External parties and transfers

Review a processor, recipient or transfer relationship

Reassess an external relationship on schedule or on event, and update the approval, the agreement, the transfers, the controls and the linked activities from the findings.

A processor approved two years ago may no longer hold the certifications it once did, or may have changed its own subprocessing arrangements without prompting a fresh look. A scheduled or event driven review is how that drift is caught.

This is exercised through the audit and review register, kept against the entity and the agreement so the review's findings are traceable to the relationship they concern, and can trigger revisions elsewhere.

The proof is that a review past its due date is reported, and that even a review finding nothing wrong still leaves a dated record behind it.

Regulation
Articles 24, 28, 32 and 44
Registers
Audit and review · Entity · Agreement · Transfer record · Risk
The audit and review register, where the relationship is reassessed.
The audit and review register, where the relationship is reassessed.

The steps

  1. 01Open the Audit and review register and use the plus button beside the register title to create the review.
  2. 02State the trigger for the review, scheduled or event driven, on the Details tab.
  3. 03Open the Linked records band and use "Link a record" to attach the entity and the agreement under review.
  4. 04Record the findings on the Details tab.
  5. 05Where findings require it, open the Privacy actions register to raise actions, or open the transfer record to revise it.
  6. 06Move the review from Open to Closed on the lifecycle bar, with the date.
The entity under review, linked to its agreement and transfers.
The entity under review, linked to its agreement and transfers.

Accepted when

  • A review past its due date is reported.
  • Findings that change nothing still leave a dated record.

Documents that carry the evidence

DPA · Data processing agreement
The processor contract, with the instructions, confidentiality, security, subprocessing, assistance, return and audit terms Article 28(3) requires.
TIA · Transfer impact assessment
The assessment of the destination, the safeguard relied upon and the supplementary measures applied to a transfer. Articles 44 and 46.

These templates are issued when the register opens, so the document exists before the record that cites it.