Skip to main content
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

Procurement Policy Support

Save risks, costs, and workload! Don't put yourself and your data subjects at risk! Update your procurement policy by requesting your service providers to be GDPR-certified.

GDPR Obligations and Liability for Service Providers

Under Art. 28 GDPR, private and public entities are liable and accountable for the GDPR breaches made by their data processors, except if the latter are GDPR-certified:

"Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject."

In consequence, it is their responsibility to monitor and prove that their processors are fully GDPR compliant. Fortunately, the same article also recognises that an approved GDPR certification can be used to demonstrate sufficient guarantees.

Impact of Processor Certification on the Data Controller

Service provider:If uncertifiedIf GDPR certified
Liability & legal risksFullReduced
Compliance monitoring workloadFullReduced
Due diligence costsFullReduced
Financial risks under Art. 83 GDPRFullReduced

Procurement Policy Strategy

While you can use certification to demonstrate your own GDPR compliance, requesting your service providers to be GDPR-certified is a no brainer. It substantially reduces your risks, costs and workload. The recommended strategy consists in:

  1. Contact your procurement team to inform them on the opportunity to reduce risks, costs, and workload for your organization.
  2. Update the procurement policy by integrating GDPR-certification as a new factor in the selection process of service providers that are receiving any personal data. You can include it as a weighted factor for a transition period of 24 months, followed by a mandatory requirement after this period.
  3. Inform your service provider about your new policy and invite them to request a GDPR certification.

Support Programme for Procurement Policy Optimization

ECCP provides free online resources to all organizations that are updating their procurement policies. In addition, a special support programme is available to companies with a large number of data processors. Any company that has a procurement programme with more than 20 data processors and a procurement budget of over 10 Million Euros can apply to our Support Programme for Procurement Policy Optimization. Selected applicants receive personalized live support for optimizing their procurement policy, as well as a Welcome Pack for free. Apply to the Support Programme.

Template Clauses

DPO Message to the procurement team

"Dear procurement team,
Under the GDPR, our organization is exposed to major and unnecessary risks, costs, and workload when using service providers that are not GDPR-certified. We invite you to update the selection criteria applied to our service providers by including the GDPR certification as a key requirement. We suggest to apply a transition phase of 24 months during which it will be a weighted criterion, before turning it into a mandatory requirement. This adaptation will contribute to reduce the risks, compliance monitoring costs, and workload for our organization.

We remain available to further explain and discuss this topic.

Sincerely,
The DPO Team"

Standard Procurement Clause

"To minimize the risks of GDPR non-compliance, service providers who are processing personal data shared by us are encouraged to demonstrate the full GDPR-compliance of their service offering by means of a GDPR certification. Such certification will be recognized as a strong advantage and competitive advantage in the selection process. By [add a date in 24 months or more], GDPR-certification is expected to become a mandatory requirement."

Message to Service Providers

"Dear Service Provider and Data Processor,
Our organization takes personal data protection and its GDPR obligations at heart and very seriously. We would like to inform you that we have decided to update our procurement policy.

Under Art. 28 GDPR, data controllers are exposed to risks and liability in case of non-compliance by their data processors. In order to mitigate our risks, we encourage our service providers to demonstrate full GDPR-compliance of their service offering by means of a GDPR certification. Such certification will be recognized as a strong competitive advantage in the selection process of our service providers and data processors.

At a later stage, in 24 months, GDPR-certification is expected to become a mandatory requirement for our procurement policy.

While such GDPR certification is likely to require some effort from our partners, we are confident that it will also constitute a strong competitive advantage for them towards other B2B partners and clients, and may enable them to gain new market shares.

You will find more information on GDPR certification online, for instance at gdprcertification.com and europrivacy.com.

Sincerely,
The Procurement Team"

Useful Actions and Resources