vStream Digital Media / ShineVR

Vendor Management Policy

Last updated: 03/02/25

Definitions

TermDefinition
Companymeans vStream Digital Media
ShineVRmeans the ShineVR product developed and operated by vStream Digital Media
GDPRmeans the General Data Protection Regulation
Responsible Personmeans Andrés Pitt, CTO
VendorAny third-party supplier, service provider, contractor, or partner providing goods or services to the Company
Critical VendorVendor with access to sensitive data, critical systems, or whose failure would significantly impact business operations
Data ProcessorVendor who processes personal data on behalf of the Company as Data Controller
Risk ClassificationAssessment of vendor risk level (Low, Medium, High, Critical) based on data access and service criticality
Data Processing Agreement (DPA)Contractual agreement defining data protection responsibilities between Company and vendor

1. Policy Statement

vStream Digital Media recognises that third-party vendors are essential to business operations but also represent potential security, privacy, and operational risks. This Vendor Management Policy establishes a comprehensive framework for assessing, selecting, contracting with, and monitoring vendors to ensure they meet the Company's security, privacy, and operational requirements.

All vendors must be evaluated for security posture, data protection practices, and business continuity capabilities before engagement. Ongoing monitoring ensures vendors continue to meet requirements throughout the relationship lifecycle.

2. Purpose

The purpose of this policy is to:

3. Scope

This policy applies to:

This policy applies throughout the vendor lifecycle:

4. Vendor Risk Classification

4.1 Risk Classification Criteria

All vendors are classified based on:

4.2 Risk Classifications

Risk LevelDefinitionExamplesAssessment Requirements
CriticalAccess to sensitive personal data, critical systems, or service failure causes major business disruptionGoogle Cloud Platform, primary payment processor, core application vendorsComprehensive security assessment, penetration testing requirements, executive approval, detailed DPA, annual reassessment, continuous monitoring
HighAccess to confidential business data, important systems, or service failure causes significant disruptionEmail/collaboration platforms (Google Workspace), customer communication tools (Slack), database vendorsDetailed security assessment, security certifications required, CTO approval, DPA if processing personal data, annual review, performance monitoring
MediumLimited data access, moderate system access, or service failure causes moderate disruptionDevelopment tools, project management software, analytics platformsStandard security assessment, basic security documentation, CTO approval, DPA if processing personal data, bi-annual review
LowNo sensitive data access, minimal system access, service failure has minimal impactOffice supplies, marketing services (no data access), generic toolingBasic vendor assessment, standard contract terms, manager approval, annual review if multi-year contract

4.3 Risk Classification Review

5. Vendor Selection And Assessment

5.1 Vendor Identification

Prior to Engaging Any Vendor:

5.2 Vendor Assessment Process

Step 1: Initial Assessment — Evaluate vendor based on: prior knowledge (Company's previous experience or industry reputation); financial stability; market position; references; service fit; geographic location (preference for EU-based vendors for data residency); pricing model (avoid "free" products that monetise through data resale).

Step 2: Security Assessment — For Medium, High, and Critical risk vendors:

Step 3: Data Protection and Privacy Assessment — For vendors processing personal data:

Step 4: Operational Assessment

Step 5: Contract and Legal Review

Step 6: Risk Assessment and Approval — Complete vendor risk assessment documenting: risk classification (Low, Medium, High, Critical); key risks identified; mitigating controls; residual risk level; compensating controls if needed.

Approval Requirements:

5.3 Vendor Assessment Documentation

All vendor assessments documented including: vendor name and contact information; service description and business purpose; risk classification and justification; security assessment results; compliance verification; references checked; contract review notes; risk assessment summary; approval signatures and dates; all documentation retained in vendor management system.

6. Vendor Selection Principles

6.1 Security-First Approach

Mandatory Principles:

Example Applications:

6.2 EU Preference

Data Residency Preference:

Current EU Vendors:

6.3 Compatibility and Integration

Technical Compatibility: Vendor solutions must integrate with existing systems; APIs and integration methods assessed; data import/export capabilities verified; compatibility with Google Cloud Platform preferred.

Operational Compatibility: Vendor support hours align with Company needs; vendor culture and values align with Company; communication and language capabilities adequate.

6.4 Vendor Reputation and Stability

Reputation Assessment: Industry reputation and customer reviews; security incident history researched; data breach history reviewed; customer references checked; media coverage and public perception.

Financial Stability: Financial health assessed for critical vendors; business viability for multi-year commitments; merger/acquisition risk considered; backup vendor identified for critical services.

7. Contractual Requirements

7.1 Data Processing Agreements (DPA)

Mandatory Requirement: All vendors processing personal data must execute a Data Processing Agreement

DPA Must Include:

Standard Contractual Clauses (SCCs):

7.2 Security Requirements in Contracts

Mandatory Security Clauses:

7.3 Audit Rights

Company Rights to Audit:

7.4 Sub-Processor Management

For vendors who use sub-processors:

7.5 Termination and Data Return

Contract Termination Provisions:

8. Vendor Onboarding

8.1 Onboarding Process

Upon vendor selection and contract execution:

Step 1: Vendor Registration — Add vendor to vendor register/inventory; assign unique vendor ID; document vendor details (contact, services, risk level, contract dates); assign vendor owner within Company.

Step 2: Access Provisioning — Provision necessary system access (least privilege principle); create vendor user accounts or service accounts; configure access controls and permissions; enable multi-factor authentication if applicable; document all access granted.

Step 3: Security Configuration — Configure security settings per contract requirements; enable logging and monitoring for vendor activity; set up security alerts for vendor-related events; configure encryption for data shared with vendor; test security controls.

Step 4: Vendor Orientation — Provide vendor with relevant Company policies; security and privacy requirements review; incident reporting procedures; communication protocols and contacts; support and escalation procedures.

Step 5: Initial Performance Baseline — Establish performance metrics and KPIs; configure monitoring and reporting; schedule regular review meetings; define success criteria.

8.2 Vendor Documentation

Maintain comprehensive vendor documentation: vendor contact information and account managers; contract and DPA copies; security assessment results; risk assessment and approval documents; access permissions and credentials; integration documentation; escalation procedures; review and audit schedules.

9. Ongoing Vendor Management

9.1 Continuous Monitoring

Automated Monitoring:

Manual Monitoring: Regular review of vendor security news and announcements; quarterly review of vendor security status; annual review of vendor certifications (renewal, expiration); periodic review of vendor financial stability.

9.2 Vendor Performance Reviews

Review Frequency Based on Risk:

Performance Review Includes: SLA compliance and performance metrics; security posture and incident history; data protection compliance; contract compliance; communication and support quality; cost effectiveness and value; business continuity preparedness; recommendations for continuation, renegotiation, or termination.

Review Documentation: Performance review meeting notes; metrics and KPIs analysis; issues and concerns identified; action items and remediation plans; decisions on contract renewal or changes.

9.3 Vendor Compliance Monitoring

Ongoing Compliance Verification:

9.4 Vendor Relationship Management

Regular Communication: Scheduled review meetings (frequency based on risk level); quarterly business reviews for critical vendors; ad-hoc meetings for issues or changes; annual strategic planning sessions for key partners.

Relationship Optimization: Identify opportunities for improved service; negotiate better terms or pricing; expand or reduce services based on needs; provide feedback on vendor performance; collaborate on innovation and improvements.

Vendor Satisfaction: Ensure timely payment of invoices; provide clear requirements and feedback; maintain professional working relationship; recognise and appreciate good performance.

10. Vendor Security Incidents

10.1 Vendor Incident Notification

Vendor Obligations: Notify Company of security incidents within 24 hours; provide initial incident details (nature of incident; data potentially affected; number of individuals affected; actions taken by vendor; estimated timeline for resolution); provide regular updates during incident response; provide final incident report with root cause analysis.

Company Response: Log incident in Company incident register; assess impact on Company operations and data; activate incident response plan if necessary; coordinate with vendor on response actions; notify affected parties if required (customers, regulators); document all communications and actions.

10.2 Vendor Incident Assessment

Upon notification of vendor security incident:

Step 1: Initial Assessment (within 2 hours) — Classify incident severity (P1, P2, P3); determine impact on Company and ShineVR systems; identify data potentially compromised; assess regulatory notification requirements.

Step 2: Containment Actions — Disable vendor system access if necessary; rotate credentials and API keys; implement additional monitoring; isolate affected systems or data; prevent further data access or loss.

Step 3: Investigation and Remediation — Work with vendor to understand root cause; verify vendor's remediation actions; assess effectiveness of vendor response; determine if additional controls needed; consider long-term vendor relationship.

Step 4: Recovery and Post-Incident — Restore normal operations when safe; enhanced monitoring for 30 days; post-incident review with vendor; update risk assessment and controls; document lessons learned.

10.3 Breach Notification Obligations

If vendor incident affects personal data: Assess GDPR notification requirements within 24 hours; notify Data Protection Commission within 72 hours if required; notify affected data subjects if high risk; document decisions and rationale; maintain detailed records of breach response.

Vendor Liability: Vendor liable for breaches caused by their actions or negligence; indemnification clauses in contract apply; financial penalties and damages per contract; potential contract termination for serious breaches.

11. Vendor Termination And Offboarding

11.1 Termination Reasons

Vendor relationships may be terminated due to: contract expiration or non-renewal; poor performance or repeated SLA breaches; security breaches or non-compliance; business requirements change; better alternative vendor identified; vendor out of business or acquired; cost optimization; strategic realignment.

11.2 Termination Process

Step 1: Termination Decision and Notification — Document termination reason and approval; review contract termination clauses; provide required notice per contract (typically 30-90 days); communicate termination to vendor in writing; establish termination timeline and milestones.

Step 2: Transition Planning — Identify replacement vendor or alternative solution; plan data migration and service transition; assign transition responsibilities; establish transition timeline; test replacement solution.

Step 3: Data Return and Deletion — Request return of all Company data from vendor; verify data completeness and integrity; import data into replacement system; request certified deletion of all Company data; obtain written certification of deletion; verify deletion if possible (audit vendor's systems).

Step 4: Access Revocation — Revoke all vendor access to Company systems; delete vendor user accounts and service accounts; rotate credentials and API keys accessed by vendor; remove vendor from authentication systems; update firewall rules and network access controls.

Step 5: Documentation and Closure — Final vendor performance review; lessons learned documentation; update vendor register (mark as terminated); archive all vendor documentation; close out financial accounts; provide feedback to vendor (if appropriate).

11.3 Emergency Termination

For serious security breaches or emergencies: immediate access revocation without notice; rapid data return or deletion; accelerated transition to alternative vendor; legal consultation for contract disputes; regulatory notification if required.

12. Vendor Inventory And Register

12.1 Vendor Register Contents

Comprehensive vendor register maintained including: vendor name and legal entity; vendor contact information; service description and business purpose; risk classification (Low, Medium, High, Critical); contract dates (start, end, renewal dates); contract value; data processing role (processor, sub-processor, joint controller); personal data processed (types, categories, volumes); system access granted; security certifications; last assessment date and next review date; vendor owner within Company; status (active, inactive, terminated); notes and special considerations.

12.2 Register Maintenance

13. Special Vendor Types

13.1 Critical Infrastructure Vendors

Google Cloud Platform (Primary Infrastructure Provider): Comprehensive annual assessment; quarterly service review meetings; continuous monitoring of Google Cloud Status and security bulletins; leveraging Google's certifications (ISO 27001, SOC 2, etc.); regular review of Google Cloud compliance documentation; participation in Google Cloud security programmes; escalation procedures for critical issues; disaster recovery planning for Google Cloud outages.

Key Characteristics: Single-source dependency for infrastructure; critical to all ShineVR operations; extensive due diligence required; enhanced monitoring and relationship management.

13.2 SaaS Application Vendors

Examples: Google Workspace, Slack, GitHub/GitLab

Management Approach: Security assessment focused on data protection; review of vendor's security and privacy policies; verification of security certifications; user access management and provisioning; regular review of user licenses and usage; integration security (APIs, SSO); data export and portability planning.

13.3 Professional Services Vendors

Examples: External security consultants, auditors, legal advisors

Management Approach: Confidentiality agreements required; limited-time access to systems or data; supervised access where possible; background checks for sensitive work; work product ownership clearly defined; engagement terms and deliverables documented.

13.4 Open-Source Software

Approach to Open-Source: Open-source acceptable if security can be verified; dependency vulnerability scanning required; active maintenance and community support verified; licensing compatibility assessed; commercial support available (preferred for critical components); security response process for vulnerabilities documented.

14. Vendor Risk Register

14.1 Risk Register Maintenance

Comprehensive risk register documenting: vendor name and service; risk classification (Low, Medium, High, Critical); specific risks identified (security, operational, financial, compliance); likelihood and impact assessment; mitigating controls implemented; residual risk level; risk owner within Company; risk treatment plan; review date.

14.2 Risk Escalation

Risk escalation triggers: vendor security incident or breach; vendor financial difficulty or instability; loss of required certifications; significant service degradation; contract disputes or non-compliance; regulatory concerns; change in vendor ownership or service.

Escalation Process: Risk owner notifies CTO immediately; enhanced monitoring implemented; risk treatment plan updated; more frequent reviews scheduled; alternative vendor evaluation initiated if necessary; senior management notified for critical vendors.

15. Compliance And Audit

15.1 Vendor Compliance Requirements

GDPR Compliance: All vendors processing personal data must comply with GDPR; Data Processing Agreements in place; data subject rights support procedures defined; breach notification procedures established; international data transfer mechanisms compliant.

Industry Standards: ISO 27001 compliance preferred for critical vendors; SOC 2 Type II reports for critical vendors; industry-specific certifications (PCI DSS, HIPAA) as applicable.

15.2 Vendor Audits

Audit Schedule: Critical vendors: annual audits; High-risk vendors: bi-annual audits or upon contract renewal; Medium-risk vendors: audit upon contract renewal; Triggered audits: following incidents or significant changes.

Audit Types: Documentation Review; Questionnaire (comprehensive security and privacy questionnaires); Third-Party Reports (review SOC 2, ISO 27001 audit reports); On-Site Audit (physical inspection for critical vendors); Technical Audit (penetration testing, vulnerability assessment for critical vendors).

Audit Documentation: Audit plan and scope; audit findings and observations; vendor responses and remediation plans; follow-up actions and timelines; audit completion sign-off.

15.3 Regulatory Audits

Supporting Customer/Regulatory Audits: Vendor documentation available for regulatory audits; vendor audit rights exercised to obtain compliance evidence; vendor security and compliance reports provided to auditors; coordinate with vendors during customer audits; maintain audit trail of vendor management activities.

16. Roles And Responsibilities

RoleResponsibilities
CTO (Responsible Person)Overall vendor management policy ownership; approve Medium/High/Critical vendor engagements; conduct vendor security assessments; manage critical vendor relationships; vendor incident response; review vendor register quarterly; escalation point for vendor issues
Department ManagersIdentify vendor needs; conduct business requirements assessment; approve Low-risk vendors; manage vendor day-to-day relationships; monitor vendor performance; report vendor issues; ensure contract compliance
Finance/ProcurementContract negotiation and execution; invoice processing; payment management; contract renewal tracking; cost optimization; financial risk assessment
Legal (External Counsel)Contract review and negotiation; Data Processing Agreement review; legal compliance advice; dispute resolution; regulatory liaison if needed
Product ManagerVendor technical requirements; vendor integration oversight; vendor performance feedback; feature and functionality assessment
All EmployeesReport vendor security concerns; comply with vendor usage policies; protect vendor credentials; follow data sharing procedures; report vendor performance issues

17. Training And Awareness

17.1 Vendor Management Training

Required Training:

Training Topics: Vendor risk classification; security assessment procedures; contract and DPA requirements; ongoing vendor monitoring; incident reporting for vendor issues; data protection when working with vendors.

17.2 Vendor Resources

Available Resources: Vendor assessment checklist and templates; standard Data Processing Agreement template; security questionnaire templates; contract security requirements checklist; vendor incident reporting procedures; vendor register and documentation repository.

18. Exceptions

18.1 Exception Process

Exceptions to vendor management requirements may be requested for: emergency situations requiring immediate vendor engagement; unique vendor services with no alternatives; cost constraints requiring compromise on requirements; technical limitations of available vendors.

All exceptions must:

18.2 Legacy Vendors

Vendors engaged before this policy implementation: retrospective assessment conducted within 12 months; bring into compliance with policy requirements; update contracts and DPAs to meet requirements; terminate if cannot meet minimum requirements.

19. Policy Review And Updates

19.1 Review Schedule

This policy will be reviewed:

19.2 Continuous Improvement

20. Related Policies

This policy should be read in conjunction with:

21. Contact Information

For questions regarding this policy or to report vendor security incidents:

Data Protection Officer / CTO: Andrés Pitt Email: andres@vstream.ie Phone: (086) 788 6570