Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Third-Party Data Access: Your Pre-Breach ChecklistPrivacy & Data Governance
5 min readFor Third-Party Risk Managers

Third-Party Data Access: Your Pre-Breach Checklist

A jury recently found that Meta willfully misled the public on 26 occasions regarding data privacy, hate speech, misinformation, and its investigation of third-party app developers after the Cambridge Analytica scandal. This verdict highlights a crucial point for you and your team: your vendors' access to customer data creates liability you can't simply delegate away.

This checklist is designed to help you establish essential controls before any third party accesses personal information. Each item reflects a completed or not completed control state. If you can't check the box, you're carrying unmitigated risk.

What This Checklist Covers

This checklist focuses on the foundational controls needed when third parties access, process, or store personal data on your behalf. It emphasizes contractual commitments, technical safeguards, and oversight mechanisms that must be in place before data flows to an external party.

It doesn't cover post-breach response or ongoing vendor monitoring. Those require separate protocols. This is your pre-engagement gate.

Prerequisites

Before using this checklist, confirm:

  • You've documented what personal data the third party will access.
  • You have a business justification for the data sharing.
  • You've identified the legal basis for processing (consent, contract performance, legitimate interest).
  • Your legal team has reviewed applicable data protection laws in all relevant jurisdictions.

If you can't confirm these four points, stop. You're not ready to onboard this vendor.

Checklist Items

1. Contract includes data processing terms that specify permissible use

Your agreement must clearly state what the third party can and cannot do with the data. Generic "confidentiality" language isn't enough.

Good looks like: A schedule or exhibit listing data categories, permitted processing activities, and prohibited uses (such as no re-identification, no sale to data brokers, no use for independent marketing). The vendor acknowledges they're acting as a processor, not a controller.

2. Contract prohibits unauthorized sub-processing

The third party must get your written approval before engaging their own vendors to handle your data.

Good looks like: A clause requiring advance notice (typically 30 days) before adding any sub-processor, with a named list of current sub-processors attached as an exhibit. You retain the right to object on reasonable grounds.

3. Contract includes Individual Participation Principle assistance obligations

When individuals exercise rights (access, deletion, correction), your vendor must help you respond.

Good looks like: A service-level commitment to respond to your requests within a defined timeframe (often 10 business days), with a documented process for handling access, deletion, and correction requests.

4. Technical access controls limit data exposure to authorized personnel

Not everyone at the vendor company should see your customer data.

Good looks like: Role-based access controls documented in the vendor's system design, with evidence that only personnel performing the contracted service can access the data. Bonus: named individuals on an access list you can audit.

5. Encryption protects data in transit and at rest

Data moving between your systems and the vendor's must be encrypted. Data sitting in the vendor's database must be encrypted.

Good looks like: TLS 1.2 or higher for data in transit. AES-256 or equivalent for data at rest. The vendor provides a technical specification document confirming both.

6. Vendor has completed a security assessment within the past 12 months

You need independent validation of their security posture.

Good looks like: A SOC 2 Type II report, ISO 27001 certificate, or equivalent third-party assessment dated within the last year. If the vendor is too small for formal certification, accept a completed security questionnaire with evidence (screenshots, policy documents) for critical controls.

7. Data retention and deletion obligations are contractually defined

The vendor must delete or return data when the relationship ends, or when you request it.

Good looks like: A clause specifying maximum retention periods tied to the business purpose, with a commitment to delete or return data within 30 days of contract termination. Include audit rights to verify deletion.

8. Breach notification timeline is contractually binding

You need to know about incidents quickly enough to meet your own notification obligations.

Good looks like: A requirement that the vendor notify you within 24 to 48 hours of discovering a data breach affecting your data, with details on what data was involved and what happened.

9. Vendor maintains cyber liability insurance

Insurance won't prevent a breach, but it shows the vendor takes risk seriously and provides a recovery mechanism.

Good looks like: Evidence of cyber liability coverage with limits appropriate to the data volume and sensitivity (typically $1 million minimum for vendors handling significant personal data). You're named as an additional insured or loss payee.

10. You have documented the vendor's geographic data storage locations

Data protection laws vary by jurisdiction. You need to know where data physically resides.

Good looks like: A written statement from the vendor listing all countries and regions where your data will be stored or processed, including cloud provider regions. If data crosses borders, confirm you have appropriate transfer mechanisms (Standard Contractual Clauses, adequacy decisions).

11. Vendor provides evidence of employee data protection training

The humans accessing your data need to understand their obligations.

Good looks like: Training records showing that employees with data access completed privacy and security training within the past 12 months. The training should cover confidentiality, secure handling, and incident reporting.

12. Audit rights are clearly defined and exercisable

You must be able to verify the vendor's compliance.

Good looks like: A contractual right to audit the vendor's data protection practices annually, either through your own audit team or a third-party assessor. If the vendor objects to on-site audits, accept the right to review SOC 2 reports and request answers to detailed questionnaires.

Common Mistakes

Assuming "confidentiality" equals data protection. Confidentiality clauses protect business secrets. Data processing terms protect individuals. You need both, and they're not interchangeable.

Accepting vendor paper without negotiation. Standard vendor terms almost never include adequate data protection provisions. You will need to negotiate. Start early.

Skipping technical validation. Contracts matter, but they don't encrypt databases. Ask for architecture diagrams and technical evidence, not just legal promises.

Treating all vendors the same. A vendor with read-only access to anonymized data needs different controls than a vendor processing payment card information. Calibrate your requirements to the actual risk.

Forgetting about sub-processors. Your vendor's vendors are your problem too. The Cambridge Analytica incident involved a third-party app developer, not Meta's direct employees. Map the full chain.

Next Steps

After you complete this checklist:

  • Document your findings in your vendor risk register.
  • Set calendar reminders for annual re-assessments (insurance renewals, security certifications, training records).
  • Establish a process for reviewing sub-processor notifications when they arrive.
  • Create a playbook for what happens if the vendor notifies you of a breach.

If you found gaps on this checklist, don't onboard the vendor until you close them. The legal exposure from unauthorized data use or inadequate security isn't hypothetical. It's a jury question about whether you acted willfully.

Data Protection and Privacy Legislation

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like