Vendor due diligence

The checks an organisation runs on a vendor before signing, to confirm it can meet the security, privacy and compliance obligations the relationship needs.

It usually means reviewing security questionnaires, certifications (SOC 2, ISO 27001), the data processing agreement, the subprocessor list and data locations, insurance and financial stability, scaled to how much data and access the vendor will have. Under the GDPR, a controller may use only processors that provide sufficient guarantees (Article 28(1)), which is the legal root of privacy due diligence.

Source: GDPR Art. 28(1) ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.