How to vet your vendors: Ensuring data privacy and security compliance

Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success. Learn More


Big data has big implications for businesses thanks to its unique ability to provide the information needed to scale and succeed.

But as data usage grows, issues of data security, privacy and compliance have come into focus, capturing the attention of both customers and regulators. As a result, strict regulations like the GDPR and CCPA have been introduced to dictate standards for companies that wish to operate both locally and internationally.

While this means that more businesses are taking data compliance more seriously, what many still overlook is the data privacy measures and compliance record of their third-party vendors — often only considering them at the last stage of the procurement process. This can lead to a nasty surprise for businesses that must still rely on the data compliance of their vendors: A vendor’s lack of compliance can compromise a business’ own.

In other words, it’s not enough for companies to ensure their own data compliance. They have a responsibility to make sure that their vendors are compliant as well. Here’s why and how businesses should vet their third-party vendors before working with them.

Event

Transform 2023

Join us in San Francisco on July 11-12, where top executives will share how they have integrated and optimized AI investments for success and avoided common pitfalls.


Register Now

The nature of vendor data compliance

Third-party vendors’ data and compliance, or the lack thereof, can hurt organizations’ own compliance with data-related regulations, potentially with a significant negative impact on their business.

Why exactly? Incomplete, inaccurate or noncompliant data, regardless of where it comes from, can quickly lead to poorly informed strategic and operational decisions which can erode a company’s productivity, reputation and bottom line.

For example, if your sales teams are operating according to bad data — reaching out to people who don’t wish to be contacted, are no longer relevant or have outdated contact information — it becomes very easy to waste effort, lose time and money and even damage a brand’s reputation. And because companies can be held accountable and fined for compliance breaches for their use of data, it is important to use a trustworthy and compliant vendor.

What organizations can do about it

A company’s compliance record is only as strong as its weakest link, so they must vet and approve any potential vendors and partners before signing on to work with them, as well as assess their existing vendors to confirm that they are data compliant.

To do so, organizations must ask the right questions and take the following precautions:

First, make sure your vendors meet the requirements of any necessary regulations or certifications, such as GDPR, CCPA, ISO, TRUST-e and IAPP, and the more, the better. This not only proves that a company takes data privacy seriously, it widens the scope of where and how data can be used (GPDR compliancy = EU reach).

Once certifications are checked, organizations must understand how a given vendor uses its data. Is it providing temporary access to licensed data or selling this data indefinitely? Does it sell customer data to third parties? Where is it getting its data from, and how is it collected and stored? A vendor that can’t keep its data sharing and usage practices above board can’t necessarily be trusted to be honest about or meet requirements for compliance.

Adherence and compliance through data infrastructure and security measures

Equally as important is ensuring that the vendors actually adhere to regulatory requirements and checking what data privacy infrastructure and security measures they have in place. Do they employ permission and user access controls, employee security awareness, patch management, system configuration management and periodic penetration testing?

How do they handle data subject concerns? Do they notify new data subjects? Is there an opt-in/opt-out feature? Are databases accurate, and are they updated regularly based on customer feedback and privacy requests?

If the answers to these sorts of questions are consistently “no,” then it may be time to look elsewhere.

The right data security and privacy mindset

Finally, ask about the organization’s overall mindset and handling of data security and privacy. Have they made it a priority across their organization? Do ALL employees receive data and privacy-related training, even if the entire team doesn’t work on those issues directly? A third-party partner that goes above and beyond in this capacity will make for a more reliable and proactive partner across the board.

Decision makers shouldn’t be afraid to ask pointed questions and express concerns when vetting new and existing vendors — asking these types of questions and acting accordingly are key to upholding privacy principles like purpose limitation. The vendors and partners a company chooses to work with can have a significant impact on success, so it is critical to ensure that these partners are reliable from a data perspective, and of course, beyond.

Likewise, when courting potential vendors, a lack of transparency regarding any of the above issues should be a major red flag and lead to a re-evaluation of the relationship.

Business as usual in the data age

We live in an age where data security and privacy are not a “nice to have.” They are a must, especially because data itself is a must. So, if organizations want to operate in the global economy safely and successfully, they must make data-related issues a top priority. This applies to both their internal data procedures and those of their vendors.

By asking the right questions and ensuring that their partners are as dedicated to data compliance as they are, organizations can earn the peace of mind that their business operations are fully up to standard and compliant.

Assaf Eisenstein is cofounder and President of Lusha.

DataDecisionMakers

Welcome to the VentureBeat community!

DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

You might even consider contributing an article of your own!

Read More From DataDecisionMakers

Read More
Assaf Eisenstein, Lusha

Latest

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Newsletter

Don't miss

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Hyperliquid News: HYPE Whales Unstake Millions as Protocol Revenue Tops $1.21 Billion

Hyperliquid is drawing attention after large HYPE holders unstaked millions of tokens, including one wallet that withdrew 1.02 million HYPE and another that transferred 1.89 million HYPE worth about $105.9 million to institutional brokers, a move often associated with over-the-counter sales. Despite the whale activity, the protocol generated $1.18 million in daily fees and burned

‘Sabah is open for business’: Hajiji courts investors with promise of sustainable growth, carbon‑negative credentials

Sabah is pitching itself as an Asia-Pacific hub for impact investing, betting that its forests, biodiversity and natural resources can become drivers of economic growth as it seeks private capital for sustainable development. — Picture by Firdaus Latif By Julia Chan First Published: Monday, 13 Jul 2026 11:44 AM MYT KOTA KINABALU, July 13 —

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...