Research and updates
Blog
DPAFlow updates and subprocessor monitoring notes.
Search
Showing 25–36 of 46.
Latest posts
2026-07-25 · vendor-risk
Vendor Discovery and Privacy Due Diligence in the Nordics
Norway and Iceland are in the European Economic Area, so transfers there are not restricted transfers. Once that is settled, Nordic vendor diligence turns on the chain behind a local supplier, sector scrutiny, and which language version you assessed.
2026-07-25 · gdpr
What Evidence Should You Retain From Vendor Reviews?
Keeping everything forever and keeping nothing both fail. How to set retention by purpose, why most of this material is not personal data, a workable schedule, and how to dispose of evidence defensibly without erasing former vendors.
2026-07-25 · subprocessors
How DPAFlow Monitors Subprocessor Pages and Preserves Evidence
How DPAFlow works, step by step: a vendor watchlist, scheduled page checks, dated change evidence, email alerts, a review workflow, exportable proof, and the boundaries stated plainly.
2026-07-25 · subprocessors
What Is a Subprocessor? Definition, Examples, and GDPR Obligations
A plain-language guide to subprocessors under the GDPR: what they are, how Article 28 governs them, how authorization and flow-down obligations work, and what controllers should do when a vendor's list changes.
2026-07-25 · schrems-ii
Transfer Impact Assessments: A Practical Walkthrough
A practical walkthrough of Transfer Impact Assessments: where the duty comes from, when you need one, the EDPB six-step method in practice, and how to keep TIAs current as vendors and subprocessors change.
2026-07-25 · gdpr
Controller, Processor, and Sub-processor: GDPR Roles Explained
Controller, processor, and sub-processor are distinct GDPR roles with different obligations. This guide explains each role with SaaS-shaped examples, covers joint controllership, and shows why classification matters.
2026-07-25 · dpa
GDPR Article 28: What Data Processing Agreements Must Cover
GDPR Article 28 sets mandatory content for every data processing agreement. This guide walks through each required clause, the sub-processing rules, the Commission's optional standard clauses, and common gaps in vendor DPAs.
2026-07-25 · dpa
Sub-processor Change Notifications Under GDPR
General authorization, notice mechanics, and the right to object: how sub-processor change notifications work under GDPR Article 28, and how to keep a silent page change from becoming an unassessed authorization.
2026-07-25 · subprocessors
Why SaaS Subprocessor Lists Change
Subprocessor lists change for operational reasons that rarely wait for contract renewals. Here is what drives the churn, why page formats vary so much, and why silent changes matter for controllers.
2026-07-25 · vendor-risk
Fourth-Party Risk: The Vendors of Your Vendors
Your vendors' subprocessors are your fourth parties: organizations you never contracted with that may still hold your customers' personal data. Here is how GDPR Article 28(4) binds the chain, and how to map and watch it.
2026-07-25 · gdpr
How to Build a Vendor and Subprocessor Inventory
Every GDPR vendor duty starts from one question: who has our data? Here is how to build a vendor and subprocessor inventory that answers it — scoping, minimal fields, collection sources, and the maintenance rhythm that keeps it true.
2026-07-25 · vendor-risk
Subprocessor Monitoring: The Complete Guide
The complete guide to subprocessor monitoring under the GDPR: why Article 28(2) makes it necessary, what to monitor, what good looks like, manual and automated approaches, and a four-stage maturity path.
Categories
Monitor subprocessor changes before they become audit work.
Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.