This article reflects our perspective as privacy consultants and should not be considered legal advice. Every organization’s risk and regulatory footprint is different; as such, we advise you to work with your legal counsel to determine the specific agreements and provisions you need in place.
You’re only as strong as your weakest link. For most companies, that weak link flies under the radar when it comes to compliance with the patchwork of privacy regulations. However, it’s often hiding in plain sight, sitting right there in your third-party agreements.
Third-party vendors have quickly become the way business gets done. Outsourcing specialized or less intensive tasks such as technology, marketing, and IT to experienced outside resources seems like a no-brainer, and it’s proven to be more efficient and cost-beneficial for most companies. But as demand for third-party vendors grows, so does the risk they bring to the table, and the responsibility for managing that risk falls on the company that brought the vendor on. In other words, you.
Evaluating a vendor once, at onboarding, is not the same as having the right terms in place with them. That is a common misconception that trips up a lot of privacy programs. In fact, a vendor can pass every security questionnaire you send and still leave you exposed if the contract itself doesn’t require the right things, such as what the vendor can do with your data, how it handles a breach, or what happens when the relationship ends. Due Diligence Questionnaires (DDQs) and evaluations will help you determine whether a vendor is trustworthy, but it’s the contract that actually holds them to it, and it’s the piece regulators expect to see.
Third-party contract requirements are now ubiquitous across the privacy landscape, and the shape of those requirements varies depending on which law you’re looking at, as does the terminology used to describe them. The GDPR refers to third-party vendors as processors, and so do most of the 23 US state privacy laws that have been signed so far with the exception of the CCPA as an outlier, which refers to them as “Service Providers,” or in some cases, “Contractors.” No matter how you refer to them, they each command their own contractual requirements based on their relationship with your business.
Table of Contents
Is a Vendor List Enough for Privacy Compliance?
The answer to that question is quite simple. No, your vendors (and their vendors) are more nuanced than a simple list. Sure, you can probably pull up a list of vendors, suppliers, distributors, and contractors your company does business with. But under most regulatory guidance, it is the nature of your relationship that will determine what you need to include in your vendor agreement.
The definition of a third-party vendor can cover any business arrangement between your organization and another entity, by contract or otherwise. That means a third-party agreement can include undocumented, verbal, and handshake arrangements. These could have been set up recently, or years ago by someone who no longer works at your company. It doesn’t matter. These vendor relationships show up in more places than most teams expect, and some are easier to overlook than others.
Cloud and SaaS business applications are usually the first thing that comes to mind because CRM platforms, payroll providers, and customer support tools all sit on large volumes of personal, employee, and business data. Marketing and advertising vendors attract just as much scrutiny since so much of what they do runs on cookies, tracking, profiling, and sharing data downstream. Then there are the vendors working quietly in the background, such as IT and security providers, from managed service and security providers that often carry privileged access to systems and the personal data sitting inside them, even though nobody thinks of them as customer-facing.
Then there are the even less obvious categories that tend to get missed entirely. Customer communications vendors, including contact centers, SMS and chatbot platforms, VoIP providers, and survey tools all handle a steady stream of direct outreach and messaging data, but rarely get flagged as a privacy risk. Professional services firms are even easier to overlook, because data sharing with outside counsel, accountants, consultants, auditors, and background check companies often happens informally, over email or a phone call, rather than through any documented process. And recruiting and workforce vendors carry a similar blind spot, as they tend to sit with HR rather than procurement, so they slip past the usual vendor review.
To take it a step further, some third parties outsource some of their own work to additional subcontractors. If that comes as a shock, don’t worry, it’s standard practice for vendors to do this without the consent or knowledge of the company they’re working for. It’s an essential piece of managing third-party agreements all the same, because your contract needs to account for what happens further down the chain, not just what the vendor itself does directly.
All this is to say that nailing down your full vendor list, including their subcontractors, and the nature of your relationship is an essential first step before you can begin to assess and understand what should(or shouldn’t be) in your agreements.
What Should You Include in Your Vendor Agreements? The Article 28 Model
There is some good news amongst the complexity. Comprehensive state privacy laws, like those found in Virginia, Colorado, Connecticut, and more recently Texas and Rhode Island, have come in various shapes and sizes over the years. And while each has its own citations and terminology, most vendor contract requirements build on a shared foundation of similar (if not the same) processor obligations laid out in the GDPR’s Article 28. If you can get comfortable with that core model, you’ll be most of the way to compliant contracts across the board. Below are the common areas to consider when deciding what to include in a vendor agreement.
Scope and purpose limitation
The contract should spell out the nature, purpose, and duration of the processing, the type of data involved, and who it relates to. The vendor should only be allowed to process data based on your documented instructions, not their own judgment about what makes sense. Most US state laws require this same level of specificity.
Confidentiality
Any vendor that has access to your business’s personal information needs to be bound by a confidentiality obligation, whether that’s contractual or a statutory duty they’re already under.
Security measures
The contract needs to require technical and organizational security measures appropriate to the risk involved. “We take security seriously” is not a provision. Specific, appropriate safeguards are, and this requirement holds pretty consistently across GDPR and the US state laws.
Subprocessor rules
If your vendor plans to bring in its own subprocessors (and as covered above, it probably will), the contract should require either your prior written consent or advance notice, and it should require the vendor to pass the same privacy obligations from your agreement down to whoever they subcontract. State laws generally expect the same.
Assistance obligations
Your vendor should be contractually required to help you respond to data subject rights requests and to support you in meeting breach notification and risk assessment obligations. It can make it difficult to fulfill a deletion request that touches vendor-held data if the vendor isn’t obligated to act on it.
Return or deletion of data
When the relationship ends, the data should come back to you or be deleted, with narrow, clearly stated exceptions for legal retention requirements.
Audit and compliance demonstration
The vendor should be required to make information available that shows it’s complying with these terms, and to allow reasonable audits or inspections.
A Word On The Nuances of Vendor Agreements Under the CCPA
It’s worth calling out some of the differences that the CCPA specifically carves out because these differences are important to understand when it comes to both ensuring your vendor list is comprehensive and what to include in your vendor agreements in California.
To understand the differences, we should first look at what each law is trying to achieve. GDPR’s Data Processing Agreements (DPAs) are built around accountability, where the processor acts only on your documented instructions. CCPA vendor agreements exist primarily to stop the unauthorized “sale or sharing” of consumer data, and that shift in focus makes it considerably more prescriptive about what has to be written into the contract itself.
That starts with how CCPA classifies your vendor in the first place. CCPA splits vendors into Service Providers and the more tightly regulated Contractors, and the category a vendor falls into changes what the contract has to say. Either way, the agreement must explicitly prohibit the vendor from selling or sharing personal information; using or disclosing it for anything beyond the specific business purposes named in the contract; using it outside the direct business relationship; or combining it with data from its other sources. Without the correct contract terms in place for service providers means that transferring personal information counts as a “sale” or “share,” which in turn can make your business liable for consumer opt-out violations.
Where it gets stricter still is with Contractors specifically. If a vendor falls into that category, CCPA requires a formal certification confirming it understands and will comply with these restrictions, something GDPR has no real equivalent of. CCPA also hands you an ongoing right to monitor the vendor and requires it to notify you if it can no longer meet its obligations. Furthermore, if you’re sending deidentified data to a vendor, the contract needs language explicitly preventing them from reidentifying it.
Putting Your Third-Party Agreements Into Practice
Knowing what belongs in the contract is one thing, but implementing that across your entire vendor list is another. There are a few steps that can make the difference in a successful contract review. The first is who owns it. This shouldn’t sit with the legal team alone, since privacy, security, and legal all have a stake in what these contracts say, and once all three have reviewed and pre-approved the language, you’re not renegotiating the same clause from scratch every time you onboard a new vendor.
From there, it helps to have something to review against. Build an evergreen inventory of the contractual terms each regulation expects you to include and use it as your baseline whenever you’re reviewing or updating an agreement, bearing in mind that meeting GDPR’s requirements doesn’t automatically satisfy CCPA or your other state law obligations.
Once that baseline exists, the next problem is scale. Manually tracking contract terms across dozens or hundreds of vendors doesn’t hold up for long, which is where platforms like OneTrust, DataGrail, and Osano can be useful for centralizing vendor contract data and flagging where terms fall short, so your team can focus on the vendors and provisions that actually need a judgment call.
Hiring a Fractional Privacy Officer (FPO) can also give you a leg up by helping create the review process, managing it from end-to-end, analyzing the assessments, and making it right inside the organization. If you’re interested in seeing how an FPO can exponentially benefit your vendor management process, we’ve got a team of experts who are well-versed in this high-risk area. Reach out today to schedule a free consultation!
Third-Party Risk Management Guide
Explore our free Third-Party Risk Management Guide to discover practical strategies for assessing vendors, managing risks, and maintaining compliance without the guesswork.