Asset manager
What an asset manager customer usually asks a supplier for: the ICT service terms a financial entity must hold, with investor data and portfolio systems as the usual scope.
What it pulls on, by where it is
read on a SaaS subscription that names personal dataAn asset manager customer is a financial entity under DORA in the EU. Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.
| In the EU (Ireland as the example) | GDPR: Ireland is in the EEA and the row names personal data you handle for the customer, so Art. 28 expects processor terms, including the audit right, and Art. 33 gives the customer its own 72-hour clock to the authority. DORA: an asset manager in Ireland is a financial entity under DORA, so an ICT service you provide it falls under Art. 28 to 30 and the Art. 30 key contractual provisions are expected in its contract; Art. 19 is why it asks for a clock in hours. Expected on a SaaS subscription with personal data: processor terms, DORA terms, security schedule, audit right, breach clock. |
|---|---|
| In the United Kingdom | UK GDPR: the customer is in the United Kingdom and the row names personal data you handle for it; the UK GDPR is held here only as a summary of its articles, so where a clause is quoted it is the EU GDPR article of the same number, and the page says so. Named, not quoted: the UK operational resilience rules for financial firms. Expected on a SaaS subscription with personal data: processor terms, security schedule, audit right, breach clock. |
| In the United States | No customer regime reaches it. Named, not quoted: the US state breach notification laws. Expected on a SaaS subscription with personal data: security schedule, audit right, breach clock. |
| In California | CCPA: an asset manager doing business in California is a business under the CCPA, so personal information you handle for it is disclosed to a service provider, and 1798.100(d) sets the contract terms, audit and inspection included. Named, not quoted: the US state breach notification laws. Expected on a SaaS subscription with personal data: processor terms, security schedule, audit right, breach clock. |
| In Australia | No customer regime reaches it. Named, not quoted: the Australian Privacy Act and its notifiable data breaches scheme. Expected on a SaaS subscription with personal data: security schedule, audit right, breach clock. |
| Elsewhere (Singapore as the example) | No customer regime reaches it. Named, not quoted: the Singapore Personal Data Protection Act. Expected on a SaaS subscription with personal data: security schedule, audit right, breach clock. |
Your own ISO/IEC 27001 and 27701 certifications add their rows to every agreement, whichever the customer; the ISO 27001 and ISO 27701 pages list them.
The clauses, quoted
25CCPA CCR §7050 Service Provider and Contractor ObligationsA service provider or contractor shall only process PI on behalf of a business for a business purpose specified in the written contract. It shall not retain, use, or disclose PI for any purpose other than the business purpose, sell or share PI, or combine PI received from one business with PI received from another business or from its own interactions with consumers (with limit...
Where it usually falls short: Service provider commingles client data
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and ContractorsA business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection...
Where it usually falls short: Legacy vendor contracts missing CPRA-required clauses
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.150 Private Right of Action for Data BreachesA consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring a civil action for statutory damages of USD 100 to 750 per consumer per inciden...
Where it usually falls short: Encryption not applied to sensitive elements
CCPA/CPRA and its regulations in The Art of Service standards library
DORA Art. 19 Reporting of major ICT-related incidentsFinancial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.
Where it usually falls short: Late or missing major-incident reporting
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 28 ICT third-party risk: general principlesFinancial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.
Where it usually falls short: No Register of Information
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 30 Key contractual provisionsContractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting crit...
Where it usually falls short: Contracts missing audit/access, termination or exit provisions
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
GDPR Art. 28 ProcessorUse only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must ...
Where it usually falls short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 29 Processing under the authority of the controller or processorThe processor, and any person acting under the authority of the controller or of the processor who has access to personal data, must not process that data except on instructions from the controller, unless required to do so by Union or Member State law.
Where it usually falls short: Instructions existing only as the original contract, never updated as the processing changed over years of service
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 32 Security of processingImplement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the...
Where it usually falls short: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 33 Notification of a personal data breach to the supervisory authorityOn becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor ...
Where it usually falls short: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
ISO 27001 A.5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
Where it usually falls short: Treating all suppliers as low risk
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
Where it usually falls short: missing explicit security clauses
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
Where it usually falls short: Treating supplier security as one-off check
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
Where it usually falls short: Relying solely on provider's security assurances
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparationDefine incident roles, processes and readiness before an incident happens.
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirementsIdentify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27701 A.2.2.2 Customer agreementWhere relevant, the contract to process personal data must address the organization's role in assisting the customer with the customer's own obligations, taking account of the nature of processing and the information available to it, covering as relevant privacy by design and by default, achieving security of processing, notifying breaches to a supervisory authority and to cust...
Where it usually falls short: Assistance promised in contract with no operational capability behind it, discovered only when the customer first asks
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.4.3 Return, transfer or disposal of PIIThe organization must provide the ability to return, transfer or dispose of personal data securely and must make its policy available to the customer, managing the capability securely whether the outcome is return to the customer, transfer to another organization or controller, deletion, destruction, de-identification or archiving, providing the assurance the customer needs tha...
Where it usually falls short: Erasure certified for primary systems while backups retain the data for the full backup cycle, which the customer is not told
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.7 Disclosure of subcontractors used to process PIIThe organization must disclose to the customer any use of subcontractors to process personal data before that use, with provisions included in the customer contract, disclosing that subcontracting is used and the names of the relevant subcontractors, the countries and international organizations to which they can transfer data, and the means by which they are obliged to meet or...
Where it usually falls short: Subcontractors disclosed only on request, with customers never told the information exists
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.8 Engagement of a subcontractor to process PIIThe organization must engage a subcontractor to process personal data only according to the customer contract, obtaining written authorization from the customer before the subcontractor processes the data, whether through appropriate clauses in the customer contract or a specific one off agreement, holding a written contract with every such subcontractor that addresses implemen...
Where it usually falls short: Subcontractor engaged on the strength of a general authorization that does not in fact cover it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.9 Change of subcontractor to process PIIWhere it holds a general written authorization, the organization must inform the customer of any intended change involving the addition or replacement of a subcontractor that processes personal data, giving the customer the opportunity to object, and where it changes the subcontractor carrying out some or all of the processing, written authorization from the customer is require...
Where it usually falls short: Notification given at the point of change or after, so the objection right is theoretical
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.10 Addressing information security within supplier agreementsAgreements with suppliers shall specify whether PII is processed and the minimum technical and organizational measures the supplier must meet for the organization to meet its information security and PII protection obligations, shall clearly allocate responsibilities between the organization, its partners, suppliers and applicable third parties taking account of the type of PII...
Where it usually falls short: Supplier contracts silent on PII while the supplier processes it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.12 Response to information security incidentsFor a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notif...
Where it usually falls short: Incidents closed as security events with no PII breach determination
ISO/IEC 27701:2025 in The Art of Service standards library
UK GDPR Arts. 24 to 43 Controller and Processor (Articles 24-43)Per UK GDPR Articles 24-43: controller + processor + DPO + RoPA + DPIA + Privacy by Design + Records + breach notification.
Where it usually falls short: DPO + DPIA + ICO partial
UK GDPR (summary of the articles held) in The Art of Service standards library
Read every asset manager customer on your list
Paste the list and every agreement with a customer in this sector carries these regimes, by its country and its kind. Eight agreements free, no account.
Check my contract list