Data Has Borders: The New Rules of Compliance - Episode 216

Data Has Borders: The New Rules of Compliance - Episode 216

Data compliance isn't just about protecting information anymore — it's about understanding where your data lives, how it moves, and how to stay compliant across borders. On this Episode of Compliance Unfiltered, The CU guys chat about how with regulations evolving faster than most organizations can keep up, knowing the difference between traditional data security and the new legal landscape is crucial. This episode uncovers why geographic location, data sovereignty, and continuous visibility could make or break your compliance efforts in today's complex data environment.


Episode Transcript:

Adam Goslin:
Especially the stories about compliance hurricanes, generically, of course. We don’t want anybody violating any NDAs or anything along those lines.

But if you can generisize it and share your pain, there may very well be things that people are experiencing that others are as well. So both the pain and any insights, oh my God, yeah, that’d be great.

Todd Coshow:
Absolutely. Reach out at complianceunfiltered@totalcompliancetracking.com.

Well, Adam, today we’re going to talk about data. That’s right, the rules have changed. And I think it’s important that we have a chat about it.

Does your company actually know where all of its data lives right now? Tell us more about this.

Adam Goslin:
There’s a lot of organizations that don’t really. They got a general idea, etc., but they couldn’t put their finger on, “This data’s here and that data’s there, and these are the processes.” It’s extremely complicated.

There’s a lot of organizations that, quite frankly, haven’t put all of those pieces together. It’s certainly an onerous task for any organization.

Todd Coshow:
There’s definitely a shift in data regulations. Fundamentally, what is changing in data compliance right now?

Adam Goslin:
It’s not just about securing. A lot of people historically would think about protecting their environment and making sure they’re in compliance with fill in the blank, and just about protecting whatever it is that they’re responsible for protecting. That’s morphing.

It’s turning more toward where is the data, how is it being used, who accesses it, for what purpose are they leveraging it, etc. There are a lot of rules, regulations, really legal agreements between organizations that govern the data access and usage. So it becomes very important to organizations to be able to have their finger on that pulse, if you will.

Todd Coshow:
Why is geography suddenly so important?

Adam Goslin:
Data is subject to the laws of the country or regions where it resides. There’s different rules and penalties. You’ve got agreements that you’ve made with different organizations. So there’s a myriad of layers that play in, but certainly where it’s at plays into it as well.

Some organizations care about where their data resides, aka what country. Some don’t. So it gets extremely complicated very quickly, if you will.

Todd Coshow:
That makes sense. What is driving this?

Adam Goslin:
Globally, privacy laws have been popping up. We’ve been seeing it just in the US. In the US, we’ve got certain states that decide to put out certain edicts around privacy laws. California, namely, was the lead in terms of privacy law within the US. But the minute that they did it, now you’ve got different data and privacy laws picking up from different states within just the United States, let alone when you take it up to a federal level within the US.

There’s other rules. Once you get international, countries have their own. So it’s a landscape that’s getting really complicated. It’s starting to remind me a lot of some of the complications that organizations would have with breach notifications. There were organizations that specialized in breach notification because of all of these layers of complexity.

You bring it from the US stage to the international stage.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Sep 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Sep 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Aug 25min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Aug 33min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Aug 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Aug 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Juli 21min

Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right p...

23 Juli 36min

Populärt inom Teknik

uppgang-och-fall
market-makers
elbilsveckan
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
rss-en-ai-till-kaffet
rss-veckans-ai
skogsforum-podcast
natets-morka-sida
rss-technokratin
rss-ai-med-jonas-benjamin
bli-saker-podden
gubbar-som-tjotar-om-bilar
rss-sakerhetspodcasten
hej-bruksbil
rss-uppgang-och-fall
rss-it-sakerhetspodden
developers-mer-an-bara-kod
rss-nytankarna
rss-digitala-influencer-podden