[{"data":1,"prerenderedAt":337},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"regulation-en-gdpr":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":48,"entities":283,"extension":286,"faq":287,"keywords":306,"meta":311,"navigation":312,"ogImage":313,"path":47,"persona":314,"publishedAt":313,"regulation":315,"relatedFeatures":316,"relatedPages":319,"seo":322,"shortTitle":46,"slug":315,"sources":323,"stem":333,"tldr":334,"updatedAt":335,"__hash__":336},"regulations_en\u002Fen\u002Fregulations\u002Fgdpr.md","GDPR: ROPA, DPIA and 72-Hour Breach Notification | CISAPP","CISAPP",{"type":108,"value":109,"toc":276},"minimark",[110,115,139,162,166,259,263,266],[111,112,114],"h2",{"id":113},"what-does-the-gdpr-require-on-vendors","What does the GDPR require on vendors?",[116,117,118,122,123,128,129,133,134,138],"p",{},[119,120,121],"strong",{},"As soon as a vendor processes personal data on your behalf, it is a processor under the GDPR and the relationship must be governed contractually."," Three artefacts structure that compliance: the ",[124,125,127],"a",{"href":126},"\u002Fen\u002Fglossary\u002Fdpa","DPA",", the ",[124,130,132],{"href":131},"\u002Fen\u002Fglossary\u002Frecords-of-processing-activities","records of processing activities"," and the ",[124,135,137],{"href":136},"\u002Fen\u002Fglossary\u002Fsub-processor","sub-processor"," chain.",[140,141,142],"key-takeaways",{},[143,144,145,149,156,159],"ul",{},[146,147,148],"li",{},"Article 28: a processing agreement is mandatory, with minimum clauses imposed.",[146,150,151,152,155],{},"Article 30: records of processing activities kept by the controller ",[119,153,154],{},"and"," by the processor.",[146,157,158],{},"Article 33: breach notification to the supervisory authority within 72 hours.",[146,160,161],{},"Article 35: impact assessment mandatory where the risk is high.",[111,163,165],{"id":164},"which-obligations-on-what-timeline","Which obligations, on what timeline?",[167,168,170],"comparison-table",{"caption":169},"GDPR obligations that shape third-party management",[171,172,173,189],"table",{},[174,175,176],"thead",{},[177,178,179,183,186],"tr",{},[180,181,182],"th",{},"Article",[180,184,185],{},"Obligation",[180,187,188],{},"Deadline or frequency",[190,191,192,204,215,226,237,248],"tbody",{},[177,193,194,198,201],{},[195,196,197],"td",{},"28",[195,199,200],{},"Processing agreement and control of sub-processors",[195,202,203],{},"At contracting, then at every change",[177,205,206,209,212],{},[195,207,208],{},"30",[195,210,211],{},"Records of processing activities",[195,213,214],{},"Kept current continuously",[177,216,217,220,223],{},[195,218,219],{},"32",[195,221,222],{},"Appropriate technical and organisational measures",[195,224,225],{},"Periodic reassessment",[177,227,228,231,234],{},[195,229,230],{},"33",[195,232,233],{},"Breach notification to the supervisory authority",[195,235,236],{},"72 hours after becoming aware",[177,238,239,242,245],{},[195,240,241],{},"34",[195,243,244],{},"Communication of the breach to data subjects",[195,246,247],{},"Without undue delay where the risk is high",[177,249,250,253,256],{},[195,251,252],{},"35",[195,254,255],{},"Data protection impact assessment (DPIA)",[195,257,258],{},"Before the processing is implemented",[111,260,262],{"id":261},"how-cisapp-links-gdpr-compliance-and-third-party-management","How CISAPP links GDPR compliance and third-party management",[116,264,265],{},"The records of processing activities are attached to the vendor record: every recipient listed points back to the third party, its DPA, its declared sub-processors and its latest security assessment. In the event of a breach, the severity wizard qualifies the incident and the 72-hour tracker follows the notification through to closure, with the associated evidence.",[116,267,268,269,272,273,275],{},"See also the ",[124,270,271],{"href":84},"vendor cyber due diligence"," guide and the ",[124,274,38],{"href":39}," page.",{"title":277,"searchDepth":278,"depth":278,"links":279},"",2,[280,281,282],{"id":113,"depth":278,"text":114},{"id":164,"depth":278,"text":165},{"id":261,"depth":278,"text":262},[284,127,285],"ROPA","Sub-processor","md",[288,291,294,297,300,303],{"q":289,"a":290},"What does the GDPR change in the relationship with a vendor?","As soon as a vendor processes personal data on your behalf, it becomes a processor within the meaning of Article 4. The relationship must then be governed by an Article 28 compliant contract, the processing entered in the records, and the vendor assessed against the Article 32 security measures.",{"q":292,"a":293},"What is the 72-hour deadline?","Article 33 requires the controller to notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. The processor must alert the controller without undue delay.",{"q":295,"a":296},"When is a DPIA mandatory?","Article 35 requires one where a processing operation is likely to result in a high risk to the rights and freedoms of individuals, in particular in cases of systematic evaluation based on automated processing, large-scale processing of special categories of data, or systematic large-scale monitoring of a publicly accessible area.",{"q":298,"a":299},"Do you have to authorise your vendor's sub-processors?","Yes. Article 28 prohibits a processor from engaging a sub-processor without the written authorisation of the controller, and requires it to flow the same contractual obligations down. The initial processor remains fully liable for their performance.",{"q":301,"a":302},"What penalties can a supervisory authority impose?","Article 83 sets two caps: EUR 10 million or 2% of total worldwide annual turnover for breaches of controller and processor obligations, and EUR 20 million or 4% for breaches of the principles and of data subject rights, whichever is higher.",{"q":304,"a":305},"Does CISAPP cover the 72-hour notification deadline?","Yes. The severity wizard guides the qualification of a breach and triggers the 72-hour notification tracker to the supervisory authority, linking the breach to the processing, the processor involved and the evidence collected.",[307,132,308,309,310],"GDPR compliance","DPIA","72-hour breach notification","GDPR Article 28",{},true,null,"entreprise","gdpr",[317,318],"GDPR — records & breaches","Processors",[320,321],"iso-27001","ai-act",{"title":105,"description":48},[324,329],{"label":325,"url":326,"publisher":327,"date":328},"Regulation (EU) 2016\u002F679 (GDPR) — consolidated text","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2016\u002F679\u002Foj","EUR-Lex","2016-04-27",{"label":330,"url":331,"publisher":332},"Notifying a personal data breach","https:\u002F\u002Fwww.cnil.fr\u002Fen\u002Fnotify-personal-data-breach","CNIL","en\u002Fregulations\u002Fgdpr","The GDPR (Regulation (EU) 2016\u002F679) has applied since 25 May 2018. On the vendor side it requires an Article 28 processing agreement, records of processing activities under Article 30, notification of breaches to the supervisory authority within 72 hours (Article 33), and control over sub-processors.","2026-08-16","evPZ00etzUfAFFE1FKWUa7V8XXnCUTUkT_09yoA2heQ",1791391138525]