Opening Scene
A traveler’s passport gets checked more than once on a single trip: at departure, on arrival, sometimes again at a connecting checkpoint run by an entirely different agency. Each checkpoint is a separate opportunity for something to go wrong, and the traveler’s overall safety depends on every single one of them doing its job properly, not just the first. Personal data passes through an equally long chain of checkpoints once it leaves an organization’s own systems — every vendor, subprocessor, and partner it touches along the way.
In Plain English
Vendor and third-party privacy risk is the exposure an organization inherits from every external party that touches its personal data, extending well beyond direct vendors to their own subprocessors, and sometimes several layers deeper still. A data processing agreement, covered earlier in this series, establishes the legal obligation, but it doesn’t by itself confirm the vendor is actually capable of meeting it — that requires ongoing vendor risk assessment, checking a vendor’s actual security practices, subprocessor list, and breach history rather than trusting the contract’s language alone. The core lesson privacy teams have learned repeatedly is that a company remains accountable for its data even after that data has legally and contractually left its hands.
The Old Way
Before vendor privacy risk was treated as a distinct, ongoing discipline:
- Vendor evaluation for privacy purposes often stopped at signing the data processing agreement, with little follow-up verification that the vendor’s actual practices matched what the contract promised.
- Subprocessor chains beyond the first-tier vendor were frequently invisible to the original company, since contracts rarely required detailed, updated disclosure of every downstream party touching the data.
- A vendor’s breach was often discovered by the company relying on it only after public disclosure, rather than through any proactive monitoring relationship.
Treating vendor risk as an ongoing relationship to actively manage, not a contract to file away, is what this discipline set out to establish.
What’s Changing (and Why AI Is the Reason)
- Vendor privacy risk assessment has become a recurring, scheduled activity at many organizations rather than a one-time gate at onboarding, often paired with periodic security questionnaires and audits.
- This connects directly to the vendor security assessment practices covered in this content library’s dedicated access control and data security series, since privacy risk and security risk from a shared vendor are really two views of the same underlying exposure.
- AI vendors have added a genuinely new dimension to this risk, since a vendor providing a foundation model or embedding service may retain or learn from submitted data in ways that traditional vendor questionnaires were never designed to probe, requiring privacy teams to ask fundamentally different questions than they would of a traditional SaaS vendor.
The Metaphor, Fully Extended
| Checkpoints Along a Multi-Leg Journey | Vendor and Third-Party Privacy Risk |
|---|---|
| Each connecting checkpoint run by a different agency along the route | Each vendor and subprocessor handling data along its journey through an organization’s systems |
| A traveler’s overall safety depending on every checkpoint doing its job, not just the first | An organization’s privacy exposure depending on every vendor’s practices, not just its own |
| A travel agency verifying each leg’s checkpoint standards before booking | A company assessing each vendor’s actual security and privacy practices before engaging them |
| Ongoing monitoring of a route’s safety record, not just a one-time booking check | Ongoing vendor risk assessment, not just a one-time contract signature |
For Beginners: What to Actually Do
- Learn to ask, for any service you use, who its data actually gets shared with beyond the company you directly signed up with.
- Understand that a signed contract between two companies doesn’t guarantee the vendor’s actual practices match what it promises.
- Notice how many subprocessors a typical privacy policy discloses, and treat a longer list as a genuinely longer chain of risk.
For Practitioners and Leaders: The Deeper Layer
- Build a recurring vendor privacy risk assessment process rather than treating the initial DPA signature as the end of due diligence.
- Coordinate vendor privacy assessments with the security assessment practices covered in this content library’s dedicated access control and data security series, treating them as a shared review rather than duplicated effort.
- Develop a specific due diligence questionnaire for AI vendors that probes data retention and model training practices directly, since standard SaaS vendor questionnaires typically don’t cover this ground.
Quick Recap
- Vendor and third-party privacy risk extends an organization’s exposure to every party that touches its data, including subprocessors several layers deep.
- A signed data processing agreement establishes legal obligation but doesn’t confirm actual vendor practices.
- Ongoing, recurring risk assessment has replaced one-time contract review as the standard approach.
- AI vendors require new due diligence questions around data retention and model training that traditional vendor reviews don’t cover.
Where This Fits in the Series
Article 16 covered compliance strategies for smaller organizations. Article 18 looks at how the growing weight of these obligations — DPIAs, breach timelines, vendor assessments, and data subject requests — is increasingly being handled through automation rather than manual process alone.
Subscribe to the Newsletter
Get the latest DataParables articles delivered straight to your inbox.