24 篇文章 · enterprise
Twenty-three member states have transposed. Several have not, and seven have been referred to the Court of Justice. Multinational entities are compliance-planning against a moving target.
Residency requirements are usually implemented as a storage decision. Regulators increasingly care about a second question that storage location does not answer.
The Department of Defense paused Phase 2 in July and guidance is expected in mid-September. The pause is an opportunity, and the work that pays off either way is evidence work.
This month's releases are about control: getting deleted things back, deciding who can reach what from where, and labelling data so the platform can enforce the difference.
Decreto-Lei 125/2025 gave Portugal its NIS2 framework. The audits now beginning are where it gets tested against real organizations.
Every enterprise fine-tuning a model on internal data is making an implicit claim about that data's integrity. Most haven't checked whether the claim is true.
Saudi Arabia's Personal Data Protection Law reaches beyond its borders. If your organization touches data on Saudi residents, it likely applies to you already.
Between a national data protection transition, a new financial-sector cyber framework, and a post-quantum mandate, the UAE's regulatory picture in 2026.
From November 10, 2026, third-party CMMC certification becomes a precondition for contracts involving controlled unclassified information - including for non-US subcontractors.
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。