Chris Lippert is a Director and Privacy Technical Lead with Schellman and is based in Atlanta, GA. With more than 10 years of experience in information assurance across numerous industries, regulations, and frameworks, Chris developed a passion for and concentration in data privacy. He is an active member of the International Association of Privacy Professionals (IAPP), holds his Fellow of Information Privacy (FIP) designation, and advocates for privacy by design and the adequate protection of personal data in today’s business world.
By:
CHRIS LIPPERT
April 23rd, 2025
Microsoft recently released v11 of their Data Protection Requirements (DPR) for suppliers required to undergo an annual security and privacy assessment through Microsoft’s Supplier Security and Privacy Assurance (SSPA) program. Microsoft DPR v11 went into effect April 2025 and features a total of 67 requirements.
By:
CHRIS LIPPERT
August 1st, 2024
When Microsoft released version 9 of their Data Protection Requirements (DPR) back in October 2023, the new framework contained several important updates, as well as a few brand new requirements, including the addition of new considerations for suppliers processing protected health information (PHI).
By:
CHRIS LIPPERT
December 14th, 2023
Since the introduction of the new Data Privacy Framework (DPF) on July 17, 2023, many have begun familiarizing themselves with its seven principles as they ready themselves to comply. However, the DPF also features 16 supplemental principles, two of which—regarding self-certification and verification—also cover particularly important topics.
By:
CHRIS LIPPERT
July 18th, 2023
In news that’s excited the privacy industry worldwide—the EU – U.S. Data Privacy Framework (DPF) was announced on Monday, July 10, 2023, and took near immediate effect. This comes after months of review and public comment, but now, with the DPF functioning as a new adequacy mechanism under General Data Protection Regulation (GDPR), organizations can once again transfer data under an adequacy decision if they adhere to and self-certify against the DPF.
By:
CHRIS LIPPERT
December 15th, 2022
You’ve probably heard the classic idiom about “keeping up with the Joneses.” According to Miriam-Webster, it means “to show that one is as good as other people by getting what they have and doing what they do.” Generally, that’s usually meant people buying expensive cars or other things they can’t afford to try and maintain the same pace as their peers.
By:
CHRIS LIPPERT
October 3rd, 2017
With the General Data Protection Regulation (GDPR) becoming effective May 25, 2018, organizations (or rather, organisations) seem to be stressing a bit. Most we speak with are asking, “where do we even start?” or “what is included as personal data under the GDPR?” It is safe to say that these are exactly the questions organizations should be asking, but to know where to start, organizations first need to understand how the GDPR applies to their organization within this new definition for personal data. Without first understanding what to look for, an organization cannot begin to perform data discovery and data mapping exercises, review data management practices and prepare the organization for compliance with the GDPR.
By:
CHRIS LIPPERT
July 18th, 2017
You most likely selected the link to this blog to discover one of two things: 1) how to effectively manage vendor requirements via SOC reports or 2) what the SOC 1/SOC 2 examination requirements are for vendor management. I don’t want to disappoint, so this article will provide you with some knowledge or at least some validation of your current thoughts on the matter.