<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GDPR Compliance of 3rd parties ... a What-If scenario in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/6126#M244</link>
    <description>I fully agree with John and you will have to renegociate your contract according to EU contractual clause for processors ....</description>
    <pubDate>Sat, 03 Feb 2018 12:56:05 GMT</pubDate>
    <dc:creator>leroux</dc:creator>
    <dc:date>2018-02-03T12:56:05Z</dc:date>
    <item>
      <title>GDPR Compliance of 3rd parties ... a What-If scenario</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/5897#M227</link>
      <description>&lt;P&gt;As part of my GDPR work, I'm looking at vendors &amp;amp; suppliers and the data that they have access to&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With respect to Article 28 - (&lt;A href="http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L:2016:119:FULL&amp;amp;from=EN" target="_blank"&gt;http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L:2016:119:FULL&amp;amp;from=EN&lt;/A&gt;), I understand the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject,”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also understand that “Controllers” must detail in written contracts how their “processors” are going to handle this customer data"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is ... imagine a third party supplier / vendor states they are NOT GDPR compliant and have NO plans to comply, and existing contracts were drawn up before GPDR came into force.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I'm reading this correctly, my company is then liable, or at least jointly liable in the event of a GDPR breach involving the third party.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 11:47:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/5897#M227</guid>
      <dc:creator>Del</dc:creator>
      <dc:date>2018-02-01T11:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Compliance of 3rd parties ... a What-If scenario</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/5906#M231</link>
      <description>&lt;P&gt;Yep.&amp;nbsp; Most contracts have an exit clause in case the third-party cannot meet the technical and/or regulatory requirements of the customer.&amp;nbsp; Even if you don't, you can break the contract and I don't know if there's a moderator out there who wouldn't side with you.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:59:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/5906#M231</guid>
      <dc:creator>John</dc:creator>
      <dc:date>2018-02-01T14:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Compliance of 3rd parties ... a What-If scenario</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/6126#M244</link>
      <description>I fully agree with John and you will have to renegociate your contract according to EU contractual clause for processors ....</description>
      <pubDate>Sat, 03 Feb 2018 12:56:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/6126#M244</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2018-02-03T12:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Compliance of 3rd parties ... a What-If scenario</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/6990#M290</link>
      <description>&lt;P&gt;In short, do not use them if your company plans to stay in compliant. Seek others who are more willing to work with you reducing regulatory risks.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 08:34:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Compliance-of-3rd-parties-a-What-If-scenario/m-p/6990#M290</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2018-02-06T08:34:09Z</dc:date>
    </item>
  </channel>
</rss>

