Third-Party Data Sharing Is Disclosed. It Is Not Controlled

Privacy notices disclose that data is shared with third parties. Data processing agreements govern how those parties are permitted to use data.

RCDr. Richard Chingombe · Founder, Verisq·8 min read·Practitioner perspective, not legal advice

Neither the notice nor the contract controls what third parties actually do with the data once it is shared. Control over third-party data handling requires more than disclosure and contractual commitment. It requires monitoring, verification, and operational governance that most programs have not built.

Why This Matters Now

Third-party data sharing is one of the highest-risk activities in enterprise data operations. Data shared with a third party leaves the organization's direct operational control. The third party's data handling practices, security posture, subprocessor relationships, and regulatory compliance are determined by the third party, not by the data-sharing organization.

The governance response has been contractual: execute data processing agreements that specify permitted uses, required security measures, and compliance obligations. These contracts are necessary and legally required. They are also dependent on third-party compliance that most organizations do not operationally monitor.

A data processing agreement creates a legally binding commitment about how data will be handled. It does not create operational control over how data is actually handled. The gap between contractual commitment and operational reality is the third-party data sharing governance gap.

The Governance Problem Beneath the Surface

Third-party data sharing governance programs are typically structured around contracting and documentation. These are necessary governance activities. They address the legal framework for the sharing without addressing the operational reality of what happens to the data at the third party.

Monitoring third-party data handling requires audit rights that most organizations have negotiated but few have exercised, technical monitoring of data flows at third-party destinations, and ongoing vendor assessment programs that most organizations conduct on annual cycles that cannot detect handling changes between assessments.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

What This Actually Means in Enterprise Practice

Third Parties Process Beyond Contracted Permissions

DPA obligations that restrict data use to specified purposes create a contractual constraint. Whether that constraint is respected in practice depends on the third party's operational compliance culture, the technical mechanisms they have built to enforce permitted use restrictions, and the monitoring they have implemented to detect compliance failures.

Subprocessor Chains Are Not Monitored

Third parties that receive shared data routinely use subprocessors for processing functions. Whether those obligations are effectively imposed, whether subprocessors comply, and whether the subprocessor chain introduces jurisdictional exposure or security risk are questions that the original DPA does not address operationally.

The data shared with a third party may be processed by a chain of subprocessors that the data-sharing organization has never assessed, has no contractual relationship with, and cannot monitor. The DPA creates an obligation that extends through the chain. The governance visibility does not.

Security Certifications Are Point-in-Time

Third-party security certifications including ISO 27001 and SOC 2 Type II demonstrate that a security management program was assessed and met the relevant standard at certification time. They do not demonstrate the third party's current security posture or that security measures applied to shared data are currently adequate.

Audit Rights Exist and Are Not Exercised

DPAs regularly include audit rights that allow the data-sharing organization to assess third-party compliance. These rights are rarely exercised. The operational cost of conducting meaningful audits and the complexity of exercising audit rights against larger technology vendors create practical barriers.

How Different Teams See This: Where They All Miss

LegalExecuting DPAs that create contractual obligations on third parties. Not monitoring whether those obligations are being met operationally.
TPRMAssessing third-party risk at onboarding and annual review cycles. Not monitoring operational data handling practices between assessments.
PrivacyDisclosing third-party sharing in privacy notices. Not monitoring what third parties do with shared data.
Information SecurityAssessing third-party security posture through questionnaires and certifications. Not monitoring security practices specific to shared data handling.

Third-party data governance requires operational monitoring that no single team owns. The contracting team creates the obligation. No team verifies that the obligation is met.

Framework Control Reference

The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.

GDPR | Article 28(3)(h)Processors must make available all information necessary to demonstrate compliance and allow for and contribute to audits. The customer's right to verify compliance exists. Exercise of that right is the customer's governance responsibility.
GDPR | Article 5(2)Controller accountability requires that compliance with data protection principles can be demonstrated. Third-party compliance with DPA obligations is part of the controller's accountability requirement.
NIST CSF 2.0 | GV.SC-06Supplier relationships and third-party risks are understood and managed. Third-party data sharing governance is within scope of supply chain risk management.
ISO 27701 | Clause 8.5.7Agreements with third-party PII processors must be documented and compliance must be monitored. Monitoring is an explicit requirement, not just documentation.
CCPA / CPRA | Civil Code 1798.100(c)Service provider agreements must require that the service provider comply with applicable sections of the CPRA. The business must confirm the service provider is complying with its obligations.
NIST Privacy Framework | Govern-P 6.1Privacy risk from third-party data relationships is managed through contractual and other mechanisms. Active management, not just contracting, is required.

These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.

The Enterprise Reality Gap

The enterprise third-party data sharing reality gap is the space between contracted data handling obligations and verified operational compliance with those obligations. The gap grows with the number of data-sharing relationships and the time since the last substantive compliance assessment of each relationship.

Every third-party data-sharing relationship for which a DPA exists but no operational monitoring has been conducted is a relationship where the governance assurance rests entirely on the third party's good faith compliance with contractual obligations that have not been independently verified.

Enterprise Scenario

The setupA consumer brand shares customer purchase data with a marketing analytics vendor under a DPA that restricts use to analytics services for the brand and prohibits use for the vendor's own products or for other customers.
What was discoveredA competitor marketing analytics vendor releases a new audience targeting product with unusual accuracy for the consumer brand's customer demographics. An internal analysis suggests the product may have been informed by data matching the profile of the shared data. The vendor denies any misuse. The consumer brand has no monitoring capability to verify the claim.

The DPA prohibited the use. The monitoring to verify compliance was not built. The potential misuse was not detected by any governance process. It was inferred from a competitor's product release. The governance gap was not in the contract. It was in the absence of any operational mechanism to verify that the contract was being honored.

Industry Signal

Enforcement actions involving third-party data misuse have found that organizations with DPAs in place could not demonstrate whether the DPAs were being honored because they had not implemented monitoring to verify compliance. The GDPR accountability principle requires that data controllers be able to demonstrate compliance, and this extends to third-party data handling.

The accountability principle requires demonstrability, not just contractual commitment. An organization that cannot demonstrate whether its third parties are honoring their DPA obligations has documented accountability without implementing it.

Enabling Capabilities

  • TPRM platforms with continuous monitoring: Including Verisq AI, BitSight, and similar platforms that provide ongoing vendor risk assessment beyond point-in-time review.
  • Audit right exercise programs: Structured programs for exercising contractual audit rights for highest-risk data-sharing relationships on a defined schedule.
  • Data flow monitoring at third-party boundaries: Technical monitoring of data flows to third parties to detect anomalous patterns suggesting unauthorized use.
  • Privacy-specific due diligence: Assessment programs that specifically address data handling practices rather than security posture alone.

A Practical Starting Point

Select your five highest-risk data-sharing relationships and conduct a compliance verification exercise. Ask each third party to confirm current compliance with DPA obligations, provide evidence of their subprocessor management, and describe their technical mechanisms for enforcing permitted use restrictions.

Third-party data governance that has never verified compliance is governance by documentation. Verify at least your highest-risk relationships.

Questions Leaders Should Be Asking

  • For our highest-risk data-sharing relationships, when did we last substantively verify that the third party is complying with their DPA obligations?
  • Have we ever exercised the audit rights in any of our DPAs, and if not, what is our assurance that contracted data handling obligations are being honored?
  • How do we assess subprocessor compliance in our third-party data-sharing relationships?
  • What is our governance response when we cannot verify third-party compliance with DPA obligations?

What to Require From Vendors

Ask directly:

"What evidence can you provide that demonstrates your current compliance with the data handling obligations in our DPA, specifically covering permitted use restrictions, subprocessor management, and security measures applied to our data?"

Expect as evidence:
  • Current compliance documentation specifically addressing DPA obligation compliance
  • Subprocessor list with data handling scope for each subprocessor
  • Technical mechanism description for enforcing permitted use restrictions

A vendor who responds to DPA compliance questions with security certification documentation has confirmed their security program. The compliance question requires specific evidence of DPA obligation adherence.

Demonstrating Diligence

  • Documentation: Third-party compliance verification records; audit right exercise documentation; data-sharing risk assessment with monitoring coverage.
  • Process: Compliance verification schedule for highest-risk data-sharing relationships; audit right exercise program.
  • Technical evidence: Data flow monitoring outputs for third-party sharing relationships; compliance questionnaire responses; audit findings and remediation records.

Third-party data governance diligence requires showing that compliance is verified, not just that obligations are contracted.

Closing Perspective

Third-party data sharing is one of the most consequential data governance activities organizations engage in. When data is shared, the organization's ability to protect it depends primarily on the third party's practices, not on its own controls.

Organizations that have built strong contracting programs and have not built equivalent monitoring programs have addressed the legal framework for third-party sharing without building the operational assurance that the framework is being honored.

Contracted obligations and verified compliance are different governance achievements. Most programs have built the first. Build the second.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.