AI Governance

DPA

Data Processing Agreement, a contract required under GDPR between data controllers and processors that specifies how personal data will be handled. DPAs must define processing purposes, data categories, retention periods, and subprocessor arrangements.

The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.