Due diligence on a supplier that processes personal data
The privacy review, for the person who has to sign it off: what the law requires you to have in the contract, what to check before you rely on it, and what to do about transfers.
As controller you stay accountable for what your processor does. That is the whole reason this review exists: you cannot contract the obligation away, only the work. This list follows the shape of what a UK or EU controller needs to be able to show, and is written for the person who will be asked to justify the choice later. It is not legal advice — take your own on anything contentious.
Before anything else
Three questions that decide how much of the rest applies.
Is the supplier a processor, a joint controller, or an independent controller for this data?
Deal-stopperSuppliers frequently describe themselves as processors while using the data for their own purposes, which makes them a controller and changes what you both owe. Product improvement and analytics are the usual giveaways.
Ask for: A written statement of role per processing activity, and the terms that describe any use for the supplier's own purposes.
Red flags
- 'Processor' claimed while data is used to improve the product
- Role unstated
- Role differs between the DPA and the privacy notice
Exactly which personal data, about whom, and for how long?
Deal-stopperArticle 28 requires the subject matter, duration, nature, purpose, data types and categories of data subject to be set out. It is also the only way to notice that the scope is wider than you assumed.
Ask for: The schedule to the DPA listing all six.
Red flags
- Schedule generic or blank
- Special category data not identified as such
- Children's data unflagged
Does this processing require a data protection impact assessment?
ImportantLarge-scale special category data, systematic monitoring, and automated decisions with legal effects are the common triggers. Deciding after go-live is the expensive order.
Ask for: Your own screening assessment, and the supplier's input where you need it.
Red flags
- Screening not done
- Supplier unable to answer questions the assessment needs
What the contract has to say
These are the terms a processor contract is required to contain. Check they are present and that they are not quietly narrowed elsewhere.
Does the supplier process only on our documented instructions?
Deal-stopperIt is the core of the processor relationship, and the clause is often undercut by a separate term letting the supplier process for its own purposes.
Ask for: The instructions clause, read against the rest of the agreement for carve-outs.
Red flags
- Broad carve-out for the supplier's own purposes
- Instructions may be varied unilaterally
Are the supplier's staff under a confidentiality obligation?
ImportantRequired, and easy to confirm.
Ask for: The confidentiality clause covering personnel.
Red flags
- Covers employees but not contractors
Are the technical and organisational measures specified, or just promised?
Deal-stopper'Appropriate measures' with nothing behind it is unenforceable and tells you nothing. A real annex lists controls you could audit.
Ask for: An annex describing actual controls — encryption, access control, logging, testing.
Red flags
- Measures described only as 'industry standard'
- Annex references a web page the supplier can change at will
Do we get prior notice of new sub-processors, and can we object?
Deal-stopperAuthorisation is required, and general authorisation is only meaningful if the notice period is long enough for you to act on an objection.
Ask for: The sub-processor clause with the notice period and what happens if you object.
Red flags
- No notice
- Objection permitted but with no remedy
- Notice period under 30 days
Will the supplier help us with data subject rights, breach notification and assessments — and at what cost?
Deal-stopperRequired assistance is sometimes priced as a professional services engagement, which effectively removes it.
Ask for: The assistance clause, with any charges stated.
Red flags
- Assistance chargeable at day rates
- Response times unstated
What audit rights do we have, and what will actually be provided?
ImportantMost suppliers satisfy audit rights with a certification report rather than an on-site audit. That can be reasonable — but you should know which you are getting before you need it.
Ask for: The audit clause, and a sample of what is normally provided.
Red flags
- Audit refused outright
- Only a marketing summary offered
- Audit permitted once per contract lifetime
At the end, is data returned or deleted at our choice?
Deal-stopperRequired, and the choice should be yours rather than the supplier's default.
Ask for: The clause, with the timetable and treatment of backups.
Red flags
- Supplier chooses
- Backups excluded
- Deletion not confirmed in writing
Data leaving the country
The part most often left until after signature, and the part with the least room to improvise.
Which countries will the data be in, including backups, logs and support access?
Deal-stopperPrimary storage is usually documented. Backups, log aggregation and the support team's location frequently are not, and each is a transfer.
Ask for: A list covering primary storage, backups, logging and every location support staff work from.
Red flags
- Only primary storage named
- Support location unstated
- 'Global team' with no detail
What is the lawful mechanism for each transfer?
Deal-stopperAdequacy, standard contractual clauses or another route — and where clauses are used, a transfer risk assessment usually goes with them.
Ask for: The mechanism named per destination, with the clauses executed and the assessment on file.
Red flags
- Mechanism unnamed
- Clauses referenced but not signed
- Assessment absent where required
Has the supplier received government requests for customer data, and does it publish a transparency report?
ImportantIt is directly relevant to a transfer risk assessment, and a supplier that publishes a report has already thought about the question.
Ask for: A transparency report, or a written statement.
Red flags
- Question not understood
- Refusal to answer in any form
Whether it works in practice
Contract terms are necessary. These questions test whether anything stands behind them.
Walk us through the last time you notified a customer of an incident.
ImportantA supplier that has done it can describe the mechanics. One that has not will describe the policy, and the difference is audible.
Ask for: A specific account, or a description of the tested process.
Red flags
- Process never exercised
- No named owner
- Notification timeline vague
How do we get one person's data out, or erased, and how long does it take?
Deal-stopperYou have a deadline to meet. If satisfying it needs a support ticket and a week, that is your problem, not the supplier's.
Ask for: A self-service route if one exists, otherwise a committed turnaround.
Red flags
- Manual process only
- No committed turnaround
- Charged per request
Does the supplier's public privacy notice match what the DPA says?
ImportantWhere they differ, the notice usually describes what actually happens and the DPA describes what was negotiated.
Ask for: Both documents, read side by side.
Red flags
- Notice describes purposes the DPA excludes
- Notice names sub-processors the list omits
Can we record this supplier in our processing records today?
Worth askingIf you cannot fill in the fields, the diligence is not finished — and the gaps are exactly the terms you have not pinned down.
Ask for: Your own record of processing activities, completed.
Red flags
- Fields left blank
- Supplier contact for privacy matters unknown
This checklist is general guidance, not legal, security or financial advice, and it does not replace your own advisers on anything contentious. It was last reviewed on 19 September 2026. Tell us if something here is wrong or missing.