Compliance
47 bites tagged Compliance — interview questions with model answers, and 60-second explainers.
Institutional Review Board (IRB): Your Research Ethics Checkpoint
An IRB is an ethics committee that acts as a mandatory checkpoint for research involving human subjects. Before running user studies or surveys, especially in academic or medical settings, you must get their approval.
Securing Research Data with a Management System
Treat data security as a living system for managing risk, not a one-off checklist. A framework like ISO 27001 helps you systematically protect sensitive research data by defining policies and controls.
The EU AI Act: Risk-Based AI Regulation
The EU AI Act isn't a blanket ban but a risk-based framework. It sorts AI into tiers—from unacceptable to minimal risk—and applies rules proportionally, affecting any company with AI users in the EU. The footgun is assuming it only applies to EU companies.
VPAT vs. ACR: The Nutrition Label for Accessibility
An ACR is a standardized report card for a product's accessibility, based on a template called a VPAT. It's a nutrition label stating conformance facts, not a pass/fail grade.
Data Retention Policy: Your Schedule for Deleting Data
A data retention policy is your company's official schedule for deleting data, not a plan to keep it forever. It's essential for legal compliance (like GDPR) and managing storage costs.
Database Auditing: Your Database's Security Camera
Think of database auditing as a security camera for your data, recording who did what and when. It's essential for security investigations and compliance, but the footgun is treating it as a substitute for access control—it only records a breach, it doesn't…
GDPR: Marketing is More Than Just Selling
Under GDPR, direct marketing isn't just selling products; it's promoting your 'aims and ideals.' This applies to email newsletters and targeted ads. The biggest footgun is assuming non-profits are exempt—they aren't, and users have an absolute right to opt…
FTC Endorsement Guides: Disclose Your Connections
The FTC requires you to disclose any material connection to a brand you endorse. If you got paid, received free products, or work there, your audience must know. This applies to social media posts, affiliate links, and reviews.
CCPA & CPRA: California's Consumer Privacy Rules
Think of CCPA/CPRA as giving California consumers a remote control for their personal data. It forces businesses to honor user requests to know, delete, correct, or stop selling their info.
Native Advertising Disclosures
Native advertising disclosures are the clear labels, like Sponsored or Ad, that must appear on content designed to blend into a publisher's normal articles or feed, so readers can tell paid promotion from independent editorial before they engage with it.
WCAG: The Technical Standard for Web Accessibility
WCAG is the technical rulebook for making web content usable by people with disabilities. It provides testable criteria for websites and apps, often required by law. The footgun is aiming too low; Level AA is the standard target, not just Level A.
CAN-SPAM Act: The Rules for Commercial Email
The CAN-SPAM Act sets the rules for commercial email, not blocks it. It requires clear identification as an ad, a physical address, and an easy opt-out method. The law applies to all promotional emails, not just bulk campaigns.
Ad Policy Compliance: Why Your Ads Get Rejected
Ad policy compliance is a gatekeeper system balancing commercial content with user safety. Platforms like Meta automatically review every ad for violations like discrimination, scams, or shocking content.
Cloud Compliance Frameworks: Security as a Standard
Think of a cloud compliance framework as a standardized rulebook for security. It translates broad security goals into specific, auditable controls, providing a checklist to prove your cloud environment is secure to regulators and customers.
Data Sovereignty: Your Data's Legal 'Citizenship'
Data sovereignty means data is subject to the laws of the country it's in; data residency is storing it there to comply. This is critical for apps in regions with strict laws like the EU's GDPR. The footgun is confusing residency with full legal compliance.
CSPM: A Single Pane of Glass for Cloud Security
A CSPM is a single pane of glass for your cloud security, continuously scanning all assets for misconfigurations. It unifies security data across multi-cloud environments, replacing disparate tools.
Cloud Audit Trail: The 'Who Did What' Record
Think of a cloud audit trail as security camera footage for your infrastructure, recording who did what, where, and when. It's essential for investigating security incidents, proving compliance, and debugging operational issues.
Encryption at Rest: Securing Your Data When It's Not Moving
Encryption at rest is like locking your data in a safe when it's not moving. It protects raw files on disk if storage is stolen, a default on platforms like Google Cloud. The footgun: it doesn't stop a compromised app with valid keys from reading.
AWS Dedicated Hosts: Your Own Physical Server in the Cloud
An AWS Dedicated Host is your own physical server in the cloud, providing single-tenant hardware. Use it for "bring your own license" (BYOL) software tied to physical cores, or for compliance rules that forbid multi-tenancy.
Compliance as Code: Automate Your Audits
Compliance as Code prevents last-minute audit scrambles by treating security rules as software. It automates checks in your CI/CD pipeline, turning manual spreadsheet work into a continuous, code-driven process.
Software Bill of Materials (SBOM): An Ingredient List for Your Code
An SBOM is a nutrition label for your code, listing every library and dependency. It's crucial for security audits and managing supply chain risk, letting you instantly find systems affected by a new vulnerability.
GDPR: Treating User Data as a Liability, Not an Asset
GDPR treats personal data as a liability borrowed from the user. It gives EU citizens strong rights over their data, like access and erasure, forcing any company processing it to comply. The footgun is assuming it doesn't apply if your company isn't in the EU.
Analytics Consent Management: Respecting User Choices
Consent management is the system that asks users for tracking permission and technically enforces their choice. It's legally required for sites using Google Analytics or Ads.
Get Compliance bites daily.
Five a day, five minutes, offline. With quizzes so it sticks.
Open testing — you’ll join as an early tester.