IAPP Global Summit 2026: Privacy | AI governance | Cybersecurity law
WASHINGTON, DC
30 March-2 April
Beyond Borders, Beyond Breaches: Managing Third-party Risks to US Data in Asia
Monday, 30 March
17:00 - 18:00 EDT
Intermediate level
Recent statistics indicate that third-party data breaches are surging. As U.S. companies increasingly leverage shared services and third-party vendors across Asia, such organizations face unprecedented challenges in protecting American personal data. This is further complicated by the Department of Justice’s new bulk data transfer restrictions that heightens regulatory scrutiny of personal data processed in Asia. This session brings together cybersecurity and privacy professionals from the U.S. and Asia to examine how to leverage local regulatory frameworks, contractual safeguards, and due diligence processes to address the threat of vulnerabilities in the supply chain. The panel will analyze real vendor breach cases, demonstrate how Asia-Pacific privacy frameworks complement US oversight requirements, and share proven strategies for strengthening third-party risk management in Asia.
What you will learn:
- How to structure comprehensive data protection strategies that combine local Asian regulatory with U.S. oversight mandates, creating cybersecurity safeguards for cross-border processing arrangements.
- Practical approaches to restructure third-party vendor relationships and agreements to comply with data transfer restrictions.
- Actionable insights into conducting effective cybersecurity assessments contractual mechanisms, tech.
Moderator and speakers

Jon Bello
CIPP/E, CIPM, FIP
Partner
Medialdea Bello and Suarez Law

Veronica Canton
CIPP/E, CIPP/US, CIPM, CIPT, FIP
AI, Cybersecurity (IR), and Data Privacy Compliance Attorney
Wilson Elser Moskowitz Edelman & Dicker

Anna Gamvros
CIPP/A, CIPT, FIP
Partner, Privacy and Cybersecurity Lead, Asia-Pacific
A&O Shearman

Abhishek Tiwari
AIGP, CIPP/A, CIPP/E, CIPM, FIP
Associate Director, Data Privacy
PwC India