This checklist is an operational tool for assessing the privacy compliance level of an external supplier before entrusting them with the processing of personal data on behalf of the controller. The questions cover the technical, organizational, and regulatory aspects required by the GDPR, with particular attention to Art. 28 regarding data processors. A structured analysis of the supplier is a full-fledged part of a Risk Assessment process that also considers the risks introduced by the supply chain.
Instructions for the supplier. This document is a privacy due diligence template that the data controller submits to the external supplier before formalizing the contractual relationship. For each item, fill in the Response column with the requested information. Where indicated with “If yes, specify” or equivalent wording, provide details only in the event of an affirmative response. Incomplete or missing responses will be considered risk indicators for assessment purposes.
1. Data processed
| Item / Question |
Response |
| What processing activities will be carried out by the supplier on behalf of the data controller? |
|
2. Personnel authorized to process data
| Item / Question |
Response |
| Has a list of personnel authorized to process data been prepared? |
|
| Have the members of the list been formally appointed? |
|
| Is the list reviewed at least annually? |
|
| Has a training program for personnel been established, with sessions held by qualified staff and/or training material provided to each individual? |
|
3. Sub-processors
| Item / Question |
Response |
| Will sub-processors be involved in the processing carried out on behalf of the controller? |
If yes, indicate for each sub-processor the company name, the processing entrusted, the country where data might be transferred, and the legitimacy of any non-EU transfer. |
4. Privacy by design and by default
| Item / Question |
Response |
| Will internal policies and measures be adopted that satisfy the principles of data protection by design and by default? |
If yes, specify the measures adopted |
5. Record of processing activities
| Item / Question |
Response |
| Does the supplier maintain a Record of categories of processing activities as a processor, for processing carried out on behalf of the controller (Art. 30.2 GDPR)? |
|
| Has a Record of processing activities been prepared as a controller (Art. 30.1 GDPR)? |
|
6. Personal data breach management
| Item / Question |
Response |
| In the event of a personal data breach involving data processed on behalf of the controller, is there a notification procedure in place for the controller? |
If yes, provide a brief description |
7. Data protection risk analysis
| Item / Question |
Response |
| Has a risk analysis been conducted on high-risk processes where personal data is processed on behalf of the controller? |
|
8. Security of processing
| Item / Question |
Response |
| Are technical and organizational measures appropriate to the risk in place for personal data processed on behalf of the controller? |
If yes, describe the measures adopted |
9. Paper-based data processing
| Item / Question |
Response |
| Have written instructions been provided to personnel for the control and custody of acts and documents containing personal data processed on behalf of the controller? |
|
| Are documents containing special categories of data or judicial data kept in a way that prevents access by unauthorized persons and returned at the end of operations? |
|
| Is there an access control system for physical environments (offices, warehouses, technical rooms) in place? |
|
| Is there an identification register for persons admitted to archives containing special or judicial data, particularly outside working hours? |
|
10. Electronic data processing
| Item / Question |
Response |
| Are the computers used connected to a local network? If yes, is the network connected to the internet? |
If yes, specify |
| Have policies for the use of IT tools been adopted? |
|
| Are portable devices (notebooks, smartphones, tablets) used for data processing? If yes, are there specific policies for these devices? |
If yes, specify |
| Is a backup procedure in place with at least weekly frequency? |
|
| Are removable media containing copies of data kept in locked archives or with systems that prevent unauthorized access? |
|
| Are backup media destroyed or reformatted when no longer used? |
|
| Have procedures been adopted to restore the availability of data and systems? |
|
| Is system maintenance entrusted to third parties? If yes, is there an updated register of authorized personnel with an indication of the interventions performed? |
If yes, specify |
| Indicate the security measures adopted for data processing carried out on behalf of the controller through electronic tools. |
|
11. IT authentication system
| Item / Question |
Response |
| Do users have personal authentication credentials (username and password) for system access? |
|
| Are passwords unique for each user and known only to the individual? |
|
| Have instructions been provided in writing to authorized personnel to ensure the secrecy of credentials and the custody of devices in exclusive use? |
|
| Describe the characteristics of the passwords (minimum length, complexity, expiration). |
|
| Are passwords changed upon first use and updated at least every six months (every three months for special categories of data)? |
|
| Is there a procedure for disabling credentials when an authorized person loses access rights? |
|
| Are instructions given not to leave the electronic tool unattended and accessible during the processing session? |
|
| In case of prolonged absence of the authorized person or urgent system interventions, are there written provisions defining how the controller can access data and tools? |
If yes, specify |
| Is there a copy of the authentication credentials entrusted in writing to a responsible custodian, with an obligation to promptly inform the authorized person of any access performed? |
|
12. System administrators
| Item / Question |
Response |
| Have system administrators been evaluated for experience, capability, and reliability, and designated in writing with an indication of their operational scope? |
|
| Are the identification details of system administrators and the list of assigned functions kept in an updated document? |
|
| Is the work of administrators subject to verification at least annually, to check compliance with the required security measures? |
|
| Is logical access logging performed for actions taken by system administrators? |
|
| Are access logs kept and constantly made available to the controller? |
|
13. Policies and procedures
| Item / Question |
Response |
| Is there a policy describing the IT incident response plan? |
If yes, provide evidence |
| Is there a procedure for the disposal and recycling of devices based on applicable standards? |
|
| Are procedures defined to manage the exercise of data subject rights provided by the GDPR (access, rectification, erasure, etc.) regarding processing entrusted to the supplier? |
|
| List the available procedures. |
|
14. Data Protection Officer (DPO)
| Item / Question |
Response |
| Has your company appointed a DPO? |
If yes, indicate name and contact details |
15. Data transfer
| Item / Question |
Response |
| Will your company process data outside the main establishment on behalf of the controller? |
|
| If yes, is the process managed in compliance with GDPR requirements? |
If yes, specify |
| In which data centers is the data stored? Specify: a) if they are owned by the supplier or third parties; b) if they are located in EU or non-EU countries. |
|
| In case of transfer to non-EU countries, indicate which countries and the legal basis for the transfer (Art. 44 GDPR). |
If applicable, specify |
| Does your company provide services in cloud mode for the service rendered? |
|
| If yes, is the process managed in compliance with GDPR requirements and the cloud computing guidelines of the Italian Data Protection Authority? |
If yes, specify |
| What security measures does the supplier adopt to protect data in the cloud? |
|
| Who is the actual provider of the cloud service acquired? Is it a single company or a consortium? |
|
| In case of internet connection interruption, is it possible to continue using the services without cloud access? |
|
| How long does it take to restore the system? Are there continuity plans for essential services? |
|
| In case of data recovery, in what format is it released? |
|
| Are there confidentiality guarantees in case a competitor shares the same cloud services? |
|
| In which State is the data stored? Is it possible to choose servers located exclusively in the national territory or in the European Union? |
|
| Is the cloud technology used proprietary? Can data be easily exported to other suppliers? |
|
| In case of data breach or loss, does the supplier guarantee compensation for damages? |
|
16. Certifications
| Item / Question |
Response |
| Is your company ISO/IEC 27001 certified or does it hold other relevant information security certifications? |
If yes, indicate the certifications held |
17. Secure software development (if applicable)
| Item / Question |
Response |
| Have the AGID secure software development guidelines been followed? |
If yes, indicate the latest version adopted |
| Have other secure development guidelines been adopted (e.g., OWASP)? |
If yes, indicate which ones and the reference version |
18. Essential cybersecurity controls
| Item / Question |
Response |
| DORA Applicability: Does your company operate in the financial or insurance sector, or provide ICT services (e.g., cloud, data analysis) to companies in these sectors? |
|
| NIS Applicability: Does your company operate in critical sectors (transport, banking, financial infrastructure) under the NIS 1 Directive, or as a digital provider, waste manager, postal service, or research organization under NIS 2? |
|
| Device and software inventory: Is an inventory of systems, software, devices, services, and applications in use within the company perimeter maintained and kept up to date? |
|
| Are third-party web services (social networks, cloud, email, etc.) to which you are registered limited to those strictly necessary? |
|
| Are critical information, data, and systems to be protected as a priority identified? |
|
| Has a contact person responsible for coordinating information and IT system management and protection activities been appointed? |
|
| Are cybersecurity-related regulations applicable to your organization identified and respected? |
|
| Malware protection: Are all devices that allow it equipped with regularly updated antivirus/antimalware software? |
|
| Password and account management: Are passwords different for each account, of adequate complexity, and is the use of two-factor authentication evaluated? |
|
| Does personnel authorized to access systems have personal, non-shared accounts? Are accounts no longer in use deactivated? |
|
| Can each user access only the information and systems within their competence (principle of least privilege)? |
|
| Training and awareness: Is personnel trained and made aware of cybersecurity risks and the safe use of company tools? |
|
| Is the configuration of systems and devices managed by expert personnel? Are default access credentials always replaced? |
|
| Are backups of critical information and data performed periodically? |
|
| Network protection: Are networks and systems protected from unauthorized access via firewalls or other anti-intrusion tools? |
|
| In case of an incident (detected attack, malware), are security managers informed and are systems secured by expert personnel? |
|
| Are all software in use (including firmware) updated to the latest version recommended by the manufacturer? Are obsolete devices and software decommissioned? |
|
19. Use of Artificial Intelligence
| Item / Question |
Response |
| Do you use algorithms or other forms of artificial intelligence? |
If yes, specify in which processes |
| Do you adopt a structured model for the management and monitoring of AI systems (AI Conformity Assessment)? |
|
| Has a Fundamental Rights Impact Assessment (FRIA) been conducted? |
|
20. Data Act
| Item / Question |
Response |
| Do you operate in the IoT sector or produce/distribute connected devices that generate data? |
|
| Do you use Privacy Preserving Technologies? |
If yes, indicate which ones |
21. Whistleblowing (Legislative Decree 24/2023)
| Item / Question |
Response |
| Is your company subject to the application of Legislative Decree 24/2023? |
|
| If yes, have the procedures provided by the Decree been adopted? |
If yes, specify |
Useful resources
- Risk Assessment — to structure a risk assessment that includes external suppliers and the supply chain.
- GDPR Compliance — to verify and maintain compliance with the European General Data Protection Regulation.
- ISO/IEC 27001 Compliance — to implement or maintain a certified information security management system.
Frequently Asked Questions
- Who must fill out this privacy due diligence checklist?
- The checklist is intended for the external supplier who will process personal data on behalf of the controller. It is the supplier’s responsibility to answer the questions and provide the requested evidence; the controller uses it to assess the level of compliance before formalizing the contractual relationship and the appointment as a data processor pursuant to Art. 28 GDPR.
- At what stage of the selection process should this due diligence be used?
- Ideally before signing the contract, during the supplier qualification phase. It is advisable to repeat it periodically — at least once a year — to verify that the supplier maintains the declared measures over time, in line with the provisions of Art. 28 GDPR.
- What should be done if the supplier is unable to answer some questions?
- Gaps in responses are themselves a risk indicator. The controller must evaluate the severity of the shortcomings relative to the type of data processed and decide whether to proceed with compensatory measures, request an adjustment plan with defined deadlines, or exclude the supplier from the selection.
Protect your organisation with Risk Assessment.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
Talk to an expert