netnet-logo 2
  • Home
  • who we are
  • What we do
  • How we do it
  • who we serve
  • Resources
    • Win(win)
    • Contact us
    • Blog
    • Newsletter Archive
    • White Papers
    • Case Studies
    • Video Library
    • News
Contact Us
  • There are no suggestions because the search field is empty.
facebook
Vector
icons8-twitter-24 (1)
Group

GDPR: An Opportunity for SSM (Strategic Supplier Management)

avatar

Tjeerd Edelman

Apr. 27,2018 | Security, GDPR, SSM - Strategic Supplier Management

Many client executives are currently working to become compliant with the new General Data Protection Regulation (“GDPR”).  The GDPR regulation goes into effect on 25 May, 2018, and while GDPR is a European Union regulation, it is expected to be implemented worldwide due to its wide reaching or near universal regulatory umbrella.

Around 20 years ago, pretty much all data was stored in the corporate datacenter. Today, that data could be in multiple locations, stored on the edge in branch offices as well as in the public cloud. Critically, Personal Identifiable Information (“PII”) could exist outside primary systems. GDPR represents “the law catching up with the digital world”.

GDPR identifies the following actors:

  • Data Controller – A controller is an entity that decides the purpose and manner that personal data is used or will be used.
  • Data Processor –  The person or group that processes the data on behalf of the controller. Processing is obtaining, recording, adapting or holding personal data.

An Ernst & Young 2018 Global Forensic Data Analytics Survey found that with respect to readiness for GDPR, respondents indicated only 33% have an established plan for GDPR compliance, with another 39% signifying they are familiar with GDPR.

The new regulation requires much tougher controls over what your third-party suppliers do with employee and customer personal data. GDPR requires that both controllers and processors know where the personal data is located for storage and processing. They will share equal liability, and this has data processors scrambling to determine how best to make sure that the data their customers are putting on their servers is properly protected. In addition, data controllers must assess whether the security measures of their Cloud providers meet GDPR requirements by conducting periodic audits. And to make it even more complex, the same applies to a processor using a sub-processor. 

It’s true the amount of Strategic Supplier Management (“SSM”) work that is needed to become GDPR compliant is significant, but there are also opportunities including a) demonstrating how a well-managed and structured approach to SSM adds value to an organization, b) raising the profile of SSM as GDPR is a board level issue and c) realizing compliance with SSM policies more widely.

With an emphasis on suppliers, GDPR makes data a SSM opportunity and priority:

  1. Get to know your data - Map the flows of personal data through supply chains to identify the recipients of personal data, including sub-processors and where the personal data is processed.
  2. Identify contract risk areas - Identify supplier contracts that involve the processing of personal data and review the data protection provisions. These are unlikely to cover all the provisions that must now be included under the GDPR.
  3. Update contracts - The financial and reputational risks posed by the regulation may change the risk profile of the supplier, leading to a different approach to liability for data protection and data security breaches. Breaches can include charges of up to €4 million or 4% of company revenue (whichever is higher)!  Seems reason enough for clients to demand and ensure compliance.
  4. Look at processes - Carry out adequate due diligence on new suppliers, starting in the RFx process, to check their GDPR compliance, obtain guarantees regarding the measures that suppliers have in place and ensure there are rights of audit within the contract together with the other mandated data processing provisions.
  5. Monitor compliance - This isn’t a one-time event: clients need to think about ongoing SSM, including audits and spot checks.

As the cover of The Economist’s May, 2017 issue proclaims, “The World’s Most Valuable Resource is No Longer Oil, but Data”, its importance to business will only increase. The GDPR rules are very complex, but NET(net)’s advice is not to be overwhelmed by them or to see GDPR as your enemy.  

NET(net) predicts protracted contractual negotiations with IaaS, PaaS and SaaS suppliers as the Data Processor will try to wrangle a shift in liabilities back to you, the Data Controller. NET(net) can help support you in minimizing that risk.

A PwC Pulse survey shows that 88% of companies expect to invest $1 million to meet requirements and another 40% expect to spend more than $10 million. And this is to get ready, however, getting ready is just the beginning.  GDPR is not a single, one-time event.  GDPR requires continuous active monitoring, and a visible, proactive SSM program. Through WIN(win), NET(net)’s proprietary platform, we provide capabilities to sustain value and ongoing compliance through Supplier Performance Management of your Agreements, Investments, and Relationships.

A November 2017 report published by Technology Law Alliance reveals that just 18% of companies will be ready for the introduction of the General Data Protection Regulation. Whether you belong to the 18% that is ready or the 82% that are not, GDPR should be viewed as an opportunity to improve your understanding, to renegotiate your agreements, and to build better procurement processes to safeguard and future proof your technology supply chain. GDPR puts strategic supplier management back in the forefront, and NET(net) has the capabilities you need to ensure your agreements include appropriate GDPR protections. Through NET(net)’s proprietary platform, WIN(win), and access to the Performance portal, clients are able to perform Strategic Supplier Management, including proactive ongoing management for GDPR.  NET(net) can help you manage these strategic supplier agreements to minimize cost and risk while maximizing the realization of value and benefit.

Contact us here and we’ll arrange a call with one of our Subject Matter Experts who can immediately assess your situation.

Click below to see how clients use WIN(win) to proactively track and monitor GDPR compliance, as well as their other ongoing contractual obligations:

 

 
 
 
Video Thumbnail
Video Thumbnail
 
 
Click for sound
 
 
 
 
 
 
 
 
 
 
 
 
 

 

 

About NET(net)

Celebrating 15 years, NET(net) is the world’s leading IT Investment Optimization firm, helping clients find, get and keep more economic and strategic value. With over 2,500 clients around the world in nearly all industries and geographies, and with the experience of over 25,000 field engagements with over 250 technology suppliers in XaaS, Cloud, Hardware, Software, Services, Healthcare, Outsourcing, Infrastructure, Telecommunications, and other areas of IT spend, resulting in incremental client captured value in excess of $250 billion since 2002. NET(net) has the expertise you need, the experience you want, and the performance you demand. Contact us today at info@netnetweb.com, visit us online at www.netnetweb.com, or call us at +1-866-2-NET-net to see if we can help you capture more value in your IT investments, agreements, and relationships.

NET(net)’s Website/Blogs/Articles and other content is subject to NET(net)’s legal terms offered for general information purposes only, and while NET(net) may offer views and opinions regarding the subject matter, such views and opinions are not intended to malign or disparage any other company or other individual or group.

Read similar posts below

By Fred Teekens - Mar. 27,2025

European Tech Leaders Mitigating Geopolitical Risk

READ MORE
By Andrea Alterman - Apr. 29,2021

Top 10 HCM HRMS Suppliers for 2021

READ MORE
By Dave Young - Feb. 27,2020

Security Operations Center: Insource or Outsource to MSSP?

READ MORE
Top12ReasonsWhyHealthcareProvidersPayWAYtOOMuchforIT-2-1

Top 12 Reasons Why: Healthcare Providers Pay WAY TOO Much for IT

Download Free PDF
Top10WaystoDefendYourselffromanOracleAudit-2

Top 10 Ways to Defend Yourself from an Oracle Audit

Download Free PDF
SLS5WaysToManageMicrosoft

SLS 5 Ways To Manage Microsoft

Download Free PDF
Top_7_reasons_Youre_Overpaying _Microsoft - 2017

Top 7 Reasons You’re Overpaying Microsoft – 2017

Download Free PDF
SupplierLockInRisk

Supplier Lock In Risk

Download Free PDF
SLSTheComplianceGambit

SLS The Compliance Gambit

Download Free PDF
SLSMicrosoftLargeAccountResellers

SLS Microsoft Large Account Resellers

Download Free PDF
SLSHiddenFinancialOpportunityinMicrosoft

SLS Hidden Financial Opportunity in Microsoft

Download Free PDF
OverpayingforTelecommunications

Overpaying for Telecommunications

Download Free PDF
OutsourcingGovernanceGuidelines

Outsourcing Governance Guidelines

Download Free PDF
OutsourcingAgreementCrisis

Outsourcing Agreement Crisis

Download Free PDF
OracleThirdPartySupport-1

Oracle Third Party Support

Download Free PDF
cover-book

The Two Greatest Threats to the Banking Industry - Part I: The Case for the Digital Bank

Download Free PDF
OptimizePersuasiveness

Top 12 Reasons Why: Healthcare Providers Pay WAY TOO Much for IT

Download Free PDF
DCSDisasterRecoveryPlanning-1

DCS Disaster Recovery Planning

Download Free PDF
AnInsideLookatSalesforce

An Inside Look at Salesforce

Download Free PDF
MOST POPULAR

image
Top 20 Mainframe Software Suppliers
Steven Zolman
image
Guide: Selecting the Right Microsoft LSP (Licensing Solution Partner)
Scott Braden
image
Top 5 Technology Research Services Firms for 2022
Steven Zolman

Companies overpay average 40% on IT services. Do you?

Learn More
footer logo

Sign up to receive updates

  • Who we are
  • What we do
  • How we do it
  • Who we serve
  • Ethics

  • Resources
  • Contact us
  • Blog
  • Newsletter Archive
  • White Papers
  • Case Studies
  • Video Library
  • News
  • Facebook
  • Instagram
  • twitter
  • linkedin

+1 616.546.3100

info@netnetweb.com

Copyright © 2026 Netnetweb. All Rights Reserved