Beyond the Contract: Are Third-Party Risks Your Weakest Link?

2026-08-04
Article Banner

Vendor risk is the modern data ecosystem’s weakest link, accounting for a staggering 60% of data breach cases reviewed by Singapore's Personal Data Protection Commission (PDPC) in 2025. 

The second panel discussion of the Singapore Data Festival 2026 titled, ‘Beyond the Contract: Are Third-Party Risks Your Weakest Link?’, moderated by Gail Wong, Assistant Commissioner, PDPC Singapore, with guests Vandit Bhatia, Director, Security & Resilience, PwC Singapore; Chua Ying-Hong, Director, HealthTech Policy Division, Ministry of Health Singapore; Stamford Low, Director, Customer Experience and Retail & Data Protection Officer, M1 Limited; and Tony Cheung, Compliance and Data Protection Director, Whyze Solutions, examined how organisations can actively address this potential Achilles' Heel.

The Illusion of the Contract and the Visibility Gap

The root of this vulnerability lies in the contractual agreements that offer a false sense of security provided by legal contracts. As organisations scale at speed towards AI capabilities and data governance focuses on dynamic versus static data, the pertinent question is, “Where is your data stored, and do you know how this data flows?” 

Risk management continues long after contracts are set, and ongoing operational guardrails need to be established. During the initial onboarding phase, companies typically conduct rigorous risk assessments of their Data Intermediaries, but as Bhatia noted, over time, processes and activities change and companies may lose visibility of what information the vendors hold. Also, organisations must also verify whether a third party has actually purged sensitive data upon completion of a task.

Human error and technical oversights on the vendor's end can also contribute to blind spots. Chua highlighted that risks often stem from "misconfigurations”, for instance, when “your IT vendor fails to conduct adequate testing before deployment of code”, or when user organisations fail to "implement the MFA [multi-factor authentication] that it requires" on a given SaaS solution. 

The Hidden “Fourth-Party” Threat in Your Supply Chain

When evaluating a potential vendor, one of the most critical questions to ask is whether the Data Intermediary utilises their own downstream Data Intermediaries. Low notes that vendors rarely process everything in-house, and may route your data to fourth parties or utilise upstream AI systems to process it, entirely stripping the original organisation of its data visibility. Thus, both Bhatia and Chua recommend that business leaders explicitly demand reassurance that their sensitive data is not being logged or utilised for downstream AI model training. 

Mitigating these risks requires active scrutiny, and Low offered a pragmatic workaround for DPOs. "Vendors are typically hesitant to open up their operations to an external party coming in to do an audit. So we work around it by saying that we're coming to have an on-site visit,” he said, noting that a conference call with overseas vendors serves the same purpose. He explained that the word ‘audit’ has a very bad connotation, and framing it as a visit helps "keep the engagement going, not just at the point when the contract is being signed but also through the life cycle of the contract".

Rethinking Incident Response 

Even with robust vendor management, breaches remain an operational inevitability. When a vendor is compromised, they are instantly swamped by inquiries from a multitude of panicked clients, leaving individual organisations struggling to determine exactly what data was lost and who to contact. Thus, Bhatia emphasises that defining your "points of contacts escalation matrix becomes really important" to avoid critical delays in containment and recovery. 

Chua offered an essential piece of advice for surviving a vendor breach. "Prepare for the scenario where all your systems are down, and this means that your incident response plan cannot only sit in your systems". Maintaining a securely stored, offline copy of key contact numbers and escalation matrices ensures that leaders are not paralyzed during an infrastructure-wide outage.

Cheung emphasised that the primary goal in those initial moments is to contain the breach to prevent further data from being compromised, before gathering forensic evidence.

Containment is only step one. True operational resilience requires recovery as well. Here are some of the recovery strategies suggested by the panelists:

Rebuilding Clean Systems: Eradicate malware, ensure original systems are entirely clean and secure, and then safely restart your technology stack.

Diversifying Vendor Concentration: You can distribute your operational risk by avoiding single points of failure. Keep alternative providers on standby to keep your business running if your primary vendor suffers an outage.

Continuous Testing: Routinely run simulated breach exercises with key vendors. Annual tabletop exercises for data breaches are essential, as Low emphasised, and Data Intermediaries are actively invited to participate.

Actionable Takeaways 

Your security perimeter is only as strong as your vendor’s weakest link. To safeguard critical data assets, organisations must move beyond static annual checklists toward active, risk-based governance: maintaining continuous visibility over third- and fourth-party data flows, enforcing shared operational accountability, and practicing joint incident response before a crisis strikes. 

To ensure your organisation isn't exposed by its weakest links, the panel recommended implementing these steps immediately:

Classify and Review: Low advises organisations to rate their Data Intermediaries based on the amount and type of personal data that they're processing. Focus on their highest-risk vendors on an annual basis minimally, and periodically check on their data protection and retention stances. This helps you to ensure that the Data Intermediary is “as good as they were at the time when you first appointed them.”

Map the Data Flow and Identify Downstream Risks: Building on your annual review of your highest-risk vendors, look past compliance checklists and ask your vendors directly, "Where are you storing our data and do you know how this data flows?" Extend your assessment to ask if they are employing any downstream parties.

Communicate Internal Changes to Maintain Accountability: Vendor risk management is a two-way street that relies on shared operational accountability. Cheung urges organisations to consistently communicate with their vendors on their future plans, because uncommunicated internal shifts (e.g. changes in process owners, departments) can severely compromise the effectiveness of your shared defense and accountability matrix.




Unlock these benefits
globe

Get access to news, enforcement cases, events, and actionable tips and guides

email

Get regular email updates and offers

job

Job opportunities, mentorship and career guidance

discuss

Exclusive access to Data Protection community - ask questions, network and share knowledge with peers and experts via WhatsApp and Linkedin

Topics
Related Articles