Third-Party Data Breaches Highlight the Importance of Vetting Vendors in Compliance With GDPR and CCPA

Diligence on third parties is a cornerstone of any cybersecurity program given the risk vendors pose, and now regulations such as GDPR and CCPA specifically address what companies need to do to vet and monitor their vendors. In this guest article, Moses and Singer attorneys Linda Malek, Jason Johnson and Nora Lawrence Schmitt provided strategies for vetting third parties, structuring contractual agreements and conducting ongoing monitoring. They also examined the costs of violations in light of these new regulatory requirements. See also our two-part series on how to maintain effective and secure long-term vendor relationships” “Understanding the Risks” (Jun. 20, 2018); “Addressing the Issues” (Jun. 27, 2018).

To read the full article

Continue reading your article with a CSLR subscription.