Privacy Policy Requirements: What Your Policy Must Disclose (Guide)
A privacy policy must disclose who you are and how to contact you, what personal data you collect, why you collect it, who receives it, how long you […]
Evidence library
Analysis of the gaps between stated controls and the data movement Melurna observes.
Explore the blog
A privacy policy must disclose who you are and how to contact you, what personal data you collect, why you collect it, who receives it, how long you […]
Session replay is a digital analytics technology that records what a visitor does on a website (clicks, scrolls, form entries, including text never submitted) and rebuilds it as […]
The General Data Protection Regulation (GDPR) is the EU’s comprehensive data privacy law, effective since 25 May 2018. It applies to any organization worldwide that offers goods or […]
Web tracking is the collection of data about a visitor’s behavior on a website, and across websites, by the site itself and by third-party code running on it. […]
A privacy impact assessment (PIA) is a formal analysis of how personal information is collected, used, shared, and protected, done before processing starts, not after something goes wrong. […]
Global Privacy Control (GPC) is a browser-level signal that automatically tells every website you visit that you opt out of the sale or sharing of your personal data […]
A Data Subject Access Request (DSAR) is a legally enforceable request from an individual to find out whether an organization holds personal data, to obtain a copy, and […]
A data retention policy is the documented set of rules that decides what data your organization keeps, where it lives, how long it stays, and how it is […]
Data privacy risk is the potential for legal, financial, or reputational harm arising from how an organization collects, uses, shares, retains, or discloses personal data. A company can […]
A privacy incident is any suspected or confirmed event that compromises the confidentiality, integrity, or availability of personal information, including unauthorized access, use, disclosure, loss, or destruction of […]