The buyer's GDPR obligations - Operational checklist
Objective: Have a complete and actionable checklist of GDPR obligations that the buyer must verify and implement for every supplier contract involving personal data.
As a data controller, the buyer is the ultimate guarantor of GDPR compliance for personal data entrusted to suppliers. This checklist guides you through the key steps at each phase of the procurement cycle.
📋 Phase 1: Pre-contractualisation (Due Diligence)
- ☐ Identify the personal data involved in the contract (contacts, HR data, customer data, browsing data...)
- ☐ Qualify the supplier's GDPR role: processor, joint controller, or independent controller?
- ☐ Verify data location: EU/EEA hosting or transfer outside the EU? If outside the EU, verify safeguards (DPF, SCCs, BCRs)
- ☐ Audit the supplier's GDPR maturity: security policy, certifications (ISO 27001, SOC 2), breach history
- ☐ Identify sub-processors used by the supplier and their locations
- ☐ Assess the need for a DPIA (Art. 35): large-scale processing, profiling, sensitive data?
📋 Phase 2: Contractualisation (DPA & Clauses)
- ☐ Draft or validate the DPA (Data Processing Agreement) compliant with Art. 28.3 GDPR
- ☐ Define authorised processing: nature, purpose, duration, categories of data and data subjects
- ☐ Require processing on documented instructions only
- ☐ Require confidentiality from persons with access to the data (written commitment)
- ☐ Detail security measures (Art. 32): encryption, pseudonymisation, access controls, backups
- ☐ Govern sub-processing: prior written consent, notification of changes, flow-down of obligations
- ☐ Provide for assistance with data subject rights (access, rectification, erasure, portability)
- ☐ Impose a breach notification deadline: 24 hours contractually recommended
- ☐ Provide for data fate at end of contract: return + secure deletion with certificate
- ☐ Include audit rights: on-site or remote audit, with reasonable notice
📋 Phase 3: Contract performance (Ongoing monitoring)
- ☐ Update the record of processing activities (Art. 30) to include processing entrusted to the supplier
- ☐ Periodically verify the supplier's compliance (annual questionnaire, audit, certification)
- ☐ Monitor changes to the supplier's sub-processors
- ☐ Document instructions given to the supplier regarding data processing
- ☐ Handle data subject rights requests (with the supplier's assistance)
- ☐ Test the breach notification process (simulation exercise recommended)
📋 Phase 4: End of contract (Reversibility)
- ☐ Require complete return of data in a usable format
- ☐ Obtain a certificate of secure deletion of all copies
- ☐ Verify deletion at sub-processors
- ☐ Archive the DPA and compliance evidence (recommended retention period: 5 years)
- ☐ Update the record of processing activities to reflect the end of the contract
Practical case - GDPR onboarding of a SaaS supplier
A buyer selects a new SaaS CRM (hosted by AWS in Ireland and the United States). Here is how to apply the checklist:
- ✅ Data identified: names, emails, phone numbers of customer and supplier contacts
- ✅ Role: The SaaS is a processor within the meaning of Art. 28
- ⚠️ Transfer outside the EU: Data replicated to the US → verify the supplier is certified under the EU-US DPF or that SCCs are in place
- ✅ DPA: Use the supplier's standard DPA as a starting point, but negotiate key points (notification deadline, audit rights, hosting location)
- ✅ Sub-processors: Require the full list and a notification mechanism in case of changes
- ⚠️ DPIA: Probably required if the CRM performs scoring or profiling of contacts
💡 Key takeaway: The GDPR makes the buyer the ultimate party responsible for the compliance of personal data entrusted to its suppliers. This responsibility cannot be delegated by contract - it is mandatory public policy. Use this checklist as a systematic tool for every sourcing project involving personal data.