Skip to content
DPAFlow

Research and updates

Blog

DPAFlow updates and subprocessor monitoring notes.

Search

Showing 1–12 of 46.

Latest posts

2026-07-29 · gdpr

How to Create a Record of Processing Activities

The Article 30 field list is the easy part. This is the practical build: discovering the processing nobody wrote down, deciding what counts as one activity, running interviews that produce facts rather than guesses, and sequencing a first register so it becomes usable before it is finished.

2026-07-29 · subprocessors

When a Vendor Adds an AI Subprocessor: What Actually Changes

An AI provider added to a vendor's subprocessor list triggers the same Article 28 notice and objection rights as any other subprocessor. Four questions are specific to model processing: whether your data trains the model, how long it is retained, where inference happens, and whether output drives decisions about people.

2026-07-29 · dpa

When a Vendor Has a Data Breach: Your GDPR Notification Duties

Your processor owes you notification without undue delay; you owe the supervisory authority a decision within 72 hours. What counts as a breach, what awareness means, the two different notification thresholds, and the one contract clause that determines how much of your 72 hours you actually keep.

2026-07-29 · gdpr

RoPA vs DPIA: What Is the Difference and Which Do You Need?

A RoPA is an inventory of all your processing; a DPIA is a risk assessment of the high-risk parts, completed before that processing starts. What Article 30 and Article 35 each require, the five differences that matter, how to tell whether a DPIA is needed, and why vendor changes affect one document far more than the other.

2026-07-29 · schrems-ii

When Is a Transfer Impact Assessment Required?

Whether you need a Transfer Impact Assessment depends on the transfer tool you rely on, not on the sensitivity of the data. A walkthrough of adequacy decisions, Article 46 safeguards, and Article 49 derogations, plus the subprocessor legs that pull transfers into scope unnoticed.

2026-07-29 · gdpr

Records of Processing Activities: What Article 30 Actually Requires

What GDPR Article 30 requires in a record of processing activities, field by field, who the small-organisation exemption really covers, and why the recipient and third-country transfer fields go out of date without anyone in your organisation changing anything.

2026-07-25 · vendor-risk

How Privacy, Legal, Security, and Procurement Can Share Vendor Reviews

Vendor review needs four functions to agree, and it stalls in the handoffs rather than the analysis. Divide by decision rather than by document, fix the three handoffs that lose weeks, and keep one record with four views.

2026-07-25 · gdpr

What Evidence Should You Retain From Vendor Reviews?

Keeping everything forever and keeping nothing both fail. How to set retention by purpose, why most of this material is not personal data, a workable schedule, and how to dispose of evidence defensibly without erasing former vendors.

2026-07-25 · vendor-risk

Vendor Discovery and Privacy Due Diligence in the Nordics

Norway and Iceland are in the European Economic Area, so transfers there are not restricted transfers. Once that is settled, Nordic vendor diligence turns on the chain behind a local supplier, sector scrutiny, and which language version you assessed.

2026-07-25 · schrems-ii

How to Verify a US Vendor's Data Privacy Framework Certification

A certification claim can remove the need for Standard Contractual Clauses, or be true in general and inapplicable to your transfer. Five checks: the entity, currency, scope, the receiving party, and whether a fallback exists.

2026-07-25 · dpa

Vendor Offboarding: Data Return, Deletion, and Evidence

The contract ends and the data often stays. How to make Article 28(3)(g) operate: choose return or deletion, map every system that holds data, bound the backup carve-out, and obtain written confirmation you can file.

2026-07-25 · schrems-ii

Data Residency vs Data Location vs International Data Transfer

Three phrases used interchangeably that mean different things. A transfer can happen without data moving at all, because access is enough. What residency is still worth, and the four questions that produce usable answers.

Categories

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow