Vendor due diligence usually arrives from two directions at once: a customer asks you to prove your own vendors are safe, and your product team wants to add a new tool by Friday. Both come down to the same question under GDPR, which is whether each processor you rely on gives you sufficient guarantees, and whether you can show it.
Key takeaways
- Under Article 28(1), a controller may use only processors providing sufficient guarantees to implement appropriate technical and organizational measures.
- Article 28(3) requires a contract or other legal act with each processor, which is the DPA.
- A processor needs your prior written authorization before it engages a sub-processor (Article 28(2)).
- Transfers outside the EU need their own safeguard, such as the Commission’s standard contractual clauses under Article 46(2)(c).
- Engage Compliance runs vendor due diligence inside its DPO service, so the same named DPO who knows your stack reviews each vendor.
What the law asks of you
Article 28 is the processor article, and it usually reaches a company through its customers rather than through a regulator. If a vendor processes personal data on your behalf, you can only use them where they provide sufficient guarantees, and the arrangement has to sit in a contract carrying the stipulations listed in Article 28(3).
That contract binds the processor to act only on your documented instructions (including on transfers), to keep the people processing the data under confidentiality, and to take the security measures Article 32 points at. It also has to respect the sub-processor conditions, help you with data subject requests and with your Articles 32 to 36 obligations (within the limits Article 28(3)(e) and (f) set), and delete or return the data at the end of the services.
Sufficient guarantees is not defined by a certification or an audit. It’s a judgment you have to be able to defend, which is why the review itself, written down, matters as much as the signed DPA.
Where a vendor moves personal data outside the EU, Article 28 is not the rule that governs the transfer; Chapter V is. Without an adequacy decision, Article 46 lets the transfer rely on appropriate safeguards, including standard data protection clauses adopted by the Commission, and we pair those with a transfer impact assessment.
What we review
- The vendor’s DPA. Whether it covers the Article 28(3) topics, and where it doesn’t, the additions to ask for. See our guide on what to do when a vendor sends you their DPA.
- Sub-processors. Whether the vendor discloses its sub-processors or commits to a process for disclosing them, and how you’ll hear about changes.
- Breach notification. Whether the vendor commits to notifying you of breaches affecting your data without undue delay, with specific commitments on what it will tell you.
- Audit rights. Direct audit rights, or third-party attestations such as SOC 2 reports.
- Return and deletion. A commitment to return or delete your data at the end of the contract, with specific timing.
- Transfers. Cross-border transfer assessments, meaning the standard contractual clauses and a transfer impact assessment where the vendor or its sub-processors sit outside the EU.
- Red flags. Terms that limit the vendor’s help with data subject rights, give it broad discretion on sub-processors, or weaken its breach commitments.
For SaaS companies this usually means vendor risk assessments for the sub-processors behind the product: hosting, analytics, payment and communications.
How Engage Compliance helps
Vendor and third-party due diligence, DPAs, cross-border transfer assessments and supplier risk management are part of our outsourced DPO services. Your DPO reviews new vendors as product and procurement bring them in. The recipients and transfers they involve go into the Records of Processing Activities we maintain for you, so the answer is ready when an enterprise customer or an investor asks how you vet your own suppliers.
Vendor management is part of DPO Foundation, From €1,000 per month. Transfer impact assessments are charged at client rates on Privacy Advisory and DPO Foundation and included in scope on DPO Partner and DPO Complete; the figures are on the pricing page.