Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination.
Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using
Conducts Privacy Impact Assessment for large-scale systematic monitoring under GDPR Article 35(3)(c).
Guides compliance with Canada''s Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5).
Guides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification…
Classifies data as pseudonymised or anonymised using Recital 26 reasonably likely test, Breyer ruling C-582/14, motivated intruder test, and WP29 Opinion 05/2014 on anonymisation…
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020.
Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, backup cycle alignment with…
Guides privacy law change monitoring and impact assessment for multi-jurisdiction organisations. Covers regulatory tracking sources, change classification, impact scoring…
Conducts comprehensive inventory of protected health information across the enterprise per HIPAA Security Rule requirements at 45 CFR §164.308(a)(1)(ii)(A) and §164.310(d).
Texas Data Privacy and Security Act (TDPSA) compliance. No revenue threshold applies to all businesses.
Add a large source-backed cybersecurity skills library to Claude Code, Codex CLI, Cursor, Gemini CLI, and other agents so security investigations follow structured analyst…
Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder,
Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex
Implements GDPR Art. 22 automated decision-making and AI Act Art. 14 human oversight requirements for AI systems.
Implements compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDP Law) and its Executive Regulations.
Guides the establishment and management of joint controller arrangements under GDPR Article 26, including determination of joint controllership, allocation of responsibilities,…
Implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange
Guides the GDPR Article 56 one-stop-shop mechanism for determining lead supervisory authority in cross-border processing. Covers main establishment identification and cooperation.
Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e). Covers required BAA provisions, business associate vs subcontractor obligations, breach…
Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving consent, one-click withdrawal…
Colorado Privacy Act (CPA) compliance implementation. Covers universal opt-out mechanism required since July 2024, profiling opt-out rights, sensitive data consent requirements,…
Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses.
Builds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, third-party identification, and…
Integrating Global Privacy Control (GPC) signals with cookie consent platforms. Covers GPC signal detection in browsers, automatic opt-out triggering, mapping GPC to US state…
Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized
On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and…
Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices,
Handles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentation requirements, and the…
Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information.
Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation.
Guides implementation of GDPR Article 42-43 data protection certification mechanisms including accredited certification bodies, criteria development, and periodic review.
Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities
Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards.
Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for…
Pre-deployment privacy compliance checklist for AI/ML systems covering DPIA completion, lawful basis verification, transparency notices, human oversight mechanisms, bias testing,…
New Jersey Data Privacy Act (NJDPA) compliance, effective January 15, 2025. Covers consumer rights (access, correction, deletion, portability, opt-out), controller obligations,…
Decision framework for choosing between consent and legitimate interest as the lawful basis for processing.
SecLists path map, hashcat rules, CeWL usage, and custom wordlist generation for all attack categories
Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation.
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Vendor certification acceptance criteria and equivalence mapping. Covers ISO 27701, SOC 2 Privacy, APEC CBPR, EU Code of Conduct evaluation, certification scope analysis, gap…
Guides compliance with South Korea''s Personal Information Protection Act (PIPA, 개인정보 보호법). Covers pseudonymisation framework, notification requirements, PIPC enforcement, consent…
Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access
Implementation guide for CNIL cookie guidelines compliance. References the EUR 150M Google fine and EUR 60M Meta fine.
Implements HIPAA Privacy Rule requirements under 45 CFR §164.500-534 for covered entities and business associates.
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation,…
Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition
Implements Children''s Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card…
Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases.
Kentucky Consumer Privacy Protection Act (KPPA) compliance. Effective January 1, 2026. Covers consumer rights, controller thresholds at 100,000 consumers, sensitive data…
Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1,
Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google
Implements profiling restrictions for children under GDPR Recital 71, Article 22, UK AADC Standard 12, and COPPA.
Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12).
Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features
Implements HIPAA minimum necessary standard under 45 CFR §164.502(b). Covers role-based access policies per workforce member category, routine vs non-routine disclosure protocols,…
Implements the GDPR Article 17 right to erasure (right to be forgotten) workflow, covering all six grounds for erasure, five exceptions, technical deletion versus anonymization…
Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, data flow analysis, and…
Guide for managing consent for scientific research under GDPR Article 89 and Recital 33 broad consent provisions.