Skip to content
BOL Conferences
Thread Options
#1024562 - 08/20/08 09:48 PM ITPP - Vendor contracts
Dave M_TCA Offline
Platinum Poster
Dave M_TCA
Joined: Oct 2000
Posts: 686
Wherever my most benevolent em...
When reviewing vendor contracts for identity theft protections, could we consider protections for safeguarding of customer information (ie. GLB) as sufficient or should we require specific identity theft safeguard language as part of our agreements?
_________________________
David J Mulkerin, CRCM
All opinions expressed are mine and not those of my employer and are not to be taken as legal advice.

Return to Top
#1048120 - 09/23/08 03:11 PM Re: ITPP - Vendor contracts Dave M_TCA
YosemiteSamIAm Offline
Power Poster
Joined: Jan 2004
Posts: 2,795
Guess
I am taking the position that the GLB protections in our vendor agreements are sufficient to cover identity theft.
_________________________
Sorry, did I just use my outside voice?

Return to Top
#1048451 - 09/23/08 05:48 PM Re: ITPP - Vendor contracts YosemiteSamIAm
Bullseye Offline
Platinum Poster
Bullseye
Joined: Jan 2004
Posts: 968
Originally Posted By: Coloradomountainman
I am taking the position that the GLB protections in our vendor agreements are sufficient to cover identity theft.


Glad to hear. So are we.

Return to Top
#1058990 - 10/06/08 06:32 PM Re: ITPP - Vendor contracts Bullseye
rcbcomply Offline
New Poster
Joined: Jul 2008
Posts: 6
Colorado, would you mind sharing your wording on this (i.e. how did you justify your reliance on GLB in your policy/program)? Thanks!

Return to Top
#1059190 - 10/06/08 08:20 PM Re: ITPP - Vendor contracts rcbcomply
KAT Offline
Platinum Poster
Joined: Aug 2004
Posts: 986
Massachusetts
We will be looking for new contracts to specify the id theft specifically but now are using GLBA reliance.

Return to Top
#1066170 - 10/16/08 11:20 PM Re: ITPP - Vendor contracts KAT
Dolly Nugent Offline
Diamond Poster
Dolly Nugent
Joined: Nov 2000
Posts: 1,820
Southern California
Supposedly, your core processor should have a program to detect, prevent and mittigate identity theft that they can provide to you. Has anyone obtained one from their processor?

Secondly, for all other service providers, we need to consider how they could contribute to identity theft. A good example that was brought up a a seminar I attended was a tri-merge vendor that was not passing along fraud alerts from all the credit bureaus they collected information from to a bank.

I'm looking for more examples of how a vendor might contribute to identity theft. Does anyone have another example?

Also, WHICH vendors will you be requiring a Red Flag covenant from?

I've talked to several of my peers and it seems like this part of the program is still confusing to many of us. I'm not confident that we can rely on the GLBA safeguarding language to satisfy this requirement.
_________________________
Dolly Nugent
CRCM
Opinions expressed are my own.

Return to Top
#1068229 - 10/22/08 12:03 AM Re: ITPP - Vendor contracts Dolly Nugent
dg Offline
Platinum Poster
Joined: Jan 2005
Posts: 811
Pacific NW
We were thinking of adding an addendum to our already third party service proveder contracts and mailing those out annually. But what would the addendum wording include?

Return to Top
#1073609 - 10/30/08 04:36 PM Re: ITPP - Vendor contracts rcbcomply
Seven11Eleven Offline
Junior Member
Seven11Eleven
Joined: Dec 2006
Posts: 30
Originally Posted By: rcbcomply
Colorado, would you mind sharing your wording on this (i.e. how did you justify your reliance on GLB in your policy/program)? Thanks!


At this time we have decided to do the GLB reliance approach, but we are curious if anyone has wording to share.

Return to Top
#1076405 - 11/04/08 10:42 PM Re: ITPP - Vendor contracts Seven11Eleven
luvflipflops Offline
100 Club
Joined: Nov 2005
Posts: 150
on a beach somewhere
I am curious too!

Return to Top
#1080950 - 11/13/08 12:54 AM Re: ITPP - Vendor contracts luvflipflops
Moman Offline
Platinum Poster
Joined: Jul 2004
Posts: 505
WA
Most contracts we reviewed also have language that supports "future regulatory requirements". We felt comfortable with that plus GLBA language.

Return to Top