vendor contracts: what you need and what you may be missing

52
Dino Tsibouris (614) 360-3133 [email protected] Vendor Contracts: What You Need and What You May Be Missing

Upload: eldon

Post on 21-Feb-2016

27 views

Category:

Documents


0 download

DESCRIPTION

Vendor Contracts: What You Need and What You May Be Missing. Dino Tsibouris (614) 360-3133 [email protected]. Let’s just use our standard agreement and attach the proposal to it, we should be good to go!. What do you need to know?. Contracts, exhibits, schedules, letters, emails - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Vendor Contracts: What You Need and What You May Be Missing

Dino Tsibouris(614) 360-3133

[email protected]

Vendor Contracts: What You Need and What You May Be Missing

Page 2: Vendor Contracts: What You Need and What You May Be Missing

Let’s just use our standard agreement and attach the proposal to it, we should be good to go!

Page 3: Vendor Contracts: What You Need and What You May Be Missing

What do you need to know?

• Contracts, exhibits, schedules, letters, emails• Who is responsible for compliance• Consumer data privacy and security roles• Ownership of data• Minimum service and data availability• Indemnities, disclaimer of warranties,

limitation of liability

Page 4: Vendor Contracts: What You Need and What You May Be Missing

…is there more?

• Termination rights and retention and access to data

• Breach notification when it happens at the vendor

• Compelled Disclosure of your data on the vendor’s system

Page 5: Vendor Contracts: What You Need and What You May Be Missing

But I’m…

• Not a lawyer• Too busy to “go deep”• Not worried, it’s a small dollar contract• Pretty sure it’s already covered• Used to lawyers making things too

complicated

Page 6: Vendor Contracts: What You Need and What You May Be Missing

The problem: Words mean things

• Some words aren’t what they seem• The cost of a deal gone wrong is time and

money, not just money• Small processors of personal data can create

big liability (SMS/TCPA)• Your issue may not be covered• Lawyers can make it complicated but it

shouldn’t be

Page 7: Vendor Contracts: What You Need and What You May Be Missing

Description of Services

Agreement Schedule

Page 8: Vendor Contracts: What You Need and What You May Be Missing

Description of Services

Page 9: Vendor Contracts: What You Need and What You May Be Missing

Description of Services

Agreement Schedule

In the event of conflict, Schedule governs.

Page 10: Vendor Contracts: What You Need and What You May Be Missing

Description of Services

Agreement Schedule

When Agreement terminates, some of the services in the Schedule need not terminate.

Page 11: Vendor Contracts: What You Need and What You May Be Missing

Privacy and Security of Customer Data in the Cloud

Source: Ponemon Institute

Page 12: Vendor Contracts: What You Need and What You May Be Missing

Privacy and Security of Customer Data in the Cloud

Source: Ponemon Institute

Page 13: Vendor Contracts: What You Need and What You May Be Missing

Privacy and Security of Customer Data in the Cloud

Page 14: Vendor Contracts: What You Need and What You May Be Missing

Privacy and Security ofCustomer Data

Page 15: Vendor Contracts: What You Need and What You May Be Missing

Privacy and Security ofCustomer Data

Page 16: Vendor Contracts: What You Need and What You May Be Missing

Privacy and Security ofCustomer Data

Page 17: Vendor Contracts: What You Need and What You May Be Missing

Privacy and Security ofCustomer Data

• Data stored in the cloud may be compromised due to a breach

• Contract must take into consideration an obligation to immediately notify, cooperate, and bear the cost of sending out breach notifications and remedial actions

• Consider insurance for breaches

Page 18: Vendor Contracts: What You Need and What You May Be Missing

Breach Notification

• Vendor may have a breach involving your data• Must they tell you?• When?• What is your obligation to your customers?

Page 19: Vendor Contracts: What You Need and What You May Be Missing

Breach Notification

• Prompt breach notification of confirmed breaches and suspected breaches is crucial.

Page 20: Vendor Contracts: What You Need and What You May Be Missing

Audit Rights

• Data collection and usage• Security procedures/contract compliance• Financials • Timing and frequency• SAS 70/third party provided audits

Page 21: Vendor Contracts: What You Need and What You May Be Missing

Service and Data Availability

Page 22: Vendor Contracts: What You Need and What You May Be Missing

Service and Data Availability

Page 23: Vendor Contracts: What You Need and What You May Be Missing

Service and Data Availability

• The cloud service may be subject to disruptions

• Where possible, negotiate fines or reimbursement for outages above and beyond scheduled maintenance

• Where possible, contract for greater availability and fault tolerance

Page 24: Vendor Contracts: What You Need and What You May Be Missing

Termination Provisions and Retention and Access to Data

Page 25: Vendor Contracts: What You Need and What You May Be Missing

Termination Provisions and Retention and Access to Data

Page 26: Vendor Contracts: What You Need and What You May Be Missing

Termination Provisions and Retention and Access to Data

Page 27: Vendor Contracts: What You Need and What You May Be Missing

Termination Provisions and Retention and Access to Data

Page 28: Vendor Contracts: What You Need and What You May Be Missing

Termination Provisions and Retention and Access to Data

Lessons: • Ensure that ownership of information is clearly

defined. • Ensure that service provider agreement takes

into consideration your ability to access your data and return of your data in the form that you want at the end of the relationship.

Page 29: Vendor Contracts: What You Need and What You May Be Missing

Disposal of Data

• How does the contract address data return?• How does the contract address data disposal?• Ensure that service provider agreement takes

into consideration your legal obligations to dispose and delete information

Page 30: Vendor Contracts: What You Need and What You May Be Missing

Compelled Disclosure

Page 31: Vendor Contracts: What You Need and What You May Be Missing

Compelled Disclosure

Page 32: Vendor Contracts: What You Need and What You May Be Missing

Compelled Disclosure

• Data stored in the cloud is subject to compelled disclosure and possibly without your knowledge due to the Stored Communications Act and National Security Letters

Page 33: Vendor Contracts: What You Need and What You May Be Missing

Pertinent Laws and Compliance with Them

Page 34: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

Page 35: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

Page 36: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

Page 37: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

Page 38: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

Page 39: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

• Translink to "use due care in providing services covered by this Agreement" and to conduct its "performance of all services called for in this Agreement . . . consistent with industry standards.”

Page 40: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

• Merchant warrants and agrees that Merchant shall fully comply with all federal, state, and local laws, rules and regulations, as amended from time to time, including the Truth-in-Lending Act and Regulation Z of the Board of Governors of the Federal Reserve System.”

Page 41: Vendor Contracts: What You Need and What You May Be Missing

Shurland v. Bacci

Lesson: Parties should clearly and unambiguously assign the responsibility to comply with each law that is material to the transaction.

Page 42: Vendor Contracts: What You Need and What You May Be Missing

Indemnification

Page 43: Vendor Contracts: What You Need and What You May Be Missing

Indemnification

• The other side pays your costs if they are specifically named

• Claims• Losses• Reasonable attorney fees• Costs

Page 44: Vendor Contracts: What You Need and What You May Be Missing

Limitation of Liability

Page 45: Vendor Contracts: What You Need and What You May Be Missing

Limitation of Liability

• No liability • As-Is• Refund of fees paid• Capped dollar amount• Insurance proceeds only• “Direct damages” only

Page 46: Vendor Contracts: What You Need and What You May Be Missing

Yes, but…

Ensure that the limitation of liability clause and the indemnification clause properly interact with one another

“Shall indemnify … Subject to Section 20 (Limitation of Liability).”

Page 47: Vendor Contracts: What You Need and What You May Be Missing

Notice

• Abide by the Notice requirements of the Agreement.

Page 48: Vendor Contracts: What You Need and What You May Be Missing

Notice

Page 49: Vendor Contracts: What You Need and What You May Be Missing
Page 50: Vendor Contracts: What You Need and What You May Be Missing

Clarity takes time…

Page 51: Vendor Contracts: What You Need and What You May Be Missing

When should we start?

Page 52: Vendor Contracts: What You Need and What You May Be Missing

Questions & Answers

Dino Tsibouris(614) [email protected]