4.4 Processor/Vendor Evaluation & Physical/Environmental Controls

Key Takeaways

  • Processor due diligence must occur before contract signing and cover security posture, sub-processor chain, cross-border transfer mechanism, and privacy track record
  • A Data Processing Agreement (DPA) or Article 28 Terms is legally required under GDPR Art. 28 and must specify purpose limitation, confidentiality, security, sub-processor rules, deletion, and audit rights
  • Post-Schrems II, restricted transfers to third countries require a transfer impact assessment (TIA) verifying the SCCs can be effectively enforced in the recipient jurisdiction
  • Physical controls — clean-desk, visitor access, media sanitization, device security, document retention and destruction — protect data that encryption cannot reach
  • Vendor risk and physical risk are assessed at the most appropriate functional level: procurement, internal audit, information security, physical security, or the DPA review
Last updated: August 2026

Two Risk Surfaces Outside the Controller's Direct Custody

Personal data does not stay inside the four walls of the organization. It moves to processors and third-party vendors (Domain III.B) and it lives in physical locations — data centers, offices, paper files, removable media, and end-user devices (Domain III.C). The CIPM Body of Knowledge treats these as a single competency cluster because the privacy manager must evaluate risk in both places where data resides outside direct application-layer controls.

III.B — Evaluating Processors and Third-Party Vendors

The Outsourcing Risk

Outsourcing processing shifts operational custody but not accountability. Under GDPR Art. 28, the controller remains responsible for the processor's compliance with the controller's instructions. Under CCPA/CPRA, service providers and contractors must be contractually bound to equivalent restrictions. Outsourcing introduces several specific risks:

  • Unauthorized use — the processor uses data for its own purposes beyond the controller's instructions.
  • Sub-processor sprawl — the processor engages sub-processors the controller never approved.
  • Cross-border exposure — data is moved to a jurisdiction without an adequate transfer mechanism.
  • Security failure — the processor's controls are weaker than the controller's, creating a weakest-link breach.
  • Concentration risk — many controllers depend on one processor (e.g., a single cloud region), creating systemic exposure.

Due Diligence Before Contract

Vendor due diligence should occur before contract signing, not after. A typical due-diligence package includes:

DimensionEvidence Requested
Security postureSOC 2 Type II report, ISO 27001 certificate, penetration test summary
Privacy programISO 27701 certificate, prior DPIAs, breach history
Sub-processor listNames, locations, functions, and sub-contract chain
Transfer mechanismSCCs, BCRs, adequacy reliance, or derogation justification
Personnel controlsBackground checks, training records, access reviews
Incident responseNotification SLA (≤ 24–48 hours), forensic capabilities
Financial viabilityAudit or credit signals indicating the vendor will persist for the contract term

The DPA / Article 28 Terms

A Data Processing Agreement (DPA) — also called Article 28 Terms — is mandatory under GDPR Art. 28(3) and must include, at minimum:

  • Subject matter and duration of processing.
  • Nature and purpose of processing.
  • Type of personal data and categories of data subjects.
  • Obligations and rights of the controller.
  • Processor obligations to: process only on documented instructions, ensure confidentiality of personnel, implement Art. 32 security, respect sub-processor conditions, assist with DSARs, assist with breach notification, assist with DPIAs, and delete or return data at end of service.
  • Audit rights — the controller's right to audit or commission audits of the processor.

The Accountability for Received Transfers (ART) clause added to the 2021 SCCs extends accountability downstream: the importer must pass equivalent obligations to any sub-importer, so the controller's reach follows the data.

Transfer Impact Assessments (TIAs)

After Schrems II (CJEU C-311/18), a controller relying on SCCs for a transfer to a third country must perform a Transfer Impact Assessment (TIA) to verify the SCCs can be effectively enforced in the recipient jurisdiction. A TIA examines:

  1. The data and transfer specifics (what data, which importer, which destination).
  2. The legal regime of the destination country — particularly government surveillance laws (e.g., US FISA 702, EO 12333).
  3. Whether the SCCs can be enforced in practice — are there supplementary measures (encryption with controller-held keys, pseudonymization, contractual transparency) needed?
  4. A documented conclusion on whether the transfer can proceed or must be suspended.

The US-EU Data Privacy Framework (DPF), adopted in 2023, provides an adequacy route for certified US companies, but transfers to non-certified importers still require SCCs plus a TIA.

Functional-Level Assessment

The Body of Knowledge stresses that processor risk is assessed at the most appropriate functional level, not always by the privacy team alone:

  • Procurement — commercial terms, vendor viability, contract execution.
  • Information security — technical security review, penetration test findings, access model.
  • Internal audit — independent assurance over the vendor's control environment.
  • Physical security — on-site inspection for data-center or paper-handling vendors.
  • DPA review — privacy counsel and the DPO confirm Art. 28 terms and transfer mechanism.

Ongoing Monitoring

Due diligence is a snapshot; monitoring is continuous. Mature programs:

  • Review SOC 2 reports annually and track any qualified opinions.
  • Reconcile the sub-processor list quarterly against notifications received.
  • Re-test the TIA on material legal changes (new surveillance law, invalidated adequacy).
  • Track vendor incidents against the DPA's notification SLA.
  • Offboard vendors with a verified deletion certificate at contract end.

III.C — Physical and Environmental Controls

Personal data often exists in forms encryption cannot protect: paper files, whiteboards, removable media, and even spoken conversations. Physical and environmental controls close that gap.

Physical Control Categories

ControlPurposeCommon Implementation
Clean-desk policyPrevent casual exposure of paper and screensLocked drawers, automatic screen lock, no sticky notes with passwords
Visitor accessLimit unauthorized physical accessSign-in logs, escorts, badge expiry, restricted zones
Media sanitization & disposalPrevent data recovery from retired mediaNIST 800-88 guidelines — Clear, Purge, Destroy; certificate of destruction
Document retention & destructionEnforce storage limitation on paperLocked retention cabinets, scheduled shredding, secure-destruction vendor
Device securityProtect laptops, phones, and removable mediaFull-disk encryption, MDM, cable locks, remote wipe, USB port control
Environmental controlsProtect data center and office integrityFire suppression, HVAC, flood detection, UPS/generator power
Data center controlsRestrict physical access to serversBiometric access, mantraps, CCTV, 24/7 staffing, dual control

Operational Risks of Physical Locations

A privacy manager should walk through each physical location where personal data is handled and ask what could go wrong:

  • Data center — fire, flood, power loss, or unauthorized rack access could destroy or expose data.
  • Open-plan office — overheard conversations, shoulder-surfing, unattended printouts.
  • Home office (post-pandemic norm) — family members, shared devices, unshredded printouts in household waste.
  • Paper records archive — uncontrolled retention, rodent/water damage, unauthorized browsing.
  • Removable media — lost USB drives, unencrypted backups leaving the building.

Worked Scenario: Cloud CRM with Paper Onboarding

A financial services firm onboards clients through a paper application form that is later scanned into a cloud CRM. The privacy team's vendor evaluation confirms the CRM provider is ISO 27701 certified, signs a DPA with an ART clause, and relies on SCCs plus a TIA showing the US importer is DPF-certified. The physical controls review, however, finds branch offices have no clean-desk policy, printouts sit in trays overnight, and the shredding vendor has not provided a destruction certificate in 18 months. The gap analysis records: (1) a High compliance gap — DPA lacks audit rights (Art. 28(3)(h)); (2) a High risk gap — no clean-desk or locked-storage policy for paper containing financial data; (3) a Medium risk gap — shredding vendor unverified. The program roadmap funds a clean-desk rollout, a locked-storage procurement, and a DPA amendment adding audit rights within 60 days.

Why Both Surfaces Matter Together

A controller can have a flawless DPA and still suffer a breach because a branch office left printouts on a desk. Conversely, rigorous clean-desk discipline cannot rescue a processor relationship without a transfer impact assessment. The privacy manager must hold both surfaces to the same standard: documented requirements, scored gaps, and verified closure.

Test Your Knowledge

After Schrems II, a controller transfers EU personal data to a US processor that is NOT certified under the Data Privacy Framework and relies on the 2021 Standard Contractual Clauses. What additional step must the controller complete before the transfer can lawfully proceed?

A
B
C
D
Test Your Knowledge

A privacy manager is evaluating a vendor that will process personal data on the controller's behalf. Which functional level is most appropriate for reviewing the vendor's SOC 2 Type II report and access-control model?

A
B
C
D
Test Your Knowledge

Which physical control most directly prevents recovery of personal data from a laptop hard drive that is being retired?

A
B
C
D