惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
罗磊的独立博客
The GitHub Blog
The GitHub Blog
L
LangChain Blog
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
DataBreaches.Net
宝玉的分享
宝玉的分享
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
N
Netflix TechBlog - Medium
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
H
Help Net Security
美团技术团队
大猫的无限游戏
大猫的无限游戏
雷峰网
雷峰网
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog

Latest blog posts

Finding Solutions for Data Bias | Demyst Using Snowflake for External Data Deployment | Demyst 5 Hurdles Facing New Financial Products | Demyst The What, Why, and How of External Data | Demyst Fast Company Recognizes How External Data Can Change the World | Demyst 5 Checks for Flagging Fraud Risk | Demyst External Data’s Tipping Point | Demyst OpenCorporates Spotlight: Data Transparency Deep Dive | Demyst Looking Ahead: High Expectations, Low Margins for Error | Demyst How Lenders and Insurers Can Use Geolocation Data | Demyst Assessing Driver Risk Without Using Credit Scores | Demyst Digital Footprints for ID Verification | Demyst Layered Solutions to Fight SMB Lending Fraud | Demyst Global IDV Workflows Demand Multi-Source Solutions | Demyst Fintechs: Drifting into Compliance Failure? | Demyst Penalties Mount for Marketers Using Toxic Data | Demyst Assess Insurance Risk with Property Data | Demyst Application Prefill: A Digital Reality | Demyst Demand for ESG Data is Accelerating | Demyst Demyst’s Entity Resolution: Multi-Source Recipes | Demyst Verifying Phone Numbers Is Key for the BNPL Vertical | Demyst Game Changer: Demyst’s Entity Resolution Tech | Demyst Social Inflation Raises Courtroom Risks | Demyst Expecting the Unexpected | Demyst Meet Demyst at AWS re:Invent 2021 | Demyst External Data Addresses Crypto Regulations | Demyst Supply Chain Risk Management | Demyst Collaboration with AWS Data Exchange | Demyst Improving Trust on Managed Platforms | Demyst Risk Management: Diving Deeper | Demyst
Vendor Due Diligence for Data Privacy | Demyst
Demyst Team · 2022-02-22 · via Latest blog posts

Companies that want to become data-sharing masters must manage that data carefully. When performing due diligence on a new data provider, it’s not enough to review representations and warranties while hoping for the best — Chief Data Officers (CDOs) must ask detailed questions to understand how external data sources operate. 

There are five key areas to consider when reviewing data providers.

Sourcing Practices 


Find out whether a provider has automated processes in place for collecting data, and understand their policies and practices for automation.
 

The provider may be using government records, publicly available sources, third-party records, or information collected from individuals, which each have their own implications for managing consent and implementing privacy policies. 

Even publicly available data can provide sensitive personal information that may be subject to regulatory oversight. Ask whether providers regularly receive data subject requests and whether and how they are prepared to respond to them. 

Lawful Purpose


Consent processes may be influenced by the data provider’s
lawful reasons for processing personal data. Whenever a provider claims that its collection of personal data is supported by a lawful reason, then that claim should be reviewed. 

Consent Policies


If a provider’s lawful basis for processing personal data is based on consent, Ask questions to examine that process: 

  • Is the consent language clear — does the provider explain what they are collecting and sharing and why?
  • Has the provider clearly described an individual’s legal rights under relevant jurisdictions?
  • Do individuals actively provide their consent, or is consent assumed by default? Do individuals need to take additional steps to prevent their data from being collected?
  • Can an individual withdraw consent, and how does the provider respond to that request?

The actual mechanisms for acquiring consent also matter. Individuals should give consent freely and affirmatively, after being informed of their rights, as opposed to assuming that they have given consent based on their participation in a survey or registration for a service.

When data providers are reviewed for inclusion in the Demyst platform, the main considerations are whether consent was obtained, whether that consent was informed and freely given, and what process was used to obtain it. 

Reviewing and Renewing Relationships


Data privacy regulations are continuing to be updated, and due diligence needs to be an ongoing process that responds to these regulatory changes. And data providers should be able to explain how they are adapting their business processes to comply with changing regulations.

Any company onboarding new data sources must not only inspect the provider’s current data collection practices, they must also review those practices at regular intervals in the future. 

Data Supply Chains


When a data provider aggregates data from other sources, or relies on other organizations to collect its data, then those collection practices should be considered.

It may not be possible to trace collection practices all the way back to the source of the data, but asking a provider about its own due diligence processes can reveal unexpected risks in the data supply chain. 

This Is No Substitute for Legal Advice


The due diligence process will be different for each data provider; data privacy regulations involve too many variables for a simple checklist. Extra care is necessary when dealing with topics like sensitive personal information, criminal information, and information pertaining to children. 

Ultimately, companies onboarding new data providers will need to make their own risk assessments after receiving legal advice from qualified attorneys. And they will need to update those risk assessments as their business relationships continue. 

This is what the future will look like for external data — any organization that wants to benefit from greater insights data must either make substantial investments in data capabilities or work with a partner who already has those capabilities. 

The Demyst platform works with data providers that meet stringent qualifications while reducing the friction associated with external data procurement, testing, and deployment. Certified providers in the Demyst data ecosystem are asked more than 150 questions for a detailed understanding of their privacy policies. 

Browse the catalog to learn more about the data sources available through Demyst.