Under the EU’s GDPR (Article 28), companies are responsible for ensuring proper data handling, whether internally or through third-party vendors. While many businesses focus on internal data policies, third-party cybersecurity risks are often overlooked.
To help mitigate these risks, the CyberVadis questionnaire includes GDPR-specific questions to assess whether your vendors have implemented the necessary controls. Our analysts evaluate:
- Appointment of data privacy roles.
- Identification and management of personal data processing.
- Consideration of data privacy requirements in personal data transfers.
- Integration of data privacy in procurement and project management.
- Employee training on data privacy.
- Compliance with data processing principles (lawfulness, rights, retention).
- Procedures for notifying controllers or regulators in case of a data breach.