In addition, for certain kinds of data (e.g., data subject to HIPAA, Gramm-Leach-Bliley, PCI-DSS, or the Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth), there may be specific security requirements that must be included in any vendor contracts.