Assess a processor
Review a provider before engagement and keep control of personal-data processing throughout the service relationship.
Checklist for selecting, contracting and monitoring processors for businesses operating in Austria.
External IT, cloud services, payroll, newsletter delivery, hosting and support may process personal data on behalf of your business. The provider’s contract label is not decisive. What matters is the actual data flow, the instructions and the decisions about the purpose and essential means of processing.
This checklist covers the review before engagement and when the service changes. It addresses role classification, provider selection, the Article 28 GDPR agreement, subprocessors, security measures, international data flows and ongoing evidence.
The checklist is limited to the data-protection review of a processor relationship. It does not replace a review of the specific agreement and technical and organisational measures, or an individual assessment of a complex provider model.
Work through the points using the actual service. The checked state is stored on your device. You can continue later, reset the list or print the checklist only.
0 of 41 points completed
01 Clarify the trigger and data flow
Start with the real processing activity, not with the provider’s template agreement.
02 Classify the role and instructions
The role follows the actual decisions about the purpose and essential means of processing.
03 Review the provider and its guarantees
Do not select a provider on price or features alone. Assess guarantees for secure and instruction-based processing.
04 Review the Article 28 GDPR agreement
The agreement must make processing controllable in practice, not merely repeat the heading processor agreement.
05 Review subprocessors and countries
Cloud and platform services require a traceable view of further providers and transfers.
06 Secure operations, incidents and rights
The arrangement must work when a data subject asks a question or a security incident occurs.
07 Maintain controls and evidence
The selection review does not end with signature. Changes in the service, data or risk must become visible.
08 Record the result and next steps
Close the review with a clear decision and a traceable plan for open points.
Legal framework
Article 28 GDPR requires a controller to use only processors that provide sufficient guarantees for appropriate technical and organisational measures. The agreement or other legal instrument must cover, among other things, the subject matter and duration, nature and purpose, data types, data-subject categories and the controller’s rights and duties. Instructions, confidentiality, security, assistance, deletion or return and audit rights must fit the actual processing.
Subprocessors are subject to separate authorisation and flow-down requirements. Article 32 GDPR is relevant to the security review. Section 48 of the Austrian Data Protection Act adds national requirements concerning processors and sufficient guarantees. These rules do not replace a concrete review of the service, data flows and technical implementation.
This checklist supports documentation of the review. It does not make a binding role determination or confirm that a particular agreement or security concept is sufficient in an individual case.
This is a first working basis. The depth of review depends on the processing, data, provider chain and risk.
Connect role, agreement and governance
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000