01

The short answer

Evaluating a software or cloud vendor requires identifying what personal data it will process, checking that it guarantees the same level of security regardless of the equipment or location used, and verifying the organisational and technical measures in place against risks of unauthorised access, alteration, or loss of data.

If the processing involves a high risk to individuals, it is also necessary to consider whether a data protection impact assessment (DPIA) is required.

02

Why the evaluation starts with the data

Personal data includes any information that identifies a person directly or indirectly: name, identification numbers such as customer codes or staff numbers, email addresses, location data, browsing or purchase history, photos, and audio recordings.

Some categories of data are considered special (sensitive) and require enhanced protection. Knowing what types of data a vendor will process is the first step in understanding what level of security to require.

03

A five-step evaluation process

Steps

  1. Map which personal data the vendor will access, process, or store, including any special categories.
  2. Check that the security level is identical regardless of device, network, or location of access.
  3. Assess the risks of unauthorised access, alteration, or loss of data and their sources, both internal and external.
  4. Check which threats to assets (hardware, software, communication channels) are covered and with which existing or planned measures.
  5. Determine whether the processing requires a DPIA, mandatory for processing that poses a high risk to individuals.

04

Hypothetical example

A company evaluates a cloud vendor to manage employee payroll. It maps the data involved (names, staff numbers, email addresses) and asks the vendor how it prevents unauthorised disclosure of payslips, a confidentiality risk cited among typical examples.

It also asks whether the vendor estimates the severity and likelihood of identified risks and whether it conducts periodic security reviews with an associated action plan.

05

Items to check before signing

  • Does the vendor regularly train staff on privacy-related risks?
  • Is there a binding internal policy on data protection?
  • Is data protection built in by design and by default?
  • Is the data processed limited to what is necessary (minimisation)?
  • Are automatic session locking, firewalls, up-to-date antivirus, and backups in place?

06

What a business can put in place with the support of a software partner

  • A vendor register listing the types of personal data each one processes, kept up to date.
  • A spreadsheet or tool for risk management, with material and human risks linked to each vendor.
  • Clear roles for who periodically reviews vendors' security measures and who approves new contracts.
  • Periodic reminders to renew vendor assessments and verify that planned measures are implemented.
  • Documentation accessible to relevant data handlers, written in clear language for each category of user.

07

Frequently asked questions about vendor evaluation

  • Responsibility for data security remains with the company even if the vendor manages infrastructure over which it has no physical or legal control.
  • A DPIA is mandatory when the processing may pose a high risk to individuals, and must set out the measures planned to address the identified risks.
  • A periodic security review should produce an action plan monitored at the highest level of the organisation.

08

Next step

Before signing a contract with a new software or cloud vendor, complete the data mapping and the security measures checklist provided here, and keep it as part of your internal vendor documentation.

FAQ

Frequently asked questions

Who remains responsible for data security if the vendor manages the infrastructure?

The company remains responsible for the security of its personal data even when it is stored on systems over which it has no direct physical or legal control, but for which it has authorised access.

When is a DPIA needed for a software or cloud vendor?

A data protection impact assessment is mandatory for any processing that may pose a high risk to individuals, and must describe the measures planned to address the identified risks.

What are the main risks to consider when evaluating a vendor?

The main risks concern unauthorised access to data (confidentiality), unauthorised alteration (integrity), and loss of data or access to it (availability), along with the related human and non-human sources.

Sources and verification