This document provides an overview of 3rd party risk due diligence best practices for privacy and security. It discusses using questionnaires and on-site reviews to assess 3rd party vendors. It also addresses considerations for evaluating foreign service providers, such as the scope of services, data sensitivity, geographic factors, business continuity, local laws, legal risks, and security controls. The document provides examples of key questions to include in a questionnaire and areas to focus on during an on-site review.