A governed register for every processor that touches personal data on your behalf. Attach the agreement, work through the nine Art. 26(3) clauses one by one, and prove your due diligence when someone asks. Law 124/2024 mirrors the GDPR here, so the same nine clauses satisfy Art. 28(3) for group reporting.
Outsourcing the work does not move the responsibility off your desk. When a review comes, nobody asks whether you have a contract with your processor. They ask what is in it, which clauses are covered, and how you know.
Signed agreements sit in shared drives and inboxes. Nobody can say which ones contain all nine mandatory clauses without opening every file and reading it again.
Your processor engages someone else, and the notification lands in an inbox nobody owns. Without a recorded authorisation or objection, you cannot show you exercised the control the law gives you.
Due diligence has to be demonstrable: what you checked, when you checked it, and what the outcome was. A recollection of a procurement conversation is not going to satisfy a reviewer.
Each third party that handles personal data on your behalf gets a single record, searchable and filterable, holding everything a reviewer would ask to see.
Processor, sub-processor or joint controller, with category, country, lifecycle status and the internal owner accountable for the relationship.
Agreement dates and review dates on the record, so the relationship has a defined review rhythm rather than drifting until something goes wrong.
The categories of data the vendor handles, plus a summary of their security posture, kept alongside the agreement rather than in a separate assessment file.
Illustrative view of a processor list
Plenty of tools let you attach a PDF. PrivaxisOS tracks the nine clauses of Art. 26(3), which mirror GDPR Art. 28(3), individually and shows completeness as a percentage, which is the difference between having a contract and knowing what is in it.
The processor acts only on your documented instructions, including for transfers to another country.
Everyone authorised to process the data is bound by confidentiality or a statutory duty of it.
The processor implements appropriate technical and organisational measures for the risk.
No sub-processor is engaged without your prior specific or general written authorisation.
The processor helps you respond to access, erasure, rectification and portability requests.
The processor notifies you without undue delay after becoming aware of a personal data breach.
The processor supports your impact assessments and any prior consultation that follows.
At the end of the service the data is deleted or returned, at your choice, and copies removed.
The processor makes available the information needed to demonstrate compliance and allows audits.
Two obligations that usually live in someone's memory become recorded states you can point at.
Record the sub-processors a vendor engages and decide on each one: authorised, pending, or objected. Specific and general authorisation are distinguished, so an objection you raised is a state you can stand behind rather than an email you have to find.
Art. 26(2), 26(4) / GDPR Art. 28(2), 28(4)A completed flag, the date, the outcome and the certifications the vendor holds, such as ISO 27001 or SOC 2, plus a linked vendor risk assessment from the Assessments module. That is what "sufficient guarantees" looks like as evidence.
Art. 26(1) / GDPR Art. 28(1)Rules VN-01 to VN-10 evaluate every vendor in the register and produce findings plus an organisation-level vendor score in the Compliance Intelligence Hub. Run an on-demand vendor audit whenever you need a current picture.
Arts. 26-27 / GDPR Arts. 28, 30The same governed record, referenced across the platform
A vendor is entered once. From then on, the record is what the rest of the platform points at, which means no re-keying and no two versions of the truth.
Link a processor named on a record of processing activities to its governed vendor, and the DPA status appears in the ROPA context. Recipients missing from the register are flagged by the ROPA checker.
Vendor gaps are not a separate report. They appear in the same findings queue and the same organisation-wide score as everything else in the Compliance Intelligence Hub.
A vendor risk assessment is linked to the vendor it assesses, so the diligence evidence and the relationship it applies to are never separated.
See the vendor register, the Art. 26(3) clause checklist and the sub-processor authorisation flow against a worked example.