| name | vendor-privacy-due-diligence |
| title | Vendor Privacy Due Diligence |
| description | Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, data flow analysis, and documented sufficiency decisions for processor engagement. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligence |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Vendor Privacy Due Diligence
Overview
GDPR Article 28(1) requires controllers to use only processors providing "sufficient guarantees to implement appropriate technical and organisational measures" to meet GDPR requirements and protect data subject rights. This obligation means controllers must conduct thorough privacy due diligence before engaging any vendor that will process personal data. The European Data Protection Board (EDPB) Guidelines 07/2020 on controller and processor concepts reinforce that this assessment must be documented and proportionate to the risk involved.
At Summit Cloud Partners, the Vendor Privacy Due Diligence Program establishes a structured process for evaluating prospective vendors before any personal data processing begins.
Due Diligence Framework
Phase 1: Initial Screening
Before engaging in detailed evaluation, determine whether the vendor will process personal data at all.
Processing Determination Checklist:
| Question | If YES |
|---|
| Will the vendor access, store, or transmit personal data? | Proceed to full due diligence |
| Will the vendor host systems containing personal data? | Proceed to full due diligence |
| Will the vendor have logical or physical access to infrastructure holding personal data? | Proceed to full due diligence |
| Is the vendor providing purely non-personal-data services (e.g., office supplies)? | No due diligence required — document determination |
Data Flow Preliminary Analysis:
Map the anticipated data flows before proceeding:
- What categories of personal data will the vendor process?
- How many data subjects are affected (approximate volume)?
- Will special category data (Article 9) be involved?
- Where will processing occur geographically?
- Will the vendor engage sub-processors?
Phase 2: Privacy Risk Questionnaire
Summit Cloud Partners issues a standardized Privacy Risk Questionnaire to all prospective vendors scoring above the initial screening threshold.
Section A — Legal and Governance
| # | Question | Expected Response |
|---|
| A1 | Does your organization have a designated Data Protection Officer (DPO) or equivalent privacy lead? | Named individual with contact details |