Comparisons
European alternatives to US TPRM platforms
What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.
TL;DR
Choosing a European TPRM platform is not a matter of preference: third-party risk data describes your critical dependencies and includes personal data of vendor contacts. A provider established in the Union, hosting in the Union, avoids relying on Chapter V of the GDPR for transfers outside the EU and simplifies demonstrating compliance.
Why the question is specific to third-party risk
A TPRM platform concentrates the description of your critical dependencies: who supplies what, at what criticality, and which weaknesses have been identified. It is a database of organisational vulnerabilities as much as a compliance tool — hence the sensitivity of where it sits.
What does choosing a European provider change in practice?
| Point | EU provider and hosting | Non-EU provider, EU hosting |
|---|---|---|
| Law applicable to the processing | European regime | European regime plus the parent company's law |
| Transfer under Chapter V | Not applicable | To be framed and documented |
| Sub-processors | To verify, generally European | To verify country by country |
| Support access to production | To document | To document, with team locations |
| Effort to demonstrate in an audit | Low | Transfer assessment to produce and maintain |
Which questions to ask before signing?
- Where are production data and backups hosted?
- What is the list of sub-processors, with their country of establishment?
- From which countries can technical support access the data?
- Does the proposed DPA cover all of the above, with prior notice of any change?
These four questions are ordinary vendor due diligence: apply to your TPRM platform the standard it exists to help you apply to everyone else.
Where CISAPP sits
CISAPP is published in France, hosted in the European Union, and manages its own supply chain inside the platform. See also TPRM platform selection criteria and CISAPP vs spreadsheet.
FAQ
Because it determines the law applicable to the processing and the sub-processing chain. A provider established and hosting in the Union processes your data under the European regime alone, without having to build a transfer mechanism under Chapter V of the GDPR.
Sources
Comparisons
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours