Cyber & Data Security
CDW maintains robust global data privacy and information security programs designed to protect information assets for our business, coworkers, customers, and partners. We meet or exceed various data protection regulations, including GDPR, HIPAA, CCPA, and applicable UK and Canadian requirements.
We require annual cybersecurity training for all coworkers, with additional requirements for roles needing specialized knowledge of regulatory compliance. Our Integrated Global Information Security Operating Model enables secure, sustainable growth through focused, agile priorities underpinned by a strong oversight structure. We address cyber threats across eight overlapping domains:
- Security Business Information
- Enterprise Security Architecture
- Cyber Defense
- Product Security
- Threat Detection
- Security Risk and Response
- Management
- Security Operations
We implement privacy enhancements to facilitate business agility while ensuring compliance with contractual obligations to customers and regulatory requirements related to the processing, handling, and storage of individuals’ personal data. We remain committed to promoting a privacy-first mindset among CDW coworkers and in all aspects of CDW’s operations.
CDW requires all third-party data processors to execute Data Processing Agreements or similar contractual terms that mandate compliance with applicable privacy laws. We conduct pre-engagement risk assessments through security questionnaires, privacy impact assessments, and review of compliance documentation, with ongoing monitoring to ensure continued compliance with contractual privacy obligations.

