
NYDFS Does Not Want Your Annual PDF. It Wants the Decision Trail.
The Department’s September 10 industry letter creates no new Part 500 duties. It does something more useful. It publishes the exam findings firms have been
Governance, Risk, and Compliance (GRC) is a holistic framework that integrates three critical elements for organizational success.
• Governance establishes the foundation for effective decision-making and ensures that organizational activities align with its strategic objectives. It encompasses a robust system of internal controls, clear lines of authority and accountability, and ethical guidelines that guide employee behavior.
• Risk Management involves identifying, assessing, and mitigating potential threats to the organization. This includes a comprehensive evaluation of various risks, such as financial, operational, reputational, legal, and technological risks. By proactively identifying and addressing these risks, organizations can minimize potential losses, protect their assets, and ensure business continuity.
• Compliance ensures adherence to all applicable laws, regulations, and industry standards. This includes complying with data privacy regulations (e.g., GDPR, CCPA), financial reporting standards, environmental regulations, and industry-specific guidelines.
Captain Compliance provides valuable resources and expertise to help organizations understand GRC. Read the free educational material below about GRC from the compliance superheroes at Captain Compliance.

The Department’s September 10 industry letter creates no new Part 500 duties. It does something more useful. It publishes the exam findings firms have been
Grindr Inc. agreed on September 2 to pay £26 million to resolve a group action in the High Court of England and Wales. Austen Hays

The Guardian reported on September 8 that it reviewed about a dozen previously unreported law-enforcement documents, obtained by the transparency group Property of the People.

A new privacy settlement involving TaxAct, Meta and Google offers businesses one of the clearest examples yet of how regulators expect companies to govern third-party

The global average cost of a data breach just hit $4.99 million — a 12% jump and a record high, according to IBM’s newly released
At least three major law firms—Herbert Smith Freehills Kramer, Goodwin Procter, and Stettinius & Hollister—disclosed data breaches to U.S. state regulators in early August 2026,

Consumer Reports has released a multi-month evaluation of five major U.S.-facing cryptocurrency exchanges—Binance.US, Coinbase, Crypto.com, Gemini, and Kraken—concluding that the platforms make buying and selling
The Senate Committee on Health, Education, Labor and Pensions voted 22-0 to advance an amended version of the Health Information Privacy Reform Act. The bipartisan
Australia’s Privacy Commissioner Carly Kind has publicly raised concerns about the rapid arrival of consumer smart glasses and other surveillance wearables, warning that existing privacy

Wrongful collection has quietly become one of the most expensive phrases in American privacy law. It describes the gathering of personal information without the legally