Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

IAPP.org
iapp.org > news > a > defining-regtech

Defining RegTech

3+ day, 17+ hour ago   (157+ words) A look at the evolution of RegTech and how organizations define its role in compliance and risk management. In their 1873 satirical novel, "The Gilded Age," authors Mark Twain and Charles Dudley Warner wrote: "History never repeats itself, but the Kaleidoscopic…...

IAPP.org
iapp.org > news > a > a-view-from-dc-what-will-all-these-ai-auditors-be-auditing

A view from DC: What will all these AI auditors be auditing?

15+ hour, 35+ min ago   (834+ words) With two new laws on the books, California is building a regulatory structure for AI auditors, even as audits remain entirely voluntary. There's an oft-quoted line from Milton Friedman: "Only a crisis — actual or perceived — produces real change. When that…...

IAPP.org
iapp.org > news > a > healthcare-organizations-tackle-ai-governance-in-fragmented-regulatory-environment

Healthcare organizations tackle AI governance in fragmented regulatory environment

2+ day, 6+ hour ago   (614+ words) Key healthcare stakeholders discussed how rapid AI adoption and innovation are leaving the sector at a crossroads with their governance and regulatory compliance practices. Global entities are facing challenges with different regulatory requirements across larger jurisdictions like China, the EU…...

IAPP.org
iapp.org > resources > article > building-privacy-safe-mcp-servers-what-gdpr-actually-requires

Building privacy-safe MCP servers: What GDPR actually requires

2+ day, 8+ hour ago   (272+ words) While the Model Context Protocol brings powerful AI integration and accountability through detailed audit trails, it also creates significant privacy and GDPR compliance risks, requiring organizations to build subject-access rights, governance controls and legal safeguards into deployments from the outset....

IAPP.org
iapp.org > news > a > patient-rights-and-ai-medical-chatbots-alignment-between-the-gdpr-and-eu-ai-act

Patient rights and AI medical chatbots: Alignment between the GDPR and EU AI Act

1+ week, 2+ day ago   (174+ words) Yet, the regulatory framework governing such online consultation services has become increasingly complex. With the EU General Data Protection Regulation and AI Act enforced concurrently in Europe, the compliance obligations under both laws present a formidable challenge that healthcare institutions…...

IAPP.org
iapp.org > news > a > the-ciso-s-new-privacy-mandate-in-enterprise-ai-governance

The CISO's new privacy mandate in enterprise AI governance

1+ week, 2+ day ago   (620+ words) Enterprise AI is pushing CISOs into a broader privacy role, requiring security leaders to help turn privacy principles into enforceable controls across AI governance, vendor oversight and incident response. The IAPP is policy neutral. We publish contributed opinion pieces to…...

IAPP.org
iapp.org > news > a > thought-for-the-week-ai-enhanced-nation-state-cyber-threats-may-be-systemic

Thought for the week: AI-enhanced nation state cyber threats may be systemic

1+ week, 4+ day ago   (133+ words) The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. This article is part of an ongoing series that will explore issues or recent developments in…...

IAPP.org
iapp.org > news > a > privacy-before-procurement

Privacy before procurement

2+ week, 2+ day ago   (1097+ words) Why healthcare AI governance starts before the contract is signed. The dreaded communication, "Can privacy review this AI contract before we go live on Friday?" For many healthcare privacy professionals, this is becoming a familiar request. The organization has identified…...

IAPP.org
iapp.org > news > a > ai-and-consumer-rights

AI and consumer rights

2+ week, 2+ day ago   (293+ words) While current U.S. state privacy laws give consumers certain rights over personal data and AI-driven decision-making, they generally do not provide a broad right to opt out of AI training. A few things are happening at once. Virtually every company is…...

IAPP.org
iapp.org > resources > article > operational-impacts-cra-product-cybersecurity-market-access-requirement

Top 5 operational impacts of the CRA: Product cybersecurity as a market-access requirement

2+ week, 3+ day ago   (206+ words) The EU Cyber Resilience Act makes cybersecurity compliance a prerequisite for selling connected products in the EU, requiring security-by-design and conformity assessments. This article is part of a series on the operational impacts of the Cyber Resilience Act. The CRA…...