Sector wise readiness
Supply chain and vendor risk: outsourcing does not transfer accountability
- Does sharing data with a vendor pass your responsibility to them?
- No. Engaging a processor does not pass your responsibility to it. You remain answerable for processing carried on for you, and you must oversee it actively, whatever sector you are in.
- Who this affects
- Every organisation sharing data with a cloud provider, payroll vendor, agency or analytics tool.
- What to do about it
- Contract every vendor, know your sub processors, and treat this as the layer that sits on top of your sector map.
The final post in this series, and the one that applies to every organisation that has read any of the others.
Because whatever sector you are in, you share personal data with someone else. A cloud provider, a payroll vendor, an agency, an analytics tool. That makes this the cross cutting layer that sits on top of every sector map in this series.
And it starts with the principle people most often get wrong.
Outsourcing does not transfer accountability
Engaging a processor does not pass your responsibility to it. You remain answerable for processing carried on for you, and you must oversee it actively. "Our vendor handles that" is not a defence.
What this layer requires, on top of your sector baseline
- ✅ Know your vendor chain, including the vendors your vendors rely on. Deep vendor mapping is audit best practice rather than an express statutory register, but it is the practice auditors expect on multi layer chains.
- ✅ Extend safeguards through contracts. Under Section 8(2) a processor may act only under a valid contract with you, and the security duty in Section 8(5) and Rule 6 reaches it through that contract. Carrying the same security and breach cooperation terms down to sub processors is the recommended safeguard.
- ✅ Agree in advance who starts the 72 hour clock. If a downstream vendor detects a breach first, settle now who detects, who escalates and who reports. Not during the incident.
- ✅ Watch for purpose creep. If a vendor uses your data beyond your instructions, for its own analytics or model training, it may itself become a Data Fiduciary for that processing, and that can expose you. Oversee for it.
The auditor's red flag, and the reason this post exists
Sub vendors several tiers down are often invisible. That is exactly where breaches hide, and where the 72 hour clock can quietly run out while nobody upstream knows anything has happened.
Across 28 sectors, one theme repeated more than any other. The gap was almost never a missing product. It was an unmapped relationship, an unwritten contract, or an assumption that someone else was handling it.
The better question, and the one this whole series has been building towards
Not "does this requirement exist in my sector?"
But "have I actually triggered it, and can I show who is accountable for it?"
Law creates obligations. Scale and risk influence implementation. Confusing the two is how organisations spend on tools they do not need while missing the basics.
That is the series. All 28 sectors, mapped, with statutory obligations separated from audit expectations and tooling suggestions.
If a sector you care about deserves a deeper look, tell us and we will take it.