| name | vendor-privacy-audit |
| title | Vendor Privacy Audit |
| description | On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and audit report generation for processor compliance verification. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-audit |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Vendor Privacy Audit
Overview
GDPR Article 28(3)(h) requires that the processor "make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28, and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller." This audit right is a cornerstone of the controller's accountability obligations and must be exercisable in practice.
The EDPB Guidelines 07/2020 (paragraph 110) emphasize that audit rights must be practical and exercisable, not merely theoretical. Controllers must develop structured audit programs proportionate to the risk of the processing.
At Summit Cloud Partners, the Vendor Privacy Audit Program provides a systematic approach to verifying processor compliance through on-site inspections, remote audits, and documentation reviews.
Audit Types
Type 1: Documentation-Based Audit (Remote)
Suitable for standard-risk vendors with current third-party certifications.
| Aspect | Detail |
|---|
| Scope | Review of processor-provided documentation and certifications |
| Duration | 3-5 business days |
| Frequency | Annual |
| Deliverable | Documentation Audit Report |
| Cost allocation | Controller bears own costs |
Evidence Reviewed:
- Current ISO 27001/27701 certificates and audit reports
- SOC 2 Type II report (including management assertions and exceptions)
- DPA compliance self-assessment questionnaire
- Sub-processor register and DPA coverage confirmation
- Incident log summary for audit period
- Training records and confidentiality agreement coverage
- Data subject request handling metrics
Type 2: Remote Technical Audit
Suitable for standard-to-high-risk vendors where on-site access is not practical.
| Aspect | Detail |
|---|
| Scope | Remote assessment including technical verification |
| Duration | 5-10 business days |
| Frequency | Annual for high-risk; biennial for standard-risk |