
How to Contract hosted this webinar with Laura Frederick, Founder and CEO of How to Contract, in the host seat. She was joined by Kimberly Pack, Privacy, Cybersecurity and Technology Counsel at Thompson Hine in Chicago, and Arohi Kashyap, Partner at Kashyap Partners & Associates LLP. Kimberly works with everyone from Fortune 500 companies down to new venture clients and spends her days on the vendor side of these provisions. Arohi practices in California and in India, handles tech transactions and data privacy, and took the customer seat for the session. Having both chairs filled at once made it easy to see where the two sides actually agreed.
Want unlimited access to 110+ webinar replays? Our paid members get permanent access to webinar recordings from 2024 and 2025, plus 30+ hours of courses courses, certifications, and our massive expert library. If you just want an individual webinar, register in advance to get access to the recording for 14 days. You can sign up for our auto registration list so you are registered for every webinar we host. Learn more about our membership →
Laura split the session in half. The first part surveyed what the state laws demanded of the contract, and the second part put two deliberately problematic clauses on the screen and let the speakers mark them up live. The conversation moved through the patchwork itself, what California required, which states went further, consumer rights flow down provisions, purpose limitation and retention, and the definitions people lean on for de-identified and aggregated data.
Here are our top ten takeaways from the speakers' comments during the webinar:
Define the universe of applicable privacy law rather than listing every state. Kimberly stopped naming states one by one and started defining applicable state privacy laws instead. She still called out CCPA by name, and sometimes a handful of others, but she did not build a list that goes stale the moment a new governor signs something. States came on board at different times, so a January effective date in one place sat next to a July date somewhere else. Broad language plus a good faith obligation to come back and renegotiate meant most new state laws required no edit at all.
Know what the state laws expected your contract to cover. Arohi named three items that showed up across most state regulations. Processing purpose, data deletion protocols with retention periods before and after termination, and audit rights. Kimberly added the CCPA list, which ran through limited and specified business purpose, no use beyond that purpose, no selling or sharing, no impermissible combining of personal information with data from other sources, notice when the vendor could not comply, deletion cooperation, flow down to subcontractors, and an explicit certification. One small habit worth borrowing is that Kimberly only said CCPA, because CPRA amended CCPA rather than replacing it.
Treat California as your starting point and not your ceiling. Complying with the strictest law you know and assuming everything else follows is where a lot of us slipped. Maryland enforced data minimization far more strictly than California and put a clear ban on the sale of sensitive data. Colorado required data protection assessments for high-risk processing. Opt-in versus opt-out and minimum revenue thresholds were the two places Arohi saw companies get caught, so those are the first two provisions to check on any audit.
Ask where your data actually went before you agreed to anything. Arohi's opening question as customer counsel was about the borders of vendor access. What exactly could they reach, what were they using it for, where did it go, and who were the sub-processors. Companies assumed a vendor brought on for HR chat or accounting help touched almost nothing, and that assumption was the blind spot. For sensitive industries she went past the certifications required by law and asked what the industry standard looked like for anyone holding that level of access.
Put firm deadlines in every clause that carried an obligation down the chain. Arohi had watched vendors write "as soon as possible" and reasonable time into provisions that needed dates. Most US states gave you 45 days to respond to a data subject, and California expected acknowledgment within 10 days, so Kimberly asked her vendors to pass requests along within 10 business days. Extensions existed for genuinely high volume or complex requests, not for the ones nobody prioritized. The lawyer who drafted the clause was rarely the person tracking the deadline later, which is exactly why the number has to be in writing.
Sort out who verified consumer requests and who answered them. Kimberly made the customer solely responsible for verifying requests and then wrote out what happened when a consumer contacted the vendor directly. Her vendors forwarded the request and waited for instructions rather than responding on their own, because the consumer was not their customer. Arohi wanted the same clarity from the other side, since a customer's own obligations to its users depended entirely on the vendor moving fast. Both of them wanted the mechanics written into the clause rather than buried in a high level compliance provision.
Sort out who verified consumer requests and who answered them. Kimberly made the customer solely responsible for verifying requests and then wrote out what happened when a consumer contacted the vendor directly. Her vendors forwarded the request and waited for instructions rather than responding on their own, because the consumer was not their customer. Arohi wanted the same clarity from the other side, since a customer's own obligations to its users depended entirely on the vendor moving fast. Both of them wanted the mechanics written into the clause rather than buried in a high level compliance provision.
Ask what happened after the subcontractor got notified. A clause saying the vendor shall notify its subcontractors of deletion requests stopped one step short of the point. Arohi wanted language requiring the vendor to ensure the subcontractor actually completed the request. Kimberly added confirmations, which are best practice rather than statute, because everyone has to be able to show they complied. She also flowed the obligation only to the subcontractors that processed the relevant data, so it stayed clear who was on the hook.
Keep every indemnity in the indemnification section. The sample clause carried a one-sided indemnity sitting on its own, missing the qualifiers Arohi wanted around acting in accordance with the contract, following instructions, acting lawfully, and negligence. Laura called these littered indemnities, the stray obligations sprinkled through a contract that nobody remembers and that never line up with each other. Her hard and fast rule was that anything using the word indemnify belongs in the indemnification section, and she rewrote that section to absorb the stray provisions when she had to. Even when you are being careful about the number of edits you make, this one earns its place near the top of the list.
Define what you meant by de-identified and aggregated data. A clause letting the vendor use aggregated or de-identified data for any purpose sounded covered until you noticed nothing defined those words. Arohi had seen masked, anonymized, aggregated, de-identified, and even hidden data used interchangeably, and they do not mean the same thing. Kimberly wanted the data to genuinely qualify as de-identified under the applicable statute, an express commitment not to re-identify, and that same commitment flowing to subcontractors. Where a real industry standard exists, such as the 18 identifiers under HIPAA, pull it into the contract so both sides are talking about the same thing.
Subscribe to Stay in the Loop
Our weekly newsletter keeps you current on upcoming How to Contract webinars and brings you recaps like this one when you cannot make the live session. Subscribe now and get the practical takeaways delivered to you.








