Privacy
Checklist

Assess a processor

Review a provider before engagement and keep control of personal-data processing throughout the service relationship.

Checklist for selecting, contracting and monitoring processors for businesses operating in Austria.

External IT, cloud services, payroll, newsletter delivery, hosting and support may process personal data on behalf of your business. The provider’s contract label is not decisive. What matters is the actual data flow, the instructions and the decisions about the purpose and essential means of processing.

This checklist covers the review before engagement and when the service changes. It addresses role classification, provider selection, the Article 28 GDPR agreement, subprocessors, security measures, international data flows and ongoing evidence.

The checklist is limited to the data-protection review of a processor relationship. It does not replace a review of the specific agreement and technical and organisational measures, or an individual assessment of a complex provider model.

Work through the points using the actual service. The checked state is stored on your device. You can continue later, reset the list or print the checklist only.

0 of 41 points completed

01 Clarify the trigger and data flow

Start with the real processing activity, not with the provider’s template agreement.

02 Classify the role and instructions

The role follows the actual decisions about the purpose and essential means of processing.

03 Review the provider and its guarantees

Do not select a provider on price or features alone. Assess guarantees for secure and instruction-based processing.

04 Review the Article 28 GDPR agreement

The agreement must make processing controllable in practice, not merely repeat the heading processor agreement.

05 Review subprocessors and countries

Cloud and platform services require a traceable view of further providers and transfers.

06 Secure operations, incidents and rights

The arrangement must work when a data subject asks a question or a security incident occurs.

07 Maintain controls and evidence

The selection review does not end with signature. Changes in the service, data or risk must become visible.

08 Record the result and next steps

Close the review with a clear decision and a traceable plan for open points.

Legal framework

Article 28 GDPR requires a controller to use only processors that provide sufficient guarantees for appropriate technical and organisational measures. The agreement or other legal instrument must cover, among other things, the subject matter and duration, nature and purpose, data types, data-subject categories and the controller’s rights and duties. Instructions, confidentiality, security, assistance, deletion or return and audit rights must fit the actual processing.

Subprocessors are subject to separate authorisation and flow-down requirements. Article 32 GDPR is relevant to the security review. Section 48 of the Austrian Data Protection Act adds national requirements concerning processors and sufficient guarantees. These rules do not replace a concrete review of the service, data flows and technical implementation.

This checklist supports documentation of the review. It does not make a binding role determination or confirm that a particular agreement or security concept is sufficient in an individual case.

This is a first working basis. The depth of review depends on the processing, data, provider chain and risk.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich