Due Diligence when Appointing a Data Processor
If you are a controller considering engaging a data processor, you can’t choose the one that suits you best based only on functionality, even if that data processor is selling the perfect product or is offering the perfect deal. If they don’t provide sufficient guarantees to keep the personal data safe and sound, don’t appoint them.
Why? As a controller, you bear the responsibility not only for your compliance with the GDPR, but also for choosing the processor that will process data on your behalf in a secure and compliant way. For this reason, before you start collaborating with any processor, you need to do thorough due diligence. This article aims to clarify what the due diligence part implicates and what you should look for when you engage a new processor.
First Steps
Before anything else, you need to do a self-assessment and figure out what the nature of the processing will be and what level of risk this processing implicates for data subjects’ rights and freedoms. For example, will vulnerable data subjects data be processed? Vulnerable data subjects refer to people who may be unable to consent or oppose the processing of their data or to exercise their rights.
Good examples of vulnerable data subjects are children, employees, mentally ill individuals and asylum seekers. So, will the processor process special categories of personal data on your behalf? If the answer is yes, you need to be even more careful when choosing the processor and make sure that they have appropriate technical and organisational security measures in place.
The Process of Appointing a Data Processor
Once this first step is completed, you can start the due diligence process, which is the first stage of processor management. Here is a checklist with the things you need to look out for when engaging a new processor.
The first thing to do is to check the processor’s website. You should read their privacy notice. You may find some positive or some negative indicators. An informative and updated privacy notice can be a positive sign that the processor takes data protection seriously. On the other hand, reading a privacy notice that is mentioning, for example, Privacy Shield as the transfer mechanism, could be a negative indicator. This shows that this processor has not bothered to update its privacy notice for more than a year.
However, that is not all. A GDPR Questionnaire should be sent and you must establish whether the processor is actually complying with the regulation. If you cannot satisfy yourself that they are then you can ask us to carry out a Data Protection Audit. We can then report back as to the potential processor’s status. We will confirm the following:
Does this Data Processor have technical security measures in place?
The processor must provide sufficient guarantees that they have technical measures in place. These measures must ensure the security of the personal data. For example, are they using encryption or pseudonymisation for the protection of the data? Do they run regular full back-ups? Do they update software regularly?
Does this processor have organisational security measures in place, including relevant data protection documentation?
A processor needs to have a Record of Processing Activities. This can never be a template and must be refer to the processing activities of the processor. It is a legal requirement. Despite that, the processor shall apply appropriate organisational measures. These will include internal data protection and information security policies and data breach and incident planning. Data Protection Impact Assessments must be in place to ensure the security of the personal data they will process on your behalf.
The provision of such documentation will enable you to make a more informed decision. Most processors have all the relevant documentation ready for the prospective controllers to examine. However, you should check they are not templates which are of no use to them or to you. You should read all of them to ensure they are fair and don’t unfairly benefit them commercially. You may be asked to sign a non-disclosure agreement (NDA) with the processor before they disclose such documentation to you.
Has this processor appointed a Data Protection Officer or another data protection contact person?
A Data Protection Officer (DPO) is an independent data protection professional who helps an organisation to manage its privacy issues. According to the GDPR, in some cases, the appointment of a DPO is obligatory. In this case, your processor is legally required to appoint a DPO. They may have not yet fulfilled this obligation yet. It is a very good indicator that it is not taking compliance with the GDPR seriously. Any appointed DPO cannot be a director or shareholder of the processor’s company. If the processor has appointed a DPO voluntarily, despite not having such an obligation, it can be a very positive sign for its respect for data protection.
If there is no legal obligation to appoint a DPO for this specific processor, a responsible person should be appointed. You should check whether they have an individual responsible for data protection matters. This person should be contactable and their details available to all.
Are relevant staff of the processor subject to confidentiality obligations?
You will require the processor to ensure that anyone it authorises to process the personal data is subject to a strict duty of confidentiality. They must confirm that they can only process the data in accordance with the permitted purpose agreed. Therefore, before engaging a new processor you could check if there is a confidentiality clause in the employment contract.
Does the processor hold any information security certifications?
Information security certifications are important. ISO 27001 is the holy grail of ISMS. Cyber Essentials and Cyber Essential Plus are also very good. Keep an eye out for the IAMSE Gold Standard also.
Has this processor suffered any data breaches in the last year?
This is very important. If the processor is compliant, you can simply ask for their data breach register. The recording of data breaches is part of the accountability principle that came in with the Data Protection Act 2018. Be wary of businesses that have not had any sort of data breach. A data breach is not necessarily a bad thing. It is the response to it and the remediation that matters. Proof should be provided and you should be satisfied that these measures were appropriate and effective.
Will the processor allow the controller to conduct audits?
You have to monitor the activities of the processor throughout the whole lifecycle of your cooperation. For this reason, it is important to choose processors willing to go through regular audits to ensure compliance with contractual obligations.
Some processors offer as part of the deal to hire an external auditor to conduct audits at specific intervals and then provide the controller with a written report of the results. Others may allow the controller to conduct onsite audits on its own. Therefore, you need to examine what this processor suggests and see if it is convenient for you.
Will the processor be transferring the data to countries outside of the European Economic Area (EEA)?
You need to examine whether by choosing this processor, you will be transferring the data outside of the EEA. If yes, you must consider whether or not you can find a legal transfer mechanism for the data processing activities that will be undertaken outside of the EEA. As a controller, it is up to you to ensure that you put in place an appropriate transfer mechanism to ensure the rights and freedoms of data subjects remain protected. Often this will be through an EU standard contractual clause agreement.
On the same note, you have to check whether the processor will be transferring the data outside of the EEA by using any sub-processors. In the first instance, you need to ask the prospect processor to provide you with a list of any sub-processors they will use for the processing of the data that you will provide them with. Second, if this list contains sub-processors established outside of the EEA, you also have to look for an appropriate transfer mechanism.
Need some help?
Does this all sound a bit much? If you think it is, you are not alone. We help many businesses who are unsure of what technical measures are and how to implement them. Don’t forget that this is not just an IT problem.
We can carry out a technical measures audit to help you understand your current status. In the first instance, you can book your audit. Alternatively you call us on 03333 22 1011 or contact us.

