Discussion
- AuthorPosts
- 1st September 2026 at 7:28 am #3505
A product can pass a security review and still create privacy risk through how it collects, uses, or shares data. What should the buyer evaluate?
2nd September 2026 at 4:18 am #3506Accepted answerMap the purpose, data categories, affected people, collection sources, processing and sharing flows, retention, deletion, inferences, automated decisions, and each party’s role. Identify legal and policy duties, possible effects on individuals, the buyer’s risk tolerance, and the controls or contract terms needed. Compare the product with a target privacy profile, record gaps and residual risk, and name the person who accepts or remediates each gap. NIST’s Privacy Framework 1.1 guidance explains how profiles can produce prioritized requirements, evaluate suppliers, and manage residual privacy risk in purchasing decisions.
- AuthorPosts
- You must be logged in to reply to this topic.