Does your organisation have formal agreements in place to control third party use of personal data, including any requirements stipulated by relevant data protection legislation?
Yes. Commonplace operates a documented Supplier Security Policy that ensures providers are using appropriate controls are in place within their organisation. Terms of service / contracts are checked to confirm all necessary clauses relating to information security and data protection with appropriate mechanisms for reporting etc.
Customer information while residing on third party services (AWS, MongoDB, Sendgrid) is not accessible to the providers and in all cases is transferred using secure mechanisms such as https.
Critical suppliers are reviewed annually to verify the maintenance of certifications (such as ISO 27001, etc) and continued resilience (any incidents, failures, etc). Where an incident affecting Commonplace services or customer information, immediate reviews of provision are undertaken.