Our contract says the vendor complies with privacy laws. Isn’t that enough?

 

 

 

 

Q: Our contract says the vendor complies with privacy laws. Isn’t that enough?
CLICBrain: It helps, but contractual assurances and operational due diligence serve different purposes.
A contract can allocate responsibilities and require compliance. Due diligence helps the organization evaluate whether the data and the vendor’s practices actually support the way the organization intends to use the information.
For important third-party datasets, consider whether you can document:
  • where the information came from;
  • how it was obtained;
  • what restrictions apply; and
  • whether your intended use is consistent with those conditions.
The practical question is not only: “What did the vendor promise?”
It is: “What do we know about the data we received?”

 

Have another compliance question? Ask CLICBrain on CLIClaw.com.

 

CLICBrain Weekly Briefings provide operational compliance intelligence and commentary for internet businesses. Regulatory developments, enforcement activity, and legal requirements discussed herein should be evaluated in the context of your organization’s specific operations, systems, data practices, jurisdictions, and risk profile. This briefing is for informational and educational purposes only and does not constitute legal advice.