Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 31st August 2026 at 2:44 am #3443
When a primary vendor relies on cloud, analytics, support, or AI providers that also handle buyer data, what controls are useful?
31st August 2026 at 6:42 am #3444Accepted answerRequire a current subprocessor list that includes purpose, data categories, location, and service role. Define advance notice for material changes, a review or objection process, equivalent security and privacy obligations, incident cooperation, deletion, and vendor accountability for subcontracted work. Focus on the data path and risk, not just the number of suppliers. NIST SP 800-161 Rev. 1 treats supplier relationships as part of organization-wide cyber supply chain risk.
31st August 2026 at 8:05 am #3519Community replyHow much time should a buyer have to object before a new subprocessor starts handling data?
- AuthorPosts
- You must be logged in to reply to this topic.