Cyber & Data Security & Privacy
CDW maintains robust global data privacy and information security programs designed to protect information assets for our business, coworkers, customers, and partners. We meet or exceed various data protection regulations to the extent applicable, including but not limited to GDPR, HIPAA, CCPA, PIPEDA, and related UK privacy laws.
We require annual cybersecurity training for all coworkers, with additional requirements for roles needing specialized knowledge of regulatory compliance. Our Integrated Global Information Security Operating Model enables secure, sustainable growth through focused, agile priorities underpinned by a strong oversight structure. We address cyber threats across eight overlapping domains:
- Security Business Information
- Enterprise Security Architecture
- Cyber Defense
- Product Security
- Threat Detection
- Security Risk and Response
- Management
- Security Operations
We implement privacy enhancements to facilitate business agility while ensuring compliance with contractual obligations to customers and regulatory requirements related to the processing, handling, and storage of individuals’ personal data. We remain committed to promoting a privacy-first mindset among CDW coworkers and in all aspects of CDW’s operations.
CDW requires all third-party data processors to execute Data Processing Agreements or similar contractual terms that mandate compliance with applicable privacy laws. We conduct pre-engagement risk assessments through security questionnaires, privacy impact assessments, and review of compliance documentation, with ongoing monitoring to ensure continued compliance with contractual privacy obligations.
Learn More