: GDPR Privacy, GDPR Privacy Notice


Feb 21 2018

Six Essential Data Protection and Privacy Requirements Under GDPR

Category: GDPRDISC @ 10:17 am
gdpr
By Leighton Johnson, CISA, CISM, CIFI, CISSP

With the advent of the European Union (EU) deadline for General Data Protection Regulation (GDPR) (EU 2016/679 regulation) coming up on 25 May 2018, many organizations are addressing their data gathering, protection and retention needs concerning the privacy of their data for EU citizens and residents. This regulation has many parts, as ISACA has described in many of its recent publications and events, but all of the efforts revolve around the protection and retention of the EU participants’ personal information. The 6 main areas for data protection defined in this regulation are:

  1. Data security controls need to be, by default, active at all times. Allowing security controls to be optional is not recommended or even suggested. “Always on” is the mantra for protection.
  2. These controls and the protection they provide must be embedded inside all applications. The GDPR view is that privacy is an essential part of functionality, the security of the system and its processing activities.
  3. Along with embedding the data protection controls in applications, the system must maintain data privacy across the entire processing effort for the affected data. This end-to-end need for protection includes collection efforts, retention requirements and even the new “right to be forgotten” requirement, wherein the customer has the right to request removal of their data from an organization’s storage.
  4. Complete data protection and privacy adds full-functional security and business requirements to any processing system in this framework for data privacy. It provides that business requirements and data protection requirements be equally important during the business process.
  5. The primary requirement for protection within the GDPR framework demands the security and privacy controls implemented are proactive rather than reactive. As its principal goal, the system needs to prevent issues, releases and successful attacks. The system is to keep privacy events from occurring in the first place.
  6. With all of these areas needed under GDPR, the most important point for organizations to understand about GDPR is transparency. The EU wants full disclosure of an organization’s efforts, documentation, reviews, assessments and results available for independent third-party review at any point. The goal is to ensure privacy managed by these companies is not dependent upon technology or business practices. It needs to be provable to outside parties and, therefore, acceptable. The EU has purposely placed some strong fine structures and responses into this regulation to ensure compliance.

Having reviewed various organizational efforts in preparation for GDPR implementation, it has been found that it is good practice to look at these 6 areas for all the collected and retained data, not just EU-based data. This zero-tolerance approach to data breaches is purposely designed to be stringent and strong. Good luck to all in meeting and maintaining the data privacy and security requirements of GDPR.

Steps to EU GDPR compliance

 






Nov 08 2017

How ISO 27001 can help to achieve GDPR compliance

Category: GDPR,ISO 27kDISC @ 2:44 pm

gdpr

By Julia Dutton

Organizations have until 25 May 2018 to comply with the EU General Data Protection Regulation (GDPR).

Those who have studied the Regulation will be aware that there are many references to certification schemes, seals and marks. The GDPR encourages the use of certification schemes like ISO 27001 to serve the purpose of demonstrating that the organisation is actively managing its data security in line with international best practice.

Managing people, processes and technology

ISO 27001 is the international best practice standard for information security, and is a certifiable standard that is broad-based and encompasses the three essential aspects of a comprehensive information security regime: people, processes and technology.  By implementing measures to protect information using this three-pronged approach, the company is able to defend itself from not only technology-based risks, but other, more common threats, such as poorly informed staff or ineffective procedures.

By implementing ISO 27001, your organisation will be deploying an ISMS (information security management system): a system that is supported by top leadership, incorporated into your organisation’s culture and strategy, and which is constantly monitored, updated and reviewed.  Using a process of continual improvement, your organisation will be able to ensure that the ISMS adapts to changes – both in the environment and inside the organisation – to continually identify and reduce risks.

What does the GDPR say?

The GDPR states clearly in Article 32 that “the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

  1. the pseudonymisation and encryption of personal data;
  2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  3. the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  4. a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.”

Let’s look at these items separately:

Encryption of data is recommended by ISO 27001 as one of the measures that can and should be taken to reduce the identified risks.  ISO 27001:2013 outlines 114 controls that can be used to reduce information security risks.  Since the controls an organisation implements are based on the outcomes of an ISO 27001-compliant risk assessment, the organisation will be able to identify which assets are at risk and require encryption to adequately protect them.

One of ISO 27001’s core tenets is the importance of ensuring the ongoing confidentiality, integrity and availability of information.  Not only is confidentiality important, but the integrity and availability of such data is critical as well. If the data is available but in a format that is not usable because of a system disruption, then the integrity of that data has been compromised; if the data is protected but inaccessible to those who need to use it as part of their jobs, then the availability of that data has been compromised.

Risk assessment

ISO 27001 mandates that organisations conduct a thorough risk assessment by identifying threats and vulnerabilities that can affect an organisation’s information assets, and to take steps to assure the confidentiality, availability and integrity (CIA) of that data. The GDPR specifically requires a risk assessment to ensure an organisation has identified risks that can impact personal data.

Business continuity

ISO 27001 addresses the importance of business continuity management, whereby it provides a set of controls that will assist the organisation to protect the availability of information in case of an incident and protect critical business processes from the effects of major disasters to ensure their timely resumption.

Testing and assessments

Lastly, organisations that opt for certification to ISO 27001 will have their ISMSs independently assessed and audited by an accredited certification body to ensure that the management system meets the requirements of the Standard. Companies need to regularly review their ISMS and conduct the necessary assessments as prescribed by the Standard in order to ensure it continues protecting the company’s information. Achieving accredited certification to ISO 27001 delivers an independent, expert assessment of whether you have implemented adequate measures to protect your data.

The requirements to achieve compliance with ISO 27001 of course do not stop there.  Being a broad standard, it covers many other elements, including the importance of staff awareness training and leadership support.  ISO 27001 has already been adopted by thousands of organisations globally, and, given the current rate and severity of data breaches, it is also one of the fastest growing management system standards today.

Related articles:

Read more about ISO 27001 and the GDPR >>>>
GDPR Documentation Toolkit and gap assessment tool >>>>
Understanding the GDPR: General Data Protection Regulation >>>>

 






Oct 18 2017

GDPR essentials and how to achieve compliance

Category: data security,GDPRDISC @ 9:51 am

gdpr

The GDPR will replace these with a pan-European regulatory framework effective from 25 May 2018.  The GDPR applies to all EU organizations – whether commercial business or public authority – that collect, store or process the personal data (PII) of EU individuals.

Organizations based outside the EU that monitor or offer goods and services to individuals in the EU will have to observe the new European rules and adhere to the same level of protection of personal data. This potentially includes organizations everywhere in the world, regardless of how difficult it may be to enforce the Regulation. Compliance consultant must know the following 9 tenants of the GDPR.

 

  • Supervisory Authority – A one-stop shop provision means that organizations will only have to deal with a single supervisory authority, not one for each of the EU’s 28 member states, making it simpler and cheaper for companies to do business in the EU.

 

  • Breach Disclosure – Organizations must disclose and document the causes of breaches, effects of breaches, and actions taken to address them.

 

  • Processor must be able to provide “sufficient guarantees to implement appropriate technical and organizational measures” to ensure that processing will comply with the GDPR and that data subjects’ rights are protected. This requirement flows down the supply chain, so a processor cannot subcontract work to a second processor without the controller’s explicit authorization. If requested by subject you must cease processing and using his or her data for some limited period of time.

 

  • Data Consent – The Regulation imposes stricter requirements on obtaining valid consent from individuals to justify the processing of their personal data. Consent must be “freely given, specific, informed and unambiguous indication of the individual’s wishes”. The organization must also keep records so it can demonstrate that consent has been given by the relevant individual. Data can only be used for the purposes that data subject originally explicitly consented. You must obtain and document consent for only one specific purpose at a time.

 

  • Right to be forgotten – Individuals have a right to require the data controller to erase all personal data held about them in certain circumstances, such as where the data is no longer necessary for the purposes for which it was collected. If requested by subject, you must erase their data on premises, in apps and on devices.

 

  • Data portability – Individuals will have the right to transfer personal data from one data controller to another where processing is based on consent or necessity for the performance of a contract, or where processing is carried out by automated means

 

  • Documentation – The Regulation requires quite a bit of documentation. In addition to the explicit and implicit requirements for specific records (especially including proof of consent from data subjects), you should also ensure that you have documented how you comply with the GDPR so that you have some evidence to support your claims if the supervisory authority has any cause to investigate.

 

  • Fines – Major noncompliance of the law will be punishable by fines of up to either 4% or €20 million of group annual worldwide turnover.

 

Data protection by design – Organization must ensure data security and data privacy across cloud and endpoints as well as design their system and processes that protects from unauthorized data access and malware.  Specifically, organizations must take appropriate technical and organizational measures before data processing begin to ensure that it meets the requirements of the Regulation. Data privacy risks must be properly assessed, and controllers may use adherence to approved codes of conduct or management system certifications, such as ISO 27001, to demonstrate their compliance.

 

How to improve information security under the GDPR

Although many businesses understand the importance of implementing the right procedures for detection, report and investigate a data breach, but not many are aware of how to go about this effectively, especially during implementation phase.

 

Seven steps that can help you prevent a data breach:

  1. Find out where your personal information resides and prioritize your data.
  2. Identify all the risks that could cause a breach of your personal data.
  3. Apply the most appropriate measures (controls) to mitigate those risks.
  4. Implement the necessary policies and procedures to support the controls.
  5. Conduct regular tests and audits to make sure the controls are working as intended.
  6. Review, report and update your plans regularly.
  7. Implement comprehensive and robust ISMS.

 

ISO 27001, the international information security standard, can help you achieve all of the above and protect all your other confidential company information, too. To achieve GDPR compliance, feel free to contact us for more detail on implementation.

Related articles on GDPR and ISO 27k

The GDPR and Personal Data…HELP! from Cloud Security Alliance




Tags: gdpr, gdpr compliance


Sep 27 2017

Data flow mapping under the EU GDPR

Category: data security,GDPR,Security ComplianceDISC @ 8:56 am

As part of an EU General Data Protection Regulation (GDPR) compliance project, organisations will need to map their data and information flows in order to assess their privacy risks. This is also an essential first step for completing a data protection impact assessment (DPIA), which is mandatory for certain types of processing.

The key elements of data mapping

To effectively map your data, you need to understand the information flow, describe it and identify its key elements.

1. Understand the information flow

An information flow is a transfer of information from one location to another, for example:

  • From inside to outside the European Union; or
  • From suppliers and sub-suppliers through to customers.

2. Describe the information flow

  • Walk through the information lifecycle to identify unforeseen or unintended uses of data. This also helps to minimise what data is collected.
  • Make sure the people who will be using the information are consulted on the practical implications.
  • Consider the potential future uses of the information collected, even if it is not immediately necessary.

3. Identify its key elements

Data items

  • What kind of data is being processed (name, email, address, etc.) and what category does it fall into (health data, criminal records, location data, etc.)?

Formats

  • In what format do you store data (hardcopy, digital, database, bring your own device, mobile phones, etc.)?

Transfer method

  • How do you collect data (post, telephone, social media) and how do you share it internally (within your organisation) and externally (with third parties)?

Location

  • What locations are involved within the data flow (offices, the Cloud, third parties, etc.)?

Accountability

  • Who is accountable for the personal data? Often this changes as the data moves throughout the organisation.

Access

  • Who has access to the data in question?

 

The key challenges of data mapping

  • Identifying personal data Personal data can reside in a number of locations and be stored in a number of formats, such as paper, electronic and audio. Your first challenge is deciding what information you need to record and in what format.
  • Identifying appropriate technical and organizational safeguards The second challenge is likely to be identifying the appropriate technology – and the policy and procedures for its use – to protect information while also determining who controls access to it.
  • Understanding legal and regulatory obligations Your final challenge is determining what your organisation’s legal and regulatory obligations are. As well as the GDPR, this can include other compliance standards, such as the Payment Card Industry Data Security Standard (PCI DSS) and ISO 27001.Once you’ve completed these three challenges, you’ll be in a position to move forward, gaining the trust and confidence of your key stakeholders.

 

Data flow mapping

To help you gather the above information and consolidate it into one area, Vigilant Software, a subsidiary of IT Governance, has developed a data flow mapping tool with a specific focus on the GDPR.

 

Order Today

 





Tags: data flow mapping, data privacy, data security, gdpr


Aug 11 2017

GDPR Documentation Toolkit and gap assessment tool

Category: GDPR,IT Governance,Security ComplianceDISC @ 10:46 am

Data Protection / EU GDPR Toolkits

 

Use this gap assessment tool to:

  • Quickly identify your GDPR compliance gaps
  • Plan and prioritize your GDPR project

EU GDPR Compliance Gap Assessment Tool

 

Accelerate your GDPR compliance implementation project with the market-leading EU GDPR Documentation Toolkit used by hundreds of organizations worldwide, now with significant improvements and new content for summer 2017:

  • A complete set of easy-to-use and customizable documentation templates, which will save you time and money, and ensure compliance with the GDPR.
  • Easy-to-use dashboards and project tools to ensure complete coverage of the GDPR.
  • Direction and guidance from expert GDPR practitioners.
  • Includes two licenses for the GDPR Staff Awareness E-learning Course.

EU General Data Protection Regulation (GDPR) Documentation Toolkit






Aug 09 2017

EU GDPR: Does my organization need to comply?

Category: GDPR,Security ComplianceDISC @ 9:36 am

By Chloe Biscoe

The General Data Protection Regulation (GDPR) is a new law that will harmonize data protection in the European Union (EU) and will be enforced from May 25, 2018. It aims to protect EU residents from data and privacy breaches, and has been introduced to keep up with the modern digital landscape.

Who needs to comply with the GDPR?

The GDPR will apply to all organizations outside of the EU that process the personal data of EU residents.

Non-compliance can result in hefty fines of up to 4% of annual global turnover or €20 million $23.5 million) – whichever is greater.

Organizations that are compliant with the new Regulation will also find that their processes and contractual relationships are more robust and reliable.

What do US organizations need to do to comply with the GDPR?

The transition period for compliance with the GDPR ends in May 2018. This means that organizations now have less than ten months to make sure they are compliant.

For US organizations, the most significant change concerns the territorial reach of the GDPR.

The GDPR will supersede the current EU Data Protection Directive. Under the current Regulation, organizations without a physical presence or employees in the EU have one main compliance issue to deal with: How to legally transfer data out of the EU. The EU–US Privacy Shield provides such a mechanism for compliance.

Almost all US organizations that collect or process EU residents’ data will need to comply fully with the requirements of the GDPR. US organizations without a physical EU presence must also appoint a GDPR representative based in a Member State.

Save 10% on your essential guide to the GDPR and the EU–US Privacy Shield

EU GDPR & EU-US Privacy Shield – A Pocket GuideAugust’s book of the month is the ideal resource for anyone wanting a clear primer on the principles of data protection and their new obligations under the GDPR and the EU–US Privacy Shield.

Alan Calder’s EU GDPR & EU-US Privacy Shield – A Pocket Guide explains in simple terms:

  • The terms and definitions used within the GDPR and the EU-US Privacy Shield
  • The key requirements
  • How to comply with the Regulation

 

Data Protection / EU GDPR Toolkits

 





Jul 10 2026

Why Supplier Security Is Under the Spotlight — and How to Build a Vendor Management Program for the AI Era

Category: AI,AI Risk,Vendor Assessmentdisc7 @ 7:22 am

Why Supplier Security Is Under the Spotlight — and How to Build a Vendor Management Program for the AI Era

Your security program is only as strong as the weakest vendor with access to your environment. That’s not a slogan anymore — it’s what the breach data says, it’s what regulators are writing into law, and it’s what enterprise buyers are now testing before they sign anything.

The numbers stopped being deniable

For years, third-party risk was something organizations acknowledged in a policy document and revisited once a year with a questionnaire. That era is over, and the data explains why.

SecurityScorecard’s 2025 Global Third-Party Breach Report attributes roughly 35% of all breaches to third parties. Other industry research puts supply chain breach exposure near-universal — the overwhelming majority of organizations experienced some form of supply chain security incident in 2025. Meanwhile, fewer than half of organizations monitor even 50% of their supply chain. And on the regulatory side, an estimated three-quarters of GDPR fines have a third-party component.

Read those together and the picture is simple: attackers have figured out that the vendor is the door, most organizations aren’t watching the door, and regulators are fining the building owner anyway.

Attackers didn’t get smarter about your perimeter. They got smarter about economics. Why spend months trying to breach one hardened enterprise when you can compromise one widely-used tool and inherit access to thousands of downstream environments at once?

The AI supply chain made it worse

The recent Trivy and LiteLLM supply chain attacks are the clearest example of where this is heading. These weren’t obscure utilities — they were trusted security and AI tooling sitting inside CI/CD pipelines. Attackers compromised the tools upstream, and the malicious code did exactly what you’d fear: harvested secrets, cloud credentials, and SSH keys from inside trusted processes, then used that access to move downstream into additional systems. Almost no warning signs, because the attack ran inside software everyone had already decided to trust.

The lesson isn’t “stop using open source” or “stop using AI tooling.” The lesson is that trust without verification is now a documented attack vector, and the AI era multiplies it in three specific ways:

First, AI tools proliferate faster than procurement can see them. Every SaaS product your vendors use is quietly adding AI features. Your data processor is now also an AI deployer, whether their contract with you contemplated that or not. Shadow AI in your supply chain is shadow AI in your risk register — you just haven’t written it down yet.

Second, AI dependencies are deep and opaque. When a vendor says “we use AI,” the real question is: whose model, trained on what, hosted where, with what access to your data, and what happens when the model provider changes terms, deprecates a version, or gets compromised? Fourth-party AI risk is real, and most vendor questionnaires never touch it.

Third, regulation now assigns you obligations for AI you didn’t build. Under the EU AI Act, if your organization uses a high-risk AI system, Article 26 puts deployer obligations directly on you — following instructions for use, ensuring human oversight and staff competence, monitoring operation, retaining logs, and reporting serious incidents. The AI Omnibus agreed in May 2026 pushed the Annex III high-risk deadline to December 2027, which is breathing room, not a reprieve. NIS 2 and DORA are applying the same logic to supply chain security generally: you are accountable for what your vendors do.

What buyers are actually testing in 2026

If you sell into enterprises or regulated industries, you’ve already felt this from the other side. Buyer expectations have shifted from trust to verification, and the deal breakers are consistent: no recent penetration test results, missing security fundamentals, no ISO 27001 or equivalent certification, slow or incomplete responses to security questionnaires, and misalignment with the regulatory frameworks the buyer answers to.

Certifications get you in the door. Evidence wins the deal. The vendors closing enterprise contracts fastest are the ones who lead with proof — current pen test reports, accredited certification rather than “aligned with,” and documentation that’s ready to share the day the security review lands. Supplier security has become a revenue function, not just a risk function. That’s the same lens you should apply when you’re the buyer.

Building a vendor management program for the AI era

A modern program has to handle two things the traditional model didn’t: continuous change and AI-specific risk. Here’s the build sequence I use with clients.

1. Inventory everything — including the AI. You can’t govern what you haven’t cataloged. Build a vendor register that captures not just who the vendor is and what data they touch, but whether they use or embed AI in delivering the service, whose models sit underneath, and what your data’s role is in those systems. ISO 42001 makes this concrete: the AI system register under Clause 4 should include third-party AI, not just what you built in-house. Most organizations I audit miss the SaaS-embedded AI entirely.

2. Tier by real risk, not spend. Classify vendors by data sensitivity, access level, operational criticality, and — new for this era — AI impact. A vendor whose AI feature makes or influences decisions about your customers or employees belongs in a higher tier than their invoice size suggests. This is where ISO 42001’s impact assessment thinking (the AISIA) earns its keep: intended purpose, affected population, severity, reversibility, human oversight. Apply that lens to vendor AI, not just your own.

3. Move due diligence from questionnaire to evidence. Stop accepting “yes” as an answer. For your critical tier, require the same things enterprise buyers now require of you: current certifications (ISO 27001, and increasingly ISO 42001 for AI-heavy vendors), recent independent testing, SOC 2 reports, and for AI vendors specifically — model documentation, data handling terms, and incident notification commitments. Under ISO 27001:2022, controls A.5.19 through A.5.22 cover the supplier relationship lifecycle; under ISO 42001, control A.10.3 requires assessing suppliers of AI systems and services. If your vendor security policy hasn’t been updated to reference AI suppliers, it’s a 2022 policy living in a 2026 threat landscape.

4. Put obligations in the contract, not the questionnaire. Questionnaire answers expire the day they’re submitted. Contracts persist. Bake in security requirements, breach and AI-incident notification timelines, audit rights, subprocessor transparency (this is where fourth-party AI risk gets managed), and for EU-relevant AI, allocation of provider and deployer responsibilities under the AI Act. When the regulator asks who was responsible, “we assumed the vendor handled it” is not an answer.

5. Monitor continuously, not annually. The Trivy and LiteLLM attacks would not have been caught by an annual review cycle. Continuous assurance means external attack surface monitoring on critical vendors, tracking certificate status and expirations, watching for vendor breach disclosures, and — for AI suppliers — monitoring for model changes, terms-of-service changes, and deprecations that alter your risk position. This is exactly the shift regulators are codifying: DORA and NIS 2 both expect ongoing oversight, not point-in-time attestation.

6. Plan for vendor failure, because it will happen. Have an exit and containment plan for your critical vendors before you need one. Know how to revoke access fast, what data comes back and how, and what the operational fallback is. Incident response plans that don’t include supply-chain scenarios are incomplete — and ISO 42001’s incident management controls (A.8.4) expect AI-specific scenarios, including incidents originating in third-party models.

My perspective

After two decades of implementing and auditing security programs — most recently taking an AI-forward SaaS platform through ISO 42001 Stage 2 certification — here’s what I’ve come to believe about vendor management.

Most vendor risk programs are theater. A 300-question spreadsheet, answered optimistically by a vendor’s sales engineer, filed in a folder nobody reopens until renewal. That model was weak before AI; it’s indefensible now. The organizations getting this right have made one mental shift: they treat their vendors as an extension of their own attack surface and their own regulatory perimeter, because functionally, that’s what vendors are. The breach data proves it, and the EU AI Act’s deployer obligations make it legally explicit.

The second shift is recognizing that vendor security has flipped from a cost center to a commercial differentiator — in both directions. Run a rigorous program and you avoid becoming the 35%. Maintain rigorous, shareable evidence of your own posture and you close enterprise deals your competitors stall on. The same investment pays twice.

And the third: don’t wait for the AI-specific regulation to fully land before governing AI in your supply chain. The December 2027 high-risk deadline feels distant. It isn’t — not when your remediation path runs through contract renegotiations, vendor replacements, and evidence collection that takes quarters, not weeks. The organizations that treated GDPR as a 2018 problem in 2017 spent that year in triage. The ones building AI vendor governance now, on an ISO 42001 backbone that already integrates with their ISO 27001 ISMS, will spend 2027 selling trust while everyone else is buying consultants in a panic.

Your supply chain already has AI in it. The only question is whether your vendor management program knows that yet.


DISC InfoSec helps B2B SaaS and financial services firms build ISO 27001 and ISO 42001 programs that stand up to enterprise scrutiny and regulatory audit. If you want a straight answer on where your vendor management program stands, book a call: calendly.com/hd-deurainfosec.

AI Attack Surface ScoreCard

AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

Your Shadow AI Problem Has a Name-And Now It Has a Score

Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

Schedule a consultation: info@deurainfosec.com

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Security

DISC InfoSec blog | DISC InfoSec Site

Tags: Vendor Management


Jul 03 2026

20 State Laws, One Enforcement Standard: Privacy by Design or Pay

Category: Information Privacy,ISO 27kdisc7 @ 10:19 am

Privacy Just Became Infrastructure. Most AI Programs Haven’t Noticed.

By DISC InfoSec

For twenty years, privacy compliance meant disclosure: post a policy, collect consent, answer the occasional access request. That era is over. In 2026, privacy is infrastructure — regulators are testing whether your controls actually work, not whether your privacy notice reads well.

I spend my days implementing management systems for companies where the data can’t leak — financial data rooms, M&A platforms, AI-enabled SaaS. Here’s what the privacy threat landscape actually looks like right now, and what I’d do about it.

In practical terms, it means:

  • Privacy is built into systems by design. Organizations must embed privacy controls into applications, AI systems, cloud platforms, and data architectures from the beginning rather than adding them later.
  • Privacy enables business operations. Just as networking, identity management, and cybersecurity are core infrastructure, privacy has become an essential capability that supports AI, data sharing, digital services, and regulatory compliance.
  • Privacy is a technical and operational discipline. Engineers, architects, security teams, and AI governance professionals are now responsible for implementing privacy-enhancing technologies, data minimization, consent management, encryption, and access controls—not just legal or compliance teams.

For organizations deploying AI, the phrase is especially relevant because regulations and frameworks increasingly require privacy to be integrated into AI governance. This includes conducting privacy impact assessments, limiting unnecessary data collection, protecting personal information, and ensuring transparency and accountability throughout the AI lifecycle.

In short, “Privacy Just Became Infrastructure” means privacy is now a foundational capability that organizations must engineer, manage, and continuously maintain—just like cybersecurity, identity, and cloud infrastructure.

The pressure on industry, in general

The patchwork is now a wall. Twenty US states have comprehensive privacy laws in force. Indiana, Kentucky, and Rhode Island went enforceable this year. California’s updated CCPA regulations now mandate independent cybersecurity audits with certifications filed to the CPPA, and formal risk assessments before any “significant risk” processing begins. Rhode Island carries no cure period — day-one enforcement exposure. If your compliance program was built for one or two state laws, it’s already behind. Compliance is no longer optional or fragmented. The growing number of regulations now creates a comprehensive set of expectations that every organization must address.

Enforcement moved from awareness to action. California imposed its largest CCPA fine to date in 2025, targeting exactly the unglamorous stuff: broken opt-out mechanisms, missing processor contract clauses, notices that don’t match actual processing. California, Colorado, and Connecticut ran a joint sweep on Global Privacy Control compliance. Regulators are no longer reading your policy — they’re testing your website.

The data you forgot about is the data that kills you. The average US breach now costs over $10M. In almost every incident I’ve reviewed, the most damaging records were the ones nobody knew the company still held. No current data inventory means no defensible position — full stop.

Cross-border transfers are a moving target. DOJ’s bulk data transfer rule, Vietnam’s new PDPL, evolving adequacy politics — transfer assessments are now a living exercise, not a one-time SCC signing ceremony.

The pressure in the AI space, specifically

AI didn’t create new privacy principles. It broke every assumption the old controls were built on.

Training data is now a regulated disclosure. California’s AB 2013 requires generative AI developers to publicly summarize the categories and sources of their training data. If you fine-tuned a model on customer data and can’t document what went in, you have a transparency problem with an enforcement hook.

Inference is processing. Every prompt containing customer PII, every RAG pipeline pulling from a CRM, every AI agent reading a mailbox — that’s personal data processing, with all the lawful-basis, minimization, and retention obligations that implies. Most AI inventories I review don’t capture inference-time data flows at all.

Automated decisions are the new high-risk zone. Colorado’s AI Act, Texas TRAIGA, and California’s ADMT regulations converge on the same target: AI making consequential decisions about employment, credit, housing, healthcare. The EU AI Act’s high-risk obligations land in August. If your AI touches a consequential decision and you can’t produce a risk assessment, you’re the test case.

Models remember. Memorization and output leakage mean personal data put into a model can come back out — to a different user, in a different context. “We deleted the source record” doesn’t answer “is it still in the weights?”

Shadow AI is shadow processing. Employees pasting customer data into consumer AI tools is the 2026 version of the rogue file share — except the data leaves your control permanently and may train someone else’s model.

Where ISO 27701:2025 changes the math

Here’s the development most compliance teams haven’t caught up with: ISO 27701 was rebuilt as a standalone standard in October 2025. You no longer need ISO 27001 first — you can implement and certify a Privacy Information Management System (PIMS) on its own, with 78 Annex A controls split across PII controller obligations (A.1), processor obligations (A.2), and shared security controls (A.3). The 2025 edition explicitly added control coverage for cloud, IoT, and AI processing — the standard caught up to the threat landscape.

It also shares the same harmonized structure as ISO 27001:2022 and ISO 42001:2023. That matters practically: if you’re building AI governance and privacy management at the same time — and in 2026, you are — the clause structures interlock. One risk methodology, one internal audit program, one management review. I’ve run that integration play; the overhead savings are real.

One honest caveat, because practitioner credibility requires it: ISO 27701 is not a GDPR safe harbor. Certification doesn’t shield you from enforcement and carries no legal presumption of compliance. What it does provide is the thing regulators actually ask for — demonstrable accountability: a current RoPA, tested data subject rights procedures, documented DPIAs, processor contracts with the right clauses, and evidence behind every control. When the CPPA or a DPA comes asking, “we have a certified, audited PIMS” is a very different conversation than “here’s our privacy policy.”

(Already certified under the 2019 edition? You have until October 2028 to transition. Start scoping now — the control structure changed materially.)

My perspective: the threat is unmanaged processing, not AI

The core privacy threat in 2026 isn’t any single technology. It’s processing that nobody owns, nobody inventoried, and nobody assessed — and AI multiplies the amount of it exponentially. Every remediation path runs through the same discipline:

1. Inventory first. Build a unified data + AI inventory: what personal data you hold, which AI systems touch it, at training and at inference. You cannot protect what you cannot see.

2. Assess before you deploy. DPIAs for every AI system processing personal data, mandatory for anything touching consequential decisions. The EU AI Act, Colorado, and California all converge here — one good assessment process serves all three.

3. Fix the processor chain. Audit your DPAs and sub-processor terms against actual data flows, including AI vendors. Contract gaps are the most-fined, least-fixed problem in privacy.

4. Operationalize rights. Data subject requests must work end-to-end — including data that went into AI systems. Test them like you’d test a DR plan.

5. Put it in a management system. Point-in-time compliance decays. A PIMS under ISO 27701:2025 forces the loop — risk assessment, treatment, internal audit, management review, corrective action — that keeps the program alive between audits.

Privacy by design used to be a slogan. In 2026 it’s the enforcement standard. The organizations that treat privacy as infrastructure will spend less, move faster, and sleep better than the ones still treating it as paperwork.


DISC (CISSP, CISM, ISO 27001 & ISO 42001 Lead Implementer) Consultant at DISC InfoSec, helping B2B SaaS and financial services firms build integrated security, privacy, and AI governance programs — including taking a financial data room platform through ISO 42001 certification. Financial data rooms are the hard mode of compliance; privacy programs built for hard mode work everywhere.

Building or transitioning a PIMS? Start the conversation: info@deurainfosec.com | deurainfosec.com

AI Attack Surface ScoreCard

AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

Your Shadow AI Problem Has a Name-And Now It Has a Score

Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

Schedule a consultation: info@deurainfosec.com

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Security

DISC InfoSec blog | DISC InfoSec Site

Tags: ISO 27701, PIMS


Jun 29 2026

ISO/IEC 27001:2022 — The Compliance Bedrock Every Serious InfoSec Program Is Built On

Category: CISO,Information Security,ISO 27k,vCISOdisc7 @ 8:53 am

ISO/IEC 27001:2022 — The Compliance Bedrock Every Serious InfoSec Program Is Built On

By Disc | Principal Consultant, DISC InfoSec


There’s a question I get from almost every B2B SaaS and financial services client at some point:

“Which compliance framework should we start with?”

My answer is almost always the same: ISO/IEC 27001.

Not because it’s the flashiest. Not because a regulator is threatening a fine. But because it is the only framework that forces you to build a real information security management system — one your entire compliance stack can grow on top of.

Here’s why.


What ISO 27001 Actually Is (And Isn’t)

ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS). It’s published by the International Organization for Standardization and the International Electrotechnical Commission, and it applies to any organization, any size, any sector.

What it is not is a checklist. It is a management system standard — meaning it requires your organization to define its context, assess risk, implement controls, measure performance, and continuously improve. That PDCA (Plan-Do-Check-Act) discipline is exactly what makes it so durable and so transferable.

The 2022 version restructured the Annex A control library from 114 controls across 14 domains down to 93 controls across 4 themes — Organizational, People, Physical, and Technological — and added 11 new controls for cloud security, threat intelligence, data masking, secure coding, and more. Every organization with a 2013 certification was required to transition by October 2025.

If you’re still operating on a 2013-era ISMS, you’re already out of conformance.


The Mandatory Clause Framework: Where the Real Value Lives

ISO 27001’s Clauses 4 through 10 apply to every organization without exception. This is where the management system lives — not in the Annex A controls, but in the operational discipline the clauses require:

  • Clause 4 — Know your context. Who are your stakeholders? What are their expectations? What’s in scope?
  • Clause 5 — Leadership owns security. A signed policy isn’t a checkbox. It’s a commitment from the top.
  • Clause 6 — Plan your risk treatment. A formal risk register, a risk treatment plan, and a Statement of Applicability (SoA) are mandatory outputs.
  • Clause 7 — Support structures. Competence records, awareness training, documented procedures.
  • Clause 8 — Operate your controls. Evidence that risk treatment is actually executing, not just documented.
  • Clause 9 — Measure and audit. KPIs, internal audits, management review — the cadence that prevents ISMS drift.
  • Clause 10 — Improve. Nonconformities get documented. Corrective actions get tracked. The system learns.

This is not bureaucracy for its own sake. This is the operational skeleton that every mature compliance program eventually needs to build — ISO 27001 just requires you to build it on day one.


Why ISO 27001 Is the Foundation Other Frameworks Stand On

Here’s the practitioner reality: most compliance frameworks are control libraries with a certification stamp. ISO 27001 is different — it’s a management system that happens to include a control library.

That distinction matters enormously when you’re trying to layer frameworks.

SOC 2

The AICPA’s Trust Services Criteria map heavily to ISO 27001 Annex A. If you have implemented access control (A.5.15–5.18), incident response (A.5.24–5.28), supplier security (A.5.19–5.22), and availability controls (A.5.29–5.30), you have already addressed the majority of CC6, CC7, A1, and C1 criteria. ISO 27001 gives SOC 2 auditors a documented ISMS they can rely on — which typically compresses audit timelines and reduces evidence burden.

ISO 42001 (AI Management Systems)

ISO/IEC 42001:2023 — the AI governance standard — was explicitly designed to be compatible with ISO 27001. The two standards share the same Annex SL high-level structure, meaning risk assessment methodology, documentation requirements, internal audit cadence, and management review processes are directly reusable. Organizations that have ISO 27001 in place have an immediate head start on 42001 implementation. For AI-powered SaaS companies facing EU AI Act pressure, this integration is not optional — it’s strategic.

EU AI Act

The EU AI Act’s requirements for high-risk AI systems — risk management systems, data governance, technical documentation, human oversight, robustness — all assume a baseline of information security hygiene. ISO 27001 provides that baseline, particularly through its new 2022 controls: A.8.9 (configuration management), A.8.28 (secure coding), A.5.23 (cloud services security), and A.8.12 (data leakage prevention). Regulators and notified bodies will look for this foundation.

NIST CSF 2.0

The NIST Cybersecurity Framework’s six functions — Govern, Identify, Protect, Detect, Respond, Recover — map cleanly to ISO 27001. The Govern function aligns to Clauses 4, 5, and 6. Protect maps to Annex A’s organizational and technological controls. Detect and Respond align to incident management controls A.5.24–5.28. If you’re pursuing FedRAMP or CMMC, your ISO 27001 ISMS is the documentation backbone the NIST SP 800-53 assessor will want to see.

GDPR and Privacy Regulations

ISO 27001 doesn’t cover privacy by itself — that’s ISO 27701 territory. But the ISMS structure, supplier security controls (A.5.19–5.22), and information classification controls (A.5.12–5.13) provide the security safeguards that GDPR Article 32 requires. A GDPR compliance program built on an ISO 27001 ISMS is structurally sounder than one built from scratch.


The Business Case: Why Enterprises and Governments Demand It

ISO 27001 certification signals something that no internal policy document can: an independent third party has verified your security management system meets a globally recognized standard.

For vendor selection in enterprise and financial services, that matters. For cross-border contracts in the EU, UK, APAC, and Middle East, it’s often a baseline requirement. For regulated industries — healthcare, fintech, government supply chains — it can be the difference between getting on the shortlist or getting cut from procurement.

This is why I tell clients: ISO 27001 is not just a compliance achievement. It’s a revenue enabler.


What “Foundation” Actually Means in Practice

When I use the word foundation, I mean something specific: the mandatory documentation that ISO 27001 requires you to produce becomes the evidentiary infrastructure for every other program you layer on top.

Your ISO 27001 ISMS produces:

  • A scoped asset inventory (feeds SOC 2, FedRAMP, CMMC)
  • A formal risk register (feeds ISO 42001, NIST AI RMF, EU AI Act)
  • A Statement of Applicability (feeds gap analysis for any other framework)
  • An internal audit programme (feeds SOC 2 Type 2, FedRAMP ConMon)
  • A supplier security process (feeds GDPR Article 28, SOC 2 CC9)
  • Management review minutes (feeds governance evidence for any board-level framework)

You build it once. Every other framework benefits.


The Practitioner’s Bottom Line

We’ve implemented ISO 27001 for organizations ranging from boutique SaaS companies to financial services platforms handling sensitive deal data. The pattern is consistent: the organizations that invest in a real ISMS — not a documentation exercise, but an operational management system — spend dramatically less time and money on every subsequent compliance program.

ISO/IEC 27001:2022 is not the finish line. It’s the starting block.

If your organization is serious about security — not just compliant on paper, but operationally disciplined — this is where you begin.


DISC InfoSec specializes in ISO 27001 and ISO 42001 implementation, vCISO and vCAIO services, and AI governance for B2B SaaS and financial services organizations. We are a PECB Authorized Training Partner and have led ISO 42001 Stage 2 certification engagements for production AI systems.

Ready to build a compliance program that actually holds up? Let’s talk. info@deurainfosec.com

https://www.deurainfosec.com/iso-27001-consulting/


#ISO27001 #InformationSecurity #ISMS #Compliance #CyberSecurity #GRC #AIGovernance #ISO42001 #vCISO #DISCINFOSEC

AI Attack Surface ScoreCard

AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

Your Shadow AI Problem Has a Name-And Now It Has a Score

Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

Schedule a consultation: info@deurainfosec.com

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Security

DISC InfoSec blog

Tags: isms, iso 27001, security program


Next Page »