#security (2024-08)

Archive: https://archive.sweetops.com/security/

2024-08-01

Soren Jensen avatar
Soren Jensen

Anyone who has a Data Security Questionnaire they can share with me for 3rd party services processing data with AI? I need some inspiration and assurance that I’m covering the basics in our questionnaire

1
Soren Jensen avatar
Soren Jensen

Also feedback on my draft questionnaire is very welcome.

Jonathan Eunice avatar
Jonathan Eunice

Question 1: You might want to ask something about subprocessors. Your vendor may not use your data to train models, but if your vendor’s vendors do…

1
Jonathan Eunice avatar
Jonathan Eunice

Unfortunately this concern with transitive effects, while valid and probably important, compounds the effort to ask, answer, and consume such questionnaires enormously. Some customers ask us for procedures 3 level deep (not just what we do, or our vendors do, but the vendors to our vendors, the “4th party” providers). It’s…a lot.

Jonathan Eunice avatar
Jonathan Eunice

Not sure I’d call GDPR and CCPA/CPRA data protection regs. Maybe “data protection and privacy”? They have a touch of data protection, but are more privacy regs (so they concern the protection of the data relevant to individuals, which becomes a very different kettle of fish to most other data protection concerns like encryption, availability, retention, secure deletion, …).

Jonathan Eunice avatar
Jonathan Eunice

But overall I would rate this a sensible and not too invasive questionnaire. Were that the majority coming our way were this concise and straightforward.

Soren Jensen avatar
Soren Jensen

Thanks a million @Jonathan Eunice appreciate the feedback. The sub-processors are definitely a miss, I will make sure to add that.

2024-08-08

2024-08-09

    keyboard_arrow_up