Research and updates
Blog
DPAFlow updates and subprocessor monitoring notes.
Search
Showing 1–12 of 46.
Latest posts
2026-07-29 · gdpr
How to Create a Record of Processing Activities
The Article 30 field list is the easy part. This is the practical build: discovering the processing nobody wrote down, deciding what counts as one activity, running interviews that produce facts rather than guesses, and sequencing a first register so it becomes usable before it is finished.
2026-07-29 · subprocessors
When a Vendor Adds an AI Subprocessor: What Actually Changes
An AI provider added to a vendor's subprocessor list triggers the same Article 28 notice and objection rights as any other subprocessor. Four questions are specific to model processing: whether your data trains the model, how long it is retained, where inference happens, and whether output drives decisions about people.
2026-07-29 · dpa
When a Vendor Has a Data Breach: Your GDPR Notification Duties
Your processor owes you notification without undue delay; you owe the supervisory authority a decision within 72 hours. What counts as a breach, what awareness means, the two different notification thresholds, and the one contract clause that determines how much of your 72 hours you actually keep.
2026-07-29 · gdpr
RoPA vs DPIA: What Is the Difference and Which Do You Need?
A RoPA is an inventory of all your processing; a DPIA is a risk assessment of the high-risk parts, completed before that processing starts. What Article 30 and Article 35 each require, the five differences that matter, how to tell whether a DPIA is needed, and why vendor changes affect one document far more than the other.
2026-07-29 · schrems-ii
When Is a Transfer Impact Assessment Required?
Whether you need a Transfer Impact Assessment depends on the transfer tool you rely on, not on the sensitivity of the data. A walkthrough of adequacy decisions, Article 46 safeguards, and Article 49 derogations, plus the subprocessor legs that pull transfers into scope unnoticed.
2026-07-29 · gdpr
Records of Processing Activities: What Article 30 Actually Requires
What GDPR Article 30 requires in a record of processing activities, field by field, who the small-organisation exemption really covers, and why the recipient and third-country transfer fields go out of date without anyone in your organisation changing anything.
2026-07-25 · vendor-risk
How Privacy, Legal, Security, and Procurement Can Share Vendor Reviews
Vendor review needs four functions to agree, and it stalls in the handoffs rather than the analysis. Divide by decision rather than by document, fix the three handoffs that lose weeks, and keep one record with four views.
2026-07-25 · gdpr
What Evidence Should You Retain From Vendor Reviews?
Keeping everything forever and keeping nothing both fail. How to set retention by purpose, why most of this material is not personal data, a workable schedule, and how to dispose of evidence defensibly without erasing former vendors.
2026-07-25 · vendor-risk
Vendor Discovery and Privacy Due Diligence in the Nordics
Norway and Iceland are in the European Economic Area, so transfers there are not restricted transfers. Once that is settled, Nordic vendor diligence turns on the chain behind a local supplier, sector scrutiny, and which language version you assessed.
2026-07-25 · schrems-ii
How to Verify a US Vendor's Data Privacy Framework Certification
A certification claim can remove the need for Standard Contractual Clauses, or be true in general and inapplicable to your transfer. Five checks: the entity, currency, scope, the receiving party, and whether a fallback exists.
2026-07-25 · dpa
Vendor Offboarding: Data Return, Deletion, and Evidence
The contract ends and the data often stays. How to make Article 28(3)(g) operate: choose return or deletion, map every system that holds data, bound the backup carve-out, and obtain written confirmation you can file.
2026-07-25 · schrems-ii
Data Residency vs Data Location vs International Data Transfer
Three phrases used interchangeably that mean different things. A transfer can happen without data moving at all, because access is enough. What residency is still worth, and the four questions that produce usable answers.
Categories
Monitor subprocessor changes before they become audit work.
Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.