New Jersey Data Privacy Act (NJDPA) compliance, effective January 15, 2025. Covers consumer rights (access, correction, deletion, portability, opt-out), controller obligations,…
Guide for obtaining explicit consent for international data transfers under GDPR Article 49(1)(a). Covers informed consent requirements including risks of transfers without…
Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder,
Conducts Privacy Impact Assessment for large-scale systematic monitoring under GDPR Article 35(3)(c).
Classifies data as pseudonymised or anonymised using Recital 26 reasonably likely test, Breyer ruling C-582/14, motivated intruder test, and WP29 Opinion 05/2014 on anonymisation…
Implements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication
Guides compliance with Singapore''s Personal Data Protection Act 2012 (PDPA). Covers PDPC advisory guidelines, Do Not Call Registry, data intermediary obligations, deemed consent,…
Guide for building a consent record-keeping system to demonstrate valid consent per GDPR Article 7(1).
Assessing privacy risks in large language model outputs including training data memorisation, PII leakage in generated text, prompt injection leading to data extraction, and…
Implements input and output validation guardrails for LLM-powered applications to prevent prompt injection,
Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, shared responsibility model…
Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breach incidents.
Integrates Records of Processing Activities with privacy management platforms including OneTrust, TrustArc, Collibra, and DataGrail.
Implements HIPAA Privacy Rule requirements under 45 CFR §164.500-534 for covered entities and business associates.
Compares PIA/DPIA methodologies: CNIL PIA tool, ICO DPIA template, NIST Privacy Framework, and ISO 29134.
Methodology for auditing A/B testing of consent banners to ensure compliance with equal ease of acceptance and rejection.
Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized
Guides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules,…
Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features
Implements GDPR Art. 22 automated decision-making and AI Act Art. 14 human oversight requirements for AI systems.
Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required.
Implements financial records retention requirements across EU directives (5-7 years), SOX Section 802 (7 years), MiFID II (5-7 years), tax records, payment data, and AML…
Manages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination,…
Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving consent, one-click withdrawal…
Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12).
Governs biometric data processing for employee timekeeping and access control under Art. 9 GDPR special category rules.
Guides privacy audit report writing including executive summary drafting, findings classification (critical, high, medium, low), evidence referencing, root cause analysis…
Conducts Privacy Impact Assessment for health data processing under GDPR Article 9, HIPAA, and sector-specific health privacy regulations.
California consumer privacy rights workflow implementation under CCPA/CPRA. Covers right to know, delete, opt-out of sale/sharing, correct, and limit sensitive PI processing.
Harmonises data classification across jurisdictions mapping GDPR special categories vs CCPA sensitive PI (1798.140(ae)) vs HIPAA PHI (160.103) vs LGPD sensitive data (Art. 5-II).
Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art. 30 and Art.
Addresses HIPAA compliance for mobile health (mHealth) applications, wearable devices, and remote patient monitoring.
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology.
Montana Consumer Data Privacy Act (MTDPA) compliance. Lowest consumer threshold at 50,000 consumers. Covers sensitive data consent, universal opt-out recognition, consumer rights,…
Designs and implements privacy notices for children that comply with GDPR Articles 12-14, UK AADC Standard 4, and COPPA Section 312.4.
Builds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, third-party identification, and…
Guides building a multi-jurisdiction privacy compliance matrix for organisations operating across multiple countries.
Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex
Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access
Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination.
Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities
US state privacy law applicability assessment tool. Evaluates revenue thresholds, data volume thresholds, business exemptions (GLBA, HIPAA, nonprofits), employee data carve-outs,…
Provides GDPR Article 14 information for personal data obtained from sources other than the data subject, covering timing requirements (within reasonable period, max one month),…
Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent.
Guides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification…
Pre-deployment privacy compliance checklist for AI/ML systems covering DPIA completion, lawful basis verification, transparency notices, human oversight mechanisms, bias testing,…
Assessment of pseudonymization techniques and re-identification risk. Covers tokenization, hashing, encryption-based pseudonymization, and hybrid approaches.
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation,…
Guides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake…
Guide for managing consent for scientific research under GDPR Article 89 and Recital 33 broad consent provisions.
Guides compliance with South Korea''s Personal Information Protection Act (PIPA, 개인정보 보호법). Covers pseudonymisation framework, notification requirements, PIPC enforcement, consent…
Implements HIPAA minimum necessary standard under 45 CFR §164.502(b). Covers role-based access policies per workforce member category, routine vs non-routine disclosure protocols,…
Guides assessment and application of GDPR Article 49 derogation conditions for international data transfers in the absence of adequacy decisions or appropriate safeguards.
Conducts retention impact assessments for new processing activities to determine appropriate data retention periods.
Implements age-gating mechanisms for online services to restrict access based on user age. Covers hard gates versus soft gates, neutral age prompts, re-verification triggers,…
Handles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentation requirements, and the…
Creates GDPR Article 30(2) Records of Processing Activities for data processors with all four mandatory fields: processor and controller names and contact details, categories of…
Addresses HIPAA privacy and security requirements for health data interoperability under the 21st Century Cures Act, ONC Health IT Certification Program, and CMS Interoperability…
Add a large source-backed cybersecurity skills library to Claude Code, Codex CLI, Cursor, Gemini CLI, and other agents so security investigations follow structured analyst…
Assesses AI bias risks for GDPR Art. 9 special category data and AI Act Art. 10 data governance. Covers fairness metrics, bias detection methods, mitigation strategies, and…