Skip to content

Tools and templates

Vendor privacy quick check

Twelve questions that separate a supplier you can sign from one that needs work first. Score, risk flags and a printable summary you can attach to a procurement record.

This tool runs entirely in your browser. Your answers are not sent to us, stored, or associated with you in any way.

Used only to label your printed summary. It stays in your browser.

Contract

A written data processing agreement is in place covering purpose, duration and instructions.

Sub-processors are listed, and you are notified before changes.

Deletion or return of data at termination is contractually committed, with a timeframe.

The vendor is contractually barred from using your data for its own purposes, including model training.

Data handling

You know which countries the data is stored in and supported from.

A transfer mechanism is in place where data leaves your primary jurisdiction.

Only the personal data actually needed is shared, and the fields have been reviewed.

Retention within the vendor's systems, including backups and logs, is defined.

Security

Encryption in transit and at rest, plus access control, are documented or certified.

The vendor commits to notifying you of incidents without undue delay, with a stated timeframe.

Operations

The vendor will assist with individual rights requests, including export and deletion.

An internal owner is accountable for this vendor and reviews it on a defined cycle.

Answer all 12 checks to continue.

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.