FERPA FAQ – What You Need to Know About FERPA Compliance

by Sarah Harvey / December 16, 2022

Does your organization process, store, transmit, or use educational records? Are you responsible for ensuring that the information of students remains secure? FERPA is one of the most significant federal regulations in the education sector, aimed at protecting the privacy of students and their parents. Undergoing a FERPA audit is one way that educational institutions can identify and mitigate any vulnerabilities in their security infrastructure and are doing what is needed…

Investing Where It Matters: Unbounce’s Commitment to GDPR Compliance

by Sarah Harvey / December 16, 2022

There’s no doubt that the GDPR is reshaping the marketing industry, and yet many marketers remain unsure about what the law actually requires. The regulation is long, confusing, and in many areas, vague. Plus, there’s immediate tension between GDPR requirements and marketing principles. A marketer’s goal is to gain identification information, while GDPR’s goal is to limit identification information to what's strictly necessary. Let’s take a look at how Unbounce,…

SOC 2 Academy: Integration with the COSO Framework

by Joseph Kirkpatrick / December 16, 2022

The Five Components of Internal Control: CRIME The COSO Internal Control — Integrated Framework is one of the most common models used to design, implement, maintain, and evaluate internal controls and is split into five components: control environment, risk assessment, information and communication, monitoring activities, and existing control activities. A common way to remember these five components that are used to evaluate the effectiveness of internal controls is the acronym…

California Consumer Privacy Act vs. GDPR: What Your Business Needs to Know

by Sarah Harvey / December 22, 2022

Data Privacy and Security in the US According to Pew Research Center, 64% of American adults have experienced data theft. Yahoo, eBay, Equifax, Target, Anthem, Home Depot – it has become habitual to worry about data breaches, identity theft, and other privacy concerns. With every new headline of a data breach, it seems like consumers are losing more control over what personal information is publicly available. At the same time,…

GDPR Readiness: Challenges for Organizations Outside of the EU

by Sarah Harvey / February 20, 2023

Although the EU’s General Data Protection Regulation (GDPR) enforcement deadline has passed, many non-EU organizations are still questioning what they need to do to ensure compliance. Do they need a designated representative? Where does their designated representative need to be located? Is a designated representative the same thing as a Data Protection Officer? Who do they need to notify that they have a designated representative? How do they do this?…