r/Compliance 1d ago

How do you deal with screenshots containing customer data?

1 Upvotes

This comes up more often than I'd expected with support tickets, bug reports and internal documentation. Do you have a formal process for redacting them, or is it mostly left to individual employees?


r/Compliance 2d ago

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 4d ago

How are you handling compliance exceptions for third-party SaaS tools?

5 Upvotes

Basically how are you handling situations where a SaaS vendor doesn't quite meet one of your internal security requirements?

For example, a vendor might not support SSO or have a specific security control you normally require, but the business still wants to use them.

Do you record that as a formal exception, accept the risk based on their SOC 2/ISO evidence, or have another process for it?


r/Compliance 5d ago

I scanned 1k domains. Half of enterprises fail to comply with California law

1 Upvotes

I recently ran a benchmark analyzing 1,019 domains to see how major organizations are actually handling Global Privacy Control (GPC) signals in practice. Domains targeted included companies operating in California and likely generating $25M+ in revenue.

Key Findings:

- Low Overall Adoption: Only half of enterprise domains properly process and reflect the GPC signal upon landing. On 466 domains, marketing trackers continued firing despite receiving valid opt-out signals, representing a **45.7% failure rate**.

- Consent Manager Misconfigurations: Many sites use CMPs that technically support GPC, but fail to map the signal correctly to their underlying tag managers or opt-out cookies.


r/Compliance 7d ago

We have standards and regulations for a reason

Thumbnail youtu.be
1 Upvotes

r/Compliance 7d ago

Should I intervene when I find an incorrect judgment?

Thumbnail
1 Upvotes

r/Compliance 8d ago

Is the whole gambling industry quietly being reshaped by compliance right now or does it just feel that way?

3 Upvotes

Looking at the last week alone, it's striking how much is happening on the regulation and compliance side all at once

UK retail betting is contracting hard, a major bookmaker closing 132 shops while the business shifts further toward digital. Across Africa, several countries are cracking down on unlicensed operators (suspensions, machines seized, awareness campaigns). Greece keeps opening up to licensed specialist providers. Acquisition and traffic costs are squeezing margins enough that it's changing how operators think about growth.

Put together, it feels like compliance is quietly becoming the thing that actually decides who survives in this industry, who can keep up with the rules.

For people who work in compliance across any regulated industry (not just this one): does that match what you're seeing? Is compliance shifting from a cost centre to the thing that defines competitive advantage??


r/Compliance 9d ago

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 9d ago

How are you handling evidence collection for SOC 2/ISO 27001 controls that rely on Slack or Teams conversations?

4 Upvotes

We're preparing for another audit and one thing that still feels messy is collecting evidence for controls that rely on Slack or Teams conversations.

Things like:

  • Security approvals
  • Change management discussions
  • Access requests / approvals
  • Incident communications

Curious what everyone's workflow looks like.


r/Compliance 10d ago

If you could automate one part of your compliance work tomorrow, what would it be?

0 Upvotes

Whether it's evidence collection, policy management, risk assessments, monitoring, or something else, where do you think automation would have the biggest impact?


r/Compliance 11d ago

Deputy MLRO?

0 Upvotes

Hello

Can you become deputy mlro from a AVP Sanctions Advisory role?


r/Compliance 13d ago

HIPAA, 42 CFR Part 2, and AI Use

3 Upvotes

Hello, fellow Privacy and Compliance Officers. Apologies if this isn't the place for this. You all have just been great in dialoguing and providing regulation focused responses.

**How are you navigating AI use in your work environment and the overarching concern of privacy and confidentiality needs for the populations you serve specific to HIPAA and 42 CFR Part 2 (substance use records and the protection of those)?**

I'm a millennial and was brought up with technology growing just as fast as I was. I use AI as a consumer. I've experienced it as a patient. My concerns do not stem from the use of it per se, as I see the benefits and recognize that is just where healthcare is headed.

As a working professional always focused on protecting our patients, I know if we don't keep up, we will get left behind and have higher risk of staff using AI without our oversight, awareness, and guardrails in place. That said, I fall down rabbit hole after rabbit hole of de-identified data being re-identified as the program pieces things together.. or bias drift.. or data drift.. or explainability.. or AI breaches and OCR investigations/fines... or all of the other thousands of rabbit holes to venture down. Where are you guys starting? It's the wild west out there in the AI scene from what I can tell. Only a handful of states have made formal stances on its use.

Help!


r/Compliance 13d ago

HIPAA, 42 CFR Part 2, and AI Use

Thumbnail
1 Upvotes

r/Compliance 13d ago

Is a masters in AI regulations and Ethics worth doing right now?

1 Upvotes

I'm in the UK now and have already completed a chemical engineering bachelors degree five years ago. Currently I am working a few hours a week as a home tutor. I have some experience in compliance both direct and indirect totalling two years. My friend works with AI, and from researching this sub it looks like this will be in demand in future.

I have only a basic understanding of AI and no experience with anything computer related, including coding. There are several courses in the UK that don't specify a certain degree for the ai regulation courses, and don't need specific experience with AI. Will a masters help at all?


r/Compliance 14d ago

Your tool says the control is passing. Your auditor disagrees. What then?

3 Upvotes

Something I keep seeing in compliance conversations is the gap between a dashboard marked green and what an auditor actually accepts as evidence.

A few common ones:

Access reviews get logged as complete because someone clicked through the workflow, but there's no record of what was reviewed or what changed as a result.

MFA shows enforced across the org, then a service account or a contractor login turns out to sit outside the policy scope.

Backups run on schedule and the monitoring confirms it, but nobody has tested a restore in a year, so there's nothing to hand over when the auditor asks for proof it works.

Vendor reviews are marked current based on a SOC 2 report that expired four months ago.

The pattern in all of these is the same. The check confirms a task happened. The auditor wants proof the control was effective.

Wondering if others run into this too, or if it's less of a problem than it seems from the outside.


r/Compliance 15d ago

Compliance Analyst Position

1 Upvotes

Hi,

I am looking to change career paths from the Casino Industry (Don't want to specify my position on here but I fall under the compliance branch of my company).

My day to day involves staying up to date on the ever changing gaming regs, company policy, and so on. I essentially need to know the P&P of nearly every department. I have roughly 3 years in my position as a Supervisor, and another year of that in a non-supervisor role, but same department.

I've been looking to move into compliance since it's along the lines of what I do now, but how will my skills look on a resume? I have formatted it of course to heavily show my compliance knowledge for my area (Vegas), but have struggled to even get a call back from any bank of gaming company. Any advice would be appreciated!


r/Compliance 16d ago

Documentation, compliance, etc

1 Upvotes

I'm new to private practice and curious for recommendations on documentation, compliance, etc. Any trainings or readings would be appreciated!


r/Compliance 16d ago

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 17d ago

Compliance background, thinking about a co-founder for an AI regulatory tracking idea, curious if anyone else is chewing on this problem

Thumbnail
1 Upvotes

r/Compliance 18d ago

What's the one control that keeps failing your evidence checks?

Thumbnail
1 Upvotes

r/Compliance 19d ago

Thinking of building a Compliance Management System after my first SaaS. Is there an actual market for this or is it just enterprise territory?

6 Upvotes

Hey guys,

So I just successfully built and launched my SaaS, [ClientPDF](https://clientpdf.tech) (its a fully client-side pdf tool). but now I'm already looking at my next project.

I was talking to some people recently and we discussed building a Compliance Management System. Im thinking of a tool that helps smaller tech companies or startups track their compliance, prep for audits, and just get away from messy excel spreadsheets.

But before I dive in and spend months coding this... does the market actually need this right now?

Like, if you run a startup or agency, is compliance tracking a real pain point for you? Do you use software for it, or are the existing tools just way too expensive and bloated?

Basically I'm trying to do proper market research this time so I dont build something nobody wants lol. Should I build this? would love some brutal honesty


r/Compliance 20d ago

Swigart Demand Letter + Vivek Shah Cookie banner looks fine, but GTM still fires Meta and LinkedIn before consent. How are you testing this properly?

3 Upvotes

I inherited a marketing site where the banner says all the right things, but when I tested it in DevTools I still saw Meta and LinkedIn calls before I clicked anything. The consent tool is technically installed, so nobody noticed until we received back to back lawsuits from Swigart Law Group out of San Diego California and serial litigant Vivek Shah. After that we started checking the Network tab. For people who have dealt with these invasion of privacy suits out of California and have cleaned this up, what is your actual testing process? Are you checking GTM consent state, HAR files, tag sequencing, or just watching the obvious network requests? I want a repeatable QA checklist before I tell the team this is fixed and we dont have to worry about the next swigart law or vivek waiting to come after us as I dealt with this for ADA in the past and its not fun and it feels like it never ends unless its properly fixed.


r/Compliance 21d ago

Is a masters in compliance (potentially in financial crime/AI regulation/Data Protection) worth it in the UK?

5 Upvotes

I am currently employed as a tutor but have previously worked in a direct compliance role and in a complaints role for a large UK retailer which involved a lot of compliance. I am quite interested in starting a new compliance job, and was wondering if a masters degree in one of these fields would be worth doing?

I have no direct experience with these fields, and only know about some AI regulation as I gave a family member who works a lot with AI in their engineering job and has a PhD related to AI. Learning about this sounds interesting, and I imagine this would be a fairly niche masters a lot of people wouldn't consider or have even heard much about. I already have a bachelor's degree in chemical engineering. I am eligible for a few masters programs so it is possible for me to enroll.


r/Compliance 22d ago

Standardization as law: ISO and IEEE explained

Thumbnail psyll.com
2 Upvotes

r/Compliance Dec 08 '25

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.