Personal data is processed not only within an organization but also through external vendors. Data processors such as cloud providers, call centers, marketing tools, and accounting software are among the most critical links in your compliance chain. Under the KVKK, as a data controller you are also responsible for the compliance of the processors you choose. Vendor Risk Management (VRM) is the way to address this risk systematically.
Distinguishing Data Controller from Data Processor
The foundation of VRM is correctly establishing the distinction between roles. The data controller is the party that determines the purposes and means of processing personal data. The data processor is the party that processes data on behalf of, and on the instructions of, the data controller. Correctly identifying which role a vendor holds determines the due diligence and contractual obligations that apply to it.
Due Diligence in Vendor Selection
Before you start working with a vendor, you need to assess its data-protection maturity. Due diligence is the process of gathering and evaluating information before a contract is signed.
- Clarify which personal data the vendor will access and where it will process it.
- Question the technical and organizational security measures it applies.
- Request any certifications, audit reports, and policies it holds.
- Find out whether data will be transferred abroad and whether sub-processors are used.
- Assess past data-breach experience and incident-response capability.
Risk Assessment and Classification
Not every vendor carries the same level of risk. Classifying vendors according to the sensitivity and volume of the data they process lets you concentrate your effort where it matters. The table below is an example of a simple risk tiering.
| Risk Level | Example Vendor Profile | Expected Control Intensity |
|---|---|---|
| Medium | Operational tools accessing limited personal data | Standard due diligence, contract, periodic review |
| Low | No access to personal data, or very limited | Basic control and inventory record |
Data Processor Contracts
Once due diligence is complete, the framework of the relationship should be secured with a written contract. A data processor contract clearly defines the parties' obligations and how the data will be processed. A good contract usually includes the following elements:
- The purpose, scope, duration, and data categories of the processing.
- The processor's commitment to act only on the data controller's instructions.
- The technical and organizational security measures to be applied.
- Confidentiality obligations and the commitment of personnel.
- The conditions for using sub-processors and the approval mechanism.
- The obligation and timeframes for notification in the event of a data breach.
- The return or destruction of data when the relationship ends.
The Sub-Processor Chain
A vendor often uses its own vendors as well; for example, a SaaS provider may host its infrastructure on a cloud provider. This sub-processor chain means your data reaches points you do not directly see. To make the chain visible, request a sub-processor list from your vendor, and secure in the contract the right to be informed when a new sub-processor is added and, if necessary, the right to object.
Ongoing Monitoring
VRM is not a one-time check but an ongoing process. A vendor's risk profile can change even after the relationship begins. Establish a regular rhythm for ongoing monitoring.
- Periodically re-assess vendors according to their risk level.
- Update security measures and certifications at contract-renewal periods.
- Track and evaluate new sub-processor notifications.
- Integrate vendor-originated data breaches into your incident-response process.
- Terminate the access and data of inactive vendors.
Example Scenario
A retail company decides to use cloud-based call-center software for its customer-support processes. The compliance team first determines that the vendor is in the data-processor role and starts a due diligence process: it questions which customer data the software will access, where the data is hosted, and which sub-processors are used. As a result of the assessment, it places the vendor in the high-risk class, because large-volume customer communication data is processed. It then signs a data processor contract covering security measures, the sub-processor notification mechanism, and breach-notification timeframes. After the relationship begins, it re-assesses the vendor annually and monitors new sub-processor notifications. In this way, it incorporates an externally sourced service into its operation without breaking the compliance chain.
Frequently Asked Questions
If my vendor is non-compliant, is the responsibility mine?
As the data controller, you are primarily responsible for the processing activity as a whole and are obliged to ensure that the processor you choose takes appropriate security measures. For this reason, the due diligence, contract, and monitoring steps both reduce risk and document that you exercised the required care.
Do I have to conduct the same depth of review for every vendor?
No. It is more efficient to scale the depth of the review in proportion to the sensitivity and volume of the data the vendor processes. Apply deep review to high-risk vendors and basic control to low-risk ones.
Do I also have to track sub-processors?
Yes, because your data moves along this chain. Even if you do not contract directly with the sub-processor, you should keep the chain visible by requesting a sub-processor list and change notifications from your main vendor.
Is signing a contract enough on its own?
No. A contract is necessary but not sufficient. You need to verify through ongoing monitoring that the commitments in the contract are met in practice, and to review the risk profile of the relationship regularly.
This content is for general informational purposes only and does not constitute legal advice.
To manage your vendor inventory, risk classes, data processor contracts, and sub-processor chain from a single place, request a JUS. demo.