Article
5 steps to GDPR-compliant vendor due diligence - DPO Centre
dpocentre.ca
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Key details to establish: “How personal data will be collected” Where it will be stored
You’ll learn how to: “Review the vendor’s data handling practices” Assess policies and procedures
Review the vendor’s data handling practices “Assess policies and procedures” Evaluate technical security measures
Assess policies and procedures “Evaluate technical security measures” Review international data transfer controls and processes
Evaluate technical security measures “Review international data transfer controls and processes” Mitigate risks & finalise the Data Processor Agreement (DPA)
Review international data transfer controls and processes “Mitigate risks & finalise the Data Processor Agreement (DPA)” Overview
According to a report by technavio, the global outsourcing market is expected to grow by $88.8 billion between 2024 and 2029, with a compound annual growth rate of 6.8%. “However, when you have vendors handling personal data, it’s critical to understand the associated data protection responsibilities of both parties.” Under the General Data Protection Regulation (GDPR), vendors include any third parties, partners, or suppliers with access to personal data – not just traditional service providers.