Vendor Data Access for Third-Party Risk
Last updated: November 6, 2025
When creating a new vendor entry, the Data Access field is an important requirement. It helps maintain an accurate inventory of third-party services that handle or have access to sensitive information, such as PII, PHI, or PCI data.

Below is a table to help categorize these data types for your third-party services.
Data Access | Description |
No Data Access | Vendors or services that do not store, process, or transmit company, customer, or employee data. These tools operate independently of your sensitive information. Examples: Github, BitBucket, Figma |
Public Data Only | Vendors or services that only access, store, or display publicly available information — data that is already accessible to anyone and does not include customer, employee, or confidential business data. These tools pose minimal privacy or confidentiality risk. Examples: Marketing websites, public documentation platforms, social media management tools. |
Internal/Non-sensitive Data | Vendors or services that access or store internal operational data that is not confidential or personally identifiable, but still not meant for public disclosure. This data is typically used for internal collaboration, planning, or productivity and poses limited risk if exposed. Examples: Project management tools, Internal documentation platforms (Confluence, Notion), or communication tools (Slack, Microsoft Teams) |
Confidential Business Data | Vendors or services that access, store, or process non-public business information that could cause competitive, financial, or operational harm if disclosed. This includes strategic, contractual, or proprietary data that must be protected but does not contain personal information like PII or PHI. Examples: Contract management tools (DocuSign, PandaDoc), or internal analytics/reporting platforms. |
Personal Identifiable Information (PII) | Vendors or services that access, store, or process information that can directly or indirectly identify an individual. This includes both customer and employee data, and must be protected to comply with privacy and data protection requirements. Examples: HR platforms (BambooHR), CRMs (Salesforce, HubSpot), communication and messaging services (Zendesk), or authentication providers (Auth0, Okta). |
Protected Health Information (PHI) | Vendors or services that access, store, or process health-related information linked to an individual. This includes any data about a person’s medical history, treatment, or health status that can be tied to their identity. Such data is subject to strict privacy regulations (e.g., HIPAA). Examples: Telehealth platforms, electronic medical record systems (e.g., Epic, Cerner), health benefits portals, or wellness apps handling patient information. |
Payment Card Information (PCI) | Vendors or services that access, store, or process credit or debit card data or are otherwise involved in payment transactions. This includes any system that handles cardholder details such as card numbers, expiration dates, or security codes, and must comply with PCI DSS requirements. Examples: Payment processors (Stripe, PayPal), subscription billing platforms, or e-commerce gateways handling customer payments. |
Sensitive Authentication Data | Vendors or services that access, store, or process authentication credentials or secrets that could be used to gain unauthorized access to systems or data. This includes passwords, API keys, cryptographic secrets, or multi-factor authentication (MFA) tokens. Proper handling of this data is critical to maintaining security and preventing breaches. Examples: Identity providers (Okta, Auth0), password managers (1Password, LastPass), API management platforms, or internal authentication services. |
Intellectual Property / Trade Secrets | Vendors or services that access, store, or process proprietary or highly sensitive business information that represents a competitive advantage. This includes source code, product designs, algorithms, research data, or other materials that are unique to the organization and not publicly disclosed. Examples: Code repositories that store proprietary or confidential code (GitHub, Bitbucket, GitLab), R&D collaboration tools, design platforms (Figma, Adobe Creative Cloud) |
Regulated Data (eg., GDPR, HIPAA, FedRamp) | Vendors or services that access, store, or process data governed by specific privacy, security, or compliance regulations. This includes any information subject to legal or contractual protections that dictate how the data must be collected, stored, transmitted, or deleted. Handling this type of data typically requires formal agreements and compliance certifications. Examples: Cloud hosting providers managing production data (AWS, GCP), or healthcare systems processing PHI under HIPAA. |