People outside your organisation.
WHAT THEY FREQUENTLY ACCESS
Customer databases Systems with personal data Files and exports Production environments
WHAT ROLE THEY USUALLY HOLD
Processor, when handling data on your instructions.
WHAT THAT REQUIRES
A written agreement covering the usual processor obligations.
WHY IT IS FREQUENTLY MISSING
Informal engagements skip contracts entirely.
WHAT TO PUT IN WRITING
What they may access What they may do with it Confidentiality Security expectations What happens at the end Ownership of anything produced
WHAT TO PROVIDE
Individual accounts, never shared credentials.
WHY
Attribution, and revocation on departure.
WHAT TO RESTRICT
Access to production data, wherever possible.
WHAT TO PREFER
Anonymised data for development.
WHAT TO DO ABOUT EXPORTS THEY HOLD
Require deletion, and confirm it.
WHY CONFIRM
Copies on personal machines persist indefinitely otherwise.
WHAT TO DO WHEN THE ENGAGEMENT ENDS
Remove every access, across every system Rotate anything they knew Confirm deletion of local copies
WHAT TO CHECK
That removal actually happened everywhere.
WHAT TO MAINTAIN
A record of who has been granted access, and when it was removed.
WHAT TO REVIEW
Active accounts, against current engagements.