Third-Party & Supply Chain

Danish Authority Clarifies When Suppliers May Share Employee Data to Show Labor Clause Compliance

The Danish Data Protection Authority has stepped into a debate over how far suppliers can go when asked to hand over employee information as proof that they’re complying with employment clauses in public and private contracts. A new guidance statement, issued in response to a request from Accura Advokatpartnerselskab, lays out the Authority’s view on the data protection rules that govern these disclosures, and confirms that many suppliers have been right to question the legal footing.

The Changing ESG Landscape Is Reshaping Supply-Chain Due Diligence

Third-party risk teams have spent the last few years preparing for a world where ESG reporting would continually grow in scope, depth, and regulatory expectation. Companies were told to map emissions throughout their supply chains, understand human-rights risks in their upstream tiers, and gather detailed data from suppliers that had never before been part of formal reporting channels. For better or worse, the direction felt clear.

The Hidden Layer of Third-Party Risk: Why Your Vendors’ Vendors Are Now Your Weakest Link

If 2024 reminded us of anything, it’s that the threat landscape never stands still. In every breach headline, there’s a familiar pattern: an organization falls not because of its own failure, but because a trusted partner left a back door open.

New York Issues Fresh Cybersecurity Guidance on Third-Party Risks

As financial institutions continue to lean on an expanding universe of cloud, fintech, and AI providers, New York’s financial regulator is reminding them that outsourcing doesn’t mean offloading responsibility.

EU Moves to Ease EUDR Reporting Burdens While Keeping Core Safeguards Intact

‍The European Commission is moving to fine-tune the EU Deforestation Regulation (EUDR), aiming to lighten the reporting load on smaller players and stabilize the IT backbone that underpins one of the world’s most ambitious supply-chain laws.

EU Recognizes First Supply Chain Due Diligence Scheme Under Conflict Minerals Regulation

European importers of tin, tungsten, tantalum, and gold will soon have an easier path to compliance after the European Commission recognized the first supply chain due diligence scheme under the EU’s Conflict Minerals Regulation.

ASIC Sounds Alarm on Outsourcing Risks After Review Exposes Governance Gaps

Australia’s financial watchdog has issued a pointed warning to licensees relying on offshore service providers, urging stronger oversight and risk management after a review uncovered governance shortfalls that could leave consumers and investors exposed.