Your suppliers work with your data, and you remain responsible for it. The GDPR requires you to choose processors that can protect personal data. If your organisation falls under NIS2, you must also manage the security risks in your supply chain. If you use a supplier's AI system, the EU AI Act places its own obligations on you. We assess the supplier on all three and ask for evidence to back up what they claim.
What we check
Privacy
- The data processing agreement, the sub-processors the supplier uses and the location where your data is stored
- The retention periods, the way the supplier deletes data and the deadline for notifying you of a data breach
Security
- The ISO 27001 or SOC 2 certificate: we verify it with the issuing body and check whether its scope covers your service
- The staff and systems with access to your data, and the way the supplier manages that access
- Encryption and backups
- The process the supplier uses to find and fix vulnerabilities, and its approach to incidents
Responsible AI
- The AI features in the service, where your data goes when you use them, and whether the supplier uses your data to train models
- The system's risk class under the EU AI Act and your obligations as a user
What you receive
- A written report with our verdict: go ahead, go ahead with conditions, or stop
- The risks in order of severity, each with a concrete step you can require from the supplier
- Contract points you can negotiate
How it works
- You order the check and tell us which supplier and which service it concerns.
- We ask the supplier for evidence. If they refuse to share it, we note that in the report.
- We review the documents, the contract and public information. Where needed, we talk to the supplier.
Je dynamische Snippet wordt hier weergegeven...
Dit bericht wordt weergegeven omdat je niet zowel een filter als een sjabloon hebt opgegeven om te gebruiken.