Regulations

GDPR: ROPA, DPIA and 72-Hour Breach Notification

Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.

TL;DR

The GDPR (Regulation (EU) 2016/679) has applied since 25 May 2018. On the vendor side it requires an Article 28 processing agreement, records of processing activities under Article 30, notification of breaches to the supervisory authority within 72 hours (Article 33), and control over sub-processors.

What does the GDPR require on vendors?

As soon as a vendor processes personal data on your behalf, it is a processor under the GDPR and the relationship must be governed contractually. Three artefacts structure that compliance: the DPA, the records of processing activities and the sub-processor chain.

Which obligations, on what timeline?

GDPR obligations that shape third-party management
ArticleObligationDeadline or frequency
28Processing agreement and control of sub-processorsAt contracting, then at every change
30Records of processing activitiesKept current continuously
32Appropriate technical and organisational measuresPeriodic reassessment
33Breach notification to the supervisory authority72 hours after becoming aware
34Communication of the breach to data subjectsWithout undue delay where the risk is high
35Data protection impact assessment (DPIA)Before the processing is implemented

The records of processing activities are attached to the vendor record: every recipient listed points back to the third party, its DPA, its declared sub-processors and its latest security assessment. In the event of a breach, the severity wizard qualifies the incident and the 72-hour tracker follows the notification through to closure, with the associated evidence.

See also the vendor cyber due diligence guide and the AI Act page.

FAQ

As soon as a vendor processes personal data on your behalf, it becomes a processor within the meaning of Article 4. The relationship must then be governed by an Article 28 compliant contract, the processing entered in the records, and the vendor assessed against the Article 32 security measures.

Sources

  1. Regulation (EU) 2016/679 (GDPR) — consolidated text — EUR-Lex, 2016-04-27
  2. Notifying a personal data breach — CNIL

Ready for the regulations that apply to you

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account