GDPR, data processing addenda, sub-processors, and transfer mechanisms — the compliance obligations that ride along with every vendor contract, and the checks we run before approving one.
1 article
April 10, 2026·8 min
Article 28 isn't optional. Here's the eight-point checklist we run on every vendor's DPA before approving a contract — sub-processor lists, transfer mechanisms, audit rights, and the rest.