Skip to content

For Legal, Privacy, Security and Third-Party Risk

Vendor data-risk negotiation resources.

Plain-English, source-linked guides for teams building a governed workflow for recurring vendor data-risk terms.

Operational guide

DORA ICT third-party contract requirements

A negotiation-oriented overview of contractual controls that regulated teams may need to operationalise for ICT third-party arrangements.

Read the guide →

Operational guide

UK GDPR processor contract requirements

A practical overview of recurring processor-contract terms that can be routed through a customer-approved DPA playbook.

Read the guide →