Making third-party processing visible and accountable
Standard: Supplier and transfer transparency
Status: Register required for each active service and Client project
| Field | What to record |
|---|---|
| Supplier and service | Legal name, service function, account owner and approved use. |
| Data and purpose | Categories processed, purpose, frequency, sensitivity and whether the supplier receives raw or minimised data. |
| Location and transfer | Processing locations, sub-processors, adequacy position or other lawful transfer safeguard. |
| Contract and security | DPA or equivalent terms, confidentiality, access controls, incident support and deletion/return capability. |
| Review | Approval date, next review date, risk owner and offboarding plan. |
Before sending data to a supplier, the project owner should ask whether the feature can operate with a coarse location, redacted receipt, pseudonymous identifier, shorter retention period or manual alternative. Supplier convenience is not by itself a sufficient reason to send more personal data than the purpose requires.
Clients should receive the supplier categories relevant to their project and a route to ask for further information. Where a Client acts as controller, the project agreement should identify who approves suppliers and who responds to data subject requests or incidents.
Related information: Governance Centre · Privacy Policy · Contact ClueCheck