When your clients rely on you for processing personal data, you should also be aware of the fact that they are relying on you to ensure that they can comply with applicable privacy laws. For example, your clients may be using your spam prevention tool on their forms, which collects IP addresses and tracks the behavior of website visitors. Your clients may be sharing names and addresses with you so that you can ship their products for them. They may use your email service to get an email whenever someone submits a contact form on their website.
As a small business or even a medium-sized business, your clients cannot build these tools on their own, which is why they are relying on your services. As you are processing this personal data on their behalf, they are also relying on you to provide accurate information as to what personal data you are processing, how you are processing it, who you are sharing it with and other privacy-related information so that they can disclose this information to their website visitors. This article is partly a rage post after having to conduct privacy vendor due diligence and partly advice for vendors on how to provide the right privacy information to your clients for whom you are processing personal data.
Provide Separate Privacy Information
Many vendors have one Privacy Policy that combines the privacy information for their own website and for their products or plugins. While this makes the vendor’s life easier (as there’s only one policy to update), it does make it significantly more difficult for their clients to understand the privacy information. For example, if the Privacy Policy states that names, emails, phone numbers, and IP addresses are collected, it is impossible to determine whether this personal data is being collected by the vendor’s website or by the vendor’s products as the website and the products are being combined under one policy.
The best practice would be to have one policy with multiple sections that outline the privacy information for the website and then outline it separately for the products or to have separate policies entirely for each. For example, MainWP accomplishes this by having a Privacy Policy for their website and then having a separate Privacy Policy for the MainWP Child Plugin. Having separate policies makes it extremely easy for customers to quickly find the relevant privacy information based on what they are using.
Provide a Data Processing Agreement
A Data Processing Agreement between you (the vendor) and your client on how you will be processing the data and the rights and responsibilities of both parties as it relates to that data. A DPA may be required under certain privacy laws such as the General Data Protection Regulation. Many vendors do not have a DPA at all and many of those who do ask clients and potential clients to reach out to them to request the DPA. Having to reach out to each vendor to request a DPA wastes valuable time and resources, and some companies will not work with a vendor if no DPA is available. This is why it is recommended to have a publicly available DPA that can easily be found on your website – so that your clients can check off this requirement and move on.
Provide a Separate Contact Method for Questions
Many companies provide a contact method for consumers to exercise their privacy rights, which is required by law. However, this does not take into account that businesses have privacy questions for their vendors that do not fit into the “I am exercising my privacy rights” mold. For many businesses performing vendor due diligence, reaching out to the privacy rights email will mean that they get a reply for exercising privacy rights, which is not an appropriate reply for a business reaching out with privacy questions or concerns. Thus, it is best to create a dedicated email inbox that can be used for these types of questions or adapt the privacy rights inbox to include the possibility that a business may reach out while performing vendor due diligence.
Test Your System
If you currently have a system for processing privacy questions and privacy requests, make sure to test that system by going through it yourself. When someone submits a privacy question, they should, at the most, receive one automated email stating that their request has been received and is being processed. After that, trained personnel should take over to ensure that they provide the answers to the questions and that your company appropriately takes any action if needed.
Train Your Staff
There should be dedicated staff whose responsibilities include processing privacy rights requests and answering privacy questions. Some larger companies have an attorney on staff for this job but, if your company is smaller and can’t afford that, regular support staff should be trained on how to answer privacy-related questions and requests. There is nothing worse than reaching out to a company with a simple privacy question and being told “I don’t know”. The person replying to such questions should know the answer to these questions or should loop in someone who does.
Answer the Questions Being Asked
Below are some examples of the less than satisfactory responses that I have received from businesses while asking basic privacy due diligence questions:
- Please read our Privacy Policy (with a link to the Privacy Policy). Unfortunately, this is the most common response. However, this response is not helpful when the person conducting the due diligence has already read the Privacy Policy and the Privacy Policy does not answer their questions or combines privacy information from their website with the privacy information for their products. This response also makes the client spend valuable time re-reading the Privacy Policy to try to prove to the vendor that their Privacy Policy does not actually answer their questions. The vendor would save the client a lot of time and frustration by just answering the questions outright, instead of just linking to their Privacy Policy. Please note that this example does not include a scenario where all of the questions are answered separately and then a link to the Privacy Policy is included at the bottom of the email due to compliance requirements to include it;
- Please use this link to exercise your privacy rights. Unfortunately, this is a pretty common response as well. This response is also not helpful as a person conducting vendor due diligence is not asking to exercise their privacy rights;
- We are waiting for our attorney to return from vacation next week and then we’ll reply to your questions. This could be a fair response if an actual response to the questions came in a week. However, in my experience, a response like this usually means that no actual response is coming (as the vendor does not actually have this information);
- We cannot disclose this information to you. This response acts as if knowing what personal data their tools are collecting, how that data is being used, and who it’s being shared with is some type of a closely guarded trade secret. However, according to GDPR, it is not as it’s required for data processors to provide this information. This is especially infuriating when the client asking the vendor this question is not a competitor of the vendor, simply someone trying to use their products;
- You need to sign up for an enterprise plan to gain access to this information. Privacy laws such as GDPR require this information to be provided to all data controllers, regardless of how much money they are paying to the vendor. This response is unhelpful as it pay walls privacy information and requires the client to sign up for extremely expensive plans that they do not need just to gain access to basic privacy information;
The above list provides the most common responses that I have received in response to privacy questions (that are not actually helpful). However, I do want to note that every once in a while, there are truly egregious responses to these questions. Responses such as “this is not our product” (where it actually is), 75 automated replies in the span of 3 hours with a link to their Privacy Policy, and signing the client up for email marketing without consent even though the only contact has been an email to the privacy email address have happened.
Many businesses have to conduct vendor due diligence before they work with a vendor. For companies that are not required to do so, they may do so anyway because it’s just the best way to ensure that they are working with reputable vendors that do not create compliance and operational risks. If the first interaction they’ve had with a potential vendor is “we don’t answer privacy questions”, “this is not our product”, “you need to sign up for an enterprise plan”, etc., you just lost a client. For most products, there are many vendor options in the marketplace and clients will select one that is easy to work with and forthcoming with answers to their questions. Thus, all vendors should take the tips above seriously and fix their privacy programs to make everyone’s lives easier. And also, props to the vendors that do actually answer these questions in a timely manner with no push back – this makes it significantly easier to choose that vendor as the preferred provider.