4.4 Vendors, Cloud, DPAs, and Third-Party Sharing
Key Takeaways
- I.C PI2 expressly tests vendor risk management, data processing agreements, cloud-computing requirements, third-party sharing, and incident response for ransomware and vendor incidents.
- FTC Start with Security and the GMR Transcription matter require selecting capable providers, putting security and use limits in the contract, and monitoring performance — the company remains responsible.
- A cloud host is a CCPA service provider only if a written contract actually prohibits sale, share, secondary use, and combining; a right to train advertising models on customer files can convert the disclosure into a sale or share.
- A CIPP/US-ready DPA addresses use limitation, deletion or return, subprocessor notice and flow-down, audit or assessment rights, and prompt breach notice.
- A ransomware event at a payroll or fundraising vendor is still the company's incident; Blackbaud-style vendor breaches do not erase the business's notice and program duties.
4.4 Vendors, Cloud, DPAs, and Third-Party Sharing
The second half of I.C PI2 is where CIPP/US stops being theoretical. Know vendor risk management, data processing agreements, requirements for cloud computing, third-party data sharing, and incident response programs for cyber threats such as ransomware and vendor incidents. If the last section was the org chart, this section is the invoice: almost every modern processing activity has a vendor on it.
Vendor risk management
A vendor program is a lifecycle, not a signature.
- Identify. The PI inventory and the flow map produce the candidate list. Shadow IT — a marketer's unsanctioned form tool, an engineer's personal notebook instance — is still a vendor if PI landed there.
- Classify. What PI will the vendor see? Is it confidential, restricted, California sensitive personal information, HIPAA PHI, or GLBA NPI? Higher classification means deeper diligence.
- Diligence. Security questionnaire, independent audit report (SOC 2, ISO 27001), breach history, subprocessors, data-location options, and whether the vendor's own product documentation admits secondary uses such as model training or advertising.
- Contract. The data processing agreement (DPA) or CCPA service-provider / contractor addendum. Diligence without paper is a conversation. Paper without diligence is a hope.
- Monitor. FTC Start with Security is blunt: take reasonable steps to select providers able to implement appropriate security, put the standards in the contract, and monitor that they meet them. The GMR Transcription matter is the official classroom example. The company sent sensitive audio files to transcription vendors without contractual security requirements; the files appeared on the public internet. The FTC's lesson is "put it in writing" and follow up — not "blame the vendor and close the file."
- Exit. Deletion or return certification, key revocation, and removal from the inventory.
The company remains responsible to consumers and to regulators for PI it chose to hand over. Outsourcing processing does not outsource accountability.
Cloud and the shared-responsibility model
Cloud computing does not move the legal role onto the provider by magic. It splits operational security:
| Layer | Typical provider duty | Typical customer duty |
|---|---|---|
| Physical data center, hypervisor, core network | Provider (especially IaaS) | Customer verifies region and certifications |
| Platform services, managed database | Shared on PaaS | Customer configures identity, encryption, logging |
| Application, tenant settings, data classification | Customer on SaaS | Customer decides what PI goes in and who has accounts |
| Identity, keys, sharing links, retention | Almost always customer | Misconfigured buckets are the customer's incident |
Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) change the split but not the legal question. The legal question is still: does the contract limit the provider to the customer's business purpose, or may the provider use the PI for its own products?
A locked-down object store in a chosen U.S. region, with encryption keys the customer holds and a contract that prohibits sale, share, secondary analytics, and advertising, is the textbook service provider. The same brand of cloud, with a checkbox that lets the provider train foundation models on customer content or inject the content into an advertising graph, is a third-party disclosure as to that extra use. The exam will give you the contract term, not the logo.
Contractual requirements that make a DPA real
Whether the document is titled DPA, business-associate agreement, or CCPA addendum, I.C expects these operative clauses:
| Clause | What it must do | Why it is on the exam |
|---|---|---|
| Use limitation | PI only for specified business purposes; no sale, no share, no commercial secondary use | Creates service-provider / contractor status; implements purpose limitation |
| Deletion or return | Delete or return PI at the end of services, including backups on a documented cycle | Supports consumer deletion and retention limits |
| Subprocessors | Advance or prompt notice, flow-down of the same restrictions, and a right to object where the deal allows | A silent chain of subprocessors is an unmapped external flow |
| Audit / assessment | Manual review, scans, or technical and operational testing; CCPA contractor language contemplates monitoring at least once every 12 months | FTC monitoring lesson; contractor statutory element |
| Breach notice | Prompt notice to the customer, with enough facts to meet multi-state and sectoral notification clocks | Vendor ransomware is still the customer's incident |
HIPAA business associate agreements, GLBA Safeguards Rule service-provider provisions, and COPPA operator-to-vendor terms add sectoral overlays. A hospital that stores PHI in a cloud with only a commercial SaaS click-through, and no business associate agreement, has a HIPAA problem and an I.C vendor problem.
CCPA service provider versus contractor versus third party is the same table as in 4.2, applied to the invoice. A payroll processor that receives employee files from the company under a use-limited contract is a service provider. A staffing firm that the company invites into its HR system to screen candidates, and that certifies the statutory restrictions and accepts 12-month monitoring, is a contractor. A data broker that buys the employee file to enrich its own products is a third party, and the disclosure is a sale if valuable consideration runs either way.
When is a cloud host a service provider, and when is the upload a sale? Status follows the contract and the facts. Storage "on behalf of" the business, for the business purpose of hosting, with the statutory prohibitions, is a service-provider disclosure and is carved out of sale/share. Hosting plus a license for the provider to use customer content to improve an advertising network is a disclosure to a third party for valuable consideration (cheaper storage, better ads, or both) and can be a sale; if the same identifiers are used for CCBA, it is also a share. Relabeling the order form "DPA" without those prohibitions does not convert the third party into a service provider.
Ransomware and vendor incidents
BoK 2.6.1 names the fact patterns on purpose. Ransomware that encrypts a payroll file, a clinic backup, or a fundraising database is a security incident and, depending on exfiltration and state definitions, a breach. If the system belongs to a vendor, it is still your processing. The playbook must include: contain and preserve, determine what PI was involved from the inventory, read the DPA notice clause, assess multi-state and sectoral notification (and any attorney-general or regulator notice), decide on consumer notice, and treat the vendor as a control failure that needs contract remedies and possibly replacement.
Paying a ransom does not make the event "not an incident." It may create separate sanctions-compliance issues, but it does not erase privacy duties. A vendor's public-relations statement that "no customer data was confirmed stolen" is not a legal determination. The business has to verify scope.
The FTC's Blackbaud matter (announced 2024) is a current vendor-incident teaching example: a widely used donor and administrative platform was charged over safeguards for the large volume of personal data it held for clients. The exam point is not the penalty number. It is that a concentration-risk vendor can create a single incident that becomes every customer's incident, and that regulators will examine both the vendor's program and the customers' vendor-management program.
Worked scenario. A regional hospital uses a cloud electronic-health-record host under a business associate agreement and a CCPA-style use-limitation addendum. Ransomware hits the host. The host delays notice for three weeks. The hospital's inventory shows which clinics' PHI sat in the affected tenant; the DPA required notice within 72 hours of confirmation. Correct moves: activate the incident plan, press the contractual notice and audit rights, assess HIPAA breach notification and state medical-privacy duties, communicate with patients when the facts support it, and document why the hospital selected and monitored that host. Incorrect moves: wait for the host's marketing blog, assume cloud equals "their problem," or argue that a ransomware event cannot be a breach because the files were encrypted by the attacker. I.C scores the hospital that owns the vendor incident, not the hospital that outsources the narrative.
A company stores California customer files in a major cloud object store. The contract lets the cloud vendor use those files to train its own advertising models. How should counsel classify the relationship as to that secondary use?
Which contractual package does I.C expect in a data processing agreement with a vendor that handles personal information?
Ransomware encrypts a payroll vendor's systems that hold the company's employee Social Security numbers. Which statement is exam-correct?