Skip to content
DPAFlow

Research and updates

Blog

DPAFlow updates and subprocessor monitoring notes.

Search

Showing 25–36 of 46.

Latest posts

2026-07-25 · vendor-risk

Vendor Discovery and Privacy Due Diligence in the Nordics

Norway and Iceland are in the European Economic Area, so transfers there are not restricted transfers. Once that is settled, Nordic vendor diligence turns on the chain behind a local supplier, sector scrutiny, and which language version you assessed.

2026-07-25 · gdpr

What Evidence Should You Retain From Vendor Reviews?

Keeping everything forever and keeping nothing both fail. How to set retention by purpose, why most of this material is not personal data, a workable schedule, and how to dispose of evidence defensibly without erasing former vendors.

2026-07-25 · subprocessors

How DPAFlow Monitors Subprocessor Pages and Preserves Evidence

How DPAFlow works, step by step: a vendor watchlist, scheduled page checks, dated change evidence, email alerts, a review workflow, exportable proof, and the boundaries stated plainly.

2026-07-25 · subprocessors

What Is a Subprocessor? Definition, Examples, and GDPR Obligations

A plain-language guide to subprocessors under the GDPR: what they are, how Article 28 governs them, how authorization and flow-down obligations work, and what controllers should do when a vendor's list changes.

2026-07-25 · schrems-ii

Transfer Impact Assessments: A Practical Walkthrough

A practical walkthrough of Transfer Impact Assessments: where the duty comes from, when you need one, the EDPB six-step method in practice, and how to keep TIAs current as vendors and subprocessors change.

2026-07-25 · gdpr

Controller, Processor, and Sub-processor: GDPR Roles Explained

Controller, processor, and sub-processor are distinct GDPR roles with different obligations. This guide explains each role with SaaS-shaped examples, covers joint controllership, and shows why classification matters.

2026-07-25 · dpa

GDPR Article 28: What Data Processing Agreements Must Cover

GDPR Article 28 sets mandatory content for every data processing agreement. This guide walks through each required clause, the sub-processing rules, the Commission's optional standard clauses, and common gaps in vendor DPAs.

2026-07-25 · dpa

Sub-processor Change Notifications Under GDPR

General authorization, notice mechanics, and the right to object: how sub-processor change notifications work under GDPR Article 28, and how to keep a silent page change from becoming an unassessed authorization.

2026-07-25 · subprocessors

Why SaaS Subprocessor Lists Change

Subprocessor lists change for operational reasons that rarely wait for contract renewals. Here is what drives the churn, why page formats vary so much, and why silent changes matter for controllers.

2026-07-25 · vendor-risk

Fourth-Party Risk: The Vendors of Your Vendors

Your vendors' subprocessors are your fourth parties: organizations you never contracted with that may still hold your customers' personal data. Here is how GDPR Article 28(4) binds the chain, and how to map and watch it.

2026-07-25 · gdpr

How to Build a Vendor and Subprocessor Inventory

Every GDPR vendor duty starts from one question: who has our data? Here is how to build a vendor and subprocessor inventory that answers it — scoping, minimal fields, collection sources, and the maintenance rhythm that keeps it true.

2026-07-25 · vendor-risk

Subprocessor Monitoring: The Complete Guide

The complete guide to subprocessor monitoring under the GDPR: why Article 28(2) makes it necessary, what to monitor, what good looks like, manual and automated approaches, and a four-stage maturity path.

Categories

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow