Articles tagged: Privacy
27 articles on Privacy from the Top Floor insights library.
2026-08-25
How Long Does GDPR Readiness Take? The Clocks That Actually Set the Date
GDPR has no certificate and no finish line, so the honest question is how long it takes to build a defined readiness file. No primary source publishes a project duration. What the Regulation does publish is a set of clocks, and those, plus the count of systems you hold, are what set the calendar.
2026-08-25
What Is a RoPA, and Does a Small Company Have to Keep One?
A record of processing activities is the Article 30 register a supervisory authority can demand on request. The under-250 derogation is narrower than most content implies: any one of three conditions removes it, and a small company that pays staff has already met one of them.
2026-08-25
What Is a Lawful Basis Under GDPR, and Why Can You Not Change It Later?
Every processing purpose needs one of the six Article 6 grounds before collection starts, and the EDPB's rule is that the choice cannot be swapped afterwards. Which basis fits which purpose, the three-step test behind legitimate interests, and the mistake of treating consent as the safe default.
2026-08-25
What Is ePHI, Exactly? The Scoping Test Behind the Definition
The regulation defines ePHI in one sentence that points at two other definitions, and the scoping decision hides in the pointer. Three nested tests decide whether a record is protected health information; one more decides whether the Security Rule reaches it.
2026-08-23
Colorado's New AI Law: What SB 26-189 Requires
Colorado repealed its 2024 AI Act roughly seven weeks before its obligations were due to take effect and replaced it with a narrower disclosure regime. The impact assessments and duty of care are gone; notice, explanation and human review are in, from January 1, 2027.
2026-08-23
What Is a DPIA, and When Does GDPR Require One?
The trigger is a property of the processing, not of your size. A twelve-person company doing large-scale profiling owes a DPIA; a thousand-person company running payroll does not.
2026-08-23
What Is a Data Processing Agreement, and When Do You Actually Need One?
A DPA is the contract GDPR Article 28(3) requires between a controller and a processor, covering eight mandatory subjects. The EDPB's position is that an agreement which merely restates the Regulation is not doing the job.
2026-08-23
India DPDP: What Is in Force Now, and What Lands in 2027
Eighteen months. That is the gap the Indian government wrote into G.S.R. 843(E) between establishing the Data Protection Board and switching on a single obligation that binds your company. As of August 2026 none of them are on, and the ones everybody is preparing for arrive together on 13 May 2027.
2026-08-23
Does GDPR Compliance Cover CCPA?
The crosswalk says 85 percent of what GDPR reaches is already inside the California footprint, and only 23 percent the other way. Both numbers are misleading in a specific, checkable way. What the mapping can and cannot see about a rights statute.
2026-08-23
Does GDPR Apply to My US Company?
GDPR reaches a US company with no EU office at exactly two triggers, and there is no revenue floor or headcount threshold under either. The targeting test, the fact patterns that put you outside the Regulation, and what changes the day you decide you are inside it.
2026-08-23
How Long Do You Have to Respond to a DSAR? Every Deadline
One month under GDPR, 45 calendar days under CCPA and the state laws that copied it, 10 business days just to acknowledge in California, and 15 business days to stop selling. The clocks, the trigger events, and the intake failure that blows all of them at once.
2026-08-23
Do You Have to Honor Global Privacy Control?
Yes, and since January 1, 2026 California also requires you to display that you processed the signal. What the regulations actually say, what the three-state enforcement sweep asked for, and why a Do Not Sell link never was an alternative.
2026-08-23
Do US Websites Need a Cookie Banner?
Mostly no, and the ones running EU-style opt-in banners are usually failing the obligation they actually have. What US state law requires instead, the two carve-outs that do demand consent, and when the ePrivacy rules reach you.
2026-08-23
Does India's DPDP Act Apply to Your Company?
It applies to any company anywhere that processes digital personal data in connection with offering goods or services to people in India, and the notified Rules set two hard dates. What the gazette actually says, what the breach rule demands, and what the penalty schedule really caps at.
2026-08-23
The CCPA Cybersecurity Audit: Does It Apply to You, and When?
California's cybersecurity audit rule took effect on January 1, 2026, with the first audit reports due April 1, 2028, 2029 or 2030 depending on revenue. Being a CCPA business is not enough to be caught by it, and the auditor independence rule disqualifies whoever built your program.
2026-08-23
42 CFR Part 2 vs HIPAA: What the Alignment Rule Changed
Substance use disorder records carry a second federal confidentiality rule on top of HIPAA, and the compliance date for its overhaul passed on February 16, 2026. What actually changed, what deliberately did not, and how to tell whether it applies to you.
2026-08-23
De-Identifying PHI: Safe Harbor vs Expert Determination
HIPAA recognizes exactly two ways to de-identify protected health information. Stripping the names is neither of them. What each method costs you, why the cheap one is usually the wrong one for analytics, and what de-identification does not buy.
2026-08-23
Does HIPAA Apply to My Health App?
For most direct-to-consumer health apps the answer is no, and founders treat that as good news. It usually is not: falling outside HIPAA drops you into the FTC's Health Breach Notification Rule, which has no risk-assessment off-ramp.
2026-08-22
How Much Does an Outsourced DPO Cost?
Published benchmarks put outsourced DPO services at EUR 1,150 to EUR 2,900 a month against EUR 80,000 to EUR 150,000 a year in salary for an in-house appointment. We work through the sourced numbers, the scope drivers, and the threshold question most buyers skip: whether you owe a DPO at all.
2026-08-22
California's ADMT Rules: Does Your AI Make a Significant Decision?
The trigger is not that you use AI. It is that a technology substantially replaces human decisionmaking about one of five listed outcomes, and compliance is required by January 1, 2027. The two-part test, the pre-use notice, and why most AI systems are out of scope.
2026-08-21
EU Representative vs DPO: Which Does a US Company Need?
Two different GDPR appointments, two different triggers, and roughly two orders of magnitude between their published prices. Which one a US company owes, why the same firm cannot be both, and the case where you owe neither.
2026-08-20
How Much Does GDPR Compliance Cost a US Company?
The most-quoted GDPR cost figure is USD 1.7 million a year for a small business, and it is from 2018. We price the line items you can actually buy at published rates, work the arithmetic, and land somewhere very different.
2026-08-19
Data Privacy Framework vs SCCs: Which Transfer Mechanism Do You Need?
DPF self-certification costs $260 a year at the smallest revenue tier and removes the SCC paperwork for covered transfers. Then the Supreme Court decided FTC commissioners can be fired at will, and the durability question got sharper.
2026-08-18
Privacy Compliance Software vs a Consultant: What Do You Need?
Consent tooling now publishes self-service tiers from EUR 7 a month, and it is genuinely good at what it does. It cannot decide which laws reach you, what your lawful bases are, or what goes in your Article 30 records. Buy the cheap tool, then buy hours.
2026-08-16
Is Zoom HIPAA Compliant? Telehealth Rules Since the Waiver Ended
Only on plans where the vendor signs a BAA. The COVID-era enforcement discretion expired on May 11, 2023 and the 90-day transition period closed at 11:59 pm on August 9, 2023, both stated in the HHS notice at 88 FR 22380.
2026-08-02
Breach Notification Deadlines: Every Clock You Are On
A breach puts you on multiple notification clocks at once, and they start on different trigger events: discovery, awareness, materiality determination. Here is the full crosswalk (SEC, HIPAA, GDPR, all 50 states, CIRCIA) and how to build your response to the shortest binding clock.
2026-02-28
State Privacy Laws: A Guide to the Patchwork
Navigate the growing maze of US state privacy laws. Compare CCPA/CPRA, Virginia, Colorado, Connecticut, Texas, and more, with a practical multi-state compliance strategy.