The European General Data Protection Regulation (GDPR) goes into effect on May 25, 2018 and covers U.S. companies in many instances. There is no ramp-up period and compliance is required on day one. A critical component of GDPR is establishing a meaningful vendor contracting and compliance process. GDPR is a game-changer for vendor compliance and penalties are substantial-up to 4% of a violating company’s total global annual turnover or €20 million, whichever is higher. Sourcing, compliance and legal professionals accountable for vendor management must understand and take action on GDPR. Although it is complex, GDPR compliance is possible with a focus on practical, risk-based, action-driven solutions. This session will outline GDPR requirements and the tools needed to comply.
- How to determine whether GDPR applies to you and your vendors
- What GDPR requires for covered vendors, including vendor contracting, diligence and information security requirements
- How to risk-rate your vendors and use these ratings to prepare a practical approach to compliance
- The key elements of an Internal Action Plan for GDPR vendor compliance
Categories: 2017 Fall - Carlsbad, Summit Presentations
SRC Type: Risk Management, Sourcing Management