Last updated:
1. Introduction
This Third-Party Service Providers Policy (TPSP) outlines the principles and procedures governing Education Management Solutions engagement with third-party service providers (TPSPs). The policy aims to ensure that TPSPs meet our security, regulatory, and performance standards while protecting our sensitive information and assets.
2. Scope
This policy applies to all TPSPs engaged by the Organisation, including:
Cloud service providers
IT service providers
Data processors
Software-as-a-Service (SaaS) providers
Managed service providers
Any other external vendor with access to our data, systems, or resources
3. Selection and onboarding
The Organisation will conduct a thorough due diligence process before selecting a TPSP. This process will consider the provider's:
Security posture and compliance with relevant standards (e.g., ISO 27001) and regulations (e.g., the Privacy Act 1988 (Cth), GDPR).
Financial stability and track record.
Ability to meet the Organisation's specific requirements.
A formal contract will be established with each TPSP, outlining:
Services provided
Responsibilities of both parties
Security expectations
Data protection obligations
Service Level Agreements (SLAs)
Termination clauses
4. Security requirements
TPSPs must implement appropriate technical and organisational security measures to protect the Organisation's data and systems.
This may include:
Strong access controls (e.g., multi-factor authentication)
Encryption of data at rest and in transit
Regular security audits and penetration testing
Incident response procedures
Compliance with relevant data protection regulations
5. Data protection
TPSPs that handle personal information must comply with all applicable privacy laws, including the Privacy Act 1988 (Cth), and any other relevant data protection regulations (e.g., GDPR where applicable).
The Organisation will only share the minimum amount of data necessary with TPSPs.
Wherever practicable, the Organisation engages TPSPs that store and process data within Australia.
Data transfer agreements will be established with TPSPs located outside the Organisation's jurisdiction.
6. Performance management
The Organisation will monitor the performance of TPSPs against agreed-upon SLAs.
Regular reviews will be conducted to assess the TPSP's security posture and adherence to the TPSP Policy.
The Organisation reserves the right to terminate a relationship with a TPSP if they fail to meet expectations.
7. Communication and training
The Organisation will communicate the TPSP Policy to all relevant personnel, including those involved in selecting and managing TPSP relationships.
Employees will be trained on their responsibilities regarding data security when interacting with TPSPs.
8. Review and update
This TPSP Policy will be reviewed and updated periodically to reflect changes in the legal landscape, industry best practices, and the Organisation's risk profile.
9. Conclusion
By establishing a robust TPSP Policy and due diligence process, Education Management Solutions can mitigate risks associated with third-party relationships and ensure the security of its data and information systems. This policy demonstrates Education Management Solutions' commitment to responsible data management and building trust with its stakeholders.
Previous
