Why Financial Institutions Must Tighten Third-Party Data Control Now
July 27, 2026
Financial services companies routinely rely on outside vendors for functions ranging from fraud detection to cloud banking infrastructure. That dependence carries substantial legal and regulatory exposure. Shumaker writes about the issue in a recent article.
Financial institutions operate under a dense web of overlapping obligations, including the Gramm-Leach-Bliley Act, state privacy statutes, banking rules, and cybersecurity requirements, all of which continue to evolve.
As data-sharing arrangements multiply, institutions face mounting pressure to build disciplined governance frameworks.
Outsourcing a function does not shift liability away from the client institution. Any failure by a third party to safeguard data typically becomes the institution’s regulatory and reputational problem.
The article outlines practical measures for managing third-party data risk throughout the vendor relationship, beginning with rigorous data mapping and minimization to ensure only necessary information is shared.
It stresses the importance of meaningful due diligence before onboarding vendors, including security audits and review of prior breach history. Contracts must clearly define permitted uses, breach notification timelines, and subcontractor restrictions.
Vendors using artificial intelligence should be vetted with particular care. Institutions must understand training data sources, bias testing, and model governance terms.
The article also addresses open banking obligations under the Consumer Financial Protection Bureau’s Personal Financial Data Rights Rule, emphasizing consumer consent and revocation mechanisms for authorized third parties.
Additional recommendations cover breach preparedness, vendor monitoring, downstream fourth-party risk, and data stewardship as a core value rather than a checklist exercise.
Counsel advising financial institutions should prioritize contractual protections addressing data restrictions, breach notification, indemnification, and subcontractor flow-down obligations as part of broader enterprise risk management. Board governance structures should ensure senior leadership receives regular reporting on third-party data risks, reinforcing fiduciary oversight responsibilities.
Attorneys negotiating vendor agreements involving AI tools should also address training data restrictions and algorithmic transparency as emerging areas of regulatory scrutiny.
Critical intelligence for general counsel
Stay on top of the latest news, solutions and best practices by reading Daily Updates from Today's General Counsel.
Daily Updates
Sign up for our free daily newsletter for the latest news and business legal developments.