<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>vendor management Archives | INGCO International</title>
	<atom:link href="https://ingcointernational.com/tag/vendor-management/feed/" rel="self" type="application/rss+xml" />
	<link>https://ingcointernational.com/tag/vendor-management/</link>
	<description>When You Need To Speak To The World, We Help You Find Your Voice.</description>
	<lastBuildDate>Wed, 08 Apr 2026 14:41:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://ingcointernational.com/wp-content/uploads/2022/04/fav-icon-150x150.png</url>
	<title>vendor management Archives | INGCO International</title>
	<link>https://ingcointernational.com/tag/vendor-management/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>GDPR and Vendor Management</title>
		<link>https://ingcointernational.com/gdpr-and-vendor-management/</link>
		
		<dc:creator><![CDATA[Ingrid Christensen]]></dc:creator>
		<pubDate>Wed, 27 Jun 2018 13:07:04 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Cultural Dignity]]></category>
		<category><![CDATA[document translation]]></category>
		<category><![CDATA[Equal Access to Information]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Tech-Enabled Human-Led]]></category>
		<category><![CDATA[Translation Services]]></category>
		<category><![CDATA[vendor management]]></category>
		<category><![CDATA[website localization]]></category>
		<category><![CDATA[Wordologists]]></category>
		<guid isPermaLink="false">https://ingco.wpenginepowered.com/?p=6470</guid>

					<description><![CDATA[GDPR and Vendor Management: How to remain compliant? Companies can’t simply outsource the responsibility of data governance and privacy compliance to their vendors. Especially under...]]></description>
										<content:encoded><![CDATA[<p><strong>GDPR and </strong><strong>Vendor <span id="urn:enhancement-bf98ddb9-5d95-47c6-9b97-43790f2ee7a3" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">Management</span>: How to remain compliant?</strong></p>
<p>Companies can’t simply outsource the responsibility of data governance and privacy <span id="urn:enhancement-46bb8147-4b37-49bb-b072-78cde8d90c33" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/compliance">compliance</span> to their vendors. Especially under the new GDPR guidelines, companies have an obligation to conduct due diligence, have appropriate contract terms in place, and monitor the <span id="urn:enhancement-b2cac798-90b5-47e6-b733-095573282bab" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/services">services</span> provided by vendors to ensure they are processing data in accordance with applicable data protection regulations. If there is a violation or data breach caused by a vendor, your organization will be liable. GDPR and vendor <span id="urn:enhancement-a0231bd1-a5f7-4f00-a042-3c7108b85174" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> is essential to remain compliant.</p>
<p><strong>A framework for vendor <span id="urn:enhancement-4b645f32-11f3-4c20-886b-eb974cb98395" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> &amp; GDPR <span id="urn:enhancement-12e1502f-76c5-46f1-85fd-aaedfd923ae1" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/compliance">compliance</span>: people, process, technology &amp; metrics:</strong></p>
<ul>
<li>identify the right people</li>
<li>formulate a process for interfacing with vendors</li>
<li>leverage technology to manage the process</li>
<li>maintain solid metrics for internal and external <span id="urn:enhancement-a186bd38-9410-481c-a304-43b1fcf20d40" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/compliance">compliance</span> purposes</li>
</ul>
<p>&nbsp;</p>
<p><img decoding="async" class="alignleft size-thumbnail wp-image-6471" src="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-People-150x150.png" alt="GDPR Compliance and People" width="150" height="150" /><strong>People: </strong>A first step is to determine who in your organization should be engaged with vendor selection and vendor <span id="urn:enhancement-4d7f2da5-39d5-4c14-82e4-8a2730e1e0a6" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span>. Identify and assign someone to be accountable within each <span id="urn:enhancement-040e2f40-b0b1-4a6e-be9c-78a665eeb8a6" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/business">business</span> team that utilizes vendors. This will help identify the privacy champions who are responsible for complying with company policy on vendor <span id="urn:enhancement-4ebf1d94-e2cc-4efb-882a-d5a4aad6681c" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> and for evangelizing a culture of mindful sharing of data with vendors. While it’s great if you have a formal Vendor <span id="urn:enhancement-26eb419a-9e5e-4ba8-9afb-bcb8f3763a0c" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">Management</span> Office, the alternative may be a committee of stakeholders from the procurement/sourcing, legal, privacy, and security departments.</p>
<p>&nbsp;</p>
<p><img decoding="async" class="alignleft size-thumbnail wp-image-6472" src="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Process-150x150.png" alt="GDPR and process" width="150" height="150" /><strong>Process: </strong>It’s important to view vendor <span id="urn:enhancement-b226bc2d-2658-4a70-aada-0031eb40e009" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> as a life cycle. It begins with the <span id="urn:enhancement-a7296a5a-55b3-418c-b9f9-269c4f5c4617" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/strategy">strategic</span> choice of vendors and should include a formal intake process. A common misconception is that free or click-through terms are GDPR-safe. Wrong! Any processing of personal data by a third-party vendor must be in scope with a GDPR-compliant vendor-<span id="urn:enhancement-781dc0e7-780f-43fd-bd2b-55ac68685b09" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> process, regardless of the cost of the service offering. Another common misconception is that these obligations only apply to processors managing customer data. Wrong! Processors that manage a company’s employee data must also be in scope.</p>
<p>Defining appropriate contractual terms, conducting security reviews, and sponsoring ongoing maintenance and monitoring are part of the cycle. The goal is consistent <span id="urn:enhancement-b99d94b3-efe5-45bd-86df-bc01d01318fa" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/treatment">treatment</span> of data by the company and its processors to maintain <span id="urn:enhancement-bb64d81a-87c7-4f63-80b7-87a87761013c" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/compliance">compliance</span> with regulatory obligations and promises made to data subjects.</p>
<p>Global companies that are interested in cross-border transfer of information out of certain countries must also pay attention to outsourcing. The data protection regimes in <span id="urn:enhancement-6d5300fa-c4a1-4718-a008-006c6053b82b" class="textannotation disambiguated wl-place" itemid="https://data.wordlift.io/wl122819/entity/europe">Europe</span> require controllers to provide direction to and monitoring of their data processors. Additionally, acceptable mechanisms for cross-border transfers of data — including binding <span id="urn:enhancement-586d814e-cb88-430c-a56c-35b47f0a75b8" class="textannotation disambiguated wl-organization" itemid="https://data.wordlift.io/wl122819/entity/corporate">corporate</span> rules and the EU-U.S. Safe Harbor agreement—require companies to have adequate assurance that onward transfers of personal data will be protected by those providers and vendors. This level of assurance is also required in many of the new laws in the Asia-Pacific region, including the Australian Privacy Principles and Hong Kong’s Personal Data Privacy Amendment.</p>
<p>&nbsp;</p>
<p><img decoding="async" class="alignleft size-thumbnail wp-image-6473" src="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Technology-150x150.png" alt="GDPR and technology" width="150" height="150" /><strong>Technology</strong>: Ad hoc vendor inventory and contract record keeping is a recipe for disaster. Many companies struggle with compiling and maintaining a complete inventory of vendors and vendor contracts. This is especially true in organizations where there is no central repository of vendor contracts, or where <span id="urn:enhancement-29888848-d7bb-4f4b-9ca6-ad1c59f1be0a" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/business">business</span> teams may keep (or not) copies of vendor contracts locally. Ideally, you should create have a centralized system which will not only track vendor contracts but will also provide robust reporting to flag vendors who process personal data, flag vendor-use by geography and alert stakeholders of contract terms with upcoming renewal dates.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-6474" src="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Metrics-150x150.png" alt="GDPR and Metrics" width="150" height="150" /><strong>Metrics: </strong>With the right technology platform in place, your organization will have superior visibility into your vendor <span id="urn:enhancement-d0c2c119-3581-4274-a002-5d1302fd58eb" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> roadmap and should have no problem tracking progress and measuring milestones. This is key, because you will want to be able to create documentation which demonstrates <span id="urn:enhancement-e2b691d8-5740-41e3-898a-ac315e507ede" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/compliance">compliance</span> with GDPR.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Vendor <span id="urn:enhancement-de0729a1-d471-4b81-8b56-067d8c9caeb1" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> is a multi-faceted process that requires many steps to ensure <span id="urn:enhancement-14e8cd71-e88f-4818-9a10-e809ddcd2158" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/accuracy">accuracy</span> and <span id="urn:enhancement-83b366fa-fb23-45bd-9f7f-f6d5d683c706" class="textannotation disambiguated wl-thing" itemid="https://data.wordlift.io/wl122819/entity/consistency">consistency</span>. <a href="https://ingcointernational.com/what-we-do/translation-services/medical-translation/" target="_blank" rel="noopener">Translation</a> and <a href="https://ingcointernational.com/legal-interpreting/" target="_blank" rel="noopener">interpreting</a> providers also have a responsibility to ensure they are following the privacy protocols of GDPR. INGCO <span id="urn:enhancement-924de08f-c28a-4c14-b887-261fa5efbea3" class="textannotation disambiguated wl-person" itemid="https://data.wordlift.io/wl122819/entity/international">International</span> works hard to comply with GDPR requirements in relation to the <span id="urn:enhancement-fbf8a069-7aab-402b-af59-b587868e50bf" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> of all or our vendors as well as recognizing our responsibilities as a vendor to our clients. This blog is not intended as legal advice rather it is our current GDPR compliant process regarding vendor <span id="urn:enhancement-0d806168-f6e1-4957-b050-9bfa3341445f" class="textannotation disambiguated wl-creative-work" itemid="https://data.wordlift.io/wl122819/entity/management">management</span> and our intention to follow industry best practices. <a href="https://ingcointernational.com/contact-us/" target="_blank" rel="noopener">Contact us now to discuss your translation and interpreting needs and how we can help ensure your projects are GDPR compliant.</a></p>
]]></content:encoded>
					
		
		
		
		<media:thumbnail url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-People-150x150.png" />
		<media:content url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-People.png" medium="image">
			<media:title type="html">GDPR People</media:title>
			<media:thumbnail url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-People-150x150.png" />
		</media:content>
		<media:content url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Process.png" medium="image">
			<media:title type="html">GDPR Process</media:title>
			<media:thumbnail url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Process-150x150.png" />
		</media:content>
		<media:content url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Technology.png" medium="image">
			<media:title type="html">GDPR Technology</media:title>
			<media:thumbnail url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Technology-150x150.png" />
		</media:content>
		<media:content url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Metrics.png" medium="image">
			<media:title type="html">GDPR Metrics</media:title>
			<media:thumbnail url="https://ingcointernational.com/wp-content/uploads/2018/06/GDPR-Metrics-150x150.png" />
		</media:content>
	</item>
	</channel>
</rss>
