QuestionQ83

Privacy Operational Lifecycle: Respond

Because it is too late to revise the vendor contract or stop the app’s deployment, what is the best next step to take?

  • A Implement a more comprehensive suite of information security controls than the one used by the vendor.
  • B Ask the vendor for verifiable information about their privacy protections so weaknesses can be identified.
  • C Develop security protocols for the vendor and mandate that they be deployed.
  • D Insist on an audit of the vendor's privacy procedures and safeguards.
Explanation

Third-party privacy risk should be assessed using verifiable evidence of the vendor’s privacy protections so that gaps in its collection, use, storage, and protection of personal data can be identified and remediated. This provides a timely, risk-based basis for addressing weaknesses before or during deployment.

Community Discussion

No comments yet. Be the first to start the discussion!