Vendor Management
Maintain a complete register of third-party vendors and processors. Track contracts, send privacy questionnaires, monitor risk tiers, and ensure your supply chain meets your privacy standards.
Vendor Register
Your vendor register is the central record of all third parties that process personal data on your behalf. Each vendor entry captures contact details, processing purposes, contract status, and risk tier.
ACTIVE
Vendor is approved and actively processing data
UNDER REVIEW
Vendor is being evaluated or re-assessed
SUSPENDED
Processing suspended pending issue resolution
OFFBOARDED
Vendor relationship terminated, data return/deletion confirmed
Risk Tiers
Vendors are classified into risk tiers based on the volume and sensitivity of data they process, their security posture, and geographic considerations.
LOW
MEDIUM
HIGH
CRITICAL
Higher-risk vendors require more frequent reviews, stronger contractual safeguards, and may trigger a vendor risk assessment.
Vendor Dashboard
Get an overview of your vendor landscape at a glance.
24
Total Vendors
18
Active
3
High Risk
5
Pending Review
Contract Management
Track Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and other contractual documents for each vendor. Set renewal reminders and monitor expiration dates.
Key Contract Documents
Generating a DPA + Transfer Impact Assessment
DPO Central can produce a signature-ready Data Processing Agreement and a standalone Transfer Impact Assessment for any vendor, populated from your own privacy program — the vendor register, submitted questionnaires, and the processing activities that name the vendor as a recipient. Documents are generated in English or Spanish.
Data Processing Agreement (PDF)
Article 28 controller-to-processor agreement with negotiated terms and Annexes I–IV: description of processing, technical and organisational measures (TOMs), incorporation of the EU Standard Contractual Clauses (with UK Addendum and Swiss adaptations), and the Transfer Impact Assessment. Annexes III–IV appear automatically when the processor is established outside the EEA/UK.
Standalone TIA (PDF)
Annex IV reproduced without modification, preceded by an identification header — ready for disclosure to a supervisory authority on request under Clause 14 of the incorporated SCCs. Follows the six-step framework of EDPB Recommendations 01/2020.
Open the vendor and choose “Produce DPA + TIA”
Privacy OfficerOn the vendor's detail page, open the Contracts tab and click “Produce DPA + TIA”. Available to Owners, Admins, and Privacy Officers.
Review the pre-filled facts
Privacy OfficerEvery fact is proposed from your own data and shown for review — nothing goes into the document unseen. Notes explain where each value came from.
- •Data categories come from the vendor's recorded data types; the processing purpose from activities naming the vendor as a recipient.
- •Establishment means where the vendor is established — it is only pre-filled when your register is unambiguous.
- •Choose the negotiated terms (breach window, sub-processor regime, audit rights, liability, governing law) and complete both parties' details.
Confirm any flagged contradictions
Privacy OfficerIf your answers contradict each other — for example claiming pseudonymization while transferring directly identifying data — generation is blocked until you explicitly confirm each flagged item.
Generate the documents
Privacy OfficerThe DPA is stored against the vendor as a contract pending signature. Any remaining fill-in blanks are listed as warnings so you can resolve them before signature.
Download and sign
Privacy OfficerDownload the DPA and TIA PDFs from the success screen or anytime from the vendor's Contracts tab. Once countersigned, update the contract status to Active.
The generator never overstates your posture
Annex II lists only security measures confirmed against actual audit evidence — certifications alone justify the audits-review safeguard in the TIA, not TOMs warranties. Importer declarations (government requests, breach history) default to “unknown” unless the vendor itself answered. And per EDPB Recommendations 01/2020, the TIA conclusion documents residual risk unless at least one technical supplementary measure is in place.
After generation
The produced DPA implies a compliance calendar: the 12-month TIA re-evaluation, the annual transparency report where government-access commitments were agreed, and the confirmed TOMs' own cadences. The earliest entry automatically pulls the vendor's next review date forward. Generated documents are templates for qualified counsel to review — not legal advice.
Privacy Questionnaires
Send privacy and security questionnaires to vendors to assess their data protection practices. Track responses and flag areas of concern for follow-up.
Questionnaire Topics
Vendor Review Process
The vendor review lifecycle from onboarding to ongoing monitoring.
Onboarding
Initial assessment
Questionnaire
Privacy review
Contract
DPA execution
Approved
Active vendor
Periodic Review
Annual reassessment
Adding and Reviewing a Vendor
Add Vendor to Register
DPONavigate to the Vendor Management module and click 'Add Vendor'. Enter the vendor name, contact details, and processing purpose.
Send Questionnaire
DPOSelect a privacy questionnaire template and send it to the vendor contact. The system tracks response status and deadlines.
Review Responses
Privacy OfficerEvaluate the vendor's questionnaire responses. Flag any areas of concern and assign a preliminary risk tier.
- •Check security certifications (ISO 27001, SOC 2, etc.)
- •Review sub-processor arrangements
- •Evaluate data transfer mechanisms
Execute Contracts
LegalUpload and track the Data Processing Agreement (DPA) and any additional contractual documents.
Approve and Monitor
DPOApprove the vendor for active use. Set up periodic review reminders based on the vendor's risk tier.
PDF Exports
Export your vendor register as a formatted PDF for audits, due diligence reviews, or regulatory submissions.
Vendor Register Report
Complete vendor inventory with risk tiers, certifications, data categories processed, countries of operation, contract/DPA status, and review schedules. Includes summary statistics and per-vendor detail cards.