01

The short answer

Evaluating a vendor means understanding what personal data it will process, verifying that the security level is the same regardless of the device or system used, and asking how risks to confidentiality, integrity and availability are addressed. If the processing involves high risk, an impact assessment (DPIA) is required.

02

Why the assessment applies to almost every vendor

Personal data means any information that identifies a person, even indirectly: name, email address, customer code, purchase history, photo. A software or cloud vendor that handles customer, employee or supplier contacts is therefore processing personal data, which triggers the need for an assessment.

03

Assessment sequence

Steps

  1. List which categories of personal data the vendor will see or store.
  2. Ask whether the security level remains identical across every device or connected terminal.
  3. Check how the vendor identifies human and non-human sources of risk.
  4. Verify whether DPIAs are performed for high-risk processing.
  5. Review organizational measures: training, internal policies, confidentiality agreements.

04

A hypothetical case

A company wants to entrust a cloud vendor with storing customer records and employee payslips. Applying the checklist, it asks the vendor: exactly what data it will process, whether security is guaranteed even if the vendor's staff use personal devices, and what measures exist against unauthorized access or data loss.

05

Concrete questions to ask the vendor

  • Does it regularly train staff on privacy-related risks?
  • Does it have a binding internal data protection policy?
  • Does it apply data minimization and classification of confidential information?
  • Does it use automatic session locking, firewalls, updated antivirus and backups?
  • Does it limit external device connections and protect physical premises?

06

How to organize the assessment with a software partner

A company can ask its software partner to keep track, for each vendor assessed, of the data categories involved, the internal roles responsible for verification and the declared security measures. This is a suggested operational choice, not a legal requirement: recording the assessment in a traceable way helps review it periodically and show it during internal checks.

07

A point often clarified

The assessment does not only concern IT systems: it also includes organizational measures such as training, internal policies and confidentiality agreements with anyone accessing data on the vendor's behalf.

08

Next step

Create an assessment sheet with data categories, identified risks and verified measures for each vendor under review, and revise it after each periodic review.

FAQ

Frequently asked questions

What counts as personal data when assessing a vendor?

Any information that identifies a person directly or indirectly counts: name, email, customer code, purchase history, photo or voice recording.

Should the security level change if the vendor uses different devices?

No: the security level of personal data processed must be the same regardless of the equipment or device used to access it.

When is a DPIA required when assessing a vendor?

When the planned processing may pose a high risk to individuals; the DPIA must indicate the measures planned to address the identified risks.

Sources and verification