vendor risk management

How to Draft a Vendor Cybersecurity Addendum That Limits Liability After a Data Breach Under New York Law

How to Draft a Vendor Cybersecurity Addendum That Limits Liability After a Data Breach Under New York Law

A well-drafted vendor cybersecurity addendum can cap breach-related exposure through three core levers: tight indemnity language, a defined liability cap, and clear security/notice duties. Under New York law, these clauses are generally enforceable in commercial contracts when negotiated and not barred by public policy. This article explains how to draft an addendum that reduces post-breach […]

How to Draft a Vendor Cybersecurity Addendum That Limits Liability After a Data Breach Under New York Law Read More »

How to Draft California-Compliant AI Vendor Contracts Under the CPRA and the 2025 AI Transparency Act

How to Draft California-Compliant AI Vendor Contracts Under the CPRA and the 2025 AI Transparency Act

California businesses should update AI vendor contracts now because the CPRA already governs “service providers” and “contractors,” and California’s 2025 AI transparency rules will add disclosure, documentation, and audit pressure. The risk is not theoretical: noncompliant data-sharing and opaque AI use can trigger consumer requests, regulator scrutiny, and downstream breach exposure. This article provides a

How to Draft California-Compliant AI Vendor Contracts Under the CPRA and the 2025 AI Transparency Act Read More »

How to Draft a SaaS Agreement for an AI-Powered Vendor to Protect Your Business from Data Breach and IP Claims

How to Draft a SaaS Agreement for an AI-Powered Vendor to Protect Your Business from Data Breach and IP Claims

A well-drafted SaaS agreement can reduce breach and IP exposure by allocating liability, mandating security controls, and locking down data/AI training rights in writing. AI-powered vendors create extra risk because they process sensitive data and may reuse inputs for model improvement. This article explains the core clauses attorneys should draft to protect customers from data

How to Draft a SaaS Agreement for an AI-Powered Vendor to Protect Your Business from Data Breach and IP Claims Read More »

What Makes a Great Law School Admission Essay Stand Out

How to Comply with the Texas Data Privacy and Security Act (TDPSA) for B2B Customer Data in 2026

Texas’s TDPSA takes effect July 1, 2024 and can apply to B2B customer data depending on how you use it. In 2026, Texas businesses selling to other businesses still must evaluate whether their “consumer” data and “personal data” processing triggers TDPSA duties. This article explains coverage, B2B pitfalls, contracts, notices, security, and a practical 2026

How to Comply with the Texas Data Privacy and Security Act (TDPSA) for B2B Customer Data in 2026 Read More »

Scroll to Top