Can we share customer data with this supplier?
A customer-support provider processing personal data on our behalf.
Review pending. A required contract clause is missing, and security safeguards still need to be verified.
Requirements checked Open a finding to follow its evidence trail
Use data only as instructedThe agreement includes this restriction. Met
-
The agreement must limit processing to documented instructions, subject to applicable legal exceptions.
- Evidence foundCustomer Data Processing Agreement.pdf
Clause 3.2 · Processing instructions · page 4
“The Provider will process Customer Data only on documented instructions from the Customer, except where required by applicable law.”
- Baselex assessmentMet
The clause limits processing to documented instructions and includes the applicable-law exception.
Delete or return data when the service endsThe required clause is missing. Not met
-
The agreement must provide for deletion or return of personal data at the customer’s choice when the service ends, and deletion of copies unless EU or Member State law requires storage.
- Evidence foundCustomer Data Processing Agreement.pdf
Section 12 · Termination and retention · pages 14 and 15
“The Provider may retain service records in line with its retention policy.”
- Baselex assessmentNot met
The section gives the customer no choice to delete or return personal data and does not address existing copies.
Appropriate security safeguardsEvidence of safeguards has not been supplied. Need evidence
-
The provider must offer sufficient guarantees and use security measures appropriate to the risks of the processing.
- Evidence foundSupplier evidence folder
Security safeguards · no file supplied
No security policy, control summary or certification was available to check.
- Baselex assessmentNeed evidence
This requirement cannot yet be verified because the supporting security evidence is missing.
What happens next?
Add the missing clause and obtain the security evidence. Agents recheck the findings; any required human approval still applies.
Real GDPR requirements; fictional documents and findings. Selected processor checks, not a full GDPR assessment or approval to share data. Read the EDPB guidance (opens in a new tab).