Skip to content
DPAFlow

Research and updates

Blog

DPAFlow updates and subprocessor monitoring notes.

Search

Showing 13–24 of 46.

Latest posts

2026-07-25 · vendor-risk

Vendor Risk Assessment Workflow for SaaS Procurement

Assess the processing, not the company. How to rate inherent exposure, weigh the control picture, express residual risk as a decision with a named owner, and define in advance what invalidates the assessment.

2026-07-25 · vendor-risk

How to Prioritize Vendors for Privacy and Compliance Review

Reviewing every vendor to the same depth is not possible past a few hundred suppliers. Triage on processing rather than spend, use three tiers, define the escalation triggers that override them, and record the reasoning.

2026-07-25 · subprocessors

General vs Specific Authorization for Subprocessors Under GDPR

Article 28(2) permits prior specific or general written authorization. Both are lawful; they place the ongoing burden in different places. What each model means in practice, what to check in the notice terms, and which to negotiate for.

2026-07-25 · subprocessors

How to Evaluate a Vendor's Subprocessor List Before Signing

A sub-processor list tells you who else touches your data and how honestly a supplier describes its chain. What a complete entry contains, the six gaps that matter, and how to turn the list into evidence you can still rely on later.

2026-07-25 · subprocessors

How to Handle a Subprocessor Objection

The objection right is procedural: it is worth what your ability to act inside the window is worth. How to assess a change, which grounds hold up, how to raise it, what remedies realistically exist, and what to record either way.

2026-07-25 · vendor-risk

Vendor Privacy Questionnaire: Questions to Ask Before Contracting

Most vendor privacy questionnaires are too long and ask questions that cannot discriminate between suppliers. The questions that earn their place, why each one works, and how to read the answers you get back.

2026-07-25 · gdpr

Processor Audit Rights Under GDPR Article 28

Article 28(3)(h) contains two rights that behave very differently: a standing information right you will use constantly, and an inspection right that standard contracts narrow heavily. What each gives you, and what to negotiate.

2026-07-25 · schrems-ii

International Data Transfer Checklist for SaaS Vendors

An eight-step operational checklist for a single vendor: establish whether there is a transfer at all, map destinations including access and backups, pick a mechanism per destination, check the clauses were completed, and record what invalidates the analysis.

2026-07-25 · schrems-ii

Standard Contractual Clauses and Subprocessors: What to Review

The clauses are boilerplate; the annexes and the onward transfer provisions carry the substance. Which module applies, what defective annexes look like, how Clause 8.8 and the docking clause govern the chain, and what to check.

2026-07-25 · schrems-ii

Data Residency vs Data Location vs International Data Transfer

Three phrases used interchangeably that mean different things. A transfer can happen without data moving at all, because access is enough. What residency is still worth, and the four questions that produce usable answers.

2026-07-25 · dpa

Vendor Offboarding: Data Return, Deletion, and Evidence

The contract ends and the data often stays. How to make Article 28(3)(g) operate: choose return or deletion, map every system that holds data, bound the backup carve-out, and obtain written confirmation you can file.

2026-07-25 · schrems-ii

How to Verify a US Vendor's Data Privacy Framework Certification

A certification claim can remove the need for Standard Contractual Clauses, or be true in general and inapplicable to your transfer. Five checks: the entity, currency, scope, the receiving party, and whether a fallback exists.

Categories

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow