What should a buyer include in a software privacy risk assessment?

Discussion

Open questionLast verified: 2026-08-15
  • Author
    Posts
  • #3505

    A product can pass a security review and still create privacy risk through how it collects, uses, or shares data. What should the buyer evaluate?

    #3506
    Accepted answer

    Map the purpose, data categories, affected people, collection sources, processing and sharing flows, retention, deletion, inferences, automated decisions, and each party’s role. Identify legal and policy duties, possible effects on individuals, the buyer’s risk tolerance, and the controls or contract terms needed. Compare the product with a target privacy profile, record gaps and residual risk, and name the person who accepts or remediates each gap. NIST’s Privacy Framework 1.1 guidance explains how profiles can produce prioritized requirements, evaluate suppliers, and manage residual privacy risk in purchasing decisions.

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account