The Weakest Link in Internet Privacy: Security and Compliance Risks in Third-Party Vendor Data Handling
Keywords:
: Explainable AI, Cyberbullying, Real-Time NLP, Multi-Teacher Knowledge Distillation, XGBoost, SHAP, Emotion Detection, Sarcasm Detection, Multilingual NLP, conscious language use, symmetry principle, , positional labelling, computational linguistic encoding, syllable typology, formal notation system, rhythm-based phonology, meter and linguistic melody, ӭagyar MᲩa-siralom, Planctus ante nescia, speech processing, NLP., Compliance, Internet privacy, third-party vendors, data breaches, GDPR, CCPA, HIPAA, PCI DSS, vendor risk management, supply chain securityAbstract
The new internet economy relies on third-party sellers, such as cloud computing service providers, SaaS and services, payment processing services, and marketing services. On the one hand, such sellers make scaling and innovativeness possible, and, on the other hand, such sellers endanger the safety of personal data and the sanctity of the law. This paper discusses the vulnerabilities inherent to vendor ecosystems using case studies of the Target and SolarWinds breaches to provide examples of the weaknesses present in systems. It also talks about the regulatory frameworks such as GDPR, CCPA, HIPAA, and PCI DSS, and outlines the impediments to implementation and lapses in responsibility. This empirical study proposal of the best internet company practices on vendor risk is provided to contribute to benchmarking in this under-researched field. Lastly, there are technical safeguards, organizational measures and policy recommendations, and finally a call to a global Vendor Privacy Assurance Standard. The results show that vendors are the least strong link in privacy protection, and that there is a need for concerted efforts across the industry, regulators, and academia.
References
(2020) California Consumer Privacy Act (CCPA). https://oag.ca.gov/privacy/ccpa
(2014) The Target data breach. https://www.csis.org/analysis/target-data-breach
(2020) Schrems II judgment (C-311/18). https://curia.europa.eu
(2020) AA20-352A: SolarWinds compromise. https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a
(2021) Alert: Compromise of Codecov. https://www.cisa.gov
(2021) Good practices for supply chain cybersecurity. https://www.enisa.europa.eu/publications/good-practices-for-supply-chain-cybersecurity
(2016) General Data Protection Regulation (GDPR). https://gdpr-info.eu
(2022) Business associate agreements. https://www.hipaajournal.com/business-associate-agreements
(2023) Cost of a data breach report 2023. https://www.ibm.com/reports/data-breach
(2017) ISO/IEC 27036: Information security for supplier relationships.
J. Isaak, M. J. Hanna (2018) User data privacy: Facebook, Cambridge Analytica, and privacy protection. 51(8), 56-59. https://doi.org/10.1109/MC.2018.3191268
N. Kshetri (2021) The economics of third-party cyber risks. 23(5), 45-51. https://doi.org/10.1109/MITP.2021.3103798
(2022) Cyber supply chain risk management practices for systems and organizations (SP 800-161 Rev. 1).
(2021) API security top 10. https://owasp.org/API-Security
(2022) PCI DSS standards. https://www.pcisecuritystandards.org
S. Pearson, A. Benameur (2010) Privacy, security and trust issues arising from cloud computing. 693-702. https://doi.org/10.1109/CloudCom.2010.66
(2022) Vendor risk management maturity model (VRMMM). https://sharedassessments.org/store/vrmmm
(2020) Former Seattle technology company software engineer indicted for computer fraud and abuse, wire fraud, and access device fraud. https://www.justice.gov
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Authors and Global Journals Private Limited

This work is licensed under a Creative Commons Attribution 4.0 International License.
