HomeNewsIndia NewsIT Procurement Methods to be adjusted to avoid GDPR Fines

    IT Procurement Methods to be adjusted to avoid GDPR Fines

    Gartner, Inc. said many organizations are still not compliant with GDPR legislation even though it has been in force since May 2018. This is because they have not properly audited data handling within their supplier relationships. Sourcing and vendor management (SVM) leaders should, therefore, review all IT contracts to minimise potential financial and reputation risks.

    “SVM leaders are the first line of defense for organizations whose partners and suppliers process the data of EU residents on their behalf,” said Yanni Karalis, research director at Gartner. “If you don’t have clarity on your organization’s role with regards to personal data handling, you have to urgently address this”, he added.

    GDPR imposes many requirements on data processors. These requirements include obligations to process personal data only on instructions from the controller, to inform the controller if it believes said instruction infringes on the GDPR, to notify data controllers of data breaches without undue delay, and to restrict personal data transfer to a third country unless legal safeguards are obtained.

    The following non-exhaustive list is a great starting point for SVM leaders to set out expectations and requirements around GDPR in new contract negotiations:

    • Definitions : Ensure definitions in your contracts reflect the revised definitions in the GDPR.
    • Data breaches : If a data breach occurs, the vendor should notify you without delay after becoming aware of the breach. The vendor should be required to cooperate, investigate and remediate the breach. The vendor must also assist with any notifications required and work with the appropriate authorities.
    • Data security: Assess if you need to use special measures such as encryption. Consider if you need to implement “data protection by design.”
    • Data processing :Set up the vendor’s data processing to allow for the fulfilment of data subject requests. For example, all information that is necessary to demonstrate a vendor’s compliance with its processing obligations should be made available to you. All data processing activities that a vendor performs for you should be documented.
    • Vendor cooperation : The vendor needs to support any audits that you perform or a third party performs on your behalf to verify the vendor’s GDPR compliance. The vendor must support any data protection impact assessments that you conduct.
    • Dealing with fines : Per the vendor’s risk profile, consider if you need to modify the indemnities, limits of liabilities and other similar clauses to hold the vendor appropriately accountable for noncompliance with the legislation.
    ELE Times Research Desk
    ELE Times Research Deskhttps://www.eletimes.ai
    ELE Times provides a comprehensive global coverage of Electronics, Technology and the Market. In addition to providing in depth articles, ELE Times attracts the industry’s largest, qualified and highly engaged audiences, who appreciate our timely, relevant content and popular formats. ELE Times helps you build awareness, drive traffic, communicate your offerings to right audience, generate leads and sell your products better.

    LEAVE A REPLY

    Please enter your comment!
    Please enter your name here

    Related News

    Must Read

    Decision Tree Learning Architecture Definition, Types and Diagram

    Decision Tree Learning's architecture is a tree-like, hierarchical structure...

    Top 10 Reinforcement Learning Applications and Use Cases

    One of the most intriguing areas of machine learning...

    How TVS Electronics is Transforming Digital India with “Make in India” AIDC

    In the fast-paced world of digital transformation, Automatic Identification...

    Lotus Microsystems and EDOM Technology Form Strategic Distribution Partnership to Expand Presence Across APAC

    Distribution Partnership to Expand Presence Across APAC Lotus Microsystems ApS,...

    Tata–Merck MoU to Accelerate Chip Manufacturing Infrastructure in India

    Tata Electronics Private Limited has signed a strategic Memorandum...

    UP Electronics Policy Draft to Boost Smartphone and Electronics Manufacturing

    The Uttar Pradesh government has introduced a draft policy...

    Semicon India 2025: PM Modi Says India’s Semiconductor Revolution Will Shape Global Future

    Prime Minister Narendra Modi inaugurated Semicon India 2025, positioning...

    Career Opportunities for Women in India’s Electronics Industry

    In the heart of India’s rapidly transforming digital economy,...