Article 28(1) of the General Data Protection Regulation (GDPR) permits a controller to use only processors providing sufficient guarantees that processing will meet the regulation's requirements. Due diligence is how you establish that those guarantees exist, and how you show later that you checked.
This is a checklist for that examination. It covers the vendor rather than the contract: what the supplier does, where the data goes, who else touches it, and what evidence supports each answer. The contract review is a separate exercise, covered in our Data Processing Agreement review checklist.
Run the depth that matches the risk. A tool holding special category data for tens of thousands of people warrants a different examination from a scheduling utility holding a handful of business email addresses. Our guidance on prioritizing vendors for privacy review sets out workable tiering criteria.
Section 1: scope the processing before you assess anything
Every later question depends on this, and skipping it is the most common cause of diligence that looks thorough and proves nothing.
- What personal data will actually flow to this vendor, by category?
- Whose data is it: customers, employees, candidates, patients, children?
- Does it include special category data under Article 9, or criminal offence data under Article 10?
- What is the purpose, and is it the purpose the data was collected for?
- What volume, and over what period?
- Is production data genuinely required, or would pseudonymized or test data serve?
Write the answers down. A vendor assessed against an inaccurate scope has been assessed against the wrong risk.
Section 2: the vendor's role
- Is the vendor a processor acting on your instructions, an independent controller, or a joint controller for part of the processing?
- What is the basis for that determination in fact, not in the contract wording?
- If the vendor claims controller status for any adjacent purpose, such as service improvement or billing analytics, is that boundary written down?
The European Data Protection Board's Guidelines 07/2020 on the concepts of controller and processor govern here, and our article on roles in the chain covers the practical tests.
Section 3: sub-processors
- Does the vendor publish a sub-processor list, and where?
- Is the list complete, or does it cover only named categories?
- Which sub-processors are outside the European Economic Area?
- What is the authorization model, general or specific?
- What notice period applies before a new sub-processor is engaged?
- What is the objection mechanism, and what happens if you object?
- How are you notified: email, a subscription page, or nothing at all?
Capture the list as it stands on the date of assessment. A link is not evidence, because the page can change. Our article on evaluating a vendor's sub-processor list covers what a good list looks like and what the gaps usually mean.
Section 4: international transfers
- Which countries will the data be stored in or accessed from?
- For each destination outside the European Economic Area, what transfer mechanism applies?
- If the mechanism is an adequacy decision, does it actually cover this vendor and this data?
- If it is the Standard Contractual Clauses, which module, and are they incorporated properly?
- Does the vendor commit to providing the information you need to assess and maintain the position?
- Does support or engineering access the data from a third country, even if storage is in the European Economic Area?
That last question catches more real transfers than the storage question does. Our international data transfer checklist sets out the operational sequence, and the assessment methodology is in the transfer impact assessment guide.
Section 5: security
- What technical and organizational measures does the vendor describe, and are they specific enough to be tested?
- Is there independent assurance, such as a third-party audit report, and can you read it rather than merely hear about it?
- How is access controlled internally, and on what basis?
- Is the data encrypted in transit and at rest, and who holds the keys?
- What is the incident detection and notification process, with what trigger and timescale?
- What is the business continuity and recovery position?
The European Union Agency for Cybersecurity publishes useful background on supply chain exposure in its threat landscape work, which is a reasonable reference point for why the sub-processor layer deserves attention.
Section 6: data subject rights and assistance
- How does the vendor support access, rectification, erasure, and portability requests?
- What is the response time, and is it compatible with your own one-month obligation?
- Does the vendor assist with impact assessments and with breach notification?
- Can the vendor locate and extract one individual's data without a disproportionate project?
Section 7: retention, return, and deletion
- What are the retention periods, and are they configurable?
- What happens to the data at the end of the service: return, deletion, or both?
- On what deadline, and how are backups treated?
- Will the vendor confirm deletion in a form you can keep?
Section 8: the evidence file
Diligence that leaves no record has to be repeated. For each vendor, retain:
- The scope description and the role determination, with reasoning.
- The sub-processor list as captured on the assessment date.
- The transfer destinations and mechanisms.
- The security documentation reviewed, with version and date.
- The questionnaire responses, if you used one.
- The decision, its conditions, the owner, and the date.
Our article on audit-ready vendor evidence covers what makes this file defensible, and evidence retention covers how long to keep it.
Frequently asked questions
Is a completed questionnaire enough diligence?
It is an input, not a conclusion. A questionnaire records what the vendor says. Diligence means testing the answers that matter against documentation, published disclosures, and the contract. Our guide to the vendor privacy questionnaire covers which questions actually discriminate between vendors.
How often should diligence be repeated?
By risk tier rather than uniformly. The facts that change most often are the sub-processor list and the transfer position, and those can be watched continuously rather than revisited annually.
What if a vendor will not answer?
Record the refusal. A supplier that resists information requests before signature is unlikely to become more forthcoming afterwards, and that itself is diligence evidence.
Where DPAFlow fits in
Diligence produces a snapshot. DPAFlow keeps the snapshot from going stale: it checks vendor sub-processor lists, Data Processing Agreement pages, and trust-center pages on a scheduled, recurring basis, records what changed with dated evidence including captured page text and change differences, and sends email alerts when something moves. Detected changes enter a review workflow where your team records its assessment.
The judgments remain with your team, and DPAFlow does not provide legal advice. You can see how teams in procurement and vendor risk use it on the vendor risk use case page.
This checklist is a structure for diligence, not legal advice. Calibrate it to your own risk profile with your counsel.