A CIPA practitioner reviews a vendor contract and notices it lacks specific data security requirements. Which contract provision should they insist be added?
-
A
Indemnification clause
-
B
Data Processing Agreement (DPA) with security obligations
-
C
Limitation of liability cap
-
D
Automatic renewal clause