How to Assess Whether a Vendor (Processor) Is GDPR-Compliant

18th March 2026

Very few organisations operate in a vacuum. Whether you are using a cloud-based CRM, a payroll provider, or an email marketing platform, you are likely sharing personal data with third-party vendors. Under the UK GDPR, these vendors are known as ‘processors’, and as the ‘controller’, the legal responsibility for that data remains firmly with you.

Choosing a vendor is not just about price or features; it is about trust. If your processor suffers a data breach because their security was subpar, it is your reputation, your bank account, and potentially your whole business, on the line.

While we have previously highlighted in our guide to common GDPR mistakes, failing to secure data properly through your supply chain is a frequent pitfall, this is the first time we have shown you how to methodically assess a vendor.

1. Start with a Pre-Selection Questionnaire

Before you sign a contract, you must perform due diligence on the processor and where possible you should ask the vendor to complete a questionnaire or provide sufficient details to assure you that they can keep your data safe. Do not be afraid to “look under the bonnet”. Some of the questions you should be asking include:

  • Where is the data physically stored? (Is it in the UK, the EEA, or a third country?)
  • What technical security measures are in place to keep our data safe? (e.g. encryption, multi-factor authentication)
  • How do they comply with their GDPR obligations, for example by training their staff, dealing with breaches, keeping accurate records?
  • Are they sub-contracting to any third parties?

In many cases a processor will be happy to complete a compliance questionnaire, as long as it is not 100 pages long! However, it would not be practical to expect large processors, such as Microsoft, Google, Amazon etc with tens of thousands of clients to complete your questionnaire. You still need to perform the due diligence but you would do this using the information you can glean from their terms and conditions, privacy notices, security policies etc. 

2. Verify Their Certifications

While a certificate does not guarantee 100% compliance, it is a strong indicator of a ‘privacy-first’ culture. Look for recognised standards such as ISO 27001 (Information Security Management) or Cyber Essentials Plus. If a vendor claims to be compliant but cannot provide evidence of independent audits or internal policies, consider it a red flag.

3. The ‘Must-Have’ Contractual Clauses

Under Article 28 of the UK GDPR, you must have a written contract (often called a Data Processing Agreement or DPA) in place with any processor. This is not optional. The contract must legally bind the processor to:

  • Only process data on your written instructions.
  • Comply fully with data protection legislation
  • Ensure their staff are committed to confidentiality.
  • Assist you in responding to Subject Access Requests (SARs).
  • Delete or return all data at the end of the contract.

Crucially, a DPA should contact a Schedule listing the approved processing activity, nature and categories of data, lawful basis, retention period and any authorised sub-processors.

(Source: ICO Guidance on Controllers and Processors)

4. Check Their Sub-Processor Chain

Most vendors use ‘sub-processors’ (their own third-party providers, like Amazon Web Services (AWS) for hosting). You need to know who these are. A vendor should be transparent about their supply chain and technically must obtain permission from the Controller before they change them, although in reality most processors simply inform you of any changes, giving you the right to object if a new sub-processor does not meet your standards. If you are a processor, be careful if you only advise of the change as it is contrary to the legislation, you may also be in breach of contract if you change sub-processors without telling the controller.

5. Due diligence versus risk assessments

Often a processor will offer many different services, just think about Microsoft, you may be storing data in emails, in SharePoint or recording video in Teams. In addition to performing due diligence on the processor, you should also be performing a risk assessment, usually in the form of a Data Protection Impact Assessment (DPIA) on the service, platform or software itself.

As mandated within the legislation, these assessments should be performed before any processing takes place. You need to build this Privacy by Design framework into your organisational processes. 

6. Ongoing Monitoring

Compliance is not a ‘one-off’ box to tick during procurement. You should have the right to audit your processors. This might mean requesting their latest penetration test results annually or asking for a summary of their staff training records.

How Griffin House Consultancy Can Help

Vetting vendors can be time-consuming and technically complex. At Griffin House Consultancy, we specialise in helping organisations design robust procurement processes, draft Data Processing Agreements, and conduct third-party risk assessments.

If you are about to onboard a new software provider or want to audit your existing supply chain to ensure you are not sitting on a ‘compliance time-bomb’, we are here to support you. Get in touch with us here or call us on 01673 885533 for expert advice.

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Sources

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/

https://www.legislation.gov.uk/eur/2016/679/article/28

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details