Due diligence before sharing data.
WHAT TO ESTABLISH BEFORE ENGAGING ANYONE
What data they will handle Where they will store it Who else they involve What security they provide
WHAT TO ASK FOR
Their security documentation Any certifications Their data processing terms Their breach notification commitments Their sub-processor list
WHAT TO VERIFY RATHER THAN ACCEPT
Claims of certification.
HOW
Ask for the certificate and check it is current.
WHAT TO ASSESS
Whether their measures are proportionate to the data's sensitivity.
WHAT TO BE CAUTIOUS OF
Vendors with no documentation Terms permitting use of your data for their purposes No commitment on deletion
WHY THAT SECOND ONE MATTERS
A provider training models or building products on your customer data is a serious problem.
WHAT TO READ CAREFULLY
Terms about data use, not just security.
WHAT TO RECORD
The assessment, and the decision.
WHY
Accountability requires demonstrating you considered it.
WHAT TO REVIEW PERIODICALLY
Whether terms changed Whether they had incidents Whether they are still used
WHAT TO DO ABOUT A VENDOR THAT WILL NOT ENGAGE
Consider whether to use them at all.
WHAT TO PLAN
How you would exit, and retrieve your data.