Learn
Short guides to the documents that govern what your vendors do with your data.
-
Standard contractual clauses vs the Data Privacy Framework: what's the difference?
Why vendors' DPAs name standard contractual clauses, the EU–US Data Privacy Framework, or both, and what each one means when your customers' personal data leaves the EU.
-
SOC 2 Type I vs Type II: what's the difference?
A SOC 2 Type I report checks that a vendor's controls are designed well on one day; a Type II checks that they worked over months. What each one tells you, and what to read in a vendor's report.
-
What is a subprocessor? (And why your vendors keep changing theirs)
A subprocessor is a third party your vendor uses to process your data on its behalf. What the term means under the GDPR, where vendors publish their lists, and why the lists change.