Regulations
GDPR: ROPA, DPIA and 72-Hour Breach Notification
Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.
TL;DR
The GDPR (Regulation (EU) 2016/679) has applied since 25 May 2018. On the vendor side it requires an Article 28 processing agreement, records of processing activities under Article 30, notification of breaches to the supervisory authority within 72 hours (Article 33), and control over sub-processors.
What does the GDPR require on vendors?
As soon as a vendor processes personal data on your behalf, it is a processor under the GDPR and the relationship must be governed contractually. Three artefacts structure that compliance: the DPA, the records of processing activities and the sub-processor chain.
Which obligations, on what timeline?
| Article | Obligation | Deadline or frequency |
|---|---|---|
| 28 | Processing agreement and control of sub-processors | At contracting, then at every change |
| 30 | Records of processing activities | Kept current continuously |
| 32 | Appropriate technical and organisational measures | Periodic reassessment |
| 33 | Breach notification to the supervisory authority | 72 hours after becoming aware |
| 34 | Communication of the breach to data subjects | Without undue delay where the risk is high |
| 35 | Data protection impact assessment (DPIA) | Before the processing is implemented |
How CISAPP links GDPR compliance and third-party management
The records of processing activities are attached to the vendor record: every recipient listed points back to the third party, its DPA, its declared sub-processors and its latest security assessment. In the event of a breach, the severity wizard qualifies the incident and the 72-hour tracker follows the notification through to closure, with the associated evidence.
See also the vendor cyber due diligence guide and the AI Act page.
FAQ
As soon as a vendor processes personal data on your behalf, it becomes a processor within the meaning of Article 4. The relationship must then be governed by an Article 28 compliant contract, the processing entered in the records, and the vendor assessed against the Article 32 security measures.
Sources
- Regulation (EU) 2016/679 (GDPR) — consolidated text — EUR-Lex, 2016-04-27
- Notifying a personal data breach — CNIL
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours