Posts

Draft Personal Data Protection Bill, 2019

Image
Introduction  The Personal Data Protection Bill, 2019 [PDP Bill, 2019 or PDPDB 2019] was introduced in 2019 with the aim of providing a clearer and robust framework for the protection and processing of data and data-related rights for the Indian citizens. Since, the usage and attendance for internet and internet-related services were showing unprecedented rise, the need for protecting the privacy rights of individuals in addition to the use of data by the entities was said to be the focal point of address.   Although, the Bill never saw the light of the day, notable developments accompanied the Bill before heading for further scrutiny at the hands of the Joint Parliamentary Committee who, after great deliberation and considerations, published a report based on the comments and recommendations made by the stakeholders.   In this write-up, the PDP Bill, 2019 shall be discussed in detail, focusing on its history, key provisions which came along with it as well as t...

How to Write an Effective Whitepaper: Tips and Best Practices

Bahrain Personal Data Protection Law The protection of confidential data is becoming more and more crucial in the current digital era. More personal information than ever before is being gathered and processed thanks to the growth of online networks and the internet of things. Governments all over the world are passing laws and regulations to safeguard the security and privacy of personal data as a consequence. Click Here:  Bahrain Personal Data Protection Law Draft American Data Privacy and Protection Act The American Data Privacy and Protection Act (ADPPA), which is a proposed new federal law, has as its primary objective the protection of the personal information of citizens of the United States. As personal information has become a more valuable commodity as a result of the increased pervasiveness of technology and the internet, businesses routinely collect and use this data for a variety of purposes, including targeted advertising and data analysis. Yet, because of this, many ...

Cyber Security Maturity Assessment — Cyber Security Certification Training — Tsaaro

Image
  In this digital world, data plays an integral part in business. Organizations use the customers’ data to get valuable insights for growth as well as to provide personalized services. Data is an asset of a company, and most of the time organizations are becoming prey to cyber breach incidents. So, it is significant for an organization to implement cybersecurity measures to safeguard from cyber threats. CYBER SECURITY MATURITY ASSESSMENT The  Cyber Security Maturity Assessment (CSMA)  is a gap analysis and risk assessment that employs cyber security best practices as well as recognized cyber frameworks to answer questions about your current security program, like your biggest risks, the potency of your cybersecurity strategy, etc. Amidst the growing reliance on technology, these assessments are essential for an organization of any size but particularly the big ones. The  cybersecurity maturity assessment  measures your organization’s strategic position in the fa...

Privacy Program Development — Data Protection and Privacy — Tsaaro

Image
How to Develop a Privacy Program for your Organization Privacy program development  is the process of creating and implementing a comprehensive program within an organization to ensure the protection of personal information and compliance with applicable privacy laws and regulations. The goal of privacy program development is to identify potential privacy risks and vulnerabilities within an organization’s operations, processes, and technologies and to establish policies, procedures, and technical controls to mitigate these risks and protect personal information. What is a Privacy Program A privacy program is a set of policies, procedures, and technical controls that an organization puts in place to protect the privacy of personal information it collects, processes, and stores. The purpose of a privacy program is to ensure compliance with applicable privacy laws and regulations, and to mitigate the risk of data breaches or unauthorized disclosure of personal information. The impleme...

Discover the WhitePapers

Image
  Understanding the EU NIS 2 Directive As defined by the EU Council, the NIS 2 directive “will set the baseline for cybersecurity risk management measures and reporting obligations across all sectors that are covered by the directive”. This whitepaper focuses on summarising the NIS 2 Directive with specific focus on the requirement to appoint an EU representative. This paper also seeks to educate and inform the audiences about the applicability of the new directive and help them identify the striking differences between the NIS 1 and NIS 2 Directives. Click Here:  Understanding the EU NIS 2 Directive KSA’s Data Management and Personal Data Protection Standards The National Data Management and Personal Data Protection Standards were created in accordance with a directive from the Saudi Authority for Data and Artificial Intelligence, under Cabinet Resolution number (292), dated 27/04/1441H. This directive instructed the National Data Management Office to develop and implement po...

Third-Party Risk Management (TPRM) — Risk Management Course — Tsaaro

Image
  What is Third-Party Risk Assessment? Third-party risk assessment  is a process that identifies and assesses the risks of third parties to your organization. This can include suppliers, contractors and other service providers who have access to your data or systems. Third-party risk management program (TPRM) is an approach to managing third-party relationships by assessing their internal controls and processes so that you can mitigate any potential threats they may pose for your business. Third-party risk assessment is a valuable tool for organizations looking to improve their security posture. It can be used to assess the level of risk associated with third parties and determine how best to manage that risk, as well as identify areas where improvements can be made. Third party assessments are conducted by an independent party who has experience in performing these types of evaluations. They are often referred to as third party security assessments or cyber risk assessments, ...

KSA’s Personal Data Protection Law — Saudi PDPL — Tsaaro

  Introduction Privacy and data protection  is becoming one of the most critical issues of an era that is characterized by the technological revolution and a paradigm shift in our interaction with each other and the digital world in general. Data protection is an essential element in protecting the rights of individuals, which is intrinsically tied to the Human Rights of Individuals. Privacy and data protection are not just the responsibility of a nation state, but the onus to have a robust privacy structure is the responsibility of organizations too. Several national laws to safeguard citizens’ privacy ights and the practical application of data protection rules in day-to-day businesses have been modelled after the European regime of data protection and privacy regulations. So, it is crucial to consider the Kingdom of Saudi Arabia’s new rules in light of the General Data Protection Regulation (GDPR). The cornerstone for the law’s effective implementation and operation in Saud...