VENDOR AND PROCESSOR MANAGEMENT

Know That Every Vendor Has a Valid DPA

A governed register for every processor that touches personal data on your behalf. Attach the agreement, work through the nine Art. 26(3) clauses one by one, and prove your due diligence when someone asks. Law 124/2024 mirrors the GDPR here, so the same nine clauses satisfy Art. 28(3) for group reporting.

9
Mandatory DPA Clauses
26-27
Law 124/2024 Articles
10
Vendor Compliance Rules
Cloud Hosting Provider
Processor · Data processing agreement
DPA.pdf
Art. 26(3) clause completeness 7 of 9
Two mandatory clauses are still missing from this agreement.
Documented instructions from the controller 26(3)(a)
Confidentiality commitment for authorised staff 26(3)(b)
Security measures 26(3)(c)
Sub-processor authorisation 26(3)(d)
Assistance with data subject rights 26(3)(e)
Audit rights for the controller 26(3)(h)

The Question Is Not Whether You Have a Contract

Outsourcing the work does not move the responsibility off your desk. When a review comes, nobody asks whether you have a contract with your processor. They ask what is in it, which clauses are covered, and how you know.

A Folder of PDFs Is Not a Register

Signed agreements sit in shared drives and inboxes. Nobody can say which ones contain all nine mandatory clauses without opening every file and reading it again.

Sub-Processors Appear Without Notice

Your processor engages someone else, and the notification lands in an inbox nobody owns. Without a recorded authorisation or objection, you cannot show you exercised the control the law gives you.

"We Trust Them" Is Not Evidence

Due diligence has to be demonstrable: what you checked, when you checked it, and what the outcome was. A recollection of a procurement conversation is not going to satisfy a reviewer.

One Governed Record per Vendor

Each third party that handles personal data on your behalf gets a single record, searchable and filterable, holding everything a reviewer would ask to see.

Role and Relationship

Processor, sub-processor or joint controller, with category, country, lifecycle status and the internal owner accountable for the relationship.

Dates That Matter

Agreement dates and review dates on the record, so the relationship has a defined review rhythm rather than drifting until something goes wrong.

What They Hold and How They Protect It

The categories of data the vendor handles, plus a summary of their security posture, kept alongside the agreement rather than in a separate assessment file.

Vendor register

Illustrative view of a processor list

Vendor
Role
DPA
Review
Cloud Hosting Provider
Processor
7 of 9
Mar 2026
Payroll Bureau
Processor
9 of 9
Sep 2026
Email Delivery Service
Sub-processor
9 of 9
Jan 2027
Marketing Analytics Co.
Joint
4 of 9
Overdue

We Verify the Clauses, Not Just Store the File

Plenty of tools let you attach a PDF. PrivaxisOS tracks the nine clauses of Art. 26(3), which mirror GDPR Art. 28(3), individually and shows completeness as a percentage, which is the difference between having a contract and knowing what is in it.

1

Documented Instructions

The processor acts only on your documented instructions, including for transfers to another country.

2

Confidentiality

Everyone authorised to process the data is bound by confidentiality or a statutory duty of it.

3

Security Measures

The processor implements appropriate technical and organisational measures for the risk.

4

Sub-Processor Authorisation

No sub-processor is engaged without your prior specific or general written authorisation.

5

Data Subject Rights Assistance

The processor helps you respond to access, erasure, rectification and portability requests.

6

Breach Notification

The processor notifies you without undue delay after becoming aware of a personal data breach.

7

DPIA Assistance

The processor supports your impact assessments and any prior consultation that follows.

8

Deletion or Return

At the end of the service the data is deleted or returned, at your choice, and copies removed.

9

Audit Rights

The processor makes available the information needed to demonstrate compliance and allows audits.

Authorise the Chain, Evidence the Diligence

Two obligations that usually live in someone's memory become recorded states you can point at.

Sub-Processor Authorisation

Record the sub-processors a vendor engages and decide on each one: authorised, pending, or objected. Specific and general authorisation are distinguished, so an objection you raised is a state you can stand behind rather than an email you have to find.

Art. 26(2), 26(4) / GDPR Art. 28(2), 28(4)

Due Diligence on File

A completed flag, the date, the outcome and the certifications the vendor holds, such as ISO 27001 or SOC 2, plus a linked vendor risk assessment from the Assessments module. That is what "sufficient guarantees" looks like as evidence.

Art. 26(1) / GDPR Art. 28(1)

Vendor Compliance Rules

Rules VN-01 to VN-10 evaluate every vendor in the register and produce findings plus an organisation-level vendor score in the Compliance Intelligence Hub. Run an on-demand vendor audit whenever you need a current picture.

Arts. 26-27 / GDPR Arts. 28, 30

Where a vendor shows up

The same governed record, referenced across the platform

ROPA Processor named on a processing record DPA status shown
HUB Vendor findings and org-level vendor score VN-01 to VN-10
RISK Linked vendor risk assessment Assessments
CHECK Recipient not in the register is flagged RP-11

Governed Once, Referenced Everywhere

A vendor is entered once. From then on, the record is what the rest of the platform points at, which means no re-keying and no two versions of the truth.

The ROPA Bridge

Link a processor named on a record of processing activities to its governed vendor, and the DPA status appears in the ROPA context. Recipients missing from the register are flagged by the ROPA checker.

Third-Party Risk in Your Score

Vendor gaps are not a separate report. They appear in the same findings queue and the same organisation-wide score as everything else in the Compliance Intelligence Hub.

Assessments Where They Belong

A vendor risk assessment is linked to the vendor it assesses, so the diligence evidence and the relationship it applies to are never separated.

Prove Every Processor Is Governed

See the vendor register, the Art. 26(3) clause checklist and the sub-processor authorisation flow against a worked example.

Request a Demo Explore the Compliance Hub