Data processing and service provider reviews.
When providers process personal data on your behalf, responsibilities, safeguards and contractual terms must be clearly defined.
What matters now.
This includes IT support, cloud and hosting, newsletters, payroll, support systems, disposal services, SaaS and many other outsourced activities.
SITsolutions supports the review, assessment and documentation of processing arrangements under the GDPR.
Need a clearer picture? We consider your current position and the requirements that actually apply.
How we help
Support that moves you forward.
The scope depends on your objectives, organisation and existing arrangements.
Reviewing existing data processing agreements
Assessing new providers before engagement
Reviewing technical and organisational measures
Assessing subprocessors and data locations
Assessing international data transfers
Preparing review records and decision papers
Supporting provider questionnaires and evidence
Your outcomes
Results you can put to work.
We focus on records and decisions that are useful internally and clear to external reviewers.
- Data processing agreement review
- Assessment of technical and organisational measures
- Pre-engagement provider assessment
- Subprocessor overview
- International data transfer assessment
- Processing and provider register
Our approach
A clear path, step by step.
- 01
Record
Identify provider, service, data, purposes, systems and records.
- 02
Review
Assess contracts, safeguards, subprocessors, locations and support services.
- 03
Assess
Document risks, gaps and required improvements.
- 04
Document
Prepare review records, action lists and decision papers.
Next step
What does your situation look like?
Together, we clarify your needs, priorities and a realistic next step.
Arrange a conversation