Among other things, they discussed:
- how to implement and test an incident response plan;
- how to use contracts and oversight procedures to ensure service providers assist in detecting unauthorized use of customer data;
- how to best safeguard data, including AI tool usage policies;
- how to provide initial and annual privacy

