GDPR Processor Assessments: what to ask software suppliers, and what evidence to collect

What Article 28 actually requires, the eight areas to verify, and how to keep the assessment defensible.

Regulatory Frameworks 9 min read

What is it?

Under the EU General Data Protection Regulation, when your organisation (the controller) engages a supplier to process personal data on its behalf, that supplier is a processor. Before engagement, and periodically afterwards, the controller is required to assess the processor's ability to meet its GDPR obligations. That assessment is the GDPR processor assessment.

Why does it matter?

GDPR Article 28 makes controllers responsible for processor selection. If a processor mishandles personal data, the controller is on the hook — supervisory authorities have fined controllers for weak processor oversight even where the incident originated at the processor. A defensible processor assessment is the evidence that oversight actually happened.

Common challenges

  • Treating the Data Processing Agreement as the entire assessment — a signed contract is a starting point, not proof of capability.
  • Missing the sub-processor chain — the processor's own processors are also in scope.
  • No mechanism to track processor changes (new sub-processors, transfer mechanism updates, security posture changes).
  • Assessment scope drifts between controllers, making findings hard to compare across the vendor portfolio over time.

Best practice

A GDPR-focused processor assessment should verify, with evidence:

  1. Role clarity — controller/processor status agreed and reflected in the contract.
  2. DPA in place — Article 28-aligned processing terms, with genuine review of the specific clauses (not just "we have a DPA").
  3. Sub-processors — an up-to-date list, a notification mechanism, and the controller's right to object.
  4. Transfer mechanisms — SCCs, adequacy decisions or approved alternatives where personal data leaves the EEA.
  5. Security of processing — technical and organisational measures appropriate to the data and the risk.
  6. Data subject rights — the processor's ability to assist with access, deletion and portability requests within GDPR timelines.
  7. Breach notification — timelines and contact points that support the controller's 72-hour obligation.
  8. Records — evidence the controller can produce to a supervisory authority on request.

How Governly supports this area

The Governly Recommended Enterprise Baseline includes a GDPR processor requirement set that maps directly to the areas above. Suppliers upload DPAs, sub-processor lists and security documentation; Governly maps that evidence to each requirement and produces a traceable record of the assessment that a controller can retrieve and reference later.

Put this into practice

Governly applies the Requirements-to-Evidence Mapping methodology to your own vendors. Start from the Recommended Enterprise Baseline, upload your own requirements, or build from scratch — then add the vendor documents and receive a traceable due diligence report.