×

or

The Legal Department’s New Nightmare: Your Vendors

The Legal Department’s New Nightmare: Your Vendors

From the European Union’s GDPR to California’s new privacy law, there has been a tidal wave of new data privacy and cybersecurity regulations globally. This surge of new laws requires legal counsel to identify, with great certainty, all the third-party service providers that access, process, or store personal and regulated data on behalf of their companies.

An average of 63 percent of a company’s personal and sensitive data is disclosed to or managed by third parties spanning a wide range of functions, including human resources, law firms, legal service providers, payroll, accounting, marketing, customer services, software development, engineering, and many more.

Any third party with access to your company’s personal, sensitive, or otherwise regulated data represents a risk and is subject to data privacy and cyber security regulations. The stakes have never been higher. You can’t afford to be surprised.

The regulations make it clear that you are responsible for your third parties — all of them. ACC’s Third-Party Compliance Best Practices white paper says effective compliance requires you to know which third parties are relevant to data privacy and cyber security regulations and to assess their data protection practices and compliance routinely and systematically

Vendor management, including the risk profiling of all third-party service providers, should squarely sit with the legal department. Otherwise, the legal department will not be fulfilling its duty of risk mitigation and prevention. The department will only be set to solve serious problems such as data breaches in a reactive rather than proactive manner.

Susanna Mcdonald
Vice President and Chief Legal Officer, Association of Corporate Counsel

About Author

Rebecca Perry

Rebecca Perry is the director of professional services at Jordan Lawrence, the world leader in helping companies meet legal and regulatory obligations related to how they manage information, and the exclusive ACC Alliance Partner for Data Privacy and Cybersecurity Compliance. Perry has been with Jordan Lawrence for 25 years helping in-house counsel, compliance, privacy, and IT executives identify and address critical information risks and comply with regulatory obligations. She provides expertise and guidance in the areas of information governance, data mapping, data minimization, records retention, and thirdparty diligence. Perry is a Certified Information Privacy Professional and frequent contributor and speaker in the legal and privacy communities.E: [email protected]