Vendor due diligence usually arrives from two directions at once: a customer asks you to prove your own vendors are safe, and your product team wants to add a new tool by Friday. Both come down to the same question under GDPR, which is whether each processor you rely on gives you sufficient guarantees, and whether you can show it.

Key takeaways

  • Under Article 28(1), a controller may use only processors providing sufficient guarantees to implement appropriate technical and organizational measures.
  • Article 28(3) requires a contract or other legal act with each processor, which is the DPA.
  • A processor needs your prior written authorization before it engages a sub-processor (Article 28(2)).
  • Transfers outside the EU need their own safeguard, such as the Commission’s standard contractual clauses under Article 46(2)(c).
  • Engage Compliance runs vendor due diligence inside its DPO service, so the same named DPO who knows your stack reviews each vendor.

What the law asks of you

Article 28 is the processor article, and it usually reaches a company through its customers rather than through a regulator. If a vendor processes personal data on your behalf, you can only use them where they provide sufficient guarantees, and the arrangement has to sit in a contract carrying the stipulations listed in Article 28(3).

That contract binds the processor to act only on your documented instructions (including on transfers), to keep the people processing the data under confidentiality, and to take the security measures Article 32 points at. It also has to respect the sub-processor conditions, help you with data subject requests and with your Articles 32 to 36 obligations (within the limits Article 28(3)(e) and (f) set), and delete or return the data at the end of the services.

Sufficient guarantees is not defined by a certification or an audit. It’s a judgment you have to be able to defend, which is why the review itself, written down, matters as much as the signed DPA.

Where a vendor moves personal data outside the EU, Article 28 is not the rule that governs the transfer; Chapter V is. Without an adequacy decision, Article 46 lets the transfer rely on appropriate safeguards, including standard data protection clauses adopted by the Commission, and we pair those with a transfer impact assessment.

What we review

  • The vendor’s DPA. Whether it covers the Article 28(3) topics, and where it doesn’t, the additions to ask for. See our guide on what to do when a vendor sends you their DPA.
  • Sub-processors. Whether the vendor discloses its sub-processors or commits to a process for disclosing them, and how you’ll hear about changes.
  • Breach notification. Whether the vendor commits to notifying you of breaches affecting your data without undue delay, with specific commitments on what it will tell you.
  • Audit rights. Direct audit rights, or third-party attestations such as SOC 2 reports.
  • Return and deletion. A commitment to return or delete your data at the end of the contract, with specific timing.
  • Transfers. Cross-border transfer assessments, meaning the standard contractual clauses and a transfer impact assessment where the vendor or its sub-processors sit outside the EU.
  • Red flags. Terms that limit the vendor’s help with data subject rights, give it broad discretion on sub-processors, or weaken its breach commitments.

For SaaS companies this usually means vendor risk assessments for the sub-processors behind the product: hosting, analytics, payment and communications.

How Engage Compliance helps

Vendor and third-party due diligence, DPAs, cross-border transfer assessments and supplier risk management are part of our outsourced DPO services. Your DPO reviews new vendors as product and procurement bring them in. The recipients and transfers they involve go into the Records of Processing Activities we maintain for you, so the answer is ready when an enterprise customer or an investor asks how you vet your own suppliers.

Vendor management is part of DPO Foundation, From €1,000 per month. Transfer impact assessments are charged at client rates on Privacy Advisory and DPO Foundation and included in scope on DPO Partner and DPO Complete; the figures are on the pricing page.

  • Same-business-day response
  • Professional indemnity and cyber insurance
  • Named DPO notified to the supervisory authority
  • Trust Center

FAQ

Frequently asked questions

What does GDPR require when we choose a vendor?

Where a vendor processes personal data on your behalf, Article 28(1) says you may use only processors providing sufficient guarantees to implement appropriate technical and organizational measures. Article 28(3) then requires a contract or other legal act binding on the processor, with specific stipulations such as processing only on your documented instructions.

Is a vendor's certification or audit report enough?

Not on its own. Sufficient guarantees in Article 28(1) is not defined by a certification or an audit. It is a judgment you have to be able to defend, and a SOC 2 report is one piece of evidence toward it, typically alongside the DPA and the sub-processor list.

What do you check in a vendor's DPA?

That it covers the Article 28(3) topics, that the vendor discloses its sub-processors or commits to a process for disclosing them, that breach notification commitments are specific, that you have audit rights, and that the vendor commits to returning or deleting the data at the end of the contract. We also flag terms that weaken your position, such as broad processor discretion on sub-processors.

Can a vendor add sub-processors without asking us?

No. Under Article 28(2) a processor may not engage another processor without your prior specific or general written authorization. Where the authorization is general, the processor has to tell you about intended additions or replacements so you have the opportunity to object.

Is vendor due diligence included in your DPO plans?

Yes. Vendor management is part of DPO Foundation, From €1,000 per month. Transfer impact assessments are charged at client rates on Privacy Advisory and DPO Foundation and are included in scope on DPO Partner and DPO Complete. See pricing for the full list.