“If that system later becomes part of a privacy complaint or claim, the question may become who understood the privacy risk, who advised on it, and who accepted it? We can’t provide legal advice, but we can provide the latest information and share best practices. “Cyber security risk, privacy risk, and operational risk should be viewed together rather than in isolation,” he said. “Review your contracts, review your MSAs, make sure your data retention practices are defensible, and be very clear about whether you are providing technical implementation, cybersecurity advice, privacy advice, or legal advice,” Irwin said. “Either way, organisations and their technology providers should not ignore it.”