Reducing Supplier Risk Through GDPR Certification
DPOs and organisations carry a significant compliance burden with the use of data processors. When personal data is shared, responsibility for managing the associated risks and ensuring compliance remains with the data controller.
It may delegate processing activities, but it does not transfer the associated risks or responsibilities.
Under Art. 28(1) GDPR, controllers must only use processors providing sufficient guarantees that their processing will meet GDPR requirements and protect data subjects’ rights.
Europrivacy is a certification mechanism approved by the European Data Protection Board (EDPB) to serve as European Data Protection Seal under Art. 42 GDPR. Article 28(5) expressly recognises approved certification as a mechanism that can be used to demonstrate sufficient guarantees.
Requesting your service providers to certify their services can help you reduce risks, monitoring efforts and associated costs, making supplier assessment easier to manage.
The practical next step:
Review your procurement policy and consider integrating GDPR certification as a supplier requirement or selection criterion.
You can also ask existing processors to certify their services within a defined and reasonable timeframe.
Don’t carry unnecessary risk. Save risks, efforts and costs by requesting your service providers’ data processing to be GDPR-certified.
Looking to put this into practice?
Europrivacy Procurement and Tenders Support
https://www.europrivacy.com/en/procurement-support
Practical recommendations for integrating GDPR certification into procurement policies, supplier requirements and tender processes.
Europrivacy Welcome Pack
https://www.europrivacy.com/en/welcomepack
Additional practical resources, tools and guidance for organisations considering or preparing for certification.

The post Reducing Supplier Risk Through GDPR Certification appeared first on Europrivacy Community.