1. Draw the line first: processor, or a controller of its own
This is the start of the arrangement, and the step most often got wrong. The test is not the title of the contract. It is who decides the purpose and the means.
- Processing on instructions: the vendor uses the data only as the company directs, not for itself. Payroll calculation, cloud storage, a call centre. The company is the handler; the vendor is the processor.
- Independent or joint handling: the vendor decides a purpose of its own, or uses the data for its own business (training a model, building its own profiles). That is a provision to a third party, and needs a separate consent and a separate notice of the recipient, contact, purpose and categories.
The cost of getting this wrong is not symmetrical. Treating a provision as a mere engagement leaves out the separate consent. That is hard to repair later. At intake, ask: will you use this project's data for any purpose outside this project? If the answer is not a clear no, treat it as a provision to a third party.
2. Three documents
1. A data-processing agreement
It may be an annex. A confidentiality clause in the main contract is not enough. Cover at least: purpose, term and means; types and scope of data; the vendor's security measures; no sub-processing without prior written consent; help with individual rights requests and the time to respond; how data is returned or deleted at the end, with proof; and how loss is shared.
2. A security-assessment record
A written conclusion at intake is the most direct evidence that the supervision duty was performed: qualifications and certifications, where the data sits and whether it leaves the country, access control, and any past incidents. Keep the form.
3. An updated notice and consent
If the arrangement is a provision to a third party, the privacy notice and the consent step have to name the recipient. This is often missed because it sits with product or marketing, not procurement.
3. An audit right that can be used
Most DPAs say the company may audit the vendor. To make that real, add three things: how it is started (notice, a yearly cap), what can be seen (types of logs and files, not "relevant materials"), and a substitute (a third-party audit report in place of a site visit).
The substitute is usually the realistic path. Large cloud vendors will not take a site audit from one customer. They will produce a standard report. Agree in advance which reports count.
4. Cross-border as a separate layer
If the vendor's servers are outside the mainland, or an overseas affiliate can see the data, a cross-border path is required (security assessment, standard-contract filing or certification, depending on type and scale). A DPA clause does not replace that. The intake questionnaire should ask, in so many words, where the data is stored and which overseas entities can reach it.
5. A place to start
A full system is not required on day one. Start with a vendor data register: every vendor that sees personal information, with type, volume, whether it is sensitive, whether it leaves the country, and whether the contract has a DPA. Priority then becomes obvious — a small share of vendors usually holds most of the exposure.
This is a general compliance path, not an opinion. The data types, the sector rules and the business model all have to be read together.