01
The question in brief
To evaluate a software or cloud provider, you must first establish whether the service processes personal data, meaning any information relating to an identified or identifiable natural person, such as names, emails, browsing histories or photos (citation-0). Once processing is confirmed, the evaluation must check how the provider protects integrity, availability and confidentiality of data, the three pillars of data security (citation-2).
02
Why a risk analysis is needed
The GDPR requires the same level of personal data security regardless of the equipment used, and the company remains responsible even when data is on devices it does not physically or legally control (citation-1). This is why the provider evaluation must identify human and external risk sources, such as administrators, users or hackers, and non-human sources, such as material damage or viruses (citation-3).
03
Steps for verification
Steps
- Check whether the provider's service processes personal data under the GDPR definition (citation-0).
- Identify human and external risk sources, such as administrators, users or hackers (citation-3).
- Verify existing measures: access control, backups, traceability, encryption (citation-3).
- Estimate severity and likelihood of risks on a scale from negligible to maximum (citation-3).
- Document the check in an action plan monitored at the highest levels of the organisation (citation-3).
04
A hypothetical case
Hypothetical example: a company evaluates a cloud provider to store employee payslips. It checks that the provider offers access control and encryption, to avoid a confidentiality breach such as identity theft following disclosure of payslips (citation-2). The company records the evaluation in a risk management spreadsheet, updating it periodically (citation-4).
05
Minimum checks before activating a provider
- Train data handlers on privacy-related risks before activating the provider (citation-1).
- Verify that the provider applies data protection by design (citation-1).
- Check the minimisation of data processed by the provider (citation-1).
- Require up-to-date backups, firewalls and antivirus on the provider's side (citation-1).
- Limit physical connection and access to the provider's premises (citation-1).
06
Organising verification with a software partner
A company can organise, together with its software partner, periodic checks on providers that process personal data, based on the organisational measures already outlined in the guidance, such as raising data handlers' awareness and defining an internal policy (citation-4). Periodic reviews can be scheduled as recurring security checks, each with a traceable action plan (citation-3). These are suggested operational choices, not features guaranteed by any specific software.
07
Frequently asked questions about provider verification
- Does a provider handling only customer codes still process personal data? Yes, if the code allows indirect identification of the person (citation-0).
- Is a contract enough to consider a provider secure? No, concrete measures such as access control and encryption must also be verified (citation-3).
- Does the required security level change if data is on employees' personal devices? No, the required security level remains the same (citation-1).
08
Practical next step
Before signing with a new provider, build a risk management spreadsheet listing material and human risks related to servers, computers or premises, and revise it regularly (citation-4). This tool becomes the basis for comparing different providers and documenting checks performed.
FAQ
Frequently asked questions
How is it determined whether a provider processes personal data?
You check whether the service processes information relating to an identified or identifiable person, such as names, emails or browsing histories: if so, it is personal data.
What risks should be assessed in a cloud provider?
You should assess risks of unauthorised access, data alteration and loss of access, identifying human and non-human sources that could cause them.
Do security measures change if employees use personal devices?
No, the GDPR requires the same security level regardless of the equipment used, and the company remains responsible for data protection.
✓