Vendor Management

Maintain a complete register of third-party vendors and processors. Track contracts, send privacy questionnaires, monitor risk tiers, and ensure your supply chain meets your privacy standards.

Vendor Register

Your vendor register is the central record of all third parties that process personal data on your behalf. Each vendor entry captures contact details, processing purposes, contract status, and risk tier.

ACTIVE

Vendor is approved and actively processing data

UNDER REVIEW

Vendor is being evaluated or re-assessed

SUSPENDED

Processing suspended pending issue resolution

OFFBOARDED

Vendor relationship terminated, data return/deletion confirmed

Risk Tiers

Vendors are classified into risk tiers based on the volume and sensitivity of data they process, their security posture, and geographic considerations.

LOW

MEDIUM

HIGH

CRITICAL

Higher-risk vendors require more frequent reviews, stronger contractual safeguards, and may trigger a vendor risk assessment.

Vendor Dashboard

Get an overview of your vendor landscape at a glance.

24

Total Vendors

18

Active

3

High Risk

5

Pending Review

Contract Management

Track Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and other contractual documents for each vendor. Set renewal reminders and monitor expiration dates.

Key Contract Documents

Data Processing Agreement (DPA)Defines processing terms under GDPR Article 28
Standard Contractual Clauses (SCCs)Safeguards for international data transfers
Sub-processor AgreementTerms for the vendor's own sub-processors
Security AddendumTechnical and organizational measures

Generating a DPA + Transfer Impact Assessment

DPO Central can produce a signature-ready Data Processing Agreement and a standalone Transfer Impact Assessment for any vendor, populated from your own privacy program — the vendor register, submitted questionnaires, and the processing activities that name the vendor as a recipient. Documents are generated in English or Spanish.

Data Processing Agreement (PDF)

Article 28 controller-to-processor agreement with negotiated terms and Annexes I–IV: description of processing, technical and organisational measures (TOMs), incorporation of the EU Standard Contractual Clauses (with UK Addendum and Swiss adaptations), and the Transfer Impact Assessment. Annexes III–IV appear automatically when the processor is established outside the EEA/UK.

Standalone TIA (PDF)

Annex IV reproduced without modification, preceded by an identification header — ready for disclosure to a supervisory authority on request under Clause 14 of the incorporated SCCs. Follows the six-step framework of EDPB Recommendations 01/2020.

1

Open the vendor and choose “Produce DPA + TIA”

Privacy Officer

On the vendor's detail page, open the Contracts tab and click “Produce DPA + TIA”. Available to Owners, Admins, and Privacy Officers.

2

Review the pre-filled facts

Privacy Officer

Every fact is proposed from your own data and shown for review — nothing goes into the document unseen. Notes explain where each value came from.

  • Data categories come from the vendor's recorded data types; the processing purpose from activities naming the vendor as a recipient.
  • Establishment means where the vendor is established — it is only pre-filled when your register is unambiguous.
  • Choose the negotiated terms (breach window, sub-processor regime, audit rights, liability, governing law) and complete both parties' details.
3

Confirm any flagged contradictions

Privacy Officer

If your answers contradict each other — for example claiming pseudonymization while transferring directly identifying data — generation is blocked until you explicitly confirm each flagged item.

4

Generate the documents

Privacy Officer

The DPA is stored against the vendor as a contract pending signature. Any remaining fill-in blanks are listed as warnings so you can resolve them before signature.

5

Download and sign

Privacy Officer

Download the DPA and TIA PDFs from the success screen or anytime from the vendor's Contracts tab. Once countersigned, update the contract status to Active.

The generator never overstates your posture

Annex II lists only security measures confirmed against actual audit evidence — certifications alone justify the audits-review safeguard in the TIA, not TOMs warranties. Importer declarations (government requests, breach history) default to “unknown” unless the vendor itself answered. And per EDPB Recommendations 01/2020, the TIA conclusion documents residual risk unless at least one technical supplementary measure is in place.

After generation

The produced DPA implies a compliance calendar: the 12-month TIA re-evaluation, the annual transparency report where government-access commitments were agreed, and the confirmed TOMs' own cadences. The earliest entry automatically pulls the vendor's next review date forward. Generated documents are templates for qualified counsel to review — not legal advice.

Privacy Questionnaires

Send privacy and security questionnaires to vendors to assess their data protection practices. Track responses and flag areas of concern for follow-up.

Questionnaire Topics

Data processing scope
Security measures
Incident response
Sub-processor management
Data retention policies
Cross-border transfers
Employee training
Certification & audits

Vendor Review Process

The vendor review lifecycle from onboarding to ongoing monitoring.

1

Onboarding

Initial assessment

2

Questionnaire

Privacy review

3

Contract

DPA execution

4

Approved

Active vendor

5

Periodic Review

Annual reassessment

Adding and Reviewing a Vendor

1

Add Vendor to Register

DPO

Navigate to the Vendor Management module and click 'Add Vendor'. Enter the vendor name, contact details, and processing purpose.

2

Send Questionnaire

DPO

Select a privacy questionnaire template and send it to the vendor contact. The system tracks response status and deadlines.

3

Review Responses

Privacy Officer

Evaluate the vendor's questionnaire responses. Flag any areas of concern and assign a preliminary risk tier.

  • Check security certifications (ISO 27001, SOC 2, etc.)
  • Review sub-processor arrangements
  • Evaluate data transfer mechanisms
4

Execute Contracts

Legal

Upload and track the Data Processing Agreement (DPA) and any additional contractual documents.

5

Approve and Monitor

DPO

Approve the vendor for active use. Set up periodic review reminders based on the vendor's risk tier.

PDF Exports

Export your vendor register as a formatted PDF for audits, due diligence reviews, or regulatory submissions.

Vendor Register Report

Complete vendor inventory with risk tiers, certifications, data categories processed, countries of operation, contract/DPA status, and review schedules. Includes summary statistics and per-vendor detail cards.

Hosted pilot: free, capped (see docs), and with no contractual safeguards. To deploy real customer details, run your own instance.