Comparisons

European alternatives to US TPRM platforms

What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.

TL;DR

Choosing a European TPRM platform is not a matter of preference: third-party risk data describes your critical dependencies and includes personal data of vendor contacts. A provider established in the Union, hosting in the Union, avoids relying on Chapter V of the GDPR for transfers outside the EU and simplifies demonstrating compliance.

Why the question is specific to third-party risk

A TPRM platform concentrates the description of your critical dependencies: who supplies what, at what criticality, and which weaknesses have been identified. It is a database of organisational vulnerabilities as much as a compliance tool — hence the sensitivity of where it sits.

What does choosing a European provider change in practice?

Points of attention depending on where the provider is established
PointEU provider and hostingNon-EU provider, EU hosting
Law applicable to the processingEuropean regimeEuropean regime plus the parent company's law
Transfer under Chapter VNot applicableTo be framed and documented
Sub-processorsTo verify, generally EuropeanTo verify country by country
Support access to productionTo documentTo document, with team locations
Effort to demonstrate in an auditLowTransfer assessment to produce and maintain

Which questions to ask before signing?

  1. Where are production data and backups hosted?
  2. What is the list of sub-processors, with their country of establishment?
  3. From which countries can technical support access the data?
  4. Does the proposed DPA cover all of the above, with prior notice of any change?

These four questions are ordinary vendor due diligence: apply to your TPRM platform the standard it exists to help you apply to everyone else.

Where CISAPP sits

CISAPP is published in France, hosted in the European Union, and manages its own supply chain inside the platform. See also TPRM platform selection criteria and CISAPP vs spreadsheet.

FAQ

Because it determines the law applicable to the processing and the sub-processing chain. A provider established and hosting in the Union processes your data under the European regime alone, without having to build a transfer mechanism under Chapter V of the GDPR.

Sources

  1. Regulation (EU) 2016/679 (GDPR) — Chapter V, transfers to third countries — EUR-Lex, 2016-04-27
  2. Transferring data outside the European Union — CNIL

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account