Standard: Supplier and transfer transparency
Status: Register required for each active service and Client project

Scope: The supplier used can vary by feature. The applicable project notice or agreement should identify the relevant category, purpose, location, transfer safeguard and deletion setting.

1. Register fields

FieldWhat to record
Supplier and serviceLegal name, service function, account owner and approved use.
Data and purposeCategories processed, purpose, frequency, sensitivity and whether the supplier receives raw or minimised data.
Location and transferProcessing locations, sub-processors, adequacy position or other lawful transfer safeguard.
Contract and securityDPA or equivalent terms, confidentiality, access controls, incident support and deletion/return capability.
ReviewApproval date, next review date, risk owner and offboarding plan.

2. Minimisation requirements

Before sending data to a supplier, the project owner should ask whether the feature can operate with a coarse location, redacted receipt, pseudonymous identifier, shorter retention period or manual alternative. Supplier convenience is not by itself a sufficient reason to send more personal data than the purpose requires.

3. Client transparency

Clients should receive the supplier categories relevant to their project and a route to ask for further information. Where a Client acts as controller, the project agreement should identify who approves suppliers and who responds to data subject requests or incidents.

Related information: Governance Centre · Privacy Policy · Contact ClueCheck