Skip to content
TrustList
Due diligence

Due diligence on a supplier that processes personal data

The privacy review, for the person who has to sign it off: what the law requires you to have in the contract, what to check before you rely on it, and what to do about transfers.

17 questions10 deal-stoppersv1.0 · reviewed 19 September 2026

As controller you stay accountable for what your processor does. That is the whole reason this review exists: you cannot contract the obligation away, only the work. This list follows the shape of what a UK or EU controller needs to be able to show, and is written for the person who will be asked to justify the choice later. It is not legal advice — take your own on anything contentious.

Before anything else

Three questions that decide how much of the rest applies.

  1. Is the supplier a processor, a joint controller, or an independent controller for this data?

    Deal-stopper

    Suppliers frequently describe themselves as processors while using the data for their own purposes, which makes them a controller and changes what you both owe. Product improvement and analytics are the usual giveaways.

    Ask for: A written statement of role per processing activity, and the terms that describe any use for the supplier's own purposes.

    Red flags

    • 'Processor' claimed while data is used to improve the product
    • Role unstated
    • Role differs between the DPA and the privacy notice
  2. Exactly which personal data, about whom, and for how long?

    Deal-stopper

    Article 28 requires the subject matter, duration, nature, purpose, data types and categories of data subject to be set out. It is also the only way to notice that the scope is wider than you assumed.

    Ask for: The schedule to the DPA listing all six.

    Red flags

    • Schedule generic or blank
    • Special category data not identified as such
    • Children's data unflagged
  3. Does this processing require a data protection impact assessment?

    Important

    Large-scale special category data, systematic monitoring, and automated decisions with legal effects are the common triggers. Deciding after go-live is the expensive order.

    Ask for: Your own screening assessment, and the supplier's input where you need it.

    Red flags

    • Screening not done
    • Supplier unable to answer questions the assessment needs

What the contract has to say

These are the terms a processor contract is required to contain. Check they are present and that they are not quietly narrowed elsewhere.

  1. Does the supplier process only on our documented instructions?

    Deal-stopper

    It is the core of the processor relationship, and the clause is often undercut by a separate term letting the supplier process for its own purposes.

    Ask for: The instructions clause, read against the rest of the agreement for carve-outs.

    Red flags

    • Broad carve-out for the supplier's own purposes
    • Instructions may be varied unilaterally
  2. Are the supplier's staff under a confidentiality obligation?

    Important

    Required, and easy to confirm.

    Ask for: The confidentiality clause covering personnel.

    Red flags

    • Covers employees but not contractors
  3. Are the technical and organisational measures specified, or just promised?

    Deal-stopper

    'Appropriate measures' with nothing behind it is unenforceable and tells you nothing. A real annex lists controls you could audit.

    Ask for: An annex describing actual controls — encryption, access control, logging, testing.

    Red flags

    • Measures described only as 'industry standard'
    • Annex references a web page the supplier can change at will
  4. Will the supplier help us with data subject rights, breach notification and assessments — and at what cost?

    Deal-stopper

    Required assistance is sometimes priced as a professional services engagement, which effectively removes it.

    Ask for: The assistance clause, with any charges stated.

    Red flags

    • Assistance chargeable at day rates
    • Response times unstated
  5. What audit rights do we have, and what will actually be provided?

    Important

    Most suppliers satisfy audit rights with a certification report rather than an on-site audit. That can be reasonable — but you should know which you are getting before you need it.

    Ask for: The audit clause, and a sample of what is normally provided.

    Red flags

    • Audit refused outright
    • Only a marketing summary offered
    • Audit permitted once per contract lifetime
  6. At the end, is data returned or deleted at our choice?

    Deal-stopper

    Required, and the choice should be yours rather than the supplier's default.

    Ask for: The clause, with the timetable and treatment of backups.

    Red flags

    • Supplier chooses
    • Backups excluded
    • Deletion not confirmed in writing

Data leaving the country

The part most often left until after signature, and the part with the least room to improvise.

  1. Which countries will the data be in, including backups, logs and support access?

    Deal-stopper

    Primary storage is usually documented. Backups, log aggregation and the support team's location frequently are not, and each is a transfer.

    Ask for: A list covering primary storage, backups, logging and every location support staff work from.

    Red flags

    • Only primary storage named
    • Support location unstated
    • 'Global team' with no detail
  2. What is the lawful mechanism for each transfer?

    Deal-stopper

    Adequacy, standard contractual clauses or another route — and where clauses are used, a transfer risk assessment usually goes with them.

    Ask for: The mechanism named per destination, with the clauses executed and the assessment on file.

    Red flags

    • Mechanism unnamed
    • Clauses referenced but not signed
    • Assessment absent where required
  3. Has the supplier received government requests for customer data, and does it publish a transparency report?

    Important

    It is directly relevant to a transfer risk assessment, and a supplier that publishes a report has already thought about the question.

    Ask for: A transparency report, or a written statement.

    Red flags

    • Question not understood
    • Refusal to answer in any form

Whether it works in practice

Contract terms are necessary. These questions test whether anything stands behind them.

  1. Walk us through the last time you notified a customer of an incident.

    Important

    A supplier that has done it can describe the mechanics. One that has not will describe the policy, and the difference is audible.

    Ask for: A specific account, or a description of the tested process.

    Red flags

    • Process never exercised
    • No named owner
    • Notification timeline vague
  2. How do we get one person's data out, or erased, and how long does it take?

    Deal-stopper

    You have a deadline to meet. If satisfying it needs a support ticket and a week, that is your problem, not the supplier's.

    Ask for: A self-service route if one exists, otherwise a committed turnaround.

    Red flags

    • Manual process only
    • No committed turnaround
    • Charged per request
  3. Does the supplier's public privacy notice match what the DPA says?

    Important

    Where they differ, the notice usually describes what actually happens and the DPA describes what was negotiated.

    Ask for: Both documents, read side by side.

    Red flags

    • Notice describes purposes the DPA excludes
    • Notice names sub-processors the list omits
  4. Can we record this supplier in our processing records today?

    Worth asking

    If you cannot fill in the fields, the diligence is not finished — and the gaps are exactly the terms you have not pinned down.

    Ask for: Your own record of processing activities, completed.

    Red flags

    • Fields left blank
    • Supplier contact for privacy matters unknown

This checklist is general guidance, not legal, security or financial advice, and it does not replace your own advisers on anything contentious. It was last reviewed on 19 September 2026. Tell us if something here is wrong or missing.