Supply Chain Fallout: Managing Legal Risk, Ransomware, and Compliance in Ed Tech

On Demand
Session Type: Featured Session
Delivery Format: On-Demand Presentation

Recent high-profile breaches across platforms like Canvas and PeopleSoft highlight a stark reality: institutional data risk frequently stems from downstream vendors. When breaches disrupt campus operations, university counsel and IT leaders must navigate complex contractual, regulatory, and incident-response challenges. This session breaks down key legal takeaways from recent  ransomware incidents:

  • Procurement & Contracts: Structuring indemnification, SLAs, and risk clauses for third- and fourth-party vendors.
  • Compliance & Privacy: Managing FERPA obligations (including faculty-student communications) alongside international laws like GDPR and PIPL.
  • Ransom Payments & Disclosure: Evaluating institutional notification duties and insurance liabilities when vendors pay extortion demands.
  • Incident Response: Practical strategies for general counsel and IT leadership to coordinate swift, cross-departmental breach response.

This session was previously recorded in Denver.

Presenters

  • Emma Bahner

    Senior Associate, XL Law & Consulting
  • Pegah Parsi

    Chief Privacy Officer, University of California San Diego