A Compliance Roadmap for ADS/ADMT - Part 3: Data Retention and Training
Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance & risk management expert with an extensive background in HR, will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.
In this third episode, Tom Fox and Alyssa DeSimone discuss recent updates on data retention policies, training, and the implications of the California Consumer Privacy Act. They explore the necessity of retaining records for four years, methods for creating effective privacy policies, and the importance of training employees. They also highlight the role of HR in compliance training and emphasize adaptable training methods to engage different learning preferences. The episode concludes with information on how listeners can connect with Alyssa for further insights and consulting.
Key highlights:
Data Retention Policies
Policy Drafting and Implementation
Encouraging Employee Engagement
Training Strategies and Approaches
Compliance and HR Collaboration
Connect with Tom Fox
LinkedIn
Connect with Alyssa DeSimone
LinkedIn
Website
Life with GDPR was recently honored as a Top Data Security Podcast.
Learn more about your ad choices. Visit megaphone.fm/adchoices
--------
16:56
--------
16:56
A Compliance Roadmap for ADS/ADMT - Part 2: Understanding Opt-In and Opt-Out Requirements
Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance & risk management expert, with an extensive background in HR, will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.
In this second episode, Tom Fox and Alyssa DeSimone review the opt-in and opt-out requirements introduced in the recent updates to the California Consumer Privacy Act (CCPA). They discuss what opting in and out entails, the concept of anti-retaliation in this context, and how disparate impact analysis can help regulators assess compliance. Additionally, they explore the importance of clear communication and training for HR departments on the use of AI in hiring, as well as the role of vendors in ensuring compliance. The episode wraps up with a discussion on the ambiguous term 'significant decision making' and its potential for litigation.
Key highlights:
Understanding Opt-In and Opt-Out Requirements
Anti-Retaliation Measures
Disparate Impact Analysis
Applicant Rights and Training
Vendor Collaboration and Compliance
Significant Decision Making
Resources:
Connect with Tom Fox
LinkedIn
Connect with Alyssa DeSimone
LinkedIn
Website
Life with GDPR was recently honored as a Top Data Security Podcast
Learn more about your ad choices. Visit megaphone.fm/adchoices
--------
18:36
--------
18:36
A Compliance Roadmap for ADS/ADMT - Part 1: Introduction & Jurisdiction
Welcome to a special series on Life with GDPR. Over the next five episodes, Tom Fox and Alyssa DeSimone, a legal/compliance & risk management expert with an extensive background in HR, will discuss the complex topic of a Compliance Roadmap for ADS/ADMT.
In this first episode, we break down the essentials of ADS/ADMT, focusing on who is covered, the nuances of jurisdiction, and the broader business implications of evolving employment laws. ADS is an automated decision system, and ADMT is an automated decision-making technology. Whether you are an HR professional, compliance professional, or legal eagle, this discussion will help you navigate the complexities of compliance in a changing legal landscape.
Key highlights:
What is ADS/ADMT?
Applies to 5+ employees (including part-time/out-of-state).
Coverage limits for out-of-state conduct.
Jurisdiction can reach beyond California.
Risk mitigation tips for businesses.
Resources:
Connect with Tom Fox
LinkedIn
Connect with Alyssa DeSimone
LinkedIn
Website
Life with GDPR was recently honored as a Top Data Security Podcast
Learn more about your ad choices. Visit megaphone.fm/adchoices
--------
17:19
--------
17:19
Endpoint Security and Data Protection: Uncovering the Hidden Compliance Risks in Printer Security with Jim LaRoe
Jonathan Armstrong remains on assignment. Today, Tom Fox visits with fellow Texan Jim LaRoe, CEO of Symphion, to discuss data privacy, data protection, and compliance related to printer security in one of the most interesting podcasts Tom has done in some time.
Jim provides insight into how 20-30% of network endpoints are printers, and alarmingly, 99% of these are unprotected. Printers, despite being integral to business functions, are typically left vulnerable, making them prime targets for sophisticated phishing and cyber-attacks. Jim shares his journey from a trial lawyer to founding Symphion in 1999 and explains Symphion’s groundbreaking work in developing comprehensive security software for printers. Jim highlights the importance of a culture of compliance in managing endpoint security and the multifaceted challenges that come with securing printers. He emphasizes the collaborative effort needed among GRC compliance teams, IT, and supply chain departments to manage printer security effectively, and offers actionable steps for businesses to mitigate these risks.
Learn more about your ad choices. Visit megaphone.fm/adchoices
--------
24:31
--------
24:31
From IT to Total Compliance Tracking with Adam Goslin
Jonathan Armstrong remains on assignment. Today, Tom visits with Adam Goslin, founder of Total Compliance Tracking, to discuss his journey from IT development and management to becoming a leader in the security and compliance sector.
Adam shares his professional background, the challenges he faced with achieving PCI compliance, and the insights that led him to create a system to streamline compliance management. He details how his company, TCT, helps organizations efficiently manage various certifications and compliance standards. Adam also discusses the unique, direct marketing approach TCT employs and shares the philosophy behind providing accessible compliance resources. This conversation offers valuable insights into the importance of pragmatic, user-friendly compliance solutions.
Key takeaways:
Adam Goslin’s Professional Journey
Founding Total Compliance Tracking
Marketing Strategy and Philosophy
Future of TCT and Industry Insights
Resources:
Connect with Tom Fox
LinkedIn
Connect with Adam Goslin
LinkedIn
Connect with Total Compliance Tracking
Website
LinkedIn
Life with GDPR was recently honored as a Top Data Security Podcast.
Learn more about your ad choices. Visit megaphone.fm/adchoices
How does GDPR, data privacy, and data protection impact your business?
In this podcast, Tom Fox, the Voice of Compliance, hosts Data Privacy/Data Security expert Jonathan Armstrong, co-founder of Cordery Compliance. They use the framework of GDPR to discuss a wide range of issues relating to data privacy and data protection.
If you are a compliance professional, business leader, or InfoSec security expert, this is the podcast to learn about what is happening in the UK, EU, US, and beyond.